
By Thomas Hamata
Many organisations do not suffer from a shortage of policies. In fact, many have exceptionally well-written policies, aligned with recognised standards and approved through the appropriate governance structures.
Yet the outcomes those policies were intended to produce are often not visible in practice.
This is one of the most persistent challenges in organisational governance: the gap between policy intent and implementation.
A policy may clearly define how risks should be managed, how information should be protected, how procurement decisions should be made or how employees are expected to conduct themselves.
However, the existence of a policy does not necessarily mean that the people expected to comply with it understand it, know how it applies to their work or have been equipped to implement it.
The policy may be excellent. The implementation environment may not be.
Closing this gap requires organisations to look beyond policy approval and consider how policies are translated, communicated, embedded and monitored. This article addresses three practical considerations that can help organisations move policies from paper into practice.
1. Translate policy requirements into practical procedures
Policy approval should be viewed as the beginning of implementation, not the end. Once a policy has been approved by the relevant governance structures, it may be uploaded onto an internal platform, circulated by email or presented during employee induction. Employees may also be required to acknowledge that they have read and understood it. However, acknowledgement is not evidence of understanding, and understanding is not evidence of implementation.
Policies are often written by specialists in risk, compliance, legal, information technology, human resources or governance. Those expected to apply them are specialists in their professions. It is therefore unreasonable to assume that every employee will interpret a requirement in the same way as its authors.
This is where standard operating procedures become essential. Policies establish principles, expectations and boundaries, while procedures explain how those expectations should be carried out in practice. They should set out who must act, what must be done, when it must happen, which approvals are required and what evidence must be retained.
2. Explain the “why” and “how” through mandatory refresher training
Training is another important bridge between policy intent and practical adherence. However, effective training must go beyond reading policy clauses, presenting rules or explaining prohibited conduct. It should help employees understand both why a policy exists and how they are expected to apply it in practice.
Policy training should be mandatory and, where possible, delivered through accessible e-learning platforms that allow completion to be tracked. It should also be interactive, engaging and memorable, using practical examples, scenarios and decision points rather than relying only on passive presentations.
Training should be tailored to the employee’s role and operating context, rather than being generic and unrelatable. Employees in different functions may be subject to the same policy, but the actions expected of them may differ. Training should also be periodic rather than once-off, with regular refreshers that keep requirements visible and provide opportunities for employees to ask questions or raise areas where a policy may be difficult to apply.
3. Embed policy requirements into controls
Policies are unlikely to become part of everyday operations unless their requirements are embedded into organisational processes and controls. A control is a practical mechanism that helps ensure that a policy requirement is followed. It may take the form of an approval, management review, system restriction, reconciliation, checklist or monitoring report.
For every significant policy requirement, the organisation should determine what control will help ensure that the intended action occurs consistently. It is not enough merely to document the control. The organisation must establish who owns it, how frequently it should operate, what evidence it should produce and how failures will be identified and addressed. It must also document these attributes in a control register.
Controls should also be independently tested periodically to confirm that they are appropriately designed and operating as intended. Without such testing, management may assume that a policy has been implemented simply because a control has been documented or assigned. This is the essence of policy embedment: moving requirements from the page into the systems, processes and routines through which the organisation operates.
When non-compliance occurs, organisations often move quickly to consequence management. However, where the root cause is unclear procedures, inadequate training or weak controls, punishment alone will not solve the problem. Another employee is likely to make the same mistake.
This is why good governance cannot be measured simply by the number of policies an organisation has. It must be measured by whether those policies are properly implemented and whether they inform day-to-day decisions, guide behaviour and enable the effective execution of daily operations.








