Skip to main content
Category: Policy and Document Management

Standard

Also known as: standards
Simply put

A standard is an agreed level of quality, or a set of criteria, principles, or rules used as a reference point to judge or measure something against. In a governance context, standards describe what is generally expected or accepted as acceptable practice. Standards can be voluntary benchmarks or, where adopted into law or regulation, binding requirements, so their force depends on the source and the jurisdiction.

Formal definition

A standard is an authoritative principle, rule, criterion, or specified level of quality that serves as a model or benchmark against which conduct, performance, controls, or outputs are assessed. The term is generic: a standard may be a voluntary benchmark issued by a standard-setting body or profession, a best-practice reference within a code or framework, or a legally binding requirement where it has been incorporated into statute, regulation, or listing rules. Whether a given standard is mandatory or advisory, and how it is enforced, typically varies by jurisdiction, sector, and entity type, and depends on the instrument that adopts or references it. This entry defines the general concept and does not address any specific published standard; it is educational and not legal, audit, or compliance advice.

Why it matters

Standards give governance, risk, and compliance work a common reference point. Without an agreed level of quality or an authoritative set of criteria, judgments about whether conduct, controls, or performance are acceptable become arbitrary and inconsistent. Standards allow a board to set expectations, allow management to design controls against a defined benchmark, and allow assurance functions to test whether those controls meet the reference point rather than a shifting or subjective target.

The practical significance of a standard depends heavily on its source and force. A voluntary benchmark issued by a standard-setting body or referenced in a code of best practice creates an expectation but generally carries no direct legal sanction on its own. The same criterion can become a binding requirement where it is incorporated into statute, regulation, or listing rules, at which point non-compliance may have legal or regulatory consequences. Confusing the two, treating an advisory benchmark as mandatory, or a legal requirement as merely aspirational, is a common and consequential error, because it misstates the level of obligation an organization actually carries.

Because whether a standard is mandatory or advisory typically varies by jurisdiction, sector, and entity type, understanding which instrument adopts or references a given standard is essential before relying on it. The label "standard" alone does not tell you its legal weight; that comes from the source and the applicable regime, and often depends on the specific facts and a professional's own judgment.

Who it's relevant to

Boards and directors
Boards use standards as reference points when setting expectations for conduct and performance and when overseeing whether management operates at an acceptable level. Directors should be clear about whether a given standard is a voluntary benchmark the board has chosen to adopt or a binding legal requirement, because that distinction affects the nature of the oversight duty and the consequences of falling short.
General counsel and compliance officers
These functions need to determine whether a standard carries legal force in the relevant jurisdiction or is a non-binding benchmark. That analysis turns on the instrument that adopts or references the standard, statute, regulation, listing rule, code, or framework, and on the sector and entity type involved.
Risk and internal audit professionals
Assurance and risk functions assess conduct, controls, and outputs against defined standards, so a clearly specified benchmark is a precondition for meaningful testing. Where the applicable standard is voluntary, findings describe deviation from an expected practice; where it is a binding requirement, deviation may indicate non-compliance with a legal obligation.
Management and operational teams
Management typically designs and operates processes and controls intended to meet applicable standards. Understanding which standards apply, and whether they are mandatory or advisory in the relevant context, allows teams to prioritize and to distinguish legal requirements from voluntary quality benchmarks.

Inside Standard

Requirement or specification
The core of a standard is a defined requirement, specification, or criterion against which a process, product, control, or behavior can be measured. Standards articulate expected characteristics rather than describing every possible implementation.
Source and issuing body
Standards are typically developed by recognized bodies such as international standards organizations (for example, ISO), professional associations, industry consortia, or regulators. The issuer's authority determines whether the standard is voluntary guidance or has been incorporated into binding requirements by law, regulation, or listing rules.
Scope and applicability
A standard defines its intended scope, including the entities, sectors, activities, or jurisdictions it addresses. Applicability generally varies by entity type and jurisdiction, and a standard voluntary in one context may be mandated in another where a regulator or contract adopts it.
Conformance or assessment basis
Standards commonly include a basis for evaluating conformance, such as criteria, control objectives, or maturity levels. This supports assessment, and in some cases independent certification or attestation, distinguishing whether an entity meets the standard's expectations.
Rules-based versus principles-based orientation
Some standards prescribe detailed rules, while others set out principles that require judgment in application. The orientation affects how conformance is demonstrated and how much interpretation practitioners must exercise.
Maintenance and versioning
Standards are typically maintained, periodically reviewed, and revised by their issuing body. Users generally need to identify the applicable version, as requirements and terminology can change between editions.

Common questions

Answers to the questions practitioners most commonly ask about Standard.

Is a standard the same thing as a law or regulation?
Not necessarily. The term standard often refers to a voluntary framework or benchmark (such as an ISO standard or an industry code) that an organization chooses or is expected to adopt, rather than binding law. Some standards do acquire legal force when a statute, regulation, or listing rule incorporates them by reference, or when a contract or regulator requires adherence. Whether a given standard is binding depends on the jurisdiction, sector, entity type, and the instrument that references it, so each case should be assessed on its facts. These entries are educational and not legal, audit, or compliance advice.
Does adopting a recognized standard guarantee compliance with applicable legal requirements?
No. Conforming to a standard and complying with the law are related but distinct. A standard typically sets out a benchmark for how an activity should be performed, while legal requirements are set by statutes, regulations, and listing rules that may impose obligations a standard does not address, or may differ from it. Adopting a standard can support a compliance program, but it does not by itself demonstrate that all applicable legal duties have been met. Organizations generally need to map standards against the specific requirements that apply to them in each relevant jurisdiction.
Who is accountable for selecting and implementing a standard within an organization?
Accountability generally differs by role. Management typically owns the decision to adopt a standard, the design and operation of the processes and controls needed to meet it, and day-to-day implementation. The board or a relevant committee generally provides oversight, satisfying itself that management's approach is reasonable, without taking on operational responsibility. Assurance functions such as internal audit typically evaluate whether the standard is being applied effectively, but do not own its implementation. The precise allocation depends on the entity's structure and governance arrangements.
How can an organization decide which standard to adopt when several are available?
Selection generally depends on the organization's objectives, sector, regulatory environment, and the nature of the activity being governed. Considerations often include whether a standard is required or expected by a regulator, customer, or listing rule; how well its scope fits the intended purpose; the resources needed to implement and maintain conformance; and whether it aligns with frameworks the organization already uses. Because standards vary in scope and none is universally mandatory, the choice is typically a matter of professional judgment informed by the specific facts.
How should conformance with a standard be monitored over time?
Monitoring generally distinguishes between whether controls and processes are designed to meet the standard and whether they are operating effectively in practice. Management typically establishes ongoing monitoring within its own processes (often described as a first-line activity), while functions such as compliance may provide independent monitoring, and internal audit may provide periodic assurance. The appropriate frequency and depth of monitoring generally depend on the significance of the standard, the associated risks, and any external requirements. Some standards also involve external certification or surveillance.
What is the difference between having a standard in place and demonstrating it works?
Documenting adoption of a standard addresses design, whereas demonstrating that it works addresses operating effectiveness over a period. Evidence of effectiveness typically includes records that controls and processes have been performed as intended, results of testing or monitoring, and any exceptions and their remediation. Boards and assurance functions generally look for this evidence rather than relying on the existence of a policy alone. What constitutes sufficient evidence depends on the standard, the risk involved, and any applicable regulatory or certification expectations.

Common misconceptions

A standard is legally binding simply because it is widely recognized or issued by a reputable body.
Most standards are voluntary in themselves. They generally become binding only where a statute, regulation, listing rule, or contract incorporates them, and that incorporation varies by jurisdiction, sector, and entity type. Recognition and mandatory force are distinct.
Conforming to a standard means an organization has eliminated the underlying risk or guarantees compliance with all applicable law.
A standard typically addresses design expectations for a process or control, not its operating effectiveness over time, and rarely covers the full landscape of legal obligations. Conformance reduces but does not eliminate residual risk, and legal compliance may require obligations beyond any single standard.
Adopting a standard shifts responsibility for the related activity onto the standard-setter or an external assessor.
Accountability generally remains with the organization. Management typically owns the design and operation of the relevant processes and controls, the board or its committees retain oversight, and assurance functions evaluate rather than assume responsibility. A certification does not transfer these duties.

Best practices

Confirm whether a given standard is voluntary guidance or has been made binding in your jurisdiction, sector, or contracts before treating it as a requirement, and document the basis for that determination.
Identify and reference the specific issuing body and current version of the standard, and establish a process to monitor revisions so your program stays aligned with the applicable edition.
Map the standard's scope against your entity's activities to determine what is and is not covered, and avoid assuming a single standard addresses all related legal or regulatory obligations.
Assign clear ownership consistent with the three lines model: have management own design and operation, define the assurance function's independent assessment role, and reserve oversight for the board or relevant committee.
When assessing conformance, evaluate both control design and operating effectiveness rather than treating a one-time certification as evidence of ongoing adherence.
Treat standards as one input alongside professional judgment, jurisdictional legal advice, and your organization's risk appetite, recognizing that entries and frameworks are educational and not a substitute for legal, audit, or compliance advice.