Having a policy and doing the thing are different achievements
Organisations are assessed on whether a document exists and operate on whether people behave a certain way. Those two states can persist independently for years.
Every organisation of any age holds a body of policy: documents that state how something will be done, approved by somebody, held in a repository, and produced when requested. The body grows steadily, because each new obligation, each incident, and each audit finding produces another one, and almost nothing is ever withdrawn. A mature organisation can hold several hundred, of which the people doing the work have read perhaps six.
This is usually described as a compliance culture problem, which locates the fault with the people who have not read them. That framing is comfortable and it is mostly wrong. A person cannot hold three hundred documents in mind, and asking them to is not a reasonable instruction. What they hold instead is a working understanding of how things are done here, acquired from colleagues, from what was corrected last time, and from the handful of rules that are actually enforced. That understanding is the operating system, and the policy library is a parallel artefact that may or may not describe it.
The consequence is a specific and very common organisational state: the documents say one thing, the operation does another, and both have been stable for years. Nobody is lying. The policy was accurate when written, the process changed, and nothing connected the two. An assessment that reads the documents finds a compliant organisation. An assessment that watches the work finds a different one, and the difference is invisible from either vantage point alone.
What makes this durable is that writing a policy is cheap and changing behaviour is expensive. When something goes wrong, the fastest available response is to write or amend a document, because it can be done by one person in an afternoon and it produces an artefact that demonstrates a response occurred. Changing what people actually do requires training, supervision, system changes and time, and it produces nothing that can be attached to a corrective action report. So the library grows after every incident and the operation frequently does not change at all.
The useful test for any policy is therefore not whether it is well written but whether removing it would change anything. If the work would proceed identically without the document, the document is not governing the work; something else is, and the something else is what would need to change to alter behaviour. This is uncomfortable to apply across an existing library because it identifies a large proportion as inert, and inert documents still carry a maintenance cost and still create exposure, because an organisation is judged against what its own policies say.
That last point deserves emphasis, since it is the practical risk. A policy that promises more than the operation delivers is worse than no policy, because it establishes a standard the organisation has publicly adopted and demonstrably does not meet. Aspirational drafting, which is extremely common and usually well intentioned, creates precisely this exposure. The document says every incident will be reviewed within five working days because that sounded right when it was written, and the actual practice is two weeks, and now there is documentary evidence of a failure that would otherwise have been a reasonable operational reality.
So the discipline that matters in this work is not eloquence or completeness. It is accuracy about what the organisation actually does, restraint about what it promises, and a willingness to retire documents that have stopped describing anything. That produces a smaller library that is worth reading, which is the only condition under which reading it is a reasonable thing to ask of anybody.
One further consequence is worth naming because it changes who should be doing this work. If accuracy about actual practice is the binding requirement, then drafting cannot sensibly sit with somebody who does not watch the operation. A compliance function writing on behalf of a department will produce documents that are well formed, internally consistent and describing a process nobody has observed. The document has to be written with the people who do the thing, which is slower, produces worse prose, and is the only way the result describes anything real.