HomeKnowledge CenterFrom Written Rules to Working Governance

From Written Rules to Working Governance

Why a published policy is not enough, and how a written rule becomes working governance through four ingredients: authority, decisions, processes and behavior.

16 Jun 2025RAISO Experts Team

From Written Rules to Working Governance

The new policy goes up on the intranet, an email reaches everyone, the meeting applauds, and people go back to work. Three months later someone asks whether the policy has changed anything. There is a short silence. Everybody knows it exists. Few know what happened after that.

In this article we follow one case from start to finish and learn the difference between having a policy and having governance. A policy is a written rule. Governance is what happens when that rule meets a real decision, a real person and real pressure. You will leave with four ingredients that turn any policy into practice you can see in daily work: a named authority, mapped decisions, processes that carry the policy, and behavior led from the top. Each section ends with a small exercise, and the end of the article gives you questions to test a real policy in your own organization.

Hind and a policy that was published but not applied

“You will follow Hind and her spending pre-approval policy. In every section we will see what was missing, what we added, and how her situation changed. At the end we put the first picture next to the last.”

— What will you take from this article?

Hind runs support services in a mid-sized, hypothetical organization. Three months ago a new policy was approved, titled “Spending Pre-Approval.” Its central sentence says that any spend above ten thousand riyals needs written approval before the commitment is made. Hind supported the policy, helped draft it, attended the approval session, and felt relieved to see the document carry its stamps.

Today she sits in the quarterly review. The internal auditor asks a simple question: how many requests went above ten thousand riyals this quarter, and how many had prior approval? Hind knows the first number is twenty-one. When she counts the second from the files, she finds only fourteen. Seven requests were paid for before anyone signed, and some were signed after the invoice arrived.

Nobody broke the policy on purpose. One employee had an air-conditioner fail in the server room and bought a replacement part in a hurry. Another had a contract renewing that same day and renewed it. A third split one large order into three small ones, because he assumed the policy spoke about a single request, not the total being bought. Each had a reasonable explanation.

What mattered more is that no one knew what to do when the policy collided with the work. There was no one to ask, no ready decision for an emergency, and no step in the system that stopped an order from passing without approval. The document said what should be. It built nothing to make it happen.

The review meeting: what the numbers said - Requests above ten thousand riyals this quarter at Hind's organization.
Illustrative numbers

“The organization did not neglect the policy. The policy simply found no one to carry it to each desk.”

“Hind, the organization and the numbers here are written for illustration only and do not refer to any real entity.”

— A hypothetical case

Hind leaves the meeting with one question in her head: what was missing from the policy, when we left no box empty? That question is the subject of this whole article.

“Five minutes, now: pick a policy your organization approved in the past year. Write on a sheet: what changed in the work after it was approved? If no answer comes quickly, that is your starting point.”

— A short experiment

Why a written rule is not enough

Look at what happened. The document is sound, the central sentence is clear, the approval is complete. Yet seven requests passed without approval. Where does the fault lie?

The policy described the destination and did not build the road. We write policies in the language of hope: must, ought, the organization commits. That language expresses will, but will alone moves nobody under pressure. The employee whose air-conditioner failed does not read the policy. He looks around: who can approve right now? Will the system let me buy? What happens to me if I wait?

Why requests pass despite the policy - Under pressure, the employee does not read the policy. He looks around.

Those three questions are what actually shape behavior, and a published policy answers none of them. That is why we say a policy starts the work and does not finish it. Publishing is the moment of birth. Life comes from other things built around it.

The difference between policy and governance

In this article “governance” has a simple meaning: governance is the arrangement that makes a written rule actually happen in the work. The policy is part of it, but not all of it. Think of a traffic sign. The sign is a rule, but the signal, the curb, the camera, the fine and the habit are what make drivers stop. Leave the sign alone and half the drivers will run it.

That is why some organizations seem to have many policies and little discipline, while others have few policies and high discipline. The first wrote the rules. The second built what carries them.

Three signs that you have a policy but not governance:

  • People know the policy by its title only, and most cannot say what it asks of them.
  • Violations are found in later audits, not at the moment they happen.
  • Each manager answers the hard case in his own way, because the document did not settle it.

“In the case now: Hind saw that her problem was not how the policy was worded. The wording is good. The problem is everything that was not built around it.”

— Hind’s case

“Write one sentence describing how your organization knew yesterday that a particular policy was being followed. If the sentence is “we did not know,” record it.”

— Apply it now

Working governance: four ingredients

What does a written text need before it becomes behavior? If you sat with Hind for three days and analyzed every request that passed without approval, you would arrive at the same list any organization reaches when it examines this question. Four things. If they come together, the policy works. If one is missing, it wobbles.

The four ingredients in brief:

  1. Authority

    One person, named, is accountable for the policy’s results and holds real power to enforce it. Writing “the finance department” is not enough.

  2. Decisions

    The policy states how hard trade-offs are settled, who decides, when the matter escalates, and within what time.

  3. Processes

    Daily workflow is redrawn so that following the policy is the easiest route, not the hardest.

  4. Behavior

    Leaders practice the policy in front of people, exceptions are visible, and adherence is reviewed in ordinary operating meetings.

Four ingredients, four silent questions - Every employee asks these. When the answers are clear, compliance becomes ordinary.

Notice the order. Authority answers: who is responsible? Decisions answer: what do we do when things conflict? Processes answer: how does it happen every day? Behavior answers: do we live what we wrote? Every employee asks these questions silently, and when the answers are clear, compliance becomes ordinary.

You do not have to build all four in one week. What matters is knowing which one is absent in your policy. Hind will now examine the spending policy ingredient by ingredient, and we will follow her through the next sections.

“A policy without authority is an orphan, without decisions it is helpless, without processes it is perfect only on paper, and without behavior it is decoration: the auditor sees it and the results do not.”

— Summary of the ingredients

“In the case now: Hind drew four boxes and wrote under each: what do we have? She found she had a document and little else. All four boxes were nearly empty.”

— Hind’s case

“Draw four boxes titled with the ingredients, and write under each what actually exists for a policy you know. Leave the empty ones empty.”

— Apply it now

Authority: who owns the policy’s results?

The problem authority solves is simple: when everyone is responsible, no one is. In the spending policy it was written that “the finance department” handles follow-up. But the finance department has twelve people, and none knew that follow-up had become part of his job. So no one called the employee who bought the air-conditioner part to ask about approval.

Authority is more than a name at the foot of a document. It is three things together: responsibility for the result, ability to take enforcement decisions, and standing to bear the consequences. If one is missing, the policy owner becomes either a clerk who follows up but owns nothing, or a manager who owns but never follows up.

How to do it

  1. Name the policy owner by name and position.

    One person, not a committee. A committee may help him, but responsibility is not divided.

  2. Write what the owner can do without asking permission.

    For example: reject a request, stop a payment, ask for a written explanation, escalate to the general manager.

  3. Write what the owner is answerable for.

    A monthly report on the number of exceptions and their causes, sent to whoever holds higher authority.

  4. Announce it to people.

    When employees know who owns the policy, they know where to go when in doubt.

Do not worry if the right owner sits below the head of the department. What matters is that his authority is written and known, and that someone above backs it. Authority that nobody supports collapses at the first resistance.

“In the case now: Hind agreed with the finance director to name Salman, head of financial control, as owner of the spending policy. He can now stop any payment that lacks approval, and he submits a monthly report on exceptions. Hind sent everyone a short email: this is the person you ask about the policy.”

— Hind’s case

“Write the name of the owner of a policy you know and three things he can do without permission. If you find no name, that is the first step.”

— Apply it now

Decisions: who settles it when things collide?

A policy works well on ordinary days. The real test comes on the day when two things the organization wants collide: keeping the controls and keeping the business running. A failed server-room air-conditioner will not wait three days. A policy that does not tell the employee what to do at that moment leaves him to decide alone, and then holds him to account for his decision.

This is what we mean by decisions: not decisions of top management, but the small repeated decisions that appear at the edges of a policy. The best way to prepare them is to ask: which three or four cases make this policy collide with the work? Then write a ready answer for each.

Hind's hard cases and their ready rules
CaseWho decidesRule and deadline
Emergency failure halts a serviceHead of affected departmentBuy at once, log within 24 hours, owner reviews next day
Split ordersPolicy ownerSame-supplier requests within 30 days count as one
Auto-renewing contractPolicy ownerRaise request 45 days ahead, no renewal without approval

For each case: who decides, what the rule is, and by when.

How to do it

Collect the five worst cases from last quarter. Do not search for imaginary ones, look for ones that happened. Then write four things for each: who decides, within how many hours, what is documented, and where it escalates if not settled.

Hind’s three cases after she analyzed them:

  • Emergency: a failure halts a service. The head of the affected department decides to buy immediately, the request is logged within twenty-four hours, and the policy owner reviews it the next day.
  • Split orders: requests to the same supplier within thirty days are treated as one request when the threshold is calculated.
  • Auto-renewing contracts: the renewal request is raised forty-five days before the date, and nothing renews automatically without approval.

This may look like a small detail, but it is the difference between a policy that punishes an employee for a decision he was forced to make and one that gives him a legitimate way to act. When the hard case is written down, the employee does not have to choose between compliance and work, because the policy chose the road for him.

Note that the decision does not cancel the principle. An emergency does not remove approval. It delays it by one day and documents it. In this form the policy is preserved and the work continues.

“In the case now: The policy now has three rules for hard cases. When another air-conditioner failed a month later, the employee bought the part, logged the request the same day, and Salman approved it in the morning. Nobody phoned anybody in anger.”

— Hind’s case

“Name three hard cases from a policy you know and write for each: who decides and within how many hours.”

— Apply it now

Processes: make compliance the easiest road

When an employee faces two options, one taking a quarter of an hour and the other three minutes, which does he choose? We do not need research to know. People lean toward the road of least resistance, even when they know it is wrong. That is not a flaw in employees. It is human nature, and work must be designed around it.

At Hind’s organization the approval request was a two-page form, printed and signed by three people, taking at least two days. The purchase order in the system took two minutes and never asked about approval. The system itself told the employee: buy now, nobody is required. The organization had built, with its own hands, the easiest road for breaking its own policy.

How to do it

Start with one question: where does the policy pass through the workflow? Then look at each step: can the employee skip it without anyone noticing? Is the compliant step slower than the skipped one? Then work on three things:

  1. Put the control inside the step itself.

    Make the approval-number field mandatory in the purchase order. The order does not save without it. Compliance then does not depend on anyone’s memory.

  2. Shorten the compliant road.

    Turn the two-page form into one page and allow approval with a tap on a phone. The goal is that complying takes less time than getting around the rule.

  3. Make violations visible.

    An automatic weekly report of requests that crossed the threshold, reaching the policy owner without his searching for it.

None of this has to become a huge technical project. Some of it can be done in a day, by a manager’s decision. The idea is what matters: when a policy is built into the workflow itself, it stops being something added to the work and becomes part of it.

“The employee who complies because the easy road is the right one needs no reminders. The one who complies out of fear needs a permanent watcher.”

— A thought to hold

“In the case now: A purchase order in the system no longer saves without an approval number. Hind cut the form to one page, and approval became a tap. A month later no request above the threshold passed without approval, and no one complained of slowness, because approval had become faster than the old road.”

— Hind’s case

“Pick one step in a policy you know that an employee could skip. Write how you would make it mandatory inside the workflow.”

— Apply it now

Behavior: what leaders do and what meetings reveal

What happens when the general manager asks for an urgent purchase by phone message and writes: “Do it now, we will tidy the paperwork later”? The employee learns a lesson stronger than every policy: rules apply to everyone but me. And that lesson spreads through the organization within a week.

Behavior is the hardest ingredient because it cannot be written in a document. You cannot write “leaders set the example.” Example is seen in small moments: what does the manager do when the rule conflicts with his speed? Does he accept being asked? Are exceptions shown or hidden?

In our case a direct request reached Hind on her phone from an assistant general manager: buy this today, fourteen thousand riyals. She had to choose between courtesy and the separation she had learned on this journey.

How to do it

Three things create behavior without speeches:

  • A calm ready reply: “I will do it now. Send it to me through the form and I will approve it within minutes.” No accusation and no delay, but no exception without a trace.
  • A fixed item in the monthly operating meeting titled “Exceptions”: how many passed, why, and do we need to amend the policy or the behavior?
  • A public story: when a leader keeps the policy at a costly moment, the story is told. People learn from stories more than from clauses.

The exceptions item has a curious effect. An exception discussed openly becomes rarer, because no one likes to be the reason for the item. And an exception that repeats becomes a signal: perhaps the policy itself needs amending. In this way the policy becomes a living thing that learns from reality.

“In the case now: Hind answered the assistant general manager with the same calm sentence. He sent the request in two minutes and Salman approved it in ten. At the next meeting the finance director asked about the exceptions item and found the count this month was zero. That is what behavior says when it works.”

— Hind’s case

“What sentence do you say when your superior asks you to bypass a rule? Write it calmly, without accusing anyone.”

— Apply it now
Test your governance: four questions each quarter
#IngredientQuestionCompliantPartly compliantNon-compliant
1AuthorityCan any employee name the policy's owner without looking it up?
2DecisionsIn a hard case, do we find a written answer instead of phoning someone?
3ProcessesDoes the system stop an employee from violating the policy unnoticed?
4BehaviorWas the last exception discussed in an operating meeting, with a decision?

Ask them about one policy and tick the closest answer.

Test your governance: four questions and one page

After Hind built the four ingredients, she needed a way to know whether they worked. A feeling that things are better is not enough. She found the easiest way was four questions, one per ingredient, which she asks herself every three months.

The test questions:

  1. Authority:

    Can any employee say the name of this policy’s owner without looking it up?

  2. Decisions:

    When a hard case occurs, do we find a written answer, or do we phone someone?

  3. Processes:

    Can an employee violate the policy without the system noticing?

  4. Behavior:

    When was the last time an exception was discussed in an operating meeting, and what was decided?

After the questions comes a single page, pinned on the policy owner’s board: the policy in one sentence, the owner’s name, the hard cases and their answers, the step the process enforces, and the next review date. One page read in two minutes that answers most of what people ask.

Remember that the goal is not perfection. The goal is to know where you stand. An organization that knows its third ingredient is weak is better off than one that believes all four are fine. It is normal to find one ingredient lagging in every review, because governance is continuing work, not a project that ends.

“In the case now: Three months later Hind returned to the review meeting. The auditor asked the same question. This time the answer was: twenty-two requests above the threshold, twenty-two with prior approval, three of them under the emergency rule and documented the same day. The policy is the same, without a new word. But the organization now has governance.”

— Hind’s case

“Run the four questions on one policy in your organization and write the answers on one sheet. This is your first page for the final exercise.”

— Apply it now
The same policy: before and after - Not one word of the document changed. Everything around it did.

Before and after

Let us place the two pictures side by side to see what changed and what stayed. The policy stayed as it was: the same central sentence, the same threshold, the same approval. What changed is everything around it.

Before: a published policy

  • Responsibility is written under a department’s name, and no one knows it is theirs.
  • Hard cases are settled by each employee alone and then judged.
  • The system allows purchase without approval, and the form is long and slow.
  • Exceptions are discovered months after the fact in an audit.

After: working governance

  • Salman owns the policy by name, with power to stop payments and a monthly report.
  • Three hard cases have ready rules and set deadlines.
  • The approval field is mandatory, the form is one page, approval is a tap.
  • Exceptions are a fixed item in the operating meeting, and leaders comply in front of everyone.

Notice that nothing changed in the original document. That is the central idea of this article: the problem is not always the policy, which may be very good. The problem is that we think writing is the end of the work, when it is the beginning.

And do not think this means longer policies or more procedures. Everything Hind did could be written in two pages. But those two pages carry what eleven pages of fine drafting do not, because they say who, when, how and why people act in this way.

“A policy says what we want. Governance makes sure it happens, even when we are not looking.”

— A central idea

What do you take with you?

Five ideas that sum up the journey:

  • A policy is a written rule. Governance is what happens when the rule meets decisions, people and pressure.
  • Working governance has four ingredients: a named authority, mapped decisions, processes that carry the policy, and behavior led from above.
  • When one ingredient is missing the policy becomes decoration: the auditor sees it and the results do not.
  • Make compliance the easiest road, because people follow least resistance even when they know it is wrong.
  • Test your governance every three months with four questions, and record it on one page.

If you return to where we began, you will find that Hind’s question was never: is our policy well written? It was: what do we do so that it happens? That is the question that separates an organization with a tidy file from one with a way of working.

If you want to practice this method with specialists and translate it into a real policy in your organization, this is exactly what RAISO’s policy management practice works on. Explore the practice, reserve a seat in the course linked to it, and start with one policy to which you apply these four questions.