A policy document describes what an organization wants. A check describes what actually happens. Between those two lies a gap, and in that gap live the questions that an auditor, a supervisory authority or a new director will ask first. Not: do you have a policy? But: can you show that the policy is also the practice?
A policy document can be complete, current and well written, and still say nothing about what happens on the floor. Policy is a promise. Practice is what has been fulfilled. The difference lies in the question of who executes the policy, how that happens, and what has been recorded of it. Without those three elements, a policy document is a statement of intent, not a piece of evidence.
That distinction is precisely what an obligations register is built on. Not: which rule applies, but: who owns compliance, what evidence exists of it, and which control demonstrates that the process is repeatable. Without an owner, an obligation remains on paper. Who should own an obligation is therefore not an administrative question, but the question that makes the difference between policy and practice.
Evidence is not the policy document itself. Evidence is the trail that the execution of that policy leaves behind: an approved form, a logged entry, an email with a decision, a report delivered on a fixed date. Evidence only exists once it has been recorded at the moment it happened, not reconstructed afterwards.
This is where many organizations stumble. The policy is there, the intention is genuine, but the evidence is fragmentary or only comes into existence once it is asked for. An assurance process exposes that difference mercilessly. What an assurance statement precisely demands of a file is therefore a separate question: what does an assurance statement demand of your file shows that the bar is higher than a collection of documents in a folder.
The Compliance Check makes visible where policy and practice diverge. That visibility is not the same as the solution. The method points out which obligation has no owner, which control is missing and which evidence does not yet exist. It does not carry out the control and it does not write the policy. It provides a structure with which an organization can itself determine where practice falls short of the promise, and that is a different achievement from closing that gap.
It is also not a snapshot that remains accurate. Obligations change, owners change roles, and what counts as evidence today may be insufficient tomorrow. How often an obligations register actually needs adjustment is a question many organizations underestimate: how often does an obligations register change describes why this is not a one-off exercise.
The difference between policy and practice grows larger as more parties are involved in the execution, and this applies especially to organizations with locations in multiple countries. A European rule is given its own interpretation per country, and the policy written at head office level does not automatically align with what is maintained locally. Practice at one location can differ significantly from practice at another, while the policy document is identical in both cases.
That makes maintaining those national variations a recurring task rather than a one-time check. How to do that without ending up in a maze of separate subscriptions and local tools is described in how do you keep track of national variations without a subscription jungle.
A report describes a state at a moment in time. The difference between policy and practice, however, changes continuously, and a snapshot becomes outdated as soon as the first change occurs. That is why a compliance check as a method aims for something different from a report: it concerns a living register in which ownership, evidence and control remain continuously linked to one another, rather than a document that is dated the moment it is delivered.
The cost of not knowing which obligations an organization falls under usually only becomes visible at the moment a supervisory authority, a bank or a major client asks for demonstrability and it turns out not to exist. What it can mean to be left without an answer at that moment is explained in what does it cost to not know what applies to you.
Establishing the difference between policy and practice naturally raises a follow-up question: who in the organization actually has the time to gather that evidence, keep it up to date and revise it as soon as an obligation changes. That is a capacity question, and it is separate from the question of whether the organization knows what needs to happen. FTE TO AI works from that follow-up question with a work scan that calculates per task which part of the work can be taken over by AI, so it becomes clear where people gain time for the work a computer cannot do: assessing, deciding and accounting for it.
Vraag maar welke verplichting op u van toepassing is, en waaraan u dat kunt aantonen.
Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.