Foundations of Rules Integrity · Chapter 7
Rule Hierarchies and Authority
Rule systems remain trustworthy only when institutions can explain where authority originates, how it is delegated, which rule has priority, and when a lower-level rule exceeds or contradicts the power that created it.
Chapter summary
A rule cannot be trusted without a defensible chain of authority
Rules govern because some source gives them force. That source may be a constitution, statute, regulation, judicial order, contract, corporate charter, board resolution, delegated office, professional standard, or recognized institutional process. The authority of a rule is therefore not contained in its wording alone.
Hierarchy organizes those sources. It identifies which rules are superior, subordinate, implementing, specialized, temporary, or merely advisory. Delegation explains how authority moves from one level to another. Precedence determines which rule controls when multiple rules appear to govern the same case.
This chapter examines authority as a structural property of rule systems. It explains how institutions should identify sources, record delegation, distinguish stricter policy from contradiction, recognize unauthorized rules, resolve conflicts, and control authority embedded in technical systems.
1. Defining authority and hierarchy
Authority gives a rule force; hierarchy organizes that force
Working definition: Rule authority is the legitimate power or accepted basis by which a rule is created, imposed, recognized, or enforced. Rule hierarchy is the structured ordering of rule sources and rule expressions according to their legal, contractual, organizational, or technical priority.
Authority answers the question: Why may this rule govern? Hierarchy answers: How does this rule relate to other rules that may also govern?
The distinction matters because a rule can possess authority without being superior to every other rule. A departmental procedure may be valid within its delegated field while remaining subordinate to enterprise policy, contract, and law. A contract may bind its parties while remaining subject to mandatory law. A technical access rule may be enforceable in software while lacking organizational authority to alter the underlying policy.
Authority is therefore both a source question and a boundary question. The source must be legitimate, and the rule must remain within the subject, population, jurisdiction, process, and procedure that source authorizes.
2. Sources of rule authority
Different rule systems derive authority from different institutions
The source of authority determines the kind of obligation created, the actors governed, the procedure for adoption, and the mechanisms for review or challenge.
These sources are not equivalent. A professional standard does not automatically have the force of law. A policy does not automatically amend a contract. A software configuration does not automatically create a valid organizational prohibition. Rules Integrity requires institutions to identify the precise mechanism by which a source becomes governing.
3. How hierarchy works
Hierarchy is a relationship of authority, implementation, and control
Rule hierarchy is often represented as a pyramid, but real rule systems are more complex. Several hierarchies may coexist: legal hierarchy, contractual hierarchy, corporate governance hierarchy, policy hierarchy, document hierarchy, and technical implementation hierarchy.
A lower layer may contain greater detail, but not greater authority. The detailed procedure explains how a higher rule will be carried out. It should not silently reverse, narrow, or expand the higher rule unless delegated discretion permits it.
Hierarchy also creates responsibility. Higher-level rules should establish purpose, authority, and governing boundaries. Lower-level rules should preserve those elements while translating them into operational decisions.
4. Delegation of authority
Delegation transfers decision power within defined limits
Institutions cannot make every decision at the highest level. Authority must be delegated to offices, roles, committees, business units, professionals, and systems. Delegation allows scale, but it also creates risk if scope and limits are unclear.
A complete delegation should identify:
- the delegating authority;
- the receiving role or body;
- the subject matter delegated;
- financial, geographic, temporal, or risk limits;
- conditions requiring consultation or escalation;
- whether redelegation is permitted;
- documentation and reporting duties;
- revocation, expiration, and succession.
Delegation does not necessarily remove responsibility from the delegating authority. Oversight, monitoring, and review may remain required. Nor does the ability to act imply authority to create permanent rules. A manager may decide individual cases without possessing authority to establish a policy for the entire organization.
In public law, delegation is constrained by enabling authority and administrative procedure. In private institutions, delegation is constrained by charter, governance documents, contract, law, and internal approval structure.
5. Precedence and priority
When several rules apply, priority must be determined rather than assumed
Precedence identifies which rule controls when multiple rules point toward different outcomes. Priority may arise from superior authority, narrower scope, later adoption, express override, emergency status, or another recognized rule of interpretation.
Common priority principles include:
- superior authority controls subordinate authority;
- a specific rule may control a general rule within the specific subject;
- a later rule may displace an earlier rule of equal authority;
- mandatory law may override contract or internal policy;
- an express exception may control the general rule;
- a temporary emergency rule may suspend ordinary operation within defined limits.
These principles are not universal algorithms. Their use depends on the rule system. A later policy cannot override an older statute. A specific local rule cannot displace a superior enterprise rule unless local variation is authorized. Priority must be supported by the authority structure, not merely by preference for the rule that is newer, stricter, or more detailed.
6. Specific and general rules
Specificity can determine application without changing authority
A general rule establishes an expectation across a broad field. A specific rule addresses a narrower category or condition. Where both apply, the specific rule may control because it was designed for the exact circumstance.
For example, an enterprise rule may require all vendor contracts to undergo review. A more specific rule may permit standard low-risk renewals to proceed through an automated review path. The specific rule does not necessarily contradict the general rule; it may define how the general requirement is satisfied for a narrower class.
Specificity should be explicit. The narrower rule should identify the general rule, the governed category, the reason for different treatment, and whether the specific rule supplements, implements, or overrides the general one.
7. Later and earlier rules
Chronology matters only within a valid authority relationship
Later rules may replace earlier rules when they arise from the same or superior authority and address the same subject. But chronology alone does not establish superiority.
Change control should distinguish:
- express repeal or replacement;
- partial amendment;
- temporary suspension;
- implicit displacement through irreconcilable later requirements;
- continued historical applicability to prior events;
- parallel versions for different jurisdictions or populations.
The safest rule system avoids relying on implicit displacement. It should record exactly which provision is superseded, which remains in force, and how historical decisions are treated.
8. Incorporation and adoption
External material becomes governing only through a valid adoption mechanism
Institutions often rely on standards, schedules, codes, guidelines, or external documents. A rule may incorporate that material by reference rather than reproduce it. The incorporation mechanism determines whether the external material is mandatory, advisory, current, or frozen to a particular version.
The U.S. Office of the Federal Register maintains formal procedures for incorporation by reference in federal regulations, including approval, identification, and availability requirements.4 Although internal organizations are not always subject to that legal process, the integrity principles remain useful.
A valid incorporation record should identify:
- the exact title, issuer, version, and date;
- the adopting authority;
- whether future revisions are automatically adopted;
- where the material is accessible;
- which portions are incorporated;
- how conflicts with internal rules are resolved.
9. Stricter internal rules
A stricter rule may be legitimate, but stricter does not automatically mean superior
Organizations often adopt internal rules more restrictive than the minimum required by law or contract. This may reflect risk tolerance, ethics, safety, quality, or strategic choice.
A stricter internal rule is legitimate when:
- the organization possesses authority over the governed actor or process;
- the stricter requirement does not violate a right, permission, or mandatory obligation;
- the burden is proportionate and feasible;
- the stricter position is intentional and documented;
- the rule is not misrepresented as an external legal requirement;
- exceptions and local constraints are addressed.
A threshold stricter than law is not necessarily a contradiction. It may be a deliberate control. But if the stricter rule prevents conduct that superior authority affirmatively requires or protects, it may be invalid.
11. Invalid and unauthorized rules
A rule may influence behavior while lacking valid authority
Organizations often contain informal rules that are widely followed because a senior person expects them, a system enforces them, or employees believe noncompliance will be punished. Operational effect does not prove validity.
A rule may be invalid because:
- the issuer lacked authority;
- the rule conflicts with superior authority;
- required procedure was not followed;
- the rule expired or was superseded;
- the governed population was never lawfully included;
- the rule was materially altered during implementation;
- the rule depends on inaccessible or unidentified incorporated material.
Invalid rules should not simply remain in place with a warning label. Their operational effects must be identified, affected decisions reviewed where necessary, and implementations corrected.
14. Conflict resolution
Authority conflicts should be resolved through method, not convenience
When two rules conflict, institutions often select the stricter rule or the rule preferred by the most powerful stakeholder. Neither method is reliable.
Do the rules actually require incompatible outcomes in the same case?
What authority created each rule?
Are both rules governing the same actor, subject, time, and jurisdiction?
Does superiority, specificity, chronology, or express override control?
Can both rules be satisfied through a lawful interpretation or alternative path?
Preserve reasoning, authority, affected rules, and implementation changes.
Some conflicts cannot be resolved administratively. They may require legal interpretation, contract amendment, policy approval, judicial review, regulator engagement, or withdrawal of the lower rule.
15. Governance responsibilities
Authority must be governed throughout the lifecycle
Authority governance includes more than approving new rules. It should ensure that every rule remains connected to a valid source, current delegation, defined owner, and appropriate level in the hierarchy.
Governance responsibilities include:
- maintaining authority maps and delegation records;
- reviewing rules for excess authority;
- controlling incorporation of external material;
- monitoring expiration and supersession;
- resolving priority disputes;
- reviewing technical controls for policy alignment;
- preserving historical authority for past decisions;
- ensuring that unauthorized rules are removed or lawfully adopted.
16. Common failure cases
Authority defects can make otherwise clear rules unreliable
Failure case 1
The procedure that changes the policy
A local procedure adds a prohibition that the enterprise policy did not authorize. Employees treat the procedure as binding because it is operationally detailed.
Failure case 2
The expired delegation
A temporary executive delegation ends, but approvals continue under the old authority because the workflow was never updated.
Failure case 3
The stricter rule misrepresented as law
An internal risk threshold is described as a legal requirement, preventing informed review of whether the additional restriction remains justified.
Failure case 4
The incorporated standard with no version
A policy requires compliance with an external standard but does not identify the edition. Later revisions silently change the institution's obligations.
Failure case 5
The system rule with no policy source
Software rejects certain transactions, but no approved rule can be found. The technical control has become the de facto authority.
Failure case 6
The local rule that conflicts with contract
A department adopts a retention period shorter than a customer agreement requires. The lower rule is clear, but compliance would breach the contract.
17. Authority review
Twenty questions for authority integrity
- 01
Source
What precise instrument or decision gives the rule authority?
- 02
Issuer
Who created or approved the rule?
- 03
Subject authority
Did the issuer possess authority over this subject matter?
- 04
Population authority
Did the issuer possess authority over the governed actors or entities?
- 05
Procedure
Were required approval, consultation, notice, publication, or adoption steps followed?
- 06
Delegation
Is delegated authority documented, current, and within limits?
- 07
Redelegation
Was the recipient authorized to transfer the power further?
- 08
Hierarchy
Where does the rule sit relative to law, contract, policy, procedure, and implementation?
- 09
Superior rules
Does any higher authority limit or displace the rule?
- 10
Specificity
Is the rule general, specific, implementing, or exceptional?
- 11
Chronology
Was the rule amended, suspended, superseded, or replaced?
- 12
Incorporation
Are external materials precisely identified, available, and validly adopted?
- 13
Stricter position
Is a stricter internal rule intentional, authorized, proportionate, and accurately described?
- 14
Excess authority
Does the rule regulate beyond the issuer's power?
- 15
Technical implementation
Does any system rule exceed or alter approved authority?
- 16
Priority
Is there a documented method for resolving overlap or conflict?
- 17
Ownership
Who is authorized to interpret, amend, suspend, and retire the rule?
- 18
Historical validity
Can the institution reconstruct which authority governed a past decision?
- 19
Challenge
Is there a process for questioning or appealing unauthorized application?
- 20
Evidence
Can the full chain from source authority to operational enforcement be demonstrated?
18. Worked examples
Tracing authority before enforcing the rule
Observed rule
“All exceptions require approval from the Chief Risk Officer.”
Authority questions
- Which policy granted this authority?
- Does it cover every rule or only risk policies?
- May the authority be delegated?
- Does law or contract reserve some exceptions elsewhere?
- What happens during vacancy or emergency?
Controlled authority model
Exception authority is mapped by rule family, subject matter, risk level, delegated role, duration, review obligation, and superior legal or contractual constraint.
Stricter internal threshold
Law requires review above $100,000; company policy requires review at $50,000.
Authority analysis
The internal rule is not automatically contradictory. Confirm organizational authority, feasibility, purpose, and that no superior rule affirmatively protects the lower threshold from restriction.
Technical control
A system blocks access for contractors even though policy permits approved contractor access.
Authority analysis
The technical control is stricter than the approved rule. Determine whether the restriction was separately authorized, is a temporary compensating control, or is an unauthorized implementation defect.
Conclusion
Authority is the structural foundation of legitimate rule systems
A rule gains force from a legitimate source acting within defined limits. Hierarchy organizes the relationship among those sources. Delegation transfers decision power. Precedence resolves overlap. Governance preserves the chain from foundational authority to operational implementation.
Without that chain, institutions accumulate rules that are detailed but unauthorized, enforceable but invalid, stricter but unjustified, or technically effective but detached from policy.
Rules Integrity therefore requires authority to be visible, bounded, traceable, and reviewable. The institution should be able to explain who may create the rule, why, within what limits, at what level, and with what relationship to every superior and subordinate rule.
Foundational principle: No rule should be treated as legitimate merely because it is written, enforced, or widely followed. Its authority must be traceable to a valid source, exercised within scope, and preserved through every level of implementation.
Selected references
Sources informing this chapter
- Cornell Law School, Legal Information Institute. Supremacy Clause. Background on constitutional priority within the United States legal system.
- Cornell Law School, Legal Information Institute. Delegation. General legal background on transfer of authority and responsibility.
- Stanford Encyclopedia of Philosophy. Authority. Philosophical analysis of legitimate authority and reasons for compliance.
- U.S. Office of the Federal Register. Incorporation by Reference Handbook.
- U.S. Office of the Federal Register. Regulatory Drafting Guide. Guidance on authority citations, scope, amendments, and regulatory structure.
- Organisation for Economic Co-operation and Development. Recommendation of the Council on Regulatory Policy and Governance.
- OASIS Open. LegalRuleML Core Specification Version 1.0. Formal representation of authority, jurisdiction, temporal attributes, and legal rule relationships.
These sources provide established perspectives on legal authority, delegation, hierarchy, incorporation, regulatory governance, and formal representation. This chapter generalizes those principles across public, contractual, organizational, professional, and technical rule systems.