Skip to main content
Category: Policy and Document Management

Procedure

Also known as: Standard Operating Procedure, SOP
Simply put

A procedure is a set of actions that represents the official or accepted way of doing something, describing the specific steps or methods used to accomplish a particular task. In a governance and compliance context, procedures generally translate broader policies into concrete, repeatable steps for staff to follow.

Formal definition

A procedure is typically a documented, prescribed method for accomplishing a defined activity, setting out the sequence of actions, responsibilities, and controls required to perform a task consistently. In governance, risk, and compliance settings, procedures generally operationalize higher-level policies by specifying how requirements are executed in practice; their design and operating effectiveness are usually owned by management as part of day-to-day operations rather than by the board, whose role is generally oversight. The precise form, mandatory status, and required content of a procedure depend on jurisdiction, sector, entity type, and any applicable framework or regulatory regime, and this entry is educational rather than legal, audit, or compliance advice.

Why it matters

Procedures matter because they are the point at which high-level policy commitments become the actual, repeatable actions staff take day to day. A policy may state what an organization intends to do and why, but without a procedure setting out the specific steps, responsibilities, and controls, that intent can remain aspirational and be applied inconsistently across teams, sites, or individuals. In a governance and compliance context, procedures are generally where the design and operating effectiveness of controls become visible and testable, which is why assurance functions and management typically focus on whether procedures are documented, followed, and produce consistent outcomes.

Because procedures translate requirements into concrete actions, weaknesses in them can undermine an otherwise sound control environment. A well-drafted policy paired with an unclear, outdated, or ignored procedure can create a gap between what an organization says it does and what actually happens in practice. Consistency is a core benefit: a standard or routine procedure, such as an established method for dealing with complaints, allows an organization to handle recurring tasks in a predictable, defensible way rather than relying on individual discretion each time.

The importance and required form of any given procedure depend heavily on jurisdiction, sector, entity type, and any applicable framework or regulatory regime, so this entry describes the concept generally rather than prescribing what a procedure must contain. It is educational and not legal, audit, or compliance advice.

Who it's relevant to

Chief Compliance Officers
Compliance officers generally rely on procedures to operationalize compliance policies into concrete, repeatable steps that staff can follow, helping ensure requirements are executed consistently. They are typically concerned with whether procedures are documented, current, and actually followed in practice.
Internal Auditors and Assurance Functions
Assurance functions typically assess both the design and the operating effectiveness of procedures, that is, whether a procedure is set up to achieve its purpose and whether it works as intended in day-to-day operation. Procedures provide the documented, prescribed methods against which actual practice can be tested.
Management
Management generally owns the design and operating effectiveness of procedures as part of day-to-day operations, defining the sequence of actions, responsibilities, and controls needed to perform tasks consistently. This is distinct from the board's role, which is generally oversight rather than the operational execution of procedures.
Boards and Board Committees
The board's role is generally one of oversight rather than drafting or operating procedures directly. Directors typically want assurance that management has established appropriate procedures to translate policies into practice, without assuming operational responsibility for them.

Inside Procedure

Purpose and Scope
A statement of what the procedure is intended to accomplish and the activities, processes, or units to which it applies. Scope typically clarifies boundaries, including what is out of scope, so users understand when the procedure governs their work.
Sequenced Steps or Tasks
The core of a procedure is an ordered set of actions describing how a task is performed. Unlike a policy, which states intent and principle, a procedure generally specifies the detailed 'how' at an operational level.
Roles and Responsibilities
An identification of who performs, reviews, or approves each step. This typically sits with management and operational staff (the first line), and procedures should not attribute board-level oversight duties to those executing operational tasks.
Controls Embedded in the Process
Points within the procedure where a control operates, such as an approval, reconciliation, or segregation of duties. Well-drafted procedures make clear both the control's design and how it is intended to operate in practice.
Inputs, Outputs, and Records
The information or artifacts required to begin the procedure, the results produced, and the documentation retained. Records generated by a procedure often support later monitoring, assurance, and evidence of operating effectiveness.
Governing References
Links to the parent policy, applicable legal or regulatory requirements, and any relevant frameworks. This helps distinguish steps required by binding law or listing rules from those adopted as voluntary good practice, which can vary by jurisdiction, sector, and entity type.
Version Control and Review Cadence
Metadata identifying the current version, owner, approval date, and next review. This supports the maintenance of the procedure over time and helps demonstrate that it remains current.

Common questions

Answers to the questions practitioners most commonly ask about Procedure.

Is a procedure the same thing as a policy?
No. A policy and a procedure operate at different levels and are typically owned and used differently. A policy generally sets out the organization's position, principles, or requirements on a topic and the outcomes it expects, whereas a procedure typically describes the specific, ordered steps by which those requirements are carried out in practice. Confusing the two can blur accountability: a policy usually reflects a management or board-approved standard, while a procedure operationalizes it at the process level. The precise relationship and terminology vary by organization, sector, and framework, so treat this as a general distinction rather than a universal rule.
Does having a documented procedure mean the related control is operating effectively?
Not necessarily. A documented procedure speaks primarily to control design, how an activity is intended to be performed, but says little on its own about operating effectiveness, which concerns whether the steps are actually followed consistently over time. Design and operating effectiveness are distinct questions, and a well-written procedure that is not adhered to may still leave a control gap. Assessing whether a procedure operates effectively generally requires evidence such as testing, monitoring, or assurance activity, and the appropriate approach depends on the facts and the applicable framework.
Who should own and approve a procedure within an organization?
Ownership of a procedure typically sits with the management or process owner responsible for the activity it describes, since procedures generally operationalize day-to-day work. This contrasts with higher-level policies, which are often approved at a more senior management or board committee level. Under a three-lines model, first-line functions commonly own and execute procedures, while second-line functions may set standards or review them and assurance functions may test adherence. The exact allocation of ownership and approval authority varies by organization, so it should be defined explicitly rather than assumed.
How often should procedures be reviewed or updated?
There is generally no single mandated review frequency; the appropriate cadence depends on the risk associated with the underlying process, regulatory expectations in the relevant jurisdiction, and the organization's own governance standards. Many organizations set a periodic review cycle and also trigger updates when there is a significant change, such as a new regulation, a process redesign, a control failure, or an identified gap. The objective is to keep procedures current and aligned with the policies and requirements they support; the specific approach is a matter of the organization's judgment and any applicable framework.
How can an organization tell whether a procedure is actually being followed?
Determining adherence generally requires looking beyond the existence of the document to evidence of practice. This can include monitoring by the process owner, second-line reviews, internal audit or other assurance testing, and examination of records or system logs generated when the procedure is executed. The distinction between whether steps are designed and whether they are consistently performed is central here. The right mix of monitoring and assurance depends on the risk, the control's importance, and the applicable framework, and this general guidance is not a substitute for professional audit or compliance judgment.
What level of detail should a procedure contain?
The appropriate level of detail generally depends on the complexity and risk of the activity, the experience of those performing it, and the need for consistency. A procedure typically provides enough specificity that the intended steps can be performed reliably and consistently, without becoming so detailed that it is impractical to maintain. Where activities are higher-risk or subject to regulatory expectations, more precise, testable steps are often warranted. Balancing usability against completeness is a matter of judgment for the process owner, informed by any applicable standards.

Common misconceptions

A procedure and a policy are the same thing.
They generally serve different functions. A policy typically sets out intent, principles, and expected outcomes, while a procedure describes the operational steps for achieving them. Conflating the two can obscure where accountability sits and what is mandatory versus discretionary.
A documented procedure proves that the underlying control is effective.
A written procedure evidences control design, how a process is intended to work. It does not by itself demonstrate operating effectiveness, which depends on whether the steps are actually performed consistently over time. Assurance functions generally test the latter separately.
Following a procedure removes the need for judgment or shifts accountability away from the individual.
Procedures guide execution but rarely eliminate the need for professional judgment, and outcomes still depend on facts and circumstances. Accountability for performing the steps typically remains with the responsible role, and entries like this are educational rather than legal, audit, or compliance advice.

Best practices

Anchor each procedure to a parent policy and, where relevant, to the applicable legal, regulatory, or framework references, distinguishing steps required by binding law from those adopted as voluntary good practice.
Assign clear roles and responsibilities for performing, reviewing, and approving each step, keeping operational execution with the first line and avoiding attribution of oversight duties to those carrying out the tasks.
Make embedded controls explicit within the steps, and design procedures so that performance generates records capable of supporting later monitoring and independent assurance of operating effectiveness.
Apply version control, name an accountable owner, and set a defined review cadence so procedures remain current as processes, systems, and requirements change.
State scope boundaries plainly, including what is out of scope, and flag where a step depends on facts, jurisdiction, or professional judgment rather than presenting it as universally applicable.
Test procedures periodically against actual practice to confirm that documented design reflects how work is genuinely performed, and update them where gaps emerge.