Lesson 11 of 36 · Strategy, Leadership, and Risk
Policy Architecture: Governing Repeated Decisions
A policy is a durable board rule for repeated decisions. A procedure explains how management implements it. Confusing them either drags the board into operations or leaves important constraints vague.
A good policy answers
- purpose: what risk or value is governed?
- scope: who, what, and where?
- principles: what must be true?
- authority: who decides, approves, signs, and reports?
- limits/thresholds: when does authority escalate?
- required controls: separation, documentation, screening, review;
- exceptions: who may grant them and how recorded?
- oversight: what does the board receive and when?
- owner/effective date/review cycle;
- related law, policy, and procedure.
Example:
Policy: two authorized people must participate in disbursement controls above defined thresholds; the executive operates within budget/delegation; finance receives monthly exception reporting.
Procedure: which software steps, approvers, forms, and bank workflow accomplish that.
The board approves policy. Management normally approves procedures unless policy or law requires otherwise.
Shake Rag policy library
Governance
- bylaws and board/officer/committee charters;
- conflict of interest and annual disclosure;
- code of ethics/conduct;
- confidentiality and board communications;
- whistleblower/non-retaliation;
- document retention/destruction and legal holds;
- board reimbursement and director giving;
- executive evaluation/compensation/succession;
- complaint escalation.
Financial and development
- budget and financial reporting;
- delegated authority, purchasing, contracting, payments, cards, reimbursements;
- reserves and board designations;
- investments and debt;
- restricted funds and grant compliance;
- gift acceptance, donor privacy, naming, sponsorship;
- fundraising events, raffles/gaming, in-kind gifts;
- Form 990 review and public disclosure.
People, program, and safety
- employment and volunteer governance;
- youth protection and background screening;
- mandatory reporting and incident response;
- accessibility/nondiscrimination/accommodation;
- instructor/vendor qualification;
- tool/studio safety and supervision;
- lodging, rentals, alcohol, transportation;
- emergency, weather, fire, medical;
- privacy, cybersecurity, acceptable technology use.
Place and intellectual/cultural assets
- historic-property stewardship;
- maintenance and capital authorization;
- collections/art/loan handling if applicable;
- image, story, copyright, and consent;
- environmental/material disposal;
- public statements and advocacy.
This is a discovery list, not a claim that every item requires a separate policy or that Shake Rag currently has or lacks any item. Combine related risks into a usable system.
Build a policy register
| Policy | Board owner | Staff owner | Approved | Next review | Training | Evidence |
|---|---|---|---|---|---|---|
| conflict | governance | executive | date | annual | directors | disclosures/minutes |
| finance | finance | finance lead | date | 2 years | approvers | exception report |
| youth safety | board/risk | program lead | date | annual | all relevant people | completion/incident trends |
Use traffic lights:
- green: current, trained, implemented;
- amber: due soon or evidence weak;
- red: absent, expired, contradicted, or material failure;
- gray: applicability unknown—assign research.
Policy development workflow
- Trigger: legal change, incident, audit, strategic change, insurer/funder requirement, or scheduled review.
- Research: current practice, law, contracts, insurance, stakeholders, examples.
- Draft: owner plus affected functions; counsel/experts as needed.
- Reality test: walk through actual scenarios and exceptions.
- Approve: board or valid delegate, with effective date.
- Implement: procedures, forms, systems, training, communications.
- Evidence: define what proves operation.
- Monitor: exceptions, incidents, compliance, outcomes.
- Revise/archive: version control and superseded-document handling.
Copying an internet template skips steps 2, 4, and 6—the places where policy becomes real.
Financial policy thresholds
Financial policies should fit organizational scale and capacity. Propel Nonprofits’ guidance emphasizes tailoring rather than adopting an example mechanically 1.
Define:
- budget authority and variance escalation;
- contract/spending thresholds;
- who may sign and who reviews;
- competitive-procurement expectations and exceptions;
- related-party process;
- bank, credit card, cash, refund, payroll, and journal-entry controls;
- reserve use and replenishment;
- debt and leases;
- grant/restricted-fund accounting;
- reporting schedule;
- suspected fraud response.
Avoid controls impossible for a small staff. Use compensating board review where perfect segregation is unavailable—but do not let “small” mean “one person controls request, approval, payment, recording, and reconciliation.”
Exception discipline
Every policy will face edge cases. The policy should say:
exception authority · required rationale · time limit · documentation · notification · after-action review
Repeated exceptions show the policy is wrong, procedures are weak, training is missing, or leaders are avoiding it. Report patterns, not just totals.
Policy reading exercise
Take one policy and answer:
- What harm/value does it govern?
- Which decisions are board, executive, or staff?
- What terms are undefined?
- What evidence proves it operates?
- What would a real violation look like?
- Who receives the report?
- Does it conflict with bylaws, another policy, practice, insurer, grant, or law?
- Can a new staff member follow it?
If you cannot answer, the policy is not yet a control.
The board’s role
The board should not rewrite every procedure. It should ensure:
- the policy inventory matches the risk/mission model;
- owners and review cycles exist;
- material exceptions and incidents reach the board;
- policy choices align across money, people, program, and place;
- training and systems make compliance feasible;
- the organization learns after failure.
The goal is not a thick binder. It is consistent judgment when nobody remembers the last case.
Source trail
References
- 1Financial Policy Guidelines and Example. Propel Nonprofits. verifiedPolicy framework for authority, conflicts, spending, contracts, records, reporting, restrictions, and reserves. Cited at: financial policy guidance.
Further reading
- Governance and Related Topics — 501(c)(3) Organizations. Internal Revenue Service. verifiedIRS governance considerations for mission, governing documents, boards, policies, financial reporting, and transparency.
- Gift Acceptance Policies. National Council of Nonprofits. verifiedPolicy guidance for restricted, noncash, hard-to-value, burdensome, and mission-conflicting gifts.
- Recommended Board Practices. BoardSource. verifiedCurrent recommendations on board composition, meetings, assessment, executive partnership, strategy, and personal giving.
Check your understanding
- What belongs in a board policy?
- Every click in a staff workflow
- Durable principles, authority, limits, required controls, exceptions, and oversight
- A single event’s run sheet
- An employee’s daily checklist
Policy governs recurring decisions while procedures explain implementation.
- Why should policies have owners and review dates?
- To create more meetings
- So outdated, contradictory, or unimplemented rules are found and corrected
- Because all policies expire monthly
- So staff cannot change procedures
Ownership and review turn documents into a functioning control system.