Organisations often produce long, detailed policy documents designed to cover a topic or activity comprehensively. These unified or combined super policies have a range of attractions. They cover every eventuality in one document, can be applied across the whole organisation, and mitigate risks around policy proliferation and version control.
But this approach masks a bigger problem: it misses the point of what policies are for, and creates it’s own risks too.

What is a Policy?
A policy is a formal statement of an organisation’s intentions, principles, and expectations about a particular issue. It explains what the organisation is committed to, why it is important, and what standards of behaviour or outcomes are expected. It provides a framework for decision-making and consistent action but does not usually describe every operational detail.
For example:
- A Data Protection Policy states the organisation’s commitment to complying with the UK GDPR and Data Protection Act 2018, protecting personal data, and ensuring staff understand their responsibilities.
- A Bullying and Harassment Policy states that bullying and harassment will not be tolerated, explains the standards of behaviour expected, and outlines the organisation’s commitment to dealing with complaints fairly.
How Should Policies Be Structured?
A good policy generally answers these questions:
- What is the purpose?
- Why does the policy exist?
- Which risks or objectives does it address?
- What is the organisation’s position?
- What commitments is the organisation making?
- Which principles will guide decisions?
- Who does it apply to?
- Employees?
- Contractors?
- Volunteers?
- Board members?
- Key responsibilities
- What are managers expected to do?
- What are employees expected to do?
- Are there specialist roles (such as a DPO or HR)?
- What are the consequences of non-compliance?
- Disciplinary action?
- Legal consequences?
- Reporting obligations?
- How will the policy be reviewed?
- Who owns it?
- How often is it reviewed?
The Difference Between Policy and Procedure
Importantly, a policy is not the same as a procedure.
| Policy | Procedure |
| States what the organisation intends to do | Explains how to do it |
| Sets principles and expectations | Gives step-by-step instructions |
| Relatively stable | Updated whenever processes change |
| Approved by senior management or the Board | Usually owned by operational managers |
For example:
Data Protection Policy
- We will process personal data lawfully, fairly and transparently.
- We will implement appropriate technical and organisational security measures.
- Individuals’ rights will be respected.
- Staff must complete appropriate training.
Subject Access Request Procedure
- Record the request.
- Verify identity.
- Locate relevant information.
- Review exemptions.
- Prepare the response.
- Respond within one month.
Similarly:
Bullying and Harassment Policy
- The organisation has zero tolerance for bullying and harassment.
- Everyone has the right to be treated with dignity and respect.
- Managers must address inappropriate behaviour promptly.
Bullying and Harassment Procedure
- How to report concerns.
- How complaints are investigated.
- Timescales.
- Appeal process.
- Confidentiality arrangements.
Find out more about the difference between and function of policies and procedures here.
A useful definition
A definition that works well across most governance disciplines is:
A policy is a formally approved statement that sets out an organisation’s intentions, principles, and expectations regarding a particular area of activity. It establishes the standards that everyone must follow and provides the framework within which procedures, guidance, and day-to-day decisions are made.
This distinction is particularly important in governance disciplines such as GDPR, information governance, risk management, conflicts of interest, and HR. Policies define the “what” and “why”, while procedures define the “how”. Many organisations blur the two, creating long documents that mix principles with operational instructions. Keeping them separate makes policies easier to understand, approve, review, and maintain.
What Are The Issues With Long Policies?
Long policies are very difficult to navigate. Even if they are well structured and have a thorough table of contents and even an index it is hard to understand a document if you need to jump between different sections to find the answers to your questions.
Secondly longer documents are harder to understand. A fifty page document will not be retained, at least in detail, in people’s memories and is much more likely to be misinterpreted or misapplied when compared to a focussed, role or department specific procedure. In our experience most people simply do not read very long policy documents because the length is offputting (in much the same way that people don’t really read the long terms and conditions attached to services they sign up for).
Lengthy policies are often as large as they are because they try to cover every scenario or outcome, but that is not possible. The unexpected or unforeseen will always occur. It is more important that people understand in general terms their responsibilities, and where to go for help, when confronted with new or unusual situations.
Finally long policies are much harder to apply and hold people to account with. It is much easier for people to argue they could not be expected to understand such complex, wide ranging documents, when they are difficult to navigate and apply to the context they are working in.
The Best Approach
The best approach is for organisations to have as few policies as possible and make them as short as possible. So long as they cover the key content set out above then specific scenarios or particular roles, teams or departments can be covered by more detailed, but focused procedural documents and guidance.
Despite being lower level than policies, people are still accountable for following these documents and they will still be overseen by executive leadership, audit functions and (where applicable) regulators. They can be owned and managed by subject matter experts and are more easily kept up to date as things change. When it comes to policies, less is more.
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: