A policy states a rule and the reasoning behind it: what must or must not happen, and why. A procedure states the specific steps that satisfy a policy: who does what, in what order. A guideline offers recommended practice without making it mandatory.
The difference that matters operationally is obligation. A policy and a procedure are binding. A guideline is not, and calling something a guideline when you mean it to be mandatory is how compliance quietly fails.
A worked example
- Policy: all supplier invoices over 10,000 require approval by a director before payment, to prevent unauthorised commitment of company funds.
- Procedure: the numbered steps by which an invoice is received, matched to a purchase order, routed to the director, approved in the finance system, and paid.
- Guideline: suggested wording for chasing a supplier who has not sent a purchase order reference.
Why keeping them separate is worth the effort
Policies change rarely and are usually approved at a higher level. Procedures change whenever a system or a role changes, which is often. Combining them into one document means every operational tweak reopens an approval that should not have been needed, so in practice people stop updating the document at all.
It also makes audits harder. An auditor tests whether the procedure implements the policy. If both live in the same paragraph, there is nothing to test one against.
Where work instructions fit
Below the procedure. A procedure names the step; a work instruction details how to perform it at one station. So the full hierarchy runs policy, then procedure, then work instruction, with guidelines sitting alongside as advisory material.