Skip to main content
Category: Policy Management

Guideline

Also known as: Guidance
Simply put

A guideline is a statement that recommends a course of action to help people make consistent decisions or follow sound practice. Unlike a mandatory rule, a guideline typically offers advisory direction rather than a strict requirement. It aims to streamline how a particular process is carried out.

Formal definition

In a governance and compliance context, a guideline is generally an advisory statement that recommends or suggests how to determine a course of action or apply a policy or standard, aiming to promote consistency and sound practice. Guidelines are commonly distinguished from policies (high-level mandatory directives), standards (specific mandatory requirements), and procedures (prescribed step-by-step instructions) in that guidelines are typically non-binding recommendations rather than enforceable obligations; however, the binding status of any given document depends on how the issuing organization defines and adopts it. This entry addresses the general meaning of the term and does not cover implementation specifics, tooling, or the requirements of any particular framework, jurisdiction, or sector.

Why it matters

In governance and compliance programs, the distinction between binding and advisory documents carries real consequences. Guidelines occupy the advisory tier of a typical document hierarchy, recommending sound practice without imposing enforceable obligations in the way policies and standards commonly do. This matters because misclassifying a document can lead either to unwarranted enforcement action against staff who deviated from what was only ever a recommendation, or to a false assumption of compliance where a genuine mandatory requirement was treated as optional.

Guidelines help promote consistency in how people interpret and apply higher-level policies and standards, particularly where a process allows for professional judgment or contextual variation. By offering suggested approaches, they can reduce ambiguity and support more uniform decision-making without removing the discretion that some situations require. Their advisory nature also allows organizations to adapt practice more readily than they might with formally adopted mandatory instruments.

Because the binding status of any given document depends on how the issuing organization defines and adopts it, professionals should not assume that a document labeled a guideline is universally non-enforceable, nor that one labeled a policy is always mandatory. The label alone is not decisive; what governs is the organization's own framework for how it classifies, approves, and applies each document type.

Who it's relevant to

Governance professionals
Those responsible for maintaining an organization's document hierarchy need to classify guidelines accurately relative to policies, standards, and procedures, and to define clearly how the organization intends each document type to be applied and enforced.
Compliance officers
Compliance staff rely on the advisory-versus-mandatory distinction when assessing whether a deviation constitutes a breach or a departure from recommended practice, recognizing that the binding status of a guideline turns on how the organization has adopted it.
Internal auditors and assurance functions
When evaluating adherence, assurance functions must be clear about whether a given document imposes an enforceable requirement or offers non-binding recommendations, as this affects how findings and conclusions are framed.
Policy and standards authors
Those drafting organizational documents use guidelines to promote consistent interpretation of higher-level policies and standards, and must be deliberate about signaling advisory intent to avoid ambiguity over enforceability.

Inside Guideline

Recommended Practice Statements
The core of a guideline consists of suggested approaches or methods for achieving an objective. Unlike a standard, these statements are typically advisory rather than mandatory, offering direction on how something may be done while leaving discretion to the practitioner.
Contextual Application Notes
Guidance on when and how the recommendations apply, often noting that suitability may vary by jurisdiction, industry, organization size, or circumstance. This helps users adapt the guideline rather than treat it as a fixed rule.
Reference to Related Policies and Standards
A guideline commonly points to the policies, standards, or procedures it supports, clarifying its subordinate role within a document hierarchy. It typically elaborates on how to meet requirements set elsewhere rather than establishing those requirements itself.
Illustrative Examples or Options
Guidelines frequently present examples, alternatives, or acceptable options to aid interpretation. These are intended to inform judgment and are generally not exhaustive or binding.
Scope and Applicability Statement
A description of the audience, activities, or situations the guidance addresses, and often what it does not cover. This helps prevent misapplication beyond the intended context.

Common questions

Answers to the questions practitioners most commonly ask about Guideline.

Is a guideline mandatory in the same way a policy or standard is?
Typically no. A guideline is generally advisory in nature, offering recommended approaches or good practice rather than binding requirements. This distinguishes it from policies and standards, which commonly express mandatory expectations. Because guidelines are usually discretionary, departure from them does not ordinarily constitute non-compliance in the way that a breach of a mandatory standard might. That said, the weight given to a guideline can vary by organization, and some documents labelled "guideline" may in practice carry mandatory force depending on how they are worded and adopted, so the operative language should be read rather than the label alone.
Are guidelines and procedures the same thing?
No. Although both sit below policies and standards in a typical document hierarchy, they serve different purposes. A procedure commonly sets out a defined sequence of steps for performing a task, often in a prescribed manner. A guideline instead offers recommended practice, judgement aids, or interpretive help, generally leaving discretion to the reader on how to apply it. Conflating the two can lead to treating advisory guidance as prescriptive workflow, or vice versa; the distinguishing feature is that guidelines advise while procedures direct.
Where should a guideline sit within our governance document hierarchy?
In many organizations, guidelines sit beneath policies and standards, and alongside or below procedures, as supporting documents that assist interpretation and application. Because their status is advisory, it is common practice to identify explicitly within the document set which items are mandatory and which are recommendatory. Establishing this hierarchy and labelling conventions is generally a governance responsibility, so that readers can tell at a glance whether a document expresses a requirement or a recommendation. Specific placement conventions vary by organization.
How should we word a guideline so its advisory status is clear?
It is generally advisable to use qualified language such as "should," "may," "is recommended," or "consider," reserving mandatory phrasing such as "must" or "shall" for policies and standards. Clearly stating the document type, purpose, and status near the front of the document helps readers understand that departures are permitted where justified. Where a guideline supports a mandatory requirement, it can be useful to cross-reference the governing policy or standard so readers can distinguish the binding obligation from the recommended approach to meeting it.
Who typically owns and maintains guidelines?
Ownership commonly rests with the function that has subject-matter expertise in the area the guideline addresses, operating within the governance framework that defines document types and approval routes. Because guidelines are advisory support documents, their review and update cycles may differ from those of mandatory policies and standards. Assigning a named owner responsible for keeping the guidance current and consistent with the policies and standards it supports is generally regarded as good practice. This entry does not address specific approval workflows or tooling.
How do we handle a departure from a guideline?
Because guidelines are typically advisory, a departure does not usually require the formal exception or waiver process that a deviation from a mandatory standard might trigger. Even so, many organizations encourage documenting the rationale where a recommended approach is not followed, particularly where the guideline supports a mandatory requirement and the chosen alternative still needs to satisfy that requirement. The appropriate handling depends on how the organization has defined the status and role of the guideline; this entry does not constitute legal advice or address specific case circumstances.

Common misconceptions

A guideline is mandatory and enforceable in the same way as a policy or standard.
In many governance document hierarchies, a guideline is typically advisory and provides recommended, non-binding direction. Mandatory requirements are more commonly expressed through policies and standards, whereas guidelines describe how those may be achieved and generally allow professional discretion.
A guideline, a standard, and a procedure are interchangeable terms.
These are distinct document types. A standard commonly sets a mandatory, measurable requirement; a procedure sets out specific step-by-step instructions; and a guideline offers recommended, non-mandatory approaches. Conflating them can obscure which obligations are enforceable and which are advisory.
A single guideline applies uniformly across all organizations and jurisdictions.
The applicability of a guideline may vary by jurisdiction, industry, and organizational context. Guidelines are typically framed to be adapted rather than adopted verbatim, and what is appropriate in one setting may not be suitable in another.

Best practices

Clarify the guideline's status within your document hierarchy, explicitly noting that it is advisory and identifying the policies or standards it supports.
State the scope, intended audience, and applicable context, and note where the guidance does not apply or where jurisdictional or sectoral differences may affect its use.
Use qualified language such as recommended, may, or typically to distinguish advisory content from any mandatory requirements referenced from standards or policies.
Include illustrative examples or acceptable options to aid interpretation, while making clear these are not exhaustive or binding.
Review and update guidelines periodically to reflect changes in supporting policies, standards, and relevant regulatory or operational context.
Assign clear ownership for maintaining the guideline and cross-reference related documents so users can trace where mandatory obligations actually reside.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide