Documents · Compared

Policy against procedure, and where a guideline fits

A policy states a rule and the reason for it, and changes rarely. A procedure states the steps that carry the rule out, names who does each one, and changes whenever the tools or people change. A guideline recommends rather than requires, so departing from it is a judgement call rather than a breach.

Almost every organisation writes these three into one document and then wonders why nobody can find anything. Keeping them apart is less about tidiness and more about how often each one has to be rewritten.

· Co-founder

5 min read · Published

The three documents against each other
PolicyProcedureGuideline
AnswersWhat the rule is and whyHow the rule is carried outWhat is recommended
ComplianceMandatoryMandatoryAdvisory
ChangesRarely, by approvalOften, as tools and roles changeAs practice improves
Approved byThe board or executiveThe owning managerThe owning team
Leave exampleStaff take leave with reasonable notice and approvalRequest in the HR system 14 days out, manager approves within 3 days, payroll is notifiedTwo weeks of leave in one block is better for recovery than scattered days
LengthOne or two pagesAs long as the steps needUsually a page

Why splitting them saves work

The split exists because the two documents have different lifespans. A rule about who may approve spending survives five years of software changes. The steps for entering that spending survive until the finance system is replaced, which may be next quarter. Keeping them in one document means the whole thing goes back through the approval chain every time a screen changes, so in practice it does not go back at all and the document quietly stops matching reality. Split them and the procedure can be updated by the person who owns the process, without a board paper, while the policy stays stable enough to be worth quoting. The second benefit is audience. Everybody needs to know the policy; only the people doing the task need the procedure.

How to tell which one you are writing

Read the sentence and ask whether removing a named system or a named role would change its meaning. If it would, it is procedure. Policy sentences survive a change of tools: expenses over a threshold need a second approver. Procedure sentences do not: attach the receipt in the finance portal and select your cost centre. A second test is tense and mood. Policy is declarative and stated in the third person about the organisation. Procedure is imperative, numbered, and addressed to the person doing the work. Guidelines are the ones that use words like consider, prefer or where practicable, and if your policy is full of those words it is really a guideline wearing a policy heading, which will be a problem the first time you try to enforce it.

Where guidelines belong

A guideline is the right shape when professional judgement has to stay in the loop. Clinical practice, editorial standards, design conventions and safe manual handling all work better as recommendations with reasons than as rules with exceptions. The risk is drift: guidelines quietly become rules in the minds of managers who enforce them, and staff are disciplined for departing from something the organisation never actually required. Mark the status on the first line of every document, in words rather than in a naming convention, so a reader who found the file through search still knows whether they are reading an obligation. If a guideline turns out to need enforcing, promote it to policy deliberately rather than by habit.

The common failure modes

Four are almost universal. A policy that names software, which dates the moment procurement changes its mind. A procedure with no owner, so nobody is responsible when the steps stop working. A document that opens with three paragraphs of scope and purpose before saying anything useful, which trains people to skip the top. And the pair that disagree, usually because the procedure was updated and the policy was not, leaving a manager to choose which document to follow. A short cross reference at the end of each, naming its counterpart and the review date, fixes most of that at almost no cost.

Building the pair as documents

A policy and its procedure work well as two separate documents rather than one long file, because they are approved by different people on different cycles. Both are short, so neither gets a cover: a cover is only added to a document a reader would expect one on, never under three pages, and never on an invoice, receipt, letter, resume or certificate. Numbered structure suits a policy that will be cited clause by clause, and a table suits a procedure that maps steps to roles. Callouts come in four variants, which is enough to mark an exception, a warning, a confirmation and a caution without inventing a house style. Input fields are not used in documents, so an approval line is written as content. Ten theme presets and four letterhead styles are available, and the letterhead is only used when the document speaks for a sender, which a policy issued by an executive team usually does.

Questions people ask

Who should approve a policy?

Whoever carries the risk it manages. A privacy policy belongs to the executive because a breach is an organisational liability; a desk procedure belongs to the team lead. Recording the approver and the date on the document itself matters more than the level, because it tells a reader whether what they are holding was ever authorised.

How long should a policy be?

One or two pages is enough for almost any single subject. If yours runs to eight, most of it is procedure, background or examples that would be better placed elsewhere. Length is not a proxy for seriousness, and a policy nobody finishes reading gives you less protection than a short one everybody has actually read.

Can a procedure change without approval?

That is the point of separating them. The owner of the process should be able to update the steps when the system changes, provided the change stays inside the policy. If a proposed step would breach the policy or shift a decision to a different role, that is a policy change and needs the policy approver, not the process owner.

What is a standard operating procedure?

It is a procedure written for a task that has to come out the same way every time, common in manufacturing, laboratories and food handling. The difference is rigour rather than kind: an SOP usually carries version control, a competency requirement for the person performing it, and a record that it was followed on a given day.

Where does a work instruction fit?

Below the procedure. A procedure spans roles and hand offs; a work instruction covers one person doing one task, often with screenshots or a checklist. Most small organisations do not need the extra layer, and adding it early tends to produce three documents saying the same thing in slightly different words.

Should every policy have a procedure?

No. Some policies are self executing, such as one that simply prohibits something. A procedure is worth writing when the rule requires several people to act in sequence, when timing matters, or when the steps produce a record somebody will later be asked to produce. Writing procedures for the rest is how policy libraries become unmaintainable.

Make one with documents

The button opens the generator with this use case already described. Change the wording to match your own.

Create a document with OneCraft

Related questions

Step by step in the builder: Create a document with AI, then Every document component and when to use it.

Sources

Written and checked by the OneCraft team. Last checked .