Skip to main content
Category: Policy and Document Management

Policies and Procedures

Also known as: Policy and Procedures Manual, Policies, Procedures and Processes
Simply put

Policies and procedures are an organization's written rules and the step-by-step instructions for following them. A policy states what the rule or standard is, while a procedure explains who is responsible for carrying it out and how they should do so. Together they document how an organization expects work to be performed and behavior to be governed.

Formal definition

Policies and procedures are formal, documented governance instruments used to communicate organizational expectations and operational requirements. A policy is a written statement that mandates, specifies, or prohibits conduct to express an organization's standards or values; a procedure sets out the detailed steps, roles, and methods for implementing that policy in day-to-day work. They are typically maintained as internal documents (often compiled into a policy and procedures manual) and are generally considered a core component of an organization's governance framework. Their content, scope, and enforceability vary by organization, sector, and jurisdiction, and specific legal or regulatory obligations to maintain particular policies depend on the applicable regime. This entry is educational and not legal, audit, or compliance advice.

Why it matters

Policies and procedures translate an organization's values and governance expectations into documented, repeatable practice. Without written rules, an organization typically relies on informal understanding and individual memory, which makes conduct inconsistent, accountability difficult to establish, and expectations hard to communicate as the organization grows or personnel change. By stating both what is required (the policy) and how it is to be carried out (the procedure), these documents help align day-to-day work with the standards the board and management have set.

From a governance, risk, and compliance perspective, policies and procedures serve as a control mechanism and as evidence. They document the design of internal controls, define who is responsible for particular activities, and provide a reference against which conduct can be measured and assurance functions can test. Documented procedures also support consistency, training, and the demonstration of intent to operate in accordance with applicable standards. It is important to distinguish, however, between a policy existing on paper and a policy operating effectively in practice; a well-drafted document does not by itself guarantee that the underlying control is designed appropriately or operating as intended.

The existence and content of specific policies is, in some cases, driven by legal or regulatory requirements, but this varies significantly by jurisdiction, sector, and entity type. In many contexts, maintaining particular policies is a voluntary matter of good practice rather than a legal mandate, while in others specific policies may be expected or required by an applicable regime. Organizations should therefore treat their policy suite as a matter requiring professional judgment about what is necessary, appropriate, and enforceable in their circumstances, rather than assuming a universal obligation exists.

Who it's relevant to

Boards and board committees
Boards and their committees generally exercise oversight of the policy framework and may be responsible for approving certain high-level or entity-wide policies. Their role is typically one of oversight and challenge rather than day-to-day drafting or implementation, and they generally rely on management and assurance functions to confirm that the framework is complete, current, and functioning.
Management and process owners
Management typically owns the creation, implementation, and ongoing operation of policies and procedures within its areas of responsibility. Process owners are usually accountable for ensuring that documented procedures reflect how work is actually performed, that responsibilities are clearly assigned, and that staff are able to follow them in daily work.
Compliance and risk functions
Compliance and risk teams generally use policies and procedures to communicate required standards and to document how identified risks are to be managed. They may help draft or coordinate policies, but the extent of any legal obligation to maintain a particular policy depends on the applicable jurisdiction, sector, and regime and is a matter requiring professional judgment.
Internal audit and assurance providers
Assurance functions rely on documented policies and procedures as a reference point for testing. They may separately evaluate whether a policy is appropriately designed and whether the associated procedure is operating effectively in practice, treating the existence of a document and its effective operation as distinct questions.
Employees and operational staff
Employees are typically the primary users of procedures, which set out who is expected to do what and how. Clear, accessible policies and procedures help staff understand organizational expectations, perform work consistently, and know where to look for guidance when a situation arises.

Inside Policies and Procedures

Policy
A high-level statement of an organization's position, principles, or expectations on a given subject, typically approved at a senior level and setting the 'what' and 'why' rather than the operational detail. Policies generally reflect the organization's risk appetite, legal obligations, and values.
Procedure
The step-by-step instructions that translate a policy into action, describing 'how' a task is performed, by whom, and in what sequence. Procedures generally sit below policies and are updated more frequently as processes change.
Scope and Applicability
A statement defining who and what the policy or procedure covers, such as which entities, business units, geographies, or roles are in scope. This is important where obligations vary by jurisdiction, sector, or entity type.
Ownership and Accountability
Identification of the individual or function responsible for drafting, approving, maintaining, and enforcing the document. Ownership typically distinguishes management's operational responsibility from the board's or a committee's oversight role.
Approval and Governance
The authority levels and process through which documents are reviewed and formally adopted, and the linkage to relevant committees or the board where applicable.
Version Control and Review Cycle
Records of document versions, effective dates, and the schedule or triggers for periodic review, helping ensure documents remain current with legal, regulatory, and business change.
Roles and Responsibilities
A description of who does what, which may reference the separation between first-line operational owners, second-line risk and compliance functions, and third-line assurance, where such a model is used.
Related References
Cross-references to applicable laws, regulations, listing rules, or voluntary frameworks, together with links to associated policies, standards, and forms.

Common questions

Answers to the questions practitioners most commonly ask about Policies and Procedures.

Are policies and procedures the same thing?
No. Although the terms are often used together and sometimes treated as interchangeable, they generally serve distinct purposes. A policy typically sets out the organization's intent, principles, and expectations on a given matter, what the organization requires and why. A procedure generally describes the specific steps, sequence, and responsibilities for carrying out that intent in practice, how the requirement is met. Many organizations maintain a documentation hierarchy in which higher-level policies are supported by more detailed procedures, standards, or work instructions. Conflating the two can obscure whether a gap is one of intent (the policy is unclear or absent) or execution (the procedure is missing or not followed). The precise terminology and structure vary by organization and framework.
Does having a documented policy mean the organization is compliant?
Not by itself. A documented policy generally reflects control design, the articulation of what is expected, but it does not demonstrate operating effectiveness, meaning whether the policy is actually understood, applied, and adhered to in practice. A well-drafted policy that is not communicated, followed, or monitored may provide limited assurance. Compliance and assurance functions typically distinguish between the existence of a policy and evidence that the associated controls operate as intended over time. Whether documentation contributes to a compliance position also depends on the applicable legal or regulatory requirements, which vary by jurisdiction, sector, and entity type. This entry is educational and not legal, audit, or compliance advice.
Who is typically responsible for owning, approving, and maintaining policies?
Responsibilities generally differ by document type and organization. Management typically owns and operates policies and procedures, meaning it drafts, implements, and maintains them as part of running the business, often through designated policy owners within the relevant function. The board or a board committee generally exercises oversight, and in many organizations approves certain high-level or enterprise-wide policies rather than operational procedures. Assurance functions, such as internal audit, generally do not own operational policies but may evaluate whether the policy framework is adequate and operating effectively. The specific allocation of ownership, approval authority, and review cadence should be defined in the organization's own governance arrangements and may depend on regulatory expectations that vary by jurisdiction.
How often should policies and procedures be reviewed and updated?
There is generally no single universal frequency; review cadence typically depends on the risk associated with the subject matter, the pace of change in the relevant environment, and any applicable regulatory expectations. Many organizations adopt a periodic review cycle, often annual for higher-risk or regulated areas, supplemented by event-driven reviews triggered by legal or regulatory changes, incidents, restructuring, new products, or findings from assurance activities. Assigning a named owner and a defined review date to each document generally helps prevent policies from becoming outdated. Where a specific review frequency is prescribed by law, regulation, or a framework applicable to the entity, those requirements should take precedence. What is appropriate ultimately depends on the facts and the organization's own judgment.
How can an organization tell whether a policy is actually being followed?
Assessing adherence generally involves gathering evidence of operating effectiveness rather than relying on the existence of the document alone. Common approaches include monitoring by management as part of first-line activity, second-line compliance monitoring or testing, and independent evaluation by internal audit or other assurance providers. Indicators may include exception and incident data, attestations, sampling of transactions or records, training completion, and management information reported to relevant committees. It is generally useful to distinguish who performs each type of review, because management monitoring, compliance testing, and independent assurance serve different roles within the three lines. The appropriate mix depends on the risk involved and the organization's structure.
What practical steps help ensure staff understand and apply policies?
Effective implementation generally extends beyond publication. Common practices include accessible, plain-language drafting; clear identification of scope and to whom the policy applies; communication and training appropriate to the audience and risk; embedding requirements into everyday systems, workflows, and controls where feasible; and providing a route to ask questions or report concerns. Version control, a single authoritative source, and clear links between policies and their supporting procedures generally help avoid confusion. Tracking acknowledgement or attestation may support awareness, though acknowledgement alone does not evidence that a policy is operating effectively in practice. The right approach depends on the organization's size, risk profile, and any applicable requirements.

Common misconceptions

Policies and procedures are the same thing and can be used interchangeably.
They are typically distinct. A policy states the organization's position and expectations (the 'what' and 'why'), while a procedure sets out the operational steps to implement it (the 'how'). Conflating them can obscure accountability and make documents harder to maintain.
Having a documented policy means the organization is compliant and the associated risk is controlled.
A documented policy speaks to control design, not operating effectiveness. Whether the policy is understood, followed, and enforced in practice is a separate question, and controls can be well designed on paper yet fail in operation. Documentation is one element among many.
The board is responsible for writing and maintaining policies and procedures.
Drafting, implementing, and maintaining procedures is generally a management responsibility. The board or a relevant committee typically provides oversight and may approve certain high-level policies, but attributing the operational drafting duty to the board misstates the usual allocation of roles.

Best practices

Maintain a clear hierarchy that distinguishes policies from the procedures beneath them, so the position and the operational detail can be updated and approved at the appropriate levels.
Assign a named owner and defined approval authority to each document, and make explicit where oversight sits (for example, a board committee) versus where operational responsibility sits (management).
Establish version control, effective dates, and a scheduled review cycle, with additional review triggered by relevant legal, regulatory, or business change.
State the scope and applicability precisely, recognizing that obligations may differ by jurisdiction, sector, and entity type, and note which provisions reflect binding requirements versus voluntary standards.
Test not only whether a policy exists but whether it operates effectively in practice, coordinating with second-line monitoring and third-line assurance as appropriate.
Cross-reference related laws, frameworks, and internal documents so users can trace a procedure back to its governing policy and any underlying obligation.
Treat these documents as educational and operational tools rather than a substitute for tailored legal, audit, or compliance advice on specific facts.