Skip to main content
Category: Policy and Document Management

Policy Development

Also known as: Policy Formulation, Policymaking
Simply put

Policy Development is the structured, step-by-step process of creating, refining, and putting into effect the written guidelines or protocols that govern how an organization or community operates. It is generally treated as an ongoing, iterative activity rather than a one-time task, because policies typically need continuous revision as new circumstances arise. The specific stages and rigor involved vary depending on the organization, sector, and purpose of the policy.

Formal definition

Policy Development refers to a staged, sequential, and iterative process for creating, refining, and implementing systems of guidelines, protocols, or rules intended to govern conduct and decision-making. Practitioners generally break the process into manageable phases, such as identifying an issue, drafting, review and consultation, approval, implementation, and periodic revision, recognizing that policies are subject to continuous revision as new considerations emerge. In an organizational governance context, accountability for approving and overseeing key policies typically sits with the board or a delegated committee, while management generally owns the drafting, operationalization, and ongoing maintenance of policies; the precise allocation of these responsibilities depends on the entity type, applicable frameworks, and jurisdiction. In a public-policy or regulatory context, policy development may encompass the advancement and implementation of laws, regulations, or voluntary practices, and whether a resulting policy is legally binding or a voluntary standard depends on its source and setting. This entry is educational and not legal, audit, or compliance advice; the appropriate process depends on facts, jurisdiction, and professional judgment.

Why it matters

Policy Development gives an organization a repeatable way to translate its values, legal obligations, and risk decisions into written guidelines that shape day-to-day conduct. Without a structured process, policies tend to be drafted reactively, approved without adequate consultation, or left to drift out of alignment with changing circumstances. Because policy development is generally understood as a never-ending process of continuous revision and refinement rather than a one-time task, treating it as a discrete project risks producing documents that are outdated the moment new considerations emerge.

Clear allocation of accountability is central to why this matters for governance. In an organizational context, approval and oversight of key policies typically sit with the board or a delegated committee, while management generally owns drafting, operationalization, and ongoing maintenance. Blurring these roles, for example, treating a management-owned drafting task as board oversight, or vice versa, can leave gaps in accountability and weaken the credibility of the policies themselves. The appropriate allocation depends on the entity type, applicable frameworks, and jurisdiction.

The stakes and the process vary considerably by setting. In a public-policy or regulatory context, policy development may encompass the advancement and implementation of laws, regulations, or voluntary practices, and whether the resulting policy is legally binding or a voluntary standard depends on its source and setting. Recognizing this distinction early helps practitioners calibrate the rigor, consultation, and approval steps to what the policy is actually intended to achieve.

Who it's relevant to

Boards and delegated committees
Directors and committee members typically hold accountability for approving and overseeing key policies. Policy Development is relevant to how they satisfy that oversight role, confirming that a sound process was followed, that consultation was adequate, and that policies are periodically revisited, without stepping into the management-owned drafting and operational work.
Management and policy owners
Management generally owns the drafting, operationalization, and ongoing maintenance of policies. Those responsible for specific policies use a structured, iterative process to identify issues, prepare drafts, coordinate review and consultation, and keep documents current as new considerations emerge.
Compliance and governance professionals
Compliance and governance staff often coordinate the policy lifecycle, helping ensure the process is documented, consultation occurs, and revisions are scheduled. They are also positioned to flag whether a given policy reflects a legal requirement or a voluntary standard, which depends on its source, sector, and jurisdiction.
Public-sector and regulatory practitioners
In a public-policy or regulatory context, policy development may encompass the advancement and implementation of laws, regulations, or voluntary practices. Practitioners in these settings apply the same staged, iterative approach while accounting for whether the resulting policy is legally binding or voluntary.

Inside Policy Development

Policy Scope and Applicability Statement
A clear articulation of which entities, business units, personnel, and activities a policy governs, and any exclusions. Scope typically varies by jurisdiction, sector, and entity type, so a well-drafted policy specifies where and to whom it applies rather than assuming universal reach.
Purpose and Objectives
A statement of the outcomes the policy is intended to achieve, often linking the policy to underlying obligations, whether those obligations arise from binding law (statutes, regulations, listing rules) or from voluntary standards, codes, or frameworks the organization has chosen to adopt.
Roles and Accountabilities
Designation of who owns, approves, implements, and monitors the policy. Typically the board or a committee provides oversight and approval of high-level policy, while management is accountable for developing, operationalizing, and enforcing policies. Assurance functions generally provide independent review rather than ownership.
Substantive Requirements and Standards
The rules, prohibitions, procedures, or expected behaviors the policy establishes. These may be rules-based (prescriptive requirements) or principles-based (outcome-focused expectations), and the drafting should make clear which approach applies and whether a requirement reflects a legal obligation or a voluntary standard.
Approval and Governance Trail
Documentation of the approving authority, effective date, and the governance process through which the policy was adopted, supporting demonstrable accountability and version control.
Review and Revision Provisions
A defined cycle and triggers for periodic review, including changes in law, regulation, framework guidance, or business circumstances, so the policy remains current and fit for purpose.
Related Procedures and Controls
References to the operational procedures, controls, and monitoring activities that give effect to the policy. Policy sets expectations; procedures and controls typically implement them, and their design and operating effectiveness are assessed separately.

Common questions

Answers to the questions practitioners most commonly ask about Policy Development.

Is a policy the same thing as a procedure or control?
No. These are related but distinct instruments, and conflating them is a common source of confusion. A policy generally sets out an organization's position, principles, and expectations on a given matter and is typically approved at a senior level. Procedures translate that policy into specific step-by-step instructions for how work is carried out, while controls are the mechanisms designed to ensure activities occur as intended and that risks are managed. A single policy may be supported by many procedures and controls. Treating a written policy as sufficient in itself, without underlying procedures and controls, often leaves a gap between stated intent and actual operating practice. The precise structure and terminology vary by organization and framework.
Does having a policy in place mean the organization is compliant?
Not on its own. A documented policy generally evidences intent and design, but it does not by itself demonstrate that the policy is understood, followed, or effective in practice. Compliance monitoring and assurance functions typically distinguish between the design of a policy and its operating effectiveness over time. A policy that exists on paper but is not communicated, embedded, or enforced may provide limited protection and can even heighten exposure if actual conduct diverges from stated commitments. Whether a given policy contributes to compliance depends on the applicable legal or regulatory requirements, the facts, and the jurisdiction, and this entry is educational rather than legal or compliance advice.
Who should own and approve a policy?
Ownership and approval generally sit at different levels depending on the policy's significance. In many organizations, management, often a designated policy owner or subject-matter function, is responsible for drafting, maintaining, and operationalizing a policy. Higher-level or enterprise-wide policies, such as a code of conduct or risk management policy, are frequently approved by the board or a relevant board committee, reflecting the board's oversight role, while day-to-day policies may be approved within management. Clear allocation of accountability for drafting, review, approval, and ongoing maintenance is typically regarded as good practice. The specific approval authority depends on the organization's governance structure, delegation framework, and any applicable requirements.
How often should policies be reviewed?
Practice varies, but many organizations adopt a defined review cycle, commonly periodic, such as annually or on a set multi-year basis, alongside event-driven reviews triggered by changes in law, regulation, business activities, risk profile, or lessons from incidents. Setting a review date and a named owner for each policy generally helps prevent documents from becoming outdated. There is no single mandated frequency across jurisdictions or sectors; the appropriate cadence depends on the policy's subject matter, the pace of change in the relevant area, and the organization's own risk-based judgment. This is a general description and not a prescriptive requirement.
How can an organization tell whether a policy is actually working?
Assessing effectiveness typically involves looking beyond the existence of the document to whether it is embedded and operating as intended. Organizations often use a combination of communication and training records, attestations, monitoring activities, testing of related controls, incident and breach data, and independent assurance where appropriate. Assurance functions generally distinguish control design from operating effectiveness, so evidence that a policy is understood and consistently followed carries more weight than the document alone. The methods used depend on the policy's importance and risk, the organization's resources, and the relevant framework, and interpreting the results calls for professional judgment.
What steps are commonly involved in developing a new policy?
While approaches differ, policy development frequently follows a broadly similar arc: identifying the need or trigger (such as a new requirement, risk, or gap); assigning a policy owner; researching applicable legal, regulatory, and framework expectations; drafting; consulting relevant stakeholders and functions; obtaining the appropriate level of approval; communicating and, where needed, training affected personnel; implementing supporting procedures and controls; and scheduling ongoing review and maintenance. Documenting each stage supports traceability and accountability. The particular sequence, rigor, and stakeholders involved depend on the policy's scope and significance and on the organization's governance arrangements. This description is general and not a substitute for tailored professional advice.

Common misconceptions

Adopting a recognized framework such as COSO or ISO 31000 in a policy means the organization is legally compliant.
These frameworks are generally voluntary standards or guidance rather than binding law. Referencing them can support good governance, but legal compliance depends on the applicable statutes, regulations, and listing rules in the relevant jurisdiction and sector, which are distinct from framework adoption.
Policy development is primarily a board responsibility.
The board or a committee typically provides oversight and approves high-level policy, but management generally owns the development, implementation, and enforcement of policies. Attributing operational drafting duties to the board, or oversight duties to management, misstates where accountability sits.
A well-written policy on paper demonstrates that controls are working.
A policy reflects control design and stated expectations. Whether the associated controls actually operate as intended is a separate question of operating effectiveness, generally established through monitoring and independent assurance rather than through the existence of the policy document alone.

Best practices

Define scope and applicability explicitly, noting that requirements vary by jurisdiction, sector, and entity type, and stating what the policy does not cover.
Distinguish clearly within the policy between binding legal requirements and voluntary standards or framework guidance the organization has chosen to adopt.
Assign explicit roles and accountabilities, keeping board or committee oversight and approval separate from management's ownership and implementation, and from independent assurance review.
Establish a defined review cycle with triggers tied to changes in law, regulation, framework guidance, or business circumstances to keep the policy current.
Link each policy to the supporting procedures, controls, and monitoring activities so that design expectations can be tested for operating effectiveness over time.
Maintain a documented approval and version-control trail to support demonstrable accountability and governance, treating the policy as educational and organizational guidance rather than a substitute for legal, audit, or compliance advice on specific facts.