Skip to main content
Category: Compliance Program Frameworks

Standards and Procedures

Also known as: Policies and Procedures, Standard Operating Procedures
Simply put

Standards and procedures are the written rules and step-by-step methods an organization sets so employees know what to do and how to do it to stay in line with company policy. Standards state the required courses of action or controls, while procedures describe the specific steps for carrying them out. Together they translate high-level policy into concrete, mandatory expectations for day-to-day conduct.

Formal definition

Within a compliance program, 'standards and procedures' refers to the layered documentation that operationalizes policy: standards specify the required, often uniform courses of action, rules, and controls that enforce a policy, and procedures prescribe the routine, mandatory methods for performing designated tasks in support of those standards. Standards commonly function as standalone requirements defining what personnel must do to adhere to policy, whereas procedures define the 'how', the prescribed methods to be followed routinely. As one component of a broader compliance and ethics program, standards and procedures are distinct from the overarching code of conduct, risk assessment, training, monitoring, and reporting functions, and are directed primarily at adherence to internal and external requirements rather than at values-based ethical judgment. Note that the precise structure, terminology, and hierarchy (policy versus standard versus procedure versus guideline) vary by organization and framework; this entry is educational and not a substitute for professional or legal advice.

Why it matters

Standards and procedures are the layer that turns a compliance program's aspirations into daily practice. A policy or code of conduct may state that the organization prohibits a category of conduct or requires a control, but without written standards specifying what personnel must do and procedures specifying how to do it, employees are left to interpret expectations on their own. This documentation gives staff concrete, mandatory reference points, and it gives the organization a basis for consistent enforcement, training, and monitoring.

Because standards and procedures are only one component of a broader compliance and ethics program, their presence alone does not demonstrate that a program is effective or that misconduct will be prevented. Written rules that are outdated, inaccessible, poorly communicated, or inconsistently applied may support little in practice. Their value depends on implementation: whether they are current, understood, actually followed, and integrated with training, monitoring, and reporting functions rather than existing as documents on a shelf.

It is also important to recognize what standards and procedures are not. They are directed primarily at adherence to internal and external requirements, not at the values-based judgment that ethics programs address. Terminology and hierarchy, policy versus standard versus procedure versus guideline, vary considerably by organization and framework, so readers should not assume a single universal structure. Where these documents touch legal obligations that vary by jurisdiction, qualified legal counsel should be consulted.

Who it's relevant to

Compliance officers and ethics program managers
These readers are responsible for ensuring that high-level policy is translated into concrete, mandatory expectations. Standards and procedures give them the operational documentation employees rely on and a reference point for consistent enforcement, but they should treat this documentation as one component of a broader program rather than as evidence of program effectiveness on its own.
Legal and audit teams
Legal and audit staff assess whether written standards and procedures are current, accurate, and consistently followed. Because these documents may touch obligations that vary by jurisdiction and are directed at adherence to internal and external requirements, matters implicating legal risk should be reviewed with qualified counsel rather than resolved from the documentation alone.
Learning and development staff
Those who design and deliver training use standards and procedures as source material for what employees must do and how to do it. Because these documents define mandatory methods, training can reinforce them, but training is a distinct program element, and its inclusion of a procedure does not by itself ensure the procedure is understood or followed in practice.
Operational managers and process owners
Managers who own day-to-day tasks depend on procedures to specify the prescribed, routine methods their teams must follow, and on standards to define the controls those procedures support. They are often best positioned to identify where documented steps diverge from actual practice and to flag when standards or procedures need updating.

Inside Standards and Procedures

Written policies
Formal, documented rules that define expected conduct and prohibited behavior for the organization. These typically operationalize the higher-level commitments expressed in a code of conduct into specific requirements.
Procedures
The step-by-step processes that describe how policies are to be carried out in practice, such as how to seek approvals, report concerns, or handle conflicts of interest. Procedures translate stated standards into repeatable actions.
Code of conduct linkage
Standards and procedures generally flow from and support an organization's code of conduct, which sets overarching values and expectations. The code is a distinct program element; standards and procedures give it operational detail.
Risk-based tailoring
Standards and procedures are intended to be shaped by the organization's specific risk profile, identified through a risk assessment. Content should reflect the legal, regulatory, and operational risks relevant to the business rather than being generic.
Assignment of responsibility
Provisions that identify who is accountable for applying, maintaining, and enforcing each standard or procedure, clarifying ownership within the compliance program structure.
Review and update mechanism
A process for periodically reviewing and revising standards and procedures so they remain current with changing laws, regulations, and organizational circumstances. Standards and procedures are not intended to be static.

Common questions

Answers to the questions practitioners most commonly ask about Standards and Procedures.

Do standards and procedures by themselves constitute a compliance program?
No. Standards and procedures are one component of a compliance program, not the whole of it. They typically work alongside other elements such as a governance and oversight structure, risk assessment, training and communication, monitoring and auditing, reporting mechanisms, and enforcement and discipline. Treating written standards as equivalent to a full program is a common misconception; documented standards that are not supported by these other functions are generally regarded as insufficient. Because expectations vary by jurisdiction and framework, confirm specific programmatic requirements against primary sources and qualified counsel.
Are standards and procedures the same thing as a code of conduct?
They are related but distinct. A code of conduct commonly articulates an organization's values and high-level expectations, which can sit toward the values-based ethics end of the spectrum, while standards and procedures are the more detailed, operational rules and steps that direct how specific requirements are met, oriented toward compliance with defined policies, laws, and regulations. A code often functions as an umbrella document, with standards and procedures providing the specificity needed to apply it. Conflating the two can obscure the difference between stated principles and the concrete controls intended to implement them.
How detailed should standards and procedures be?
The appropriate level of detail generally depends on the underlying risk and the audience. Procedures addressing higher-risk activities are commonly written with greater specificity so that expected actions are unambiguous, while lower-risk areas may be stated more generally. The aim is to give the people performing a task enough guidance to act consistently without creating documentation so voluminous that it is not read or followed. Detail that reflects the organization's actual risk profile is generally regarded as more defensible than a one-size-fits-all approach. Because suitable detail is context-dependent, this should be calibrated with input from relevant subject-matter and legal expertise.
How often should standards and procedures be reviewed and updated?
Standards and procedures are generally treated as living documents rather than fixed once issued. Common practice is to review them on a defined cycle and also in response to triggering events such as changes in applicable law or regulation, findings from monitoring and auditing, results of a risk assessment, organizational changes, or identified incidents. The specific cadence is a matter of organizational judgment and any applicable requirements, so intervals and triggers should be confirmed against the frameworks that apply to your organization and with qualified counsel where legal obligations are involved.
Who should be responsible for drafting and approving standards and procedures?
Responsibility is commonly shared across functions rather than held by a single role. Subject-matter owners in the relevant business area often contribute operational content, compliance and legal functions review for consistency with applicable requirements and internal policy, and an appropriate level of management or governance typically approves the final documents. Assigning clear ownership for maintenance is generally regarded as important so that documents do not become outdated. The exact allocation of drafting, review, and approval authority depends on organizational structure and, where legal obligations are implicated, should involve qualified counsel.
How can an organization tell whether its standards and procedures are actually being followed?
Written standards indicate expected conduct but do not demonstrate adherence on their own; that is generally assessed through separate monitoring and auditing activities, which are distinct program components. These functions can help identify gaps between documented procedures and actual practice, and their findings may feed back into revising the standards themselves. Communication and training are typically needed so that affected personnel are aware of and understand the procedures, though awareness alone does not establish compliance. Because this glossary entry is educational and not a substitute for professional advice, approaches to measuring adherence should be tailored to your context and applicable requirements.

Common misconceptions

Having written standards and procedures means an organization has an effective compliance program.
Standards and procedures are only one component of a broader compliance program that also includes elements such as training, risk assessment, monitoring and auditing, reporting channels, and enforcement. Documentation alone does not establish effectiveness, which depends on implementation and context.
Standards and procedures are the same thing as a code of conduct.
A code of conduct sets out overarching values and expectations, while standards and procedures provide the specific rules and operational steps that implement those expectations. They are related but distinct elements of a program.
Once adopted, standards and procedures do not need to change.
Standards and procedures are generally expected to be reviewed and updated over time to reflect changes in applicable laws, regulations, and the organization's risk profile. Treating them as fixed can leave the program outdated.

Best practices

Base standards and procedures on a documented risk assessment so their content reflects the organization's actual legal, regulatory, and operational risks rather than generic language.
Ensure standards and procedures clearly connect to and operationalize the code of conduct, keeping the two consistent while recognizing they are distinct program elements.
Assign clear ownership for applying, maintaining, and enforcing each standard or procedure so accountability is explicit.
Establish a defined schedule and process for periodic review and update to keep standards and procedures aligned with changing laws and business circumstances.
Write procedures with enough operational detail that employees understand the specific steps expected of them, and integrate them with training and reporting channels rather than relying on documentation alone.
Where standards touch obligations that vary by jurisdiction or involve legal interpretation, consult qualified legal counsel, as this glossary content is educational and not a substitute for professional advice.