Are Approved Policies and Procedures Enough? The real challenge lies in implementation and oversight
Many business entities take pride in having a comprehensive set of policies, procedures, and operating manuals. These documents may be developed as per leading professional practices and formally approved by executive management or the Board of Directors. However, the more important question remains:
“Does the mere existence of these documents mean that employees are applying them in practice?”
As a matter of fact, many operational failures, regulatory breaches, fraud incidents, and even significant financial losses reveal that the problem was not the absence of policies and procedures, but rather weak implementation or non-compliance.
How many business entities possess a comprehensive Delegation of Authority (DOA) Matrix, yet practically allow authority limits to be bypassed? How many companies maintain clear procurement, risk management, or compliance procedures, while day-to-day decisions are made outside those established frameworks?
The real challenge is not drafting policies; it is ensuring that they become an integral part of the entity’s day-to-day operating culture.
From Formal Compliance to Effective Compliance
Some business entities suffer from what may be described as “formal compliance”, where all policies and procedures are available, updated, and approved, yet actual practices do not reflect their content.
Leading business entities, on the other hand, strive to achieve “effective compliance”, i.e., a state in which operating manuals, policies, and procedures become embedded within the corporate culture, decision-making processes, and operational activities.
At this stage, documentation evolves from being a regulatory requirement into a practical tool for risk management, performance enhancement, and governance strengthening.
The difference between having documentation and achieving effective implementation
Many business entities consider the preparation of policy and procedure as a standalone project. Once the documents are completed and approved, they often consider the task accomplished.
However, experience consistently demonstrates a fundamental distinction between policies and procedures that exist on paper and those that are genuinely implemented in practice.
A business entity may have a Human Resources Manual, an Operations Manual, a Delegation of Authority Matrix, and comprehensive Risk Management and Compliance Policies. Yet, when actual operations are tested, it may become evident that employees rely on customary practices, verbal instructions, or personal judgment rather than approved official documentation.
This is commonly referred to as the “implementation gap”, one of the most significant challenges facing governance and internal control systems.
Why Does the Implementation Gap Occur?
Several factors may contribute to ineffective implementation of policies and procedures, including:
-
Insufficient Awareness and Training
Policies may be issued without adequately explaining them to employees or providing practical training on how to apply them.
-
Lack of Monitoring and Oversight
When clear mechanisms for verifying compliance are absent, adherence to procedures may become optional rather than mandatory.
-
Business Changes Without Updating Documentation
Business entities continuously evolve. Systems, organizational structures, workflows, and business processes may change, while policies and procedures remain unchanged, causing them to lose relevance to operational realities.
-
A Culture of Exceptions
In some business entities, exceptions become more common than the rule itself, gradually eroding the effectiveness of policies and procedures.
-
Weak Accountability
When there is no clear accountability for non-compliance, employees may not perceive a genuine need to adhere to approved procedures.
Indicators That Policies and Procedures Are Not Being Effectively Applied
Boards of Directors and executive management may observe several indicators suggesting a gap between documentation and actual implementation, including:
- Recurring operational errors.
- Repeated findings from regulators, inspectors, or auditors.
- A high volume of unjustified exceptions.
- Lack of supporting documentation for completed transactions or activities.
- Inconsistent execution of the same task between employees, departments, or projects.
- Reliance on personal experience rather than documented procedures.
- Limited employee awareness of policy and procedure requirements.
- Recurring violations despite the existence of policies and procedures addressing them.
The presence of one or more of these indicators does not necessarily signify a major problem; however, it warrants independent and professional assessment.
Risks Associated with Ineffective Implementation of Policies and Procedures
Failure to effectively implement operating manuals, policies, and procedures can expose business entities to several risks, including:
-
Regulatory Findings and Potential Sanctions
In Kuwait, inadequate adherence to approved policies and procedures may result in observations from regulatory authorities, auditors, or inspection committees, particularly within sectors subject to governance, internal control, and compliance requirements.
In many cases, the issue is not the absence of a policy, but rather the business entity’s inability to demonstrate its effective implementation.
Where sufficient evidence of implementation cannot be provided, the business entity may become exposed to regulatory findings, sanctions, penalties, or supervisory restrictions, depending on the nature of the business and the applicable regulator.
-
Reduced Operational Efficiency and Effectiveness
Non-compliance with procedures often leads to inconsistent execution of activities across departments and personnel. Over time, institutional processes are replaced by individual practices based on personal experience or verbal instructions.
This may result in delays, repeated errors, lower-quality outputs, duplication of effort, and unclear accountability. Furthermore, the business entity becomes increasingly dependent on specific individuals rather than sustainable and well-defined operating processes.
-
Ineffective Internal Controls
Internal controls do not achieve their objectives merely through design; they must be consistently applied and periodically tested for effectiveness.
When approval requirements are bypassed, authority limits are ignored, or transactions are processed without supporting documentation, controls become merely symbolic and lose their ability to prevent or detect errors and irregularities in a timely manner.
-
Erosion of Stakeholder Confidence
Executive management and Boards of Directors rely on policies, procedures, and internal controls as mechanisms to support sound decision-making and effective risk management.
When these mechanisms are not effectively implemented, confidence may be undermined in management reporting, management effectiveness, and the business entity’s ability to comply with governance and regulatory requirements.
Responsibility for Verifying Effective Implementation
Responsibility for ensuring effective implementation rests with both the Board of Directors and executive management.
From a Board perspective, the Audit Committee, which is supported by the Internal Audit function reporting to the Committee, is responsible for conducting periodic reviews of operating manuals, policies, and procedures to assess both their adequacy and actual implementation.
The role of the Board and senior management extends beyond approving policies. It includes ensuring that policies are communicated, understood, implemented, monitored, and updated whenever changes occur in regulations, organizational structures, systems, or business operations.
From an executive management perspective, accountability rests with the Chief Executive Officer (CEO) and the department heads reporting to the CEO.
Methodology for Assessing Effective Implementation
A robust implementation review should include:
- Verifying alignment of policies and procedures with applicable laws, regulations, and supervisory requirements in the State of Kuwait.
- Ensuring policies and procedures are practical, clear, and operationally implementable rather than theoretical documents.
- Directing management to communicate policies and provide employee training.
- Monitoring compliance indicators and instances of non-compliance.
- Ensuring clear processes exist for managing exceptions and special approvals.
- Holding management accountable for deficiencies in implementation, documentation, or oversight.
- Supporting the independence of Internal Audit and empowering it to assess actual compliance.
- Ensuring timely remediation of regulatory, internal audit, and external audit findings.
Accordingly, policies become effective not when they are approved, but when they are embedded into daily organizational practices and supported by ongoing monitoring, accountability, and continuous oversight.
How Can Business Entities Verify Effective Implementation?
Business entities can adopt several measures to assess the actual level of compliance with policies and procedures.
-
Conduct Compliance Testing
Samples of completed transactions and activities should be selected and compared against approved procedures to verify compliance.
This may include, but is not limited to:
- Reviewing supporting documentation.
- Examining approvals and authorization records.
- Verifying workflow execution.
- Confirming adherence to delegated authority limits.
-
Conduct Employee Interviews
Direct discussions with employees often reveal the actual level of awareness, understanding, and application of approved procedures, as well as clarity regarding roles and responsibilities.
-
Test the Effectiveness of Information Systems
The more controls are embedded within automated systems, the greater the likelihood of consistent compliance.
Business entities should therefore verify that systems prevent—or at least significantly limit—the circumvention of approved controls.
-
Monitor Compliance Metrics
Management should establish Key Compliance Indicators (KCIs) and relevant performance measures to continuously monitor adherence levels, including:
- Percentage of transactions executed in compliance with procedures.
- Number of non-compliance incidents.
- Number of approved exceptions.
- Average time required to resolve regulatory findings.
- Percentage of improvement actions successfully closed.
-
Leverage Internal Audit
Internal Audit represents one of the most effective independent assurance mechanisms for assessing actual implementation. Rather than merely confirming the existence of policies and procedures, Internal Audit should evaluate:
- The extent of compliance with approved policies and procedures
- The effectiveness of related internal controls
- Root causes of deviations and non-compliance
- Risks arising from ineffective implementation.
Internal Audit should also provide practical recommendations to improve operational efficiency and effectiveness.
Conclusion
In light of the above, it is evident that the existence of processes, policies, and procedures manuals is an important step for any entity seeking to strengthen governance, internal controls, and compliance. However, this step alone is not sufficient.
The determining factor lies in the extent to which these policies and procedures are effectively implemented within the workplace, the degree of employee compliance, and the business entity’s ability to continuously monitor and verify such compliance.
In today’s business environment, the strength of a control framework is not measured by the number of approved processes, policies, and procedures manuals, but by the extent to which those manuals influence decisions, operations, and outcomes in practice.
Please contact the Business Development Department at +965 1887 799 , Ext.: 335, and a meeting can be arranged accordingly for further discussion.

