Policy and Procedure
Overview
Policies define what must be done and why. Procedures define how. Both should be precise, accessible, and maintainable.
When to Use
- Organizational policies (security, HR, data handling, etc.)
- Standard operating procedures
- Compliance documentation
- Internal standards that need consistent interpretation
Structure Guidance
Policy
- Purpose and scope
- Definitions
- Policy statements
- Roles and responsibilities
- Exceptions and enforcement
- Related documents and review cycle
Procedure
- Purpose and when to use
- Roles
- Step-by-step instructions
- Inputs / outputs
- Exceptions and escalation
Principles
- Use plain language
- Be specific enough to be enforceable
- Separate mandatory requirements from guidance
- Keep documents versioned and owned
- Design for the reader who must comply or execute
Verification
- Scope and applicability are clear
- Requirements are unambiguous
- Related procedures or policies are linked