HotDraftingVersion controlApprovalFindingsReviewRetirement
Latest A policy nobody has read is not a control. It is a document about a control that does not exist.
The gap

Having a policy and doing the thing are different achievements

Organisations are assessed on whether a document exists and operate on whether people behave a certain way. Those two states can persist independently for years.

Every organisation of any age holds a body of policy: documents that state how something will be done, approved by somebody, held in a repository, and produced when requested. The body grows steadily, because each new obligation, each incident, and each audit finding produces another one, and almost nothing is ever withdrawn. A mature organisation can hold several hundred, of which the people doing the work have read perhaps six.

This is usually described as a compliance culture problem, which locates the fault with the people who have not read them. That framing is comfortable and it is mostly wrong. A person cannot hold three hundred documents in mind, and asking them to is not a reasonable instruction. What they hold instead is a working understanding of how things are done here, acquired from colleagues, from what was corrected last time, and from the handful of rules that are actually enforced. That understanding is the operating system, and the policy library is a parallel artefact that may or may not describe it.

Continue reading

Writing

Every 'must' is a commitment somebody has to keep

Modal verbs are the load-bearing part of a policy.

Who is this written for

A document addressed to an auditor will not be read by staff.

Keeping

The review cycle that reviews nothing

Annual review is usually annual re-dating.

Approval, and who is actually accountable

A signature at the bottom is not the same as ownership.

Assessment

Responding to a finding without making it worse

The reflex is to write another document.

Evidence that a policy operated

Records are the control. The document only describes it.

The library

Templates, frameworks and bought policy sets

They solve the blank page and create a different problem.

How big should a library be

Smaller than it is, in almost every organisation.

About Policy Experts

Policy Experts is about the documents that govern how an organisation operates: drafting them accurately, versioning them so past periods can be evidenced, reviewing them meaningfully, and retiring them when they stop describing anything.

The editorial position is that having a policy and doing the thing are separate achievements which can persist independently for years, that aspirational drafting creates the exposure it was meant to prevent, and that most policy libraries are considerably larger than the number of documents anybody uses.

This publication is independent. It is not affiliated with any regulator, certifying body, consultancy or document management vendor, it does not accept payment for coverage, and it does not sell policy templates or drafting services.

Nothing here is legal advice or a statement of any regulator's requirements. Obligations differ by jurisdiction, sector and the specific arrangements an organisation operates under, and the applicable legislation, standards and conditions of registration should be read directly and, where consequences are material, with qualified advice.