Join our Newsletter — 33% off our NHI Course

What should organisations do when employees or contractors struggle to understand a policy?

Organisations should treat confusion as a governance issue, not just a training issue. They need a clear path for questions, a consistent way to explain changes, and a policy format that non technical people can understand. Open dialogue helps surface friction early, reduces accidental noncompliance, and gives teams a better chance of preventing avoidable insider threat incidents.

Why confusion about a policy is a governance problem

When people cannot understand a policy, the issue is usually not just awareness, it is control design. A policy that users cannot interpret consistently will produce uneven decisions, informal workarounds, and exceptions handled by memory instead of process. That weakens accountability and makes it harder to prove that the organisation is enforcing requirements consistently.

Confusion also creates hidden operational risk. Employees and contractors may do the “safe-looking” thing, but still miss a rule that matters for access, data handling, approvals, or escalation. In practice, policy clarity is part of NIST Cybersecurity Framework 2.0 governance because the organisation has to define, communicate, and maintain expectations in a way that can actually be followed.

What good policy communication looks like

A usable policy is short enough to navigate, specific enough to act on, and written for the audience that must follow it. If the policy applies to contractors or third parties, the explanation should match their work context, not the internal language of the control owner. For that reason, organisations should treat contractor-facing clarity as part of their access governance, not as an afterthought.

Where the policy depends on exceptions, the exception path should be obvious and stable. People need to know where to ask, who answers, and what evidence is needed when a requirement is unclear. For contractor and supplier populations, Third-Party, B2B and Contractor Access Guide is a useful companion because the same clarity problem often shows up around onboarding, sponsorship, reviews, and offboarding.

Clear communication also means change management. If a policy changes but the explanation does not tell people what is new, what is different, and what action they must take now, confusion will persist even when the document is technically current. The goal is not only publication, it is comprehension at the point of use.

How unclear policies lead to avoidable failures

Unclear policies do not usually fail as dramatic single events. They fail as repeated small deviations: someone delays reporting, shares information the policy would have restricted, or uses an old habit because the new rule is not obvious. Over time, those weak signals can become a pattern of accidental noncompliance that looks like user behaviour but is really a governance defect.

That same ambiguity can blur ownership. If the policy is hard to interpret, teams start relying on local interpretation, which creates inconsistent enforcement across functions or locations. The result is often more manual intervention, more disputes over exceptions, and less confidence that the policy means the same thing everywhere it is used.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context Policy clarity depends on shared understanding of roles, scope, and expectations.
GV.RR-02 — Roles, Responsibilities, and Authorities Confusion often reflects unclear ownership for questions and exceptions.
PR.AT-01 — Awareness and Training Users need understandable policy communication to follow requirements correctly.
Recommendation — Define policy scope and audience so users can apply the rule consistently. Assign a clear owner for policy questions, exceptions, and updates. Deliver policy training in plain language tied to the actual task and audience.
CIS Controls v8 CIS-6 — Access Control Management Policy confusion commonly affects access decisions and exception handling.
Recommendation — Standardise access rules so users know what is permitted and how to request exceptions.

Practitioner Guidance

What to prioritise: Fix the highest-friction policy first, usually the one that affects access, data handling, or approvals, because those are the rules most likely to produce operational mistakes when people do not understand them.

What to verify: Test the policy with non-specialists, including contractors, and check whether they can explain the required action, the exception path, and the escalation route in their own words. If they cannot, the document is not yet operationally clear.

Common mistake: Treating confusion as a training gap alone. Training helps, but if the policy is written in internal jargon or changes without a clear update path, the organisation will keep generating preventable misunderstandings.

Practitioner takeaway: The best policy is one that people can apply consistently without having to interpret it for themselves; clarity, reviewability, and an obvious question path are what turn policy from text into control.