How to Write a Review Response Policy (Template)
A review response policy sets who replies to reviews, how fast, in what tone, and what must never be said. Here's what to include, plus a template outline you can adapt.
A review response policy is a short internal document that sets out who replies to online reviews, who approves replies, how quickly you respond, what tone to use, what must never be said, and when a review gets escalated to management, legal or a crisis team. A useful one fits on two or three pages and is specific enough that a new manager could follow it on their first day.
Without one, replies depend on whoever happens to have the login and whatever mood they’re in. That is how businesses end up with a defensive reply going viral, or a patient’s diagnosis mentioned in public.
Who needs a review response policy
Any business where more than one person can reply to reviews benefits from writing the rules down. It matters most if you:
- Have several locations, managers or franchisees replying under the same brand.
- Work in a regulated or confidential field, such as healthcare, law, finance or education.
- Use an agency, a virtual assistant or software to draft replies.
- Have had a reply go wrong before.
A solo business owner doesn’t need a formal document, but the sections below still work as a checklist.
What to include in a review response policy
1. Scope
List the platforms the policy covers: Google, Yelp, Facebook, industry sites, app stores, employer review sites. State whether it also covers social media comments and direct messages, or whether those sit under a separate social media policy.
2. Who responds
Name roles, not people, so the policy survives staff changes. For example: “Location managers reply to reviews for their location. The marketing lead replies to reviews on national platforms.” Say who covers when that person is away, and make clear that employees who aren’t authorized should never reply from personal or business accounts. On Google, give each reply author their own manager access rather than a shared login; our guide on responding to Google reviews explains the profile roles.
3. Approval levels
Not every reply needs sign-off. Tie approval to risk:
- No approval needed: positive reviews and routine negative reviews using the standard structure.
- Manager approval: reviews that mention a staff member by name, dispute facts, or involve a refund or complaint in progress.
- Senior or legal review: reviews that allege discrimination, injury, illegal activity or safety problems, threaten legal action, or come from a journalist or regulator.
4. Response times
Set targets your team can actually meet. A common standard is one to two business days for negative reviews and within a week for positive ones. Escalated reviews can take longer, but should get an acknowledgment first if the delay will be significant. Say what happens on weekends and holidays.
5. Tone and structure
Describe your voice in a sentence or two (“warm, direct, no jargon”), then give the basic structure for replies: acknowledge the specific issue, take responsibility for what’s yours, add brief context if it helps readers, and offer a direct next step. Our guide on responding to negative reviews explains that structure in detail. Require replies to be signed with a first name and role, and ban copy-paste replies.
6. What never to say
This is the section that prevents the most damage. At a minimum, replies must never:
- Share private details about the customer: order history, account details, appointment dates, or anything they didn’t mention themselves.
- Confirm that someone is a client or patient where your industry treats that as confidential.
- Name, blame or discuss discipline of employees.
- Accuse the reviewer of lying, or speculate about who they are.
- Threaten legal action.
- Offer anything in exchange for changing or removing a review.
- Admit legal liability in matters that may become claims.
7. Industry confidentiality rules
If you work in a regulated field, spell out the rules in plain language and have your compliance lead or counsel review this section. In general terms:
- Healthcare: HIPAA means providers must not confirm someone is a patient or disclose health information in a reply, even if the patient disclosed it first. See our page on healthcare reputation management.
- Law firms: attorney confidentiality rules limit what a lawyer can reveal about a client, including in response to criticism. See law firm reputation management.
- Financial services: privacy rules such as those under the Gramm-Leach-Bliley Act (GLBA) restrict sharing customers’ nonpublic personal information, and advisors have their own advertising and testimonial rules.
- Schools: FERPA protects the privacy of student education records, so replies shouldn’t discuss a student’s records or circumstances.
The safe pattern in all of these is the same: speak about your policies and standards in general terms, and take specifics offline.
8. Escalation
Define what triggers escalation and to whom. Typical triggers are reviews that allege a safety issue, discrimination, a data breach or criminal conduct; reviews from media; a sudden spike of negative reviews; and anything involving threats. Say who gets notified, how (a named channel or phone number, not “email someone”), and that nobody replies until the escalation owner decides. If a review signals a wider crisis, the policy should hand off to your crisis communication plan.
9. Reporting reviews that break platform rules
State who is allowed to flag reviews and on what grounds: fake reviews, conflicts of interest, harassment, hate speech, personal information, off-topic content. Require that the reason be recorded. Make clear that negative but genuine reviews are not reported, and that nobody may ask friends, staff or customers to flag reviews on the business’s behalf.
10. Review requests and incentives
Your response policy is a natural home for the rules on asking for reviews, because the same people handle both:
- Ask every customer the same way; no filtering out unhappy ones first.
- No incentives in exchange for reviews, and never anything conditioned on a positive review. The FTC’s 2024 rule on consumer reviews prohibits incentives conditioned on sentiment, and Google’s policies prohibit incentives for reviews altogether.
- Employees and their families don’t review the business or competitors.
11. Record keeping
Decide what gets logged: escalated reviews, reported reviews and the outcome, replies that were edited or removed, and any contact with reviewers offline. A shared spreadsheet or your review software’s notes field is enough. Records help with training, with spotting patterns in complaints, and if a dispute ever reaches a lawyer or regulator.
12. Training and review
Say who trains new staff on the policy and how often the policy itself is reviewed, at least once a year and after any incident. Our guide on training staff on online reviews covers the training side.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditReview response policy template outline
Use this as a starting structure. Replace the examples with your own roles, platforms and standards.
| Section | What to write | Example |
|---|---|---|
| Purpose | One or two sentences on why the policy exists | “To make sure every review gets a timely, honest and compliant reply.” |
| Scope | Platforms and channels covered | Google, Yelp, Facebook, industry directories |
| Owners | Roles that reply, and backups | Location manager; assistant manager as backup |
| Approval levels | Which reviews need sign-off, and from whom | Named staff: manager. Legal allegations: owner and counsel. |
| Response times | Targets by review type | Negative: within two business days. Positive: within a week. |
| Tone and structure | Voice and reply structure | Acknowledge, own it, context, next step. Signed with name and role. |
| Never say | Prohibited content | Private details, confirming client status, blaming staff, legal threats |
| Industry rules | Confidentiality rules that apply | HIPAA, attorney confidentiality, GLBA, FERPA |
| Escalation | Triggers, contacts and hold rules | Safety or discrimination allegations go to the owner the same day |
| Reporting | Grounds for flagging, who flags, what’s logged | Only policy violations; reason recorded |
| Requests and incentives | How reviews are requested; incentive ban | Same ask for every customer; no rewards |
| Records | What’s logged and where | Shared review log, kept for a set period |
| Training and updates | Who trains, how often the policy is reviewed | New hires trained in first week; policy reviewed yearly |
Keep a one-page summary of the “never say” and escalation sections next to wherever replies are written. That’s the part people need in the moment.
A worked example
This scenario is illustrative, not a real client.
A group of four veterinary clinics has no written policy. Each clinic manager replies in their own style. One reply mentions a pet’s diagnosis and the owner’s unpaid bill; another argues with a reviewer across three replies.
The practice owner writes a three-page policy using the outline above. Clinic managers handle routine replies within two business days. Any review mentioning a pet’s death, a treatment complaint or a staff member by name goes to the medical director before anyone replies. Replies never mention medical details, bills or visit dates, even when the reviewer has. Anything alleging mistreatment of an animal goes to the owner the same day.
The owner also adds a short review log, and after a few months notices several complaints about the same clinic’s phone wait times. That becomes a staffing fix rather than another round of apologetic replies.
Common mistakes
- Writing it and filing it. A policy nobody has read doesn’t change behavior. Train on it, and keep the summary visible.
- Making every reply need approval. Replies slow down and managers stop replying. Reserve approval for the risky ones.
- Leaving out industry rules. The biggest risks in regulated fields are confidentiality breaches, not tone.
- No escalation contact. “Escalate if serious” without a name and a phone number means nothing happens at 9 p.m. on a Saturday.
- Forgetting agencies and software. If a vendor or AI tool drafts replies, the policy applies to them too, and someone at your business still owns what gets posted.
If you’d rather not build the process from scratch, our review management service can set up the policy, the workflow and the replies for you.
Frequently asked questions
What should a review response policy include?
At minimum: which platforms it covers, who replies and who approves, response time targets, tone and reply structure, what must never be said, industry confidentiality rules, escalation triggers and contacts, rules for reporting reviews and requesting them, and what gets recorded.
How long should a review response policy be?
Two or three pages is usually enough for a small or mid-sized business. Keep a one-page summary of the prohibited content and escalation steps where replies are written.
Who should approve replies to negative reviews?
Routine negative reviews can be answered by a trained manager without extra approval. Reviews that name staff, dispute facts or involve legal, safety or discrimination allegations should be approved by a senior person, and by counsel where needed.
Should we reply to every review?
Aim to reply to every negative review and to detailed positive ones. Reviews that break platform rules, such as spam or harassment, may be better reported than answered, and your policy should say who makes that call.