Effective documentation: How to get the corporate policies under control

Effective documentation: How to get the corporate policies under control

Your organization’s policies are the foundation of your corporate governance system. If you need to prove that your organization is effectively governed, you need to be able to demonstrate that your policies are under control—

  • There is no doubt about which policies are currently in effect, nor about which policies were in effect at any time in the past. (In the event of an accident or incident, the organization may be called upon to produce them.)
  • You have records to prove that employees are familiar with the policies relevant to their work.
  • There is an assigned accountability for each policy, and a documented procedure defining that accountability, to ensure that each policy is communicated and implemented effectively, non-compliance is detected, and performance is measured and reported.
  • You have a formal method to ensure that the organization has all—and only—the policies it needs.
No alt text provided for this image

Setting up a policy management system is not difficult. Here is one way to do it—


1. Make an inventory of the existing policies

Make a list of all the documents with ‘policy’ in the title or listed somewhere under a Policies heading. Check who created them, how old they are, what’s in them, and—if there’s any way to know—how often they get looked at.

It’s not uncommon to find multiple sets of ‘policy documents’—

  • Board-approved policies, under the control of the company secretary or general counsel.
  • Policies used by HR as part of the induction for new employees.
  • Framed statements about safety, quality, and environment on the wall in the office foyer, read only by visitors while they wait.

It’s also common to find shared-drive folders called Policies with large numbers of extraneous documents in them (2,400 in one organization we helped): prior and alternative versions, drafts-in-progress, supporting notes, implementation procedures, forms. Valuable information, no doubt, but not documents you’d want to be defending if your corporate governance system were under investigation.


2. Define what ‘policy’ means in your organization

Some organizations use ‘policy’ loosely, for any guideline intended to help employees make decisions. Others use ‘policy’ strictly for Board-issued statements of corporate intent. A strict definition is easier to manage for corporate governance purposes—

  • A policy articulates a governance objective.
  • A policy authorises the use of organization resources.
  • A policy establishes management accountability: someone has responsibility for implementing the policy and will be held to account if the objective is not achieved.
  • A policy may authorise employees to act outside the normal chain of command (for example, a safety policy may authorise any employee to halt an activity if they think it dangerous).

There is no ‘right’ definition of policy (although there are plenty of wrong ones). The important point is that you have a definition. In general, the more precise the definition, the fewer policies you will have; and the fewer policies you have, the simpler and more effective will be your corporate governance. If a document is merely a guideline for employees, then call it a ‘guideline’.

Your definition will determine, in turn, who may issue a policy: Board only? Senior management team? Any manager?


3. Establish what policies you need

Map your policies against your governance objectives. Every governance objective should be supported by a policy; every policy should support a governance objective. This mapping is not necessarily one-to-one. You might have a single sustainability governance objective, implemented through separate policies for health, safety, and environment.

  • If you have a governance objective with no supporting policy, there is a policy missing.
  • If you have a policy that does not support a governance objective, then either there is an unstated governance objective, or the policy is unnecessary.

Management system standards like ISO 9001 and ISO 14001 mandate the existence of a supporting policy.


4. Create a register

There should be no doubt about which policies are in effect at any time. A folder called ‘Policies’ on a shared drive is not sufficient. At a minimum, your register should show—

  • ID number
  • Status: draft, current, superseded, withdrawn
  • Date issued
  • Accountability
  • Approved by (if the policy is Board-approved, this should be a reference to the meeting record)

In the event of an accident or investigation, the organization may be called on, as a matter of document discovery, to produce every policy that was in effect at a given date. With an effective register, this is trivial; without, this could be an expensive embarrassment.

For the same reason, policies should have ID numbers. Policies are sometimes renamed: the Policy on A, B, and C is re-issued as the Policy on B, C, and Q. Without ID numbers, it might be difficult to prove that the earlier policy is not still in effect.


5. Spell out what it means to be accountable for a policy

It’s not enough for a policy simply to make a statement about the organization’s good intentions. For every policy there needs to be a position or team accountable for giving effect to the policy. The details and procedures of this accountability should be spelled out in the policy management system. This accountability might cover—

  • Determining what the policy means in the context of the organization’s actual activities.
  • Planning, budgeting, and managing the actions necessary to implement the policy.
  • Verifying compliance and reporting performance.
  • Detecting and reporting non-compliance.
  • Annual review


6. Create awareness and notification procedures

You should be able to prove that your people are aware of the policies with which they must comply. This means—

  • Induction: new employees, and employees moving to a new position, must be made aware of the policies relevant to their work.
  • Notification: all affected employees must be notified if a new policy is issued or an existing policy is updated or withdrawn.
  • Annual review: it is prudent to require all employees to confirm, annually, that they have reviewed the relevant policies.

Some organizations use a written Policy Acknowledgement form (‘I have read and understood these policies….’) to be signed by new employees as part of their induction, and by all employees as part of their annual review.

No alt text provided for this image

Contact me on +61 409 606 899 or [email protected] if you'd like to see how policy management works using Phrontex.

Founder Principal Consultant

STRATEGY | PROJECT DEPLOYMENT | BSC & EA | CAPABILITIES | CMMI | INTELLIGENCE | DISRUPTION & AGILITY | IMPROVEMENT & QUALITY | ECOSYSTEM SPINUP | UX-Rex/CI-DevOps Community | 4.0 Industry & Technology | FabLab & Startup

5 年

Employees and managers play all the time with rules and procedures respect and apply to match with work and environment constraints. Policies and instructions must be open to agility, not closed, but you would say me it's difficult to be compliant status if you turn/spinup all the time around it... Reality is this.

回复
Tim Hainsworth

Volunteer and Adviser

5 年

So true we are undertaking this critical analysis and review right now - a timely piece.

回复

要查看或添加评论,请登录

George Kesteven的更多文章

  • Why is most corporate documentation so awful?

    Why is most corporate documentation so awful?

    Most organizations have a terrible time with their policy and procedure documentation. Most corporate documentation is…

    3 条评论
  • How to build a governance management system

    How to build a governance management system

    The core purpose of an organization’s knowledge management — its system for creating, maintaining, and communicating…

    4 条评论
  • The meanings and measures of corporate governance

    The meanings and measures of corporate governance

    The term ‘corporate governance’ is used with a wide variety of meanings. It’s taken for granted that ‘good governance’…

    1 条评论
  • Why is corporate documentation so bad?

    Why is corporate documentation so bad?

    The traditional approach to documentation, as a collection of separate documents, cannot work. This is not an…

    2 条评论
  • Knowledge management: Taming the compliance requirements

    Knowledge management: Taming the compliance requirements

    Most compliance requirements, taken individually, are relatively straightforward. Time-consuming and expensive perhaps,…

    1 条评论
  • Results of the documentation benchmarks survey

    Results of the documentation benchmarks survey

    Over the past few months we have conducted a number of surveys asking people about documentation management in their…

    5 条评论
  • The two meanings of 'quality'

    The two meanings of 'quality'

    The word ‘quality’ is used in a lot of ways. In the ISO 9000 world, uses of the word sometimes verge on mysticism…

    10 条评论
  • Integrated compliance: how to make it work

    Integrated compliance: how to make it work

    Every organization has a primary objective. For a business, this is usually commercial performance: returning a profit…

    1 条评论
  • Dealing with the documentation disaster

    Dealing with the documentation disaster

    Most documentation goes unread, for good reason: most documentation isn’t worth reading. It is rare to find an…

    3 条评论

社区洞察

其他会员也浏览了