What it means
A policy states what must happen and why, while a procedure explains the steps involved. Keeping the two separate is useful, because the principle changes rarely but the mechanics change every time a system or supplier does.
Policies matter commercially because they convert individual judgement into a repeatable standard. Without them, expense approval, discount authority and supplier onboarding depend on who happens to be asked, which produces inconsistent decisions and unpleasant surprises.
They also form the backbone of the internal control environment that auditors, insurers and regulators examine. A documented delegation of authority, a clear conflict of interest policy and a data protection policy are frequently the first things an external reviewer asks to see.
The practical test of a policy is whether an average employee can find it, understand it and follow it under time pressure. Anything that fails that test is theatre, and worse, it creates the false impression that a risk is being managed.
Most organisations maintain a policy register with an owner and a review date for each document, typically refreshed annually or when legislation changes. The discipline that matters is retiring policies that no longer apply, because a bloated policy library is read even less than a short one.
Enforcement is the part most often neglected. A policy only changes behaviour when someone monitors compliance, applies a consequence when it is ignored, and can point to a case where a senior person was held to the same standard as everyone else.
In practice
Real-world examples.
Example
A growing agency introduces a travel and expense policy setting a $75 dinner limit, a receipt requirement above $25 and a fourteen-day submission deadline. Monthly expense processing time falls sharply because finance stops adjudicating individual claims by email, and managers can approve against a written standard instead of a hunch.
Example
A healthcare services firm adopts a data protection policy specifying what personal data may be stored, for how long, where it may be held and who may access it. When a large client's security questionnaire arrives midway through a competitive tender, the answers already exist in a form the team can cite. The bid is submitted on time while a rival asks for an extension.
Example
A manufacturer sets a delegation of authority policy requiring two signatures on any purchase order above $10,000 and board approval above $250,000. A duplicate order for $48,000 of components is caught at the second signature before it is placed. The policy pays for itself in a single afternoon.
Think of it
“Company policy is the rules you follow-formal guidelines for how to behave or decide.
Case study
Seen in the real world.
Camberwell Fitters is an illustrative, fictional shopfitting contractor with 90 staff and, by its own admission, no meaningful policy set. Discounting decisions sat with whichever director a salesperson reached first, and expense claims were approved on trust.
Two problems arrived in the same quarter. A client disputed a $40,000 variation because nobody could show who had authorised it or on what basis, and an internal review found that a supervisor had been claiming personal fuel for eighteen months, a total of around $9,000. Neither loss was large on its own, but both were entirely avoidable and both were embarrassing to explain to the bank.
The response was deliberately modest rather than a full policy manual: four documents, each under two pages, covering delegation of authority, expenses, variation approval and conflicts of interest, each published on the intranet with a named owner and an annual review date. Staff were walked through all four in a single half-hour session rather than asked to read them alone. In this fictional example the finance director's own view was that the documents mattered less than the fact that the managing director's expenses went through the same approval route as everyone else's, which is what made the rules credible.
Watch out
Common mistakes.
- Writing policies nobody can find. A policy stored in an unlabelled folder on a shared drive provides documentation but no actual control.
- Mixing policy and procedure in one long document. When the software changes, the whole thing needs rewriting, so it usually is not rewritten at all.
- Applying policies selectively to junior staff. Nothing destroys the authority of a rule faster than a visible exception granted at the top.
Questions
People also ask.
How often should policies be reviewed?
Annually as a default, and immediately when relevant law, systems or the structure of the business changes.
What is the difference between a policy and a procedure?
A policy sets the rule and its purpose, while a procedure gives the step-by-step instructions for complying with it.
Do small companies really need written policies?
Yes, at least for expenses, authority limits, data handling and workplace conduct, because these are precisely the areas where an informal approach creates the largest financial and legal exposure, and because customers and insurers increasingly ask to see them.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%