Controls
Policies, Procedures, Controls and Evidence
How the main building blocks of a compliance system differ and connect.
Why this matters
How the main building blocks of a compliance system differ and connect.
Policy
A policy states the organization’s expectation, rule or principle. It should identify scope, authority, responsibilities, exceptions and consequences. It should not pretend to be a detailed work instruction.
Procedure
A procedure explains how work is performed: steps, systems, roles, inputs, approvals, handoffs and records. Procedures should match the current process rather than the process designers wish existed.
Control
A control is a specific activity that prevents, detects or corrects a compliance failure. Examples include approval thresholds, automated validation, reconciliations, exception reports, restricted access and supervisory review.
Evidence
Evidence demonstrates that the procedure or control operated. It may include logs, signed approvals, reports, tickets, system records, meeting minutes, attestations or retained communications. Evidence should be identifiable, retrievable and protected from inappropriate alteration.
Traceability
Strong programs connect the obligation to the policy, procedure, control, evidence and owner. This chain lets the organization explain not only what it intends to do, but how it knows the requirement is being met.
Questions to document
- Which obligations and processes are in scope?
- Who owns the activity and who independently reviews it?
- What record demonstrates that the activity operated?
- What happens when the control fails or circumstances change?
Related planning tools
Use the local planning tools to turn the concepts into a structured working note.