Policy vs Procedure
Why
This is a standard response for security questionnaires. Use this to clear deal-flow bottlenecks.
Mini Glossary
Definition
Policy is the high-level 'What/Why'; Procedure is the detailed 'How/When'.
Short Answer
We maintain formal policies for all SOC 2 domains, supported by detailed operating procedures.
Detail
Policy is the high-level ‘What/Why’; Procedure is the detailed ‘How/When’.