Governance & Compliance

Having a policy is not the same as implementing it.

Policies are useful only when people understand them, responsibilities are clear and the organisation actually follows them.

Published September 13, 2026 Reading time 3 minutes By Naleli Innovations
Need help with this? Talk to us →

Most organisations have policies. Fewer have policies that anyone reads, and fewer still can show that a policy is being followed. When a client, an auditor, a funder or a regulator asks, the question is never “do you have a policy?” It is “show me that it works.”

A policy is a statement of intent

Take a line that appears in many information-security policies: “user access must be reviewed regularly.” It sounds responsible. It also answers none of the practical questions. Who reviews access? How often? Where is the record of the last review? Who checks that the review actually happened? Until those questions have answers, the policy manages nothing.

From policy to evidence

Practical compliance follows a simple chain. Each link is a decision somebody has to make and write down.

  • Policy. What the organisation intends: access is reviewed regularly.
  • Responsibility. Who owns it: the person responsible for user accounts.
  • Process. How it happens: every quarter, a list of users is pulled, checked against staff records and signed off.
  • Control. What stops it slipping: a calendar reminder, a template, a second person who checks.
  • Evidence. What proves it: the signed quarterly list, filed where it can be found.
  • Review. Whether it is working: someone looks at the evidence and the exceptions and adjusts the process.

When all six links exist, the policy is implemented. When any link is missing, you have a document.

Why this matters for small and growing organisations

Growth brings more information, more customers, more suppliers and more obligations. Privacy law applies to a small organisation that holds personal information just as it applies to a large one. Funders and corporate clients increasingly ask for evidence, not assurances. The organisations that cope are not the ones with the thickest policy folder; they are the ones that made responsibilities clear and kept simple records.

A policy nobody understands does not manage risk. A checklist completed once a year does not make an organisation compliant.

A practical way to start

Choose the three policies that matter most for your organisation right now. For each one, fill in the chain: responsibility, process, control, evidence, review. Where a link is blank, that is your action. Where evidence exists but nobody can find it, that is your filing job. Do this over a 90-day cycle rather than in one exhausting week, and it will still be true in six months.

Be clear about scope, too. Implementing a policy is not the same as legal advice, an external audit or certification. Where those are required, involve the right professionals. What you can do yourself is make the policy real inside the organisation, which is where most of the value is.

If you would like support

This is the practical side of Governance, Risk & Compliance at Naleli Innovations: turning requirements into responsibilities, processes, controls and evidence that an organisation actually uses. If you are growing, taking on new clients or facing new requirements, start with the biggest gaps.