In the project/pom.xmls pluginManagement section we have defined various plugins. Does a policy exists about when
updating to a newer version of plugins (same for artifacts)?

There's no policy per say but I personally try to update before a new release.

Before releasing the project/pom.xml (now including the rat report generation) a decision should be made about including
the rat:check into the release process or not.

Yes I think we already do this for ApacheDS project when the -Prelease flag is present to trigger the release profile.  If we do not then we should - we should do what you suggest TLP wide.