Policies, Procedures, Protocols and Guidelines: What's the Difference?

Care staff and managers routinely use "policy," "procedure," "protocol" and "guideline" as if they mean the same thing. They don't — and CQC inspectors are trained to spot the gap between what your documents say and what staff can actually describe doing. This guide sets out the practical hierarchy, with concrete health and social care examples.

Learnsignal Education Team
9 min read
Updated

Ask five care staff to explain the difference between a policy, a procedure, a protocol and a guideline, and you will usually get five different answers — if you get an answer at all. In practice the terms get used interchangeably: "check the protocol" might mean the folder in the manager's office, an NHS document nobody has read since induction, or a laminated sheet by the medication trolley. That vagueness is not a harmless quirk of workplace language. It is one of the most common reasons providers come unstuck at inspection, because why providers fail CQC inspections so often comes down to exactly this: paperwork that says one thing and staff who, when asked, describe doing something else.

This article sets out what each term actually means in a UK health and social care context, how they sit together as a practical hierarchy rather than four interchangeable synonyms, and why getting the distinction right — on paper and in practice — matters so much to CQC inspectors.

Why the distinction matters, not just semantics

It is tempting to treat this as pedantry. It isn't. Each of the four document types carries a different level of authority, a different amount of professional discretion, and a different consequence if it isn't followed. A guideline you deviate from with good clinical reasoning is defensible. A protocol you deviate from without justification, in a situation designed to have none, is a safety incident. A procedure you simply never follow suggests your policy exists only on paper. Conflating the four means staff don't know which documents bind their actions, which support their judgement, and which describe an external body's recommended approach rather than their own employer's rule. That confusion is exactly what regulators are trained to probe for.

The four terms, defined

Policy

A policy is a statement of an organisation's position and intent on a given topic — what the provider commits to doing, and why. A safeguarding policy states that the organisation will protect adults and children from abuse and neglect, that it takes a zero-tolerance approach, and that every member of staff has a duty to report concerns. It sets direction. It does not, on its own, tell a support worker what to physically do if they witness something concerning at 11pm on a Saturday.

Procedure

A procedure translates that policy into a repeatable sequence of steps. Following the safeguarding example, the procedure explains who to contact, in what order, within what timeframe, how to record what was seen, and which form to complete. Procedures are internal to the provider — they reflect how this organisation, with its own reporting lines and local authority contacts, expects staff to act.

Protocol

A protocol is more prescriptive still: a fixed, step-by-step pathway for a specific clinical or operational task where variation itself is a risk. A protocol for administering insulin, managing a choking episode, or responding to a resident whose National Early Warning Score (NEWS2) crosses a threshold leaves little room for individual interpretation, because the whole point of a protocol is consistency under pressure. Protocols are often built directly from external clinical evidence — NICE guidance, NHS England pathways, Resuscitation Council UK algorithms — but once adopted by a provider they typically function with procedure-like force for that specific task.

Guideline

A guideline is recommendation, not instruction. It supports professional judgement rather than replacing it. NICE guidelines are the clearest national example: NICE itself is explicit that healthcare professionals must "take NICE clinical guidelines fully into account when exercising their clinical judgement," but that this "does not override the responsibility of healthcare professionals and others to make decisions appropriate to the circumstances of each patient, in consultation with the patient and/or their guardian or carer" (NICE, The guidelines manual). A guideline tells you what good practice generally looks like; it deliberately leaves room for the professional in front of the person to decide differently, for good reason, and document why.

The practical hierarchy

Rather than four unrelated documents, these sit on a spectrum running from broad organisational intent down to precise, individual action. The table below sets out the core distinction side by side.

TermWhat it answersLevel of discretionTypical authorExample
PolicyWhat do we believe and commit to?None — sets the positionRegistered provider / senior managementMedicines management policy
ProcedureHow do we put that into practice, step by step?Low — sequence is fixed, judgement is limitedRegistered manager, department leadProcedure for ordering, storing and disposing of controlled drugs
ProtocolExactly what do I do in this specific, defined situation?Very low — designed for consistency under pressureClinical lead, drawing on national guidanceProtocol for administering PRN medication when a resident is in pain
GuidelineWhat does good practice generally recommend?High — supports, doesn't replace, professional judgementExternal body (NICE, Royal Colleges, NHS England)NICE guideline on managing medicines in care homes

Where NICE guidelines and national frameworks fit

One of the most persistent sources of confusion is treating a NICE guideline as if it were the provider's own policy. It isn't, and the distinction has real consequences. NICE guidelines are national, evidence-based recommendations aimed at everyone delivering that type of care; they are not written with any single provider's staffing, service users or resources in mind, and as set out above, NICE is explicit that they do not override professional judgement in an individual case. A provider's policy and procedure, by contrast, are binding internal documents that translate relevant national guidance — NICE, CQC's Single Assessment Framework quality statements, professional body standards — into "this is what we, specifically, do here." A good policy will reference the guideline it draws on; it should never simply be the guideline with the provider's logo added. National training frameworks work the same way — they set the baseline for what training should cover, and each provider's own procedures then set out how that gets delivered and evidenced locally.

Concrete examples across a care setting

Seeing all four levels applied to one topic makes the hierarchy concrete. Take falls management in a residential care setting:

  • Guideline: NICE guidance on falls in older people recommends multifactorial risk assessment and targeted interventions for those identified as at risk.
  • Policy: The provider's falls prevention policy states that every resident will have a falls risk assessment on admission and at defined review points, and that the service is committed to minimising avoidable falls.
  • Procedure: The procedure sets out which assessment tool to use, who completes it, how often it is reviewed, and how the resulting care plan is updated and communicated to the whole team.
  • Protocol: The post-fall protocol is the fixed sequence followed the moment a fall happens — do not move the person, check for injury using a defined checklist, take observations at specified intervals, when to call 999 versus 111, and exactly how and when to notify the family, the manager and, where required, CQC.

The same structure applies to medicines management, safeguarding, infection prevention and control, and end-of-life care. In every case, the guideline informs the policy, the policy is delivered through the procedure, and the protocol handles the specific high-stakes moment where there is no time, and no room, for individual variation.

Why CQC inspectors care so much about this distinction

CQC's Regulation 17 (Good governance) requires providers to operate systems that assess, monitor and improve the quality and safety of the services they deliver, and to maintain records that are accurate, complete and up to date. Having a policy folder that looks comprehensive satisfies none of that on its own. What inspectors are actually testing, under the Single Assessment Framework's evidence categories, is alignment: they compare what your processes say (your written policies, procedures and protocols) against what they see in observations of care and hear in feedback from staff. A care worker who cannot describe the post-fall protocol in their own words, or who describes doing something different from what is written down, is a direct governance finding — regardless of how polished the document itself looks.

This is precisely the gap that catches providers out. A policy written by a consultant and never worked into day-to-day practice; a protocol copied from another organisation's template and never adapted to local staffing or equipment; a procedure so vague it offers no real step-by-step guidance at all. Inspectors are trained to ask staff to explain, in their own words, what they would actually do — not to recite policy, but to describe practice. Where the two don't match, that's the finding, and it sits squarely within the well-led and safe key questions. It is also a recurring theme in incident reviews: when something goes wrong, the first question is almost always whether staff knew, and followed, the right protocol — see our guide to incident investigation and documentation standards for how that gets tested after the fact.

Getting the hierarchy right in your service

A few practical habits close most of the gap between paper and practice:

  • Name each document correctly. If it's a fixed sequence for a high-risk task, call it a protocol, not a "policy," so staff understand it isn't optional.
  • Keep procedures and protocols short and specific. A 40-page policy document that also tries to be the procedure and the protocol will be read once, at induction, and never again.
  • Reference the source. Link your protocols and procedures back to the NICE guideline, professional standard or CQC quality statement they implement, so the chain of reasoning is visible to an inspector and to staff.
  • Test understanding, not just sign-off. A signature on an induction checklist proves someone read a document; asking a member of staff to talk through what they'd do in a scenario proves they understood it.
  • Review after incidents and audits. If practice has drifted from the written protocol, the question is not just "retrain the individual" but "is the protocol still realistic for how we actually work?"

Getting training right underpins all of this — staff need to understand not just the content of a policy but the difference between what is optional guidance and what is a fixed rule. Structured, up-to-date CPD is one of the most reliable ways to keep policies, procedures and protocols something staff genuinely understand rather than simply sign for — explore Learnsignal's CPD training library for courses that build this understanding across safeguarding, medicines management, and regulatory compliance.

The distinction between policies, procedures, protocols and guidelines will never be the most exciting part of working in care. But it is one of the clearest, most fixable ways to close the gap between what your documentation says and what your inspection actually finds.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans