Organisational policies and procedures are the practical framework that helps an organisation operate consistently, responsibly and efficiently. They clarify what the organisation stands for, how decisions should be made, who is responsible for particular actions and what employees should do in common or sensitive situations.
They are relevant to every organisation, from a small Kenyan enterprise with five employees to a large non-governmental organisation, school, health facility, bank or public institution. However, policies and procedures are valuable only when they are clear, realistic, accessible and applied fairly. A document that sits in a file but does not guide behaviour is not effective management.
What Are Organisational Policies and Procedures?
An organisational policy is a formal statement of principle or intention. It sets direction and explains the organisation’s position on an issue. For example, a policy may state that the organisation is committed to fair recruitment, responsible use of company resources, protection of confidential information or a workplace free from harassment.
An organisational procedure explains the specific steps people must follow to put a policy into practice. A recruitment procedure might describe how a vacancy is approved, advertised, shortlisted, interviewed and documented. A procurement procedure might explain how suppliers are selected, quotations are compared and purchases are authorised.
The distinction can be expressed simply:
- Policy: what the organisation believes, requires or intends.
- Procedure: how people carry out the requirement in practice.
Policies usually allow some judgement because they describe principles. Procedures tend to be more detailed because they guide actions. Both are needed. A policy without a procedure may be too vague to apply, while a procedure without a policy may become a mechanical process disconnected from organisational values and objectives.
Why Policies and Procedures Matter
They create consistency
Without agreed guidance, similar situations may be handled differently by different managers. One supervisor may approve leave informally, while another may demand extensive documentation. One employee may be disciplined for a particular action, while another is ignored for doing the same thing. Clear policies and procedures reduce arbitrary decisions and make expectations more predictable.
They support accountability
Good procedures identify who is responsible for an action, who has authority to approve it and what records should be kept. This makes it easier to trace decisions and identify where a process failed. Accountability does not mean blaming people automatically; it means ensuring that responsibilities are understood and that decisions can be reviewed.
They protect people and organisational resources
Policies can help protect employees, customers, beneficiaries, suppliers and the organisation itself. Guidance on workplace conduct, safeguarding, data handling, financial controls, health and safety, conflicts of interest and complaints management reduces avoidable harm and supports responsible behaviour.
They improve efficiency
When routine processes are documented, employees do not need to reinvent the same process each time. A new staff member can follow an approved workflow, and managers can spend less time answering recurring operational questions. Procedures can also reveal unnecessary approvals, duplicated work and delays.
They support organisational culture
People learn what an organisation values not only from speeches but also from its systems. A clear conflict-of-interest policy signals integrity. A transparent complaints procedure signals that concerns will be taken seriously. A performance management procedure signals that feedback and development should be handled deliberately rather than through surprise or favouritism.
Common Types of Organisational Policies
The exact policy set depends on the organisation’s size, sector, risks and activities. Common categories include:
- Governance policies: decision-making authority, board responsibilities, delegation and conflicts of interest.
- Human resource policies: recruitment, induction, attendance, leave, performance management, discipline, equal opportunity and workplace conduct.
- Financial policies: budgeting, expenditure approval, cash handling, financial reporting, asset management and fraud prevention.
- Procurement policies: purchasing thresholds, supplier selection, approval requirements and separation of duties.
- Information and technology policies: acceptable technology use, passwords, data access, records management and incident reporting.
- Health, safety and wellbeing policies: risk prevention, emergency response, workplace safety and employee wellbeing.
- Customer or beneficiary service policies: service standards, complaints handling, confidentiality and accessibility.
- Environmental and social responsibility policies: responsible resource use, community impact and ethical conduct.
An organisation should resist the temptation to create a policy for every possible situation. Too many documents can create confusion, especially when they overlap or contradict one another. The better approach is to identify important risks, recurring decisions and behaviours that require consistent guidance.
What Makes a Policy Effective?
An effective policy should be linked to a real organisational need. Before drafting, ask what problem the policy is intended to address, whose behaviour it will guide and what could happen if no guidance exists. A policy should also align with the organisation’s strategy, values, internal structure and applicable professional or legal obligations.
Clear language is essential. Avoid unnecessary technical terms, vague expressions and overly complex sentences. For example, a statement such as “staff must deal with expenses appropriately” is difficult to apply. A clearer policy would explain that employees must claim only legitimate business expenses, provide required evidence and obtain approval through the stated process.
A practical policy normally includes:
- Purpose: why the policy exists.
- Scope: who and what it applies to.
- Definitions: explanations of important terms, where needed.
- Policy statement: the organisation’s main position or requirement.
- Roles and responsibilities: who implements, approves, monitors and reviews it.
- Related procedures or documents: instructions, forms, templates or guidelines.
- Exceptions and escalation: how unusual cases are handled.
- Approval and review information: the owner, approval date, version and next review date.
The policy should also be proportionate. A small business may need a straightforward purchasing policy with clear approval limits rather than a lengthy document designed for a multinational corporation. Good management matches the level of control to the organisation’s actual risks and capacity.
Designing Procedures That People Can Follow
Procedures should be written from the user’s perspective. The person performing the task should be able to understand what triggers the process, what information is required, which steps come next, who approves the action and what record must be retained.
A useful procedure often follows this sequence:
- Identify the trigger: explain when the procedure starts, such as when a customer complaint is received or a purchase is requested.
- Gather the required information: list forms, documents, evidence or approvals needed.
- Complete the main steps: use numbered actions in the order they should occur.
- Assign responsibility: identify the role responsible for each significant step.
- Specify decision points: explain what happens if an application is incomplete, a risk is identified or approval is refused.
- Record and follow up: state how the action is documented and how unresolved matters are monitored.
For example, a small wholesaler in Nairobi might create a stock-reordering procedure. The procedure could require the storekeeper to check stock levels weekly, complete a requisition, obtain approval from the operations manager, request quotations where appropriate, confirm delivery quantities and update the stock record. The related procurement policy would explain the organisation’s principles on value, authorisation and fair supplier treatment.
Procedures should not hide important decisions behind unexplained instructions. If staff are told to obtain three quotations, the document should explain when this is required and what to do when fewer suitable suppliers are available. Practical exceptions make procedures more useful because real work rarely follows a perfect pattern.
Developing Policies and Procedures: A Step-by-Step Approach
1. Identify the need
Review recurring problems, audit findings, customer complaints, operational delays, incidents and strategic priorities. Speak with the people who perform the work. They often understand practical risks that senior managers may not see.
2. Map the current process
Document what currently happens, including informal practices. This helps distinguish the desired process from the actual process. It may also expose duplicate approvals, unclear authority or dependence on one individual’s knowledge.
3. Consult relevant stakeholders
Involve managers, employees, finance or human resource staff, technical specialists and other affected groups. Consultation improves accuracy and increases the likelihood that people will accept the final document. It should not become an excuse for indefinite delay; the responsible leader should set a clear timetable.
4. Draft in plain language
Separate principles from instructions. Use headings, short paragraphs, numbered steps and examples where they clarify the process. Avoid writing a procedure that depends on knowledge not available to the intended user.
5. Check risks and consistency
Compare the draft with other policies and existing organisational practices. Check for contradictory approval limits, unclear terms or responsibilities assigned to roles that do not exist. Where the subject involves employment, finance, safety, data or another regulated area, obtain appropriate specialist advice rather than assuming that a general template is sufficient.
6. Approve and control the document
Each document should have a named owner and an authorised approver. Record its version, effective date and review date. Remove obsolete copies from shared folders and noticeboards so that employees do not rely on outdated instructions.
7. Communicate and train
Publishing a policy is not the same as implementing it. Explain what has changed, why it matters and what employees must do differently. Training may be a short briefing for a simple process or a more detailed session for issues such as safeguarding, financial controls or emergency response. Managers need particular support because they apply policies in daily decisions.
8. Monitor, learn and revise
Use feedback, process data, incidents, complaints and internal reviews to determine whether the policy is working. A policy should be updated when the organisation changes its systems, structure, services or risk profile. Review dates are useful, but an important event may require an earlier review.
Implementation Challenges and How to Address Them
A common challenge is the gap between formal rules and operational reality. If a procedure requires five approvals for a low-value purchase, employees may bypass it because it is impractical. The answer is not simply to punish non-compliance; managers should examine whether the process is proportionate and whether staff have the tools and authority needed to follow it.
Another challenge is selective enforcement. A policy loses credibility when senior employees ignore it or when managers apply it differently according to personal relationships. Leaders must model the expected behaviour and document exceptions transparently.
Language and accessibility also matter. Where employees work in multilingual or highly diverse environments, important guidance may need to be explained orally or supported with translated materials, visual steps or examples. Digital publication is useful, but it should not exclude staff who have limited access to organisational systems.
Finally, policies can become outdated. An organisation may continue using a process designed for paper records after moving to digital systems, or retain approval arrangements that no longer match its structure. Assigning ownership to a specific role helps prevent documents from being forgotten.
Applying This in Practice
When reviewing one policy or procedure, use the following questions:
- What specific risk, inconsistency or operational need does this document address?
- Can the intended users understand it without asking the author to explain every step?
- Does it clearly distinguish mandatory requirements from guidance or recommendations?
- Are roles, approval levels and escalation routes realistic?
- Does the process create unnecessary delay, duplication or cost?
- How will employees learn about it, and what evidence will show that it is being followed?
- Who owns the document and when will it be reviewed?
For an entrepreneur, the first priority may be a small set of essential policies covering finances, people, customer information, workplace conduct and delegated authority. For a larger organisation, the priority may be to rationalise overlapping documents, strengthen version control and connect policies to risk management and performance monitoring.
The most useful test is practical: give the document to a competent employee who has not helped write it and ask them to complete the relevant task. Observe where they hesitate, make assumptions or reach a dead end. Their questions reveal where the policy or procedure needs clarification.
Key Takeaways
- Policies state organisational principles and requirements, while procedures explain the steps for applying them.
- Effective documents are clear, proportionate, accessible, owned by a responsible role and linked to a real organisational need.
- Consult the people who perform the work so procedures reflect operational reality rather than assumptions.
- Approval, version control, communication and training are essential parts of implementation.
- Apply policies consistently, document genuine exceptions and ensure leaders model the required behaviour.
- Review policies after organisational changes, incidents or evidence that the process is no longer working.
No comments yet.