How Long Should Policies Be?

Organisations often produce long, detailed policy documents designed to cover a topic or activity comprehensively. These unified or combined super policies have a range of attractions. They cover every eventuality in one document, can be applied across the whole organisation, and mitigate risks around policy proliferation and version control.

But this approach masks a bigger problem: it misses the point of what policies are for, and creates it’s own risks too.

 

 

What is a Policy?

A policy is a formal statement of an organisation’s intentions, principles, and expectations about a particular issue. It explains what the organisation is committed to, why it is important, and what standards of behaviour or outcomes are expected. It provides a framework for decision-making and consistent action but does not usually describe every operational detail.

For example:

  • A Data Protection Policy states the organisation’s commitment to complying with the UK GDPR and Data Protection Act 2018, protecting personal data, and ensuring staff understand their responsibilities.
  • A Bullying and Harassment Policy states that bullying and harassment will not be tolerated, explains the standards of behaviour expected, and outlines the organisation’s commitment to dealing with complaints fairly.

How Should Policies Be Structured?

A good policy generally answers these questions:

  1. What is the purpose?
    • Why does the policy exist?
    • Which risks or objectives does it address?
  2. What is the organisation’s position?
    • What commitments is the organisation making?
    • Which principles will guide decisions?
  3. Who does it apply to?
    • Employees?
    • Contractors?
    • Volunteers?
    • Board members?
  4. Key responsibilities
    • What are managers expected to do?
    • What are employees expected to do?
    • Are there specialist roles (such as a DPO or HR)?
  5. What are the consequences of non-compliance?
    • Disciplinary action?
    • Legal consequences?
    • Reporting obligations?
  6. How will the policy be reviewed?
    • Who owns it?
    • How often is it reviewed?

The Difference Between Policy and Procedure

Importantly, a policy is not the same as a procedure.

Policy Procedure
States what the organisation intends to do Explains how to do it
Sets principles and expectations Gives step-by-step instructions
Relatively stable Updated whenever processes change
Approved by senior management or the Board Usually owned by operational managers

For example:

Data Protection Policy

  • We will process personal data lawfully, fairly and transparently.
  • We will implement appropriate technical and organisational security measures.
  • Individuals’ rights will be respected.
  • Staff must complete appropriate training.

Subject Access Request Procedure

  • Record the request.
  • Verify identity.
  • Locate relevant information.
  • Review exemptions.
  • Prepare the response.
  • Respond within one month.

Similarly:

Bullying and Harassment Policy

  • The organisation has zero tolerance for bullying and harassment.
  • Everyone has the right to be treated with dignity and respect.
  • Managers must address inappropriate behaviour promptly.

Bullying and Harassment Procedure

  • How to report concerns.
  • How complaints are investigated.
  • Timescales.
  • Appeal process.
  • Confidentiality arrangements.

Find out more about the difference between and function of policies and procedures here.

A useful definition

A definition that works well across most governance disciplines is:

A policy is a formally approved statement that sets out an organisation’s intentions, principles, and expectations regarding a particular area of activity. It establishes the standards that everyone must follow and provides the framework within which procedures, guidance, and day-to-day decisions are made.

This distinction is particularly important in governance disciplines such as GDPR, information governance, risk management, conflicts of interest, and HR. Policies define the “what” and “why”, while procedures define the “how”. Many organisations blur the two, creating long documents that mix principles with operational instructions. Keeping them separate makes policies easier to understand, approve, review, and maintain.

What Are The Issues With Long Policies?

Long policies are very difficult to navigate. Even if they are well structured and have a thorough table of contents and even an index it is hard to understand a document if you need to jump between different sections to find the answers to your questions.

Secondly longer documents are harder to understand. A fifty page document will not be retained, at least in detail, in people’s memories and is much more likely to be misinterpreted or misapplied when compared to a focussed, role or department specific procedure. In our experience most people simply do not read very long policy documents because the length is offputting (in much the same way that people don’t really read the long terms and conditions attached to services they sign up for).

Lengthy policies are often as large as they are because they try to cover every scenario or outcome, but that is not possible. The unexpected or unforeseen will always occur. It is more important that people understand in general terms their responsibilities, and where to go for help, when confronted with new or unusual situations.

Finally long policies are much harder to apply and hold people to account with. It is much easier for people to argue they could not be expected to understand such complex, wide ranging documents, when they are difficult to navigate and apply to the context they are working in.

The Best Approach

The best approach is for organisations to have as few policies as possible and make them as short as possible. So long as they cover the key content set out above then specific scenarios or particular roles, teams or departments can be covered by more detailed, but focused procedural documents and guidance.

Despite being lower level than policies, people are still accountable for following these documents and they will still be overseen by executive leadership, audit functions and (where applicable) regulators. They can be owned and managed by subject matter experts and are more easily kept up to date as things change. When it comes to policies, less is more.