When Following Every Policy Still Breaks a Rule

Article · Policy

The same action, two different rulings

A remote work policy says employees may work from any location with manager approval. A data security policy says client data may only be accessed from company-approved, on-premise devices.

An employee gets manager approval to work from home, uses their personal laptop, and accesses client data — fully compliant with the first policy, and in direct violation of the second, at the exact same moment, doing the exact same thing.

Why this isn't a rare edge case

Policy conflicts like this are structurally common, not unusual exceptions, because most organizational policies get written separately, by different departments, at different times, addressing different specific concerns, without a coordinated review of how they interact with every other policy already on the books.

A remote work policy gets written by HR to support flexibility and retention. A data security policy gets written by IT or legal to reduce breach risk. Neither team is necessarily reviewing the other's document when their own gets drafted, which means overlap and contradiction accumulate quietly over time as more policies get added, each one reasonable in isolation.

The three shapes a policy conflict usually takes

Direct contradiction is the cleanest case: one policy explicitly permits something a second policy explicitly forbids, as in the remote work example above. Both statements are unambiguous on their own; they simply can't both be satisfied at once in the same situation.

Scope overlap with different thresholds is subtler: two policies both apply to the same situation but set different standards for it. An expense policy might allow purchases under $500 with a single manager's approval, while a procurement policy requires two approvals for any purchase involving a new vendor, regardless of amount.

A $200 purchase from a new vendor technically satisfies the expense policy's single-approval threshold while violating the procurement policy's new-vendor requirement — neither policy is wrong, they were simply built around different variables that weren't checked against each other.

Silent gaps are the third shape, and arguably the hardest to catch: a situation genuinely not addressed by either policy, where each department assumes the other's policy already covers it.

A policy on data retention and a policy on employee offboarding might each assume the other handles what happens to a departing employee's saved files, when in fact neither document actually specifies it, leaving a real procedural gap that only becomes visible when an actual departure happens and nobody can point to the rule that governs it.

Why compliance with each individual policy doesn't guarantee overall compliance

This is the core practical trap: an employee, or even a manager, can read each relevant policy individually, follow it correctly, and still end up in violation of the organization's actual combined rule set.

"The rules" aren't one document — they're however many separate documents happen to apply to a given situation, and nobody may have ever checked whether those documents agree with each other. Compliance with policy A and compliance with policy B are not the same thing as compliance with "company policy" as a coherent whole, precisely because that coherent whole may not actually exist as a single, internally consistent thing.

How conflicts actually get resolved when they surface

When a genuine conflict is identified, resolution usually follows a rough hierarchy. Legal and regulatory requirements typically override internal policy, since external law isn't optional regardless of what an internal document says.

More specific, narrowly scoped policies typically override more general ones covering the same territory, on the reasoning that a rule written specifically for a situation reflects more deliberate consideration of that exact case than a broad policy that happens to also technically apply.

More recently updated policies sometimes take precedence over older ones on the assumption that the newer document reflects the organization's current thinking — though this assumption fails badly when the newer policy was drafted without anyone checking it against the older one still in effect, which is often exactly how the conflict got created in the first place.

What to actually do when you spot a conflict

The practical move isn't guessing which policy wins based on instinct — it's flagging the specific conflict explicitly to whoever has authority over both policies, or over policy generally, rather than quietly picking one to follow and hoping it was the right call.

A genuine policy conflict is an organizational gap that needs a decision, not a puzzle an individual employee is equipped to solve correctly on their own, since the actual resolution may require input from both departments that wrote the conflicting documents in the first place.

Policy Tool Insight

Two policies can each be followed to the letter and still produce a real violation, because most policies are written separately, by different departments, without checking against everything else already in effect. Spotting a genuine conflict — direct contradiction, overlapping scope with different thresholds, or a silent gap — is the first step; the second is flagging it rather than guessing which rule wins.