Policy and procedure template

A policy says what the rule is and why. A procedure says who does what, in which order, to follow it. Put both in one document, with the rule on top and a numbered step table underneath, and people stop asking HR how the policy actually works.

Use this format for any rule that needs steps behind it: expenses, equipment requests, access to client systems, travel, data handling. For a short statement with no steps, such as a dress code, the policy half on its own is enough.

[COMPANY NAME]
[POLICY TITLE]

Policy number: [POLICY NUMBER]
Category: [POLICY CATEGORY]
Version: [VERSION NUMBER]
Effective from: [EFFECTIVE DATE]
Policy owner: [POLICY OWNER]
Approved by: [APPROVER NAME AND TITLE]
Next review: [REVIEW DATE]

1. PURPOSE
[ONE-PARAGRAPH PURPOSE]

2. SCOPE
Applies to: [WHO IT APPLIES TO]
Does not cover: [WHAT SITS IN ANOTHER POLICY]

3. DEFINITIONS
[TERM]: [MEANING IN THIS POLICY]
[TERM]: [MEANING IN THIS POLICY]

4. POLICY STATEMENT
4.1 [RULE]
4.2 [RULE]
4.3 [RULE]

5. PROCEDURE
Step | What happens | Who does it | Time limit | Record kept
1 | [ACTION] | [ROLE] | [TIME LIMIT] | [RECORD]
2 | [ACTION] | [ROLE] | [TIME LIMIT] | [RECORD]
3 | [ACTION] | [ROLE] | [TIME LIMIT] | [RECORD]
4 | [ACTION] | [ROLE] | [TIME LIMIT] | [RECORD]
5 | [ACTION] | [ROLE] | [TIME LIMIT] | [RECORD]

6. ROLES
Role | Responsibility under this policy
[ROLE] | [RESPONSIBILITY]
[ROLE] | [RESPONSIBILITY]

7. EXCEPTIONS
Who may approve an exception: [EXCEPTION APPROVER]
How to ask: [EXCEPTION ROUTE]

8. WHAT HAPPENS IF THE POLICY IS NOT FOLLOWED
[CONSEQUENCE]

9. RELATED DOCUMENTS
[RELATED POLICY OR FORM]
[RELATED POLICY OR FORM]

10. VERSION LOG
Version | Date | Changed by | What changed
[VERSION NUMBER] | [CHANGE DATE] | [EDITOR NAME] | [CHANGE SUMMARY]

ACKNOWLEDGEMENT
I have read and understood [POLICY TITLE], version [VERSION NUMBER].
Name: [EMPLOYEE NAME]    Signature: [SIGNATURE]    Date: [DATE]

What to put in each blank

[POLICY NUMBER]
Give every policy a short code, such as FIN-03, and never reuse one. Your staff and auditors will quote the number, not the title.
[POLICY CATEGORY]
File it under one of a handful of fixed groups, such as workplace conduct or compensation and benefits, so your people can find it by browsing.
[ONE-PARAGRAPH PURPOSE]
Say in two or three sentences what goes wrong without this rule. A purpose that only repeats the title gives nobody a reason to follow it.
[WHAT SITS IN ANOTHER POLICY]
Name the neighbouring policy that covers the edge case, so your two documents never give two answers.
[RULE]
Write one rule per line, starting with a verb or a must. If you need a paragraph to explain a rule, it probably needs its own step in section 5.
[ACTION]
Describe a single action, such as "submits the request form". Two actions in one step means two steps.
[TIME LIMIT]
Enter a real deadline in working days, such as 2 days. A step with no time limit is the step where requests sit for a month.
[RECORD]
Say what proof the step leaves behind: a form, an approval email, a ticket, a signed copy.
[CONSEQUENCE]
State plainly what follows a breach, and point to your disciplinary procedure rather than restating it.
[CHANGE SUMMARY]
Write what changed in one line, such as "approval limit raised for team leads". Readers of version 4 need to know what's new since version 3.

Before you send it

  • Write the procedure with the person who does the work, not for them. They know which step gets skipped, and the table should close that gap.
  • Keep one owner per policy. When you get a question, you know whose inbox it goes to, and the review date has someone to chase it.
  • Use the same format for every policy you have. Once your team knows that section 5 always holds the steps, they'll read the steps first.
  • Publish every version in one place staff can reach, and remove old copies from shared drives. The version people follow is the one they find first.

PeopleMuster keeps every company policy in one place with a category, a slug, a summary and its last editor, and HashBot answers staff questions from the published text.

Questions people ask about this letter

What is the difference between a policy and a procedure?

A policy states the rule and the reason for it; a procedure lists the steps people take to follow it. "Expenses need approval before purchase" is policy. "Submit the form, the lead approves within two days, finance pays on the next run" is procedure.

What should a policy and procedure document include?

At minimum: purpose, scope, the rules, the procedure steps with an owner for each, and a version log. Most companies also add definitions, exceptions, consequences and a signed acknowledgement, as in the template above.

How often should policies be reviewed?

Review each policy at least once a year, and straight away when the process, the team or the tools behind it change. Put the next review date on the document so the owner has a deadline.

Should policies and procedures be separate documents?

Keep them together for most internal rules, because your staff read the rule and then want the steps. Split them only when the procedure is long or changes far more often than the rule above it.