Policy vs Process vs Procedure: What’s the Difference?

Every organization runs on three kinds of documents: policies, processes and procedures. People often use the words interchangeably, but they do different jobs. Mixing them up leads to policies that read like instruction manuals, procedures nobody can find, and compliance gaps that only show up during an audit.

This guide explains what each one is, how they fit together, and how to tell them apart, with worked examples from HR, healthcare and IT. It is written for compliance officers, HR managers and IT administrators who write, own or enforce these documents.

The short answer

  • A policy is a formal rule or guideline that sets out what the organization expects and why. It tells people what must (or must not) happen.
  • A process is the sequence of stages that turns an input into an outcome, such as hiring a new employee or onboarding a customer. It shows what happens, in what order, and who is involved.
  • A procedure is the step-by-step instruction for carrying out one specific task within a process. It tells a person exactly how to do the work.

Put simply: the policy sets the rule, the process maps the journey, and the procedure gives the directions for each step.

Policy vs process vs procedure at a glance

Policy Process Procedure
Answers What and why What happens, in what order, and who is involved How, step by step
Level of detail Broad and high level Medium: stages and handoffs Detailed and task specific
Usually owned by Senior leadership, legal, HR or compliance Department or process owners Team leads and the people who do the work
How often it changes Rarely, usually after a law, regulation or strategy change When the way work flows between people or teams changes Often, whenever a system, tool or task changes
Typical format Written statement with scope, responsibilities and consequences Flowchart, swimlane diagram or stage list Numbered steps, checklists, screenshots, SOPs
Example “All new hires must complete a background check before their start date.” Recruitment: advertise, shortlist, interview, offer, pre-employment checks, start “How to request and record a background check in the HR system”

What is a policy?

A policy is a formal rule, requirement or guideline that explains the standards the organization expects everyone to follow. Policies reflect the organization’s goals and values, as well as the laws and regulations it has to meet. They are usually approved at senior management or board level.

A good policy states its purpose, who it applies to, what is required, who is responsible, and what happens if it isn’t followed. It does not try to explain every step of how the work gets done. That is the job of processes and procedures. For a fuller definition, see our guide on what policies are and why they matter.

Common examples include a code of conduct, an equal employment opportunity policy, a data protection policy, a health and safety policy and an acceptable use policy for IT systems. If you are building out your set, this list of essential organizational policies is a useful starting point.

What is a process?

A process describes the series of stages needed to reach a business outcome, such as hiring someone, delivering a service or closing a financial period. It gives an overview of the workflow: what happens first, what happens next, who is responsible at each stage and roughly how long each stage should take.

Processes often cross team boundaries. A recruitment process, for example, may involve the hiring manager, HR, finance and IT. Every process must operate within the rules the relevant policies set. A process is usually easiest to understand as a diagram, because its main value is showing the order of stages and the handoffs between people.

What is a procedure?

A procedure is the most detailed of the three. It gives step-by-step instructions for performing one specific task inside a process, written clearly enough that anyone with the right access and training can follow it and get the same result.

Procedures are where consistency is won or lost. If two people do the same task in different ways, one of them may be breaking a policy without realizing it. Clear procedures reduce errors, make training faster and give auditors something concrete to check against.

Where SOPs and work instructions fit

A standard operating procedure (SOP) is a formally controlled procedure, typically used for tasks that must be done the same way every time, often in regulated settings. Work instructions go one level deeper still, covering a single action at a single workstation or screen. Both sit under the procedure layer. If your SOPs aren’t being followed, the cause is often one of these common problems organizations have with SOPs, and these ten steps for rolling out SOPs in SharePoint can help fix them.

How policies, processes and procedures fit together

Think of the three as layers, each one supporting the one above it:

  1. Policy sets the rule and the reason for it.
  2. Process maps the stages needed to follow that rule in day-to-day work.
  3. Procedure spells out how to complete each task within those stages.

A single policy may be supported by several processes, and a single process may contain many procedures. When a policy changes, work down through the layers and check whether each related process and procedure still matches. This is where many organizations slip: the policy is updated, but the procedures employees actually use still describe the old way of working.

Examples of policies, processes and procedures

HR example: recruitment

  • Policy: The organization recruits on merit and provides equal employment opportunity, without discrimination on the basis of any protected characteristic.
  • Process: Advertise the role, screen applications against the job criteria, shortlist, interview, make an offer, complete pre-employment checks and confirm the start date.
  • Procedure: How to complete pre-employment checks, including confirming the offer and salary in writing, verifying eligibility to work in the United States, requesting references and recording the results in the HR system before the start date.

Healthcare example: medication administration

  • Policy: Only qualified, authorized clinical staff may administer medication to patients.
  • Process: Receive and store medication securely, authorize staff to administer it, administer it according to the prescription, and record and review every administration.
  • Procedure: Step-by-step instructions for administering a specific medication, including checking the patient’s identity and the prescription, giving the correct dose by the correct route, and documenting it in the patient record.

IT example: user access

  • Policy: Employees are given access only to the systems and data they need for their role, and access is removed promptly when it is no longer needed.
  • Process: Access request, manager approval, provisioning, periodic access review and removal when an employee changes role or leaves.
  • Procedure: How an IT administrator adds a new user to the correct Microsoft 365 security groups, confirms multi-factor authentication is set up and logs the change ticket.

Policy vs procedure: the difference people confuse most

The most common mix-up is between policies and procedures, because both are written documents that people are expected to follow. A quick test helps:

  • If the document says what is required and why, it is a policy.
  • If the document says how to do a task, one step after another, it is a procedure.

Keeping them separate has practical benefits. Policies stay short and stable, so they only need formal re-approval when something significant changes. Procedures can then be updated as often as systems and tools change, without sending the whole policy back through senior approval.

Tips for writing each one

  • Policies: Keep them short and use plain language. State the purpose, scope, requirements, responsibilities and consequences. Include an owner, an approval date and a review date. Our free policy and procedure template for Microsoft Word gives you a consistent layout to start from.
  • Processes: Map them visually, name an owner for each stage, and mark where work passes from one person or team to another.
  • Procedures: Write numbered steps in the order they happen, start each step with a verb, and add screenshots or checklists where they help. Test the procedure by asking someone new to follow it.
  • All three: Link each document to the ones above and below it, so people can see which policy a procedure supports and which procedures carry out a policy.

Keeping policies and procedures up to date

Documents that are out of date are a compliance risk in their own right. Set a review date for every policy, and review sooner when a law, regulation, system or role changes. Use version control so you can show which version was in force on any given date, and retire old versions so employees can’t open the wrong one.

If your documents live in SharePoint, these best practices for policy change management in SharePoint cover versioning, naming and approval. For larger organizations with many policy owners, see our guide to scaling policy management with governance frameworks.

Making sure employees read and understand them

Writing a good policy or procedure is only half the job. You also need to get it in front of the right people and be able to show that they have read it. Emailing a link and hoping for the best leaves no evidence when an auditor, regulator or court asks who knew about a rule and when.

That is the problem Collaboris built DocRead to solve. DocRead for Microsoft 365 and SharePoint Online lets you:

  • Send policies and procedures to the right audiences based on role, department, location or group membership
  • Ask employees to read and formally acknowledge each document
  • Send automated reminders and escalate overdue acknowledgements to managers
  • Track completion by document or by user, and see each person’s acknowledgement history
  • Keep your documents in your existing SharePoint libraries, with version control and audit trails

Frequently asked questions

Which comes first: the policy, the process or the procedure?

The policy. It sets the rule the process and procedures must follow. In practice, organizations often document an existing process first and then realize a policy is needed to formalize it, but the finished set should always trace back to a policy.

Is an SOP a policy or a procedure?

An SOP is a procedure. It describes how to carry out a task in a standard, controlled way. It supports a policy but does not replace one.

Can a process exist without written procedures?

Yes, but it is risky. Without written procedures, each person does the task their own way, training takes longer and it is hard to show an auditor how the work is meant to be done.

Who should own each document?

Policies are usually owned by senior leaders or by functions such as HR, legal, compliance or IT. Processes are owned by the manager responsible for the outcome. Procedures are best written by, or with, the people who actually do the task.

How often should policies and procedures be reviewed?

Many organizations review policies on a fixed cycle, such as once a year, and review procedures whenever the task or system changes. Any change to a relevant law, regulation, system or role should trigger an earlier review. Check any regulatory requirements that apply to your industry for specific review periods.

Conclusion

Policies, processes and procedures are all essential, and each has its own job. Policies set the rules and the reasons behind them, processes map how work flows from start to finish, and procedures give people clear instructions for each task. Keep them separate, link them together, review them regularly, and make sure you can show who has read them. That way, your documents do more than sit in a library: they shape how work actually gets done.