Controls

Policies, Procedures, Controls and Evidence

How the main building blocks of a compliance system differ and connect.

Why this matters

How the main building blocks of a compliance system differ and connect.

Policy

A policy states the organization’s expectation, rule or principle. It should identify scope, authority, responsibilities, exceptions and consequences. It should not pretend to be a detailed work instruction.

Procedure

A procedure explains how work is performed: steps, systems, roles, inputs, approvals, handoffs and records. Procedures should match the current process rather than the process designers wish existed.

Control

A control is a specific activity that prevents, detects or corrects a compliance failure. Examples include approval thresholds, automated validation, reconciliations, exception reports, restricted access and supervisory review.

Evidence

Evidence demonstrates that the procedure or control operated. It may include logs, signed approvals, reports, tickets, system records, meeting minutes, attestations or retained communications. Evidence should be identifiable, retrievable and protected from inappropriate alteration.

Traceability

Strong programs connect the obligation to the policy, procedure, control, evidence and owner. This chain lets the organization explain not only what it intends to do, but how it knows the requirement is being met.

Questions to document

  • Which obligations and processes are in scope?
  • Who owns the activity and who independently reviews it?
  • What record demonstrates that the activity operated?
  • What happens when the control fails or circumstances change?

Related planning tools

Use the local planning tools to turn the concepts into a structured working note.

Educational limitation: This page explains general concepts. It does not determine legal duties, eligibility, coverage, tax treatment, immigration status or the correct action in a specific situation. Check current official sources and qualified advice where needed.