Writing policies people actually follow
Somewhere on almost every company’s shared drive there’s a folder of policies. They were written with good intentions, probably by someone who no longer works there. Most staff have never opened them. A few have signed to say they read them, which is not the same thing at all.
This is shelf-ware: documents that exist to be pointed at rather than used. They give a false sense of security, because the business believes it has addressed something it hasn’t. When something goes wrong, a policy nobody follows offers no protection whatsoever — if anything it makes matters worse, since you’ve documented that you knew what should happen and it didn’t.
A good policy is different. It changes what people do. Here’s what separates the two.
What makes a policy useful
A useful policy answers a real question that real people actually have. That sounds obvious, but a great many policies exist because someone thought a business like this ought to have one — not because anyone was unclear about anything.
Before writing one, it’s worth asking: what decision does this help someone make? If you can’t answer, you may not need the policy. Genuine reasons include a real risk you need to manage, an obligation you have to meet, or a situation where people keep getting it wrong because nobody ever told them what “right” looks like.
A useful policy also tends to be short. There’s an inverse relationship between length and influence: the longer a document, the less likely anyone is to read it, and the less it shapes behaviour. Two clear pages will outperform twenty comprehensive ones every time.
Write it in plain English
Policies attract a peculiar register — passive, formal, faintly legal. “Employees are required to ensure that all such devices are maintained in an appropriately secure manner at all times.” Nobody talks like this, and importantly, nobody remembers it either.
Compare: “Lock your laptop when you leave your desk.” Same intent, and this one might actually happen.
Some things that reliably help:
- Use “you” and “we”. Address the reader directly rather than describing a hypothetical employee.
- Say what to do, not what to ensure. Verbs beat abstractions.
- Be specific. “Promptly” means different things to different people; a stated timescale doesn’t.
- Cut the throat-clearing. Pages of purpose and scope before any content lose the reader before you’ve started.
- Include the awkward bit. If there’s a genuine grey area, say so and explain who to ask. Pretending it’s simple is why people stop trusting policies.
A decent test: could someone follow this on their second day, without asking anyone? If not, it needs another pass.
Not sure whether your policies are doing anything useful? We can introduce an independent specialist to review them.
Get StartedOwnership and version control
Every policy needs a named owner — a person, not a department. The owner is responsible for whether it’s still accurate, still followed, and still needed. Without one, policies drift out of date silently, because nobody’s job includes noticing.
Version control matters more than it sounds. The classic failure is several copies of the same policy circulating — one on the drive, one in an old induction pack, one someone downloaded and emailed round eighteen months ago. Staff follow whichever they happen to have, and everyone is sincerely convinced they’re compliant.
The essentials are unglamorous but sufficient:
- One authoritative location — and everyone knows where it is.
- A version number and date on the document itself.
- The owner’s name, so people know who to ask.
- A short change note — what changed and when.
Keeping policies in a properly managed shared system rather than scattered across local drives and inboxes solves most of this by default. It’s a small part of what good managed IT does, but it removes a whole category of avoidable confusion — and it produces the version history an auditor will ask for.
Training and sign-off
Sending a document round and collecting confirmations that it’s been read is not training. It’s evidence collection, and fairly weak evidence at that, because everyone knows nobody read it.
That doesn’t make sign-off worthless — it has a real place, and you may well need the record. But treat it as the paperwork that follows understanding, not a substitute for it. Actual training means people encountering the policy where it applies: at induction, when their role changes, and in the moments when it matters. A five-minute conversation about the two situations people genuinely find confusing beats an hour of slides covering everything.
The clearest sign that training worked isn’t a signature. It’s that people ask better questions afterwards.
Review cycles that actually happen
Most policies carry a review date. Many carry a review date that passed some time ago, which is worse than having none — the document is now advertising its own neglect, and it’s often the first thing an auditor spots.
Reviews work when they’re owned and scheduled rather than aspirational. Put them in a diary, spread them out so you’re not reviewing everything in one grim January, and keep the review honest. A real review asks whether the policy still matches how the work is done — not whether the wording still scans.
Reviewing policies as part of your wider governance routine keeps them tethered to reality. And events should trigger reviews too: a new system, a change in what you do, a near miss, or an obligation that’s shifted.
Reviews should also be allowed to delete. If a policy no longer serves a purpose, retiring it is a legitimate and valuable outcome. A slimmer set of live, trusted policies is worth far more than a comprehensive library nobody believes in.
Avoiding shelf-ware
The difference between a policy that works and one that doesn’t is rarely the writing. It’s whether the policy describes something the business genuinely does, owned by someone who cares, kept current, and short enough to be read.
If you only change one thing, make it this: write fewer policies, and make each one describe reality. A business with five accurate policies is in a stronger position than one with forty that are quietly fictional.
Which policies you actually need depends on your sector, size and obligations — this is general guidance rather than legal or regulated advice, and requirements vary considerably. If you’d like an independent view on whether yours are fit for purpose, get in touch and we’ll introduce a vetted compliance and governance specialist. We’re an introducer rather than the adviser, so there’s no obligation and nothing for us to sell you.
FAQs
Common questions
As short as it can be while still answering the questions people actually have. Length is usually a symptom of trying to cover every conceivable situation rather than the ones that come up. If a policy runs to many pages, it's often several policies wearing a trench coat — or one that would be better as a short policy plus a separate procedure.
Yes, but understand what it does and doesn't give you. It records that a policy was issued and acknowledged, which you may well need. It doesn't tell you anyone understood or will follow it. Treat it as the paperwork that follows real training, not as the training itself.
Annually is a common default, but the honest answer is that it depends on how fast the subject changes — and that events should trigger reviews as much as the calendar. A new system, a change in what you do, a near miss or a shift in your obligations all warrant a look, whether or not the review date has come round.
Work out which one is wrong. Sometimes the practice has drifted and needs correcting; often the policy was never realistic and people found a sensible way round it. Both are worth knowing. What you shouldn't do is leave the gap open — a documented process the business visibly ignores is a genuine liability.
Related
Related services
Compliance & Governance
Health checks and risk reviews through an independent specialist introduction.
ExploreManaged IT Services
Shared systems, version history and access controls that keep documents current.
Explore Compliance & GovernanceBuilding a compliance culture
How to make the right thing the easy thing, so good practice doesn't depend on willpower.
ReadReady when you are
Make your policies work harder
Tell us what you’ve got and we’ll introduce an independent specialist to review it — free, and with no obligation.
Get Started