Foundations of Rules Integrity · Chapter 1
What Is a Rule?
A rule is more than a sentence that tells someone what to do. It is a structured constraint on decision-making, created under authority, applied in context, and intended to produce or protect an outcome.
Chapter summary
The starting point for the discipline
Rules are among the most common instruments of organized life. Governments use them to exercise lawful authority. Businesses use them to coordinate work, manage risk, meet contractual commitments, and maintain consistent operations. Courts, hospitals, schools, manufacturers, software systems, professional bodies, and families all depend upon rules in different forms.
Yet the word rule is often used loosely. It may refer to a legal command, an internal policy, a technical condition, a social expectation, a procedural step, a mathematical relationship, or an automated decision instruction. These things share important characteristics, but they are not identical. A serious discipline of Rules Integrity therefore needs a definition broad enough to work across institutions and technologies, while still being precise enough to support analysis, design, validation, and measurement.
This chapter proposes such a working definition. It explains what rules do, how they differ from neighboring concepts, what elements make a rule complete, how rules acquire authority, and why no rule can be understood apart from the system in which it operates. It concludes with practical tests that can be applied before a rule is adopted or when an existing rule is reviewed.
1. A working definition
A rule guides or constrains a decision
Working definition: A rule is an authoritative or accepted statement that guides, requires, permits, limits, or prohibits action or decision-making under defined conditions in order to produce, protect, or preserve an intended outcome.
This definition is intentionally broader than a definition limited to law. A rule may be legally binding, contractually binding, organizationally mandatory, technically enforced, professionally expected, or socially accepted. What matters is that it has normative or decision-directing force: it changes what an actor is expected, allowed, required, or forbidden to do.
Cornell Law School's Legal Information Institute describes a rule in general terms as a standard, principle, or norm that guides conduct.1 That description captures the essential connection between a rule and a decision. When a real situation arises, the actor must determine which rule applies and what decision follows if the rule is honored.
The Rules Integrity definition adds four elements that are necessary for organizational analysis:
- Direction: the rule affects what may, must, should, or must not be done.
- Conditions: the rule applies only within some context, even when that context is not stated well.
- Authority or acceptance: the rule derives force from a source, role, agreement, system, or established practice.
- Purpose: the rule exists to produce, protect, or preserve an outcome.
A sentence that merely describes a fact is not ordinarily a rule. “The warehouse closes at 6:00 p.m.” is descriptive if it reports a schedule. It becomes rule-like when it directs conduct: “All non-emergency shipments must be received before 6:00 p.m.” The second statement identifies a subject, a required condition, and a boundary on action.
2. Rules as decision constraints
A rule narrows the field of acceptable choices
The phrase decision constraint does not mean that every rule removes all discretion. It means that a rule changes the set of choices that can properly be made. Some rules command a single action. Others establish a range, threshold, process, priority, presumption, or condition within which judgment may still be exercised.
Consider a procurement policy stating that purchases above $50,000 require competitive bids. The rule does not determine which vendor must be selected. It constrains the decision process by requiring a method before the final choice is made. A clinical protocol may require an additional review when a risk score exceeds a threshold, while still leaving treatment selection to professional judgment. A contract may permit termination after a defined breach, creating an option rather than a command.
Monitoring closes the loop: observed results may justify clarification, amendment, replacement, or retirement of the rule.
This outcome-oriented view is important. Rules are not valuable simply because they exist or because someone complied with their wording. Their value depends upon whether they reliably support legitimate objectives without producing disproportionate harm. Regulatory analysis frameworks used by governments therefore examine the need for action, available alternatives, expected effects, and unintended consequences before or after rules are adopted.6 7
A rule can be followed perfectly and still be badly designed. Employees may complete a required approval step that adds no meaningful control. A hospital may meet a documentation requirement while the requirement diverts attention from patient care. A software system may apply a threshold consistently even though the threshold no longer reflects the underlying risk. Rules Integrity therefore asks two different questions: Was the rule followed? and Was the rule itself coherent, justified, and effective?
4. The anatomy of a rule
A complete rule contains more than a verb
The shortest rule may be only a few words: “No smoking.” But most organizational rules require more structure. A reliable analysis should identify the following components, whether they appear in one sentence, several clauses, a table, or multiple documents.
The person, role, system, unit, or entity governed by the rule.
Whether the action is required, permitted, prohibited, recommended, or discretionary.
The conduct, decision, state, information, or result addressed.
The trigger, threshold, sequence, deadline, duration, or effective period.
The jurisdiction, business unit, system, population, transaction, or location covered.
The defined circumstances in which the general rule does not control.
The outcome, interest, right, risk, or institutional intent the rule serves.
The source that gives the rule force and the record demonstrating its adoption and application.
Missing components do not always make a rule invalid, but they increase the need to infer meaning from context. “Reports must be filed promptly” identifies an action and obligation but leaves the actor, report type, event, deadline, and destination uncertain. Those details may exist elsewhere. If they do not, the rule invites inconsistent application.
A rule may also contain a consequence: denial, escalation, correction, penalty, suspension, loss of authority, or another response. Consequences are not necessary to the concept of a rule—many rules are followed because of professional duty, coordination, or technical enforcement—but consequences affect how the rule operates and how people perceive its seriousness.
5. Obligation, permission, and prohibition
The force of a rule is carried by its modality
Normative systems commonly distinguish obligations, permissions, and prohibitions. Philosophers and logicians examine these relationships through deontic logic, but the practical distinction is familiar: an actor may be required to act, allowed to act, or forbidden to act.2
Drafting conventions use modal words to signal that force. The U.S. Office of the Federal Register uses must for a requirement, should for a strong recommendation, may for an option, and can for capability or possibility.4 ISO drafting rules similarly distinguish requirements, recommendations, permissions, possibilities, and capabilities so readers can identify the intended status of a statement.3
Must
Obligation
The actor is required to perform the action when the stated conditions apply.
May
Permission or discretion
The actor is allowed, but not necessarily required, to choose the action.
Must not
Prohibition
The actor is forbidden from performing the action within the rule's scope.
Should
Recommendation
The action is preferred or strongly advised, but departure may be acceptable.
Modal wording must be interpreted together with authority and context. In ordinary conversation, “should” may sound almost mandatory. In a controlled standard, it may have a defined meaning. “May” can grant discretion, acknowledge a legal possibility, or describe uncertainty. “Shall” has historically been used for obligations but can create ambiguity when it is also used to describe future events. The safest practice is not merely to choose a strong verb, but to use a documented drafting convention consistently.
Negative constructions require special care. “Employees may not disclose customer data” is commonly understood as a prohibition, but grammatically it can be read as either “are not permitted to disclose” or “might not disclose.” A direct form—“Employees must not disclose customer data”—states the prohibition more clearly.
7. Rules exist in systems
No rule is truly isolated
A rule derives meaning from the environment around it. Definitions may be located in another section. Exceptions may appear in an appendix. Authority may come from a contract or statute incorporated by reference. A procedure may determine how the rule is carried out, and a technical system may enforce a narrower interpretation than the text suggests.
This is why copying a sentence from one document into another can be dangerous. The copied words may retain their appearance while losing their original scope, definitions, precedence, exceptions, or effective date. A rule that is reasonable for one department may be impossible for another. A threshold intended for one category of transaction may become irrational when applied universally.
Context also includes organizational purpose. Suppose a business adopts a rule requiring all customer complaints to be closed within five days. The rule appears clear, measurable, and customer-focused. Yet if “closed” means administratively marked complete rather than substantively resolved, the rule may create pressure to close difficult complaints prematurely. The metric is achieved while the intended outcome is defeated.
Strong rule design therefore connects wording to process, incentives, data, accountability, technology, and future change. It asks how the rule will interact with the rest of the organization, not merely whether the sentence reads well.
8. Forms of rules
Rules may be written, embedded, inferred, or automated
The most visible rules are written in statutes, regulations, contracts, policies, manuals, standards, and procedures. But organizations also operate through rules that are not plainly stated.
Explicit and implicit rules
An explicit rule is intentionally expressed. An implicit rule is inferred from repeated practice, system behavior, organizational expectations, or the combined effect of other statements. Implicit rules can coordinate work effectively, but they are difficult to audit and may differ across teams. A common warning sign is the phrase, “Everyone knows that is how we do it,” when no authoritative source can be identified.
Written and unwritten rules
Unwritten rules include customs, professional norms, conventions, and local practices. They may be legitimate and valuable, especially where judgment and trust matter. They also create vulnerability when critical expectations depend upon individual memory, informal transmission, or institutional culture that may change when personnel change.
Human-readable and machine-executable rules
A machine-executable rule is implemented in code, configuration, a workflow, database constraint, decision table, or model. It may faithfully implement a written rule, narrow it, expand it, or silently contradict it. For example, a policy may permit an exception with executive approval while the software offers no exception path. The implemented rule is then stricter than the written rule.
Rules Integrity requires traceability between human and technical forms. An organization should be able to identify which authority a system rule implements, which version is active, how exceptions are handled, and whether the technical behavior still matches the governing intent.
Constitutive and regulative rules
Some rules regulate an activity that already exists: speed limits regulate driving. Others help create the activity or institution itself: rules define what counts as a valid vote, an approved transaction, a licensed professional, or a completed contract. These constitutive rules are especially important because changing them can alter the meaning of the system, not merely behavior within it.
9. Qualities of a trustworthy rule
A good rule must survive more than grammatical review
Clear writing is essential, but clarity alone is not enough. A trustworthy rule should be evaluated across several dimensions.
Necessary
It addresses a real problem or purpose that cannot be handled better through a less restrictive mechanism.
Authorized
It comes from a legitimate source acting within its authority and required process.
Clear
Affected readers can identify the actor, action, conditions, scope, and force without avoidable uncertainty.
Consistent
It does not create unresolved conflict with superior, related, or dependent rules.
Feasible
The required action can actually be performed with available authority, time, information, systems, and resources.
Proportionate
The burden, restriction, and consequence are reasonably related to the importance and risk of the objective.
Traceable
Its source, purpose, adoption, dependencies, versions, and implementation can be reconstructed.
Testable
There is a fair and reliable way to determine whether the rule applied and whether it was satisfied.
Adaptable
It can be reviewed and changed responsibly when surrounding facts, laws, technology, or objectives evolve.
These qualities sometimes compete. Greater precision may reduce flexibility. Broader discretion may improve responsiveness but reduce consistency. A strict deadline may improve timeliness while harming complex cases. Rule design is therefore not a search for a single perfect sentence. It is the disciplined balancing of legitimate objectives, risks, rights, resources, and future conditions.
10. Common failure cases
Rules can fail even when their purpose is sound
Failure case 1
The rule without a defined subject
Statement: “Background checks must be completed before access is granted.”
The rule does not identify who must complete the check, who grants access, which forms of access are covered, or whether temporary emergency access is included. Different departments may assume different responsibilities, creating gaps despite apparent agreement with the rule.
Failure case 2
The measurable rule that rewards the wrong result
Statement: “All support tickets must be closed within 24 hours.”
The deadline is easy to measure, but it may encourage closure before resolution, repeated reopening, or avoidance of complex issues. The rule measures administrative completion rather than service quality.
Failure case 3
The rule that conflicts with superior authority
Statement: “Customer records must be destroyed after two years.”
A contract or regulation may require retention for five years. The internal rule is clear and technically implementable, but compliance would violate a higher obligation. The defect is relational, not grammatical.
Failure case 4
The exception that consumes the rule
Statement: “Competitive bidding is required unless a manager determines that bidding is impractical.”
Without criteria, documentation, review, or limits on the exception, the manager's discretion can replace the general rule. The organization has the appearance of a control without a dependable constraint.
Failure case 5
The rule that became obsolete
Statement: “Signed forms must be faxed to the Records Office.”
Technology and process changed, but the rule remained. Employees develop workarounds, local interpretations, and undocumented exceptions. The gap between the official rule and real operation becomes rule drift.
11. A practical test
Ten questions to ask before trusting a rule
The following test is not a substitute for legal, technical, or professional review. It is a general Rules Integrity screen that can expose weaknesses before adoption or during periodic review.
-
01
Purpose
What problem, risk, right, obligation, or outcome justifies this rule?
-
02
Necessity
Is a rule required, or could information, training, design, incentives, or a narrower control solve the problem more effectively?
-
03
Authority
Who is authorized to issue the rule, and what source establishes that authority?
-
04
Structure
Are the actor, modality, action, object, conditions, timing, scope, and exceptions identifiable?
-
05
Consistency
Does the rule agree with superior authority, contracts, related rules, definitions, and established priorities?
-
06
Feasibility
Can affected actors comply using the available time, information, systems, resources, and delegated power?
-
07
Interpretation
Would reasonable readers in different roles reach materially similar conclusions about what the rule requires?
-
08
Consequences
What intended and unintended behaviors, incentives, burdens, exclusions, or risks may result?
-
09
Evidence
How will the organization know when the rule applies, whether it was followed, and whether it achieved its purpose?
-
10
Lifecycle
Who will own, review, amend, suspend, replace, and retire the rule as conditions change?
A rule that cannot answer these questions may still be legitimate, especially in urgent or highly discretionary settings. But each unanswered question represents uncertainty that should be acknowledged and managed rather than hidden.
12. Worked examples
From vague direction to an analyzable rule
Initial statement
“Important vendors should be reviewed regularly.”
What is missing?
- Who determines whether a vendor is important?
- What risk or service criteria apply?
- Who performs the review?
- What does the review include?
- How often is “regularly”?
- What happens when deficiencies are found?
More complete rule
“The Vendor Risk Manager must complete a documented risk review of each critical vendor at least once every twelve months and before renewal of a material contract. A vendor is critical when interruption of its service could prevent a designated essential business function from operating for more than four hours.”
The revised rule is not automatically correct. The four-hour threshold may be too strict or too lenient. Annual review may be insufficient for a rapidly changing threat. The Vendor Risk Manager may lack access to necessary information. But the rule is now analyzable. Its subject, action, frequency, trigger, scope, and classification criterion can be tested against authority, contracts, resources, other rules, and observed outcomes.
Permission
“The Chief Privacy Officer may approve a temporary exception for emergency access when delay would create a material threat to life or safety.”
Integrity questions
Is the permission discretionary or mandatory when the condition is met? How long may the exception last? Must the decision be documented? Who reviews it afterward? Does another rule prohibit the same access without exception?
These questions demonstrate a central lesson: a rule is not trustworthy merely because its wording appears professional. Trust comes from the relationship between language, authority, context, implementation, evidence, and continuing review.
Conclusion
A rule is a small instrument with system-wide effects
A rule is an authoritative or accepted statement that guides, requires, permits, limits, or prohibits action or decision-making under defined conditions for an intended purpose. It constrains choices, but it may also create rights, options, roles, processes, institutions, and expectations.
Understanding a rule requires more than reading its sentence. The reader must identify its source, subject, modality, action, conditions, scope, timing, exceptions, purpose, dependencies, and implementation. The rule must then be evaluated against surrounding law, contracts, policies, systems, objectives, evidence, and real-world consequences.
This is why Rules Integrity begins with the rule itself. Before contradictions can be detected, drift measured, dependencies mapped, or maturity assessed, the discipline must know what kind of instrument it is examining and what makes that instrument worthy of reliance.
Foundational principle: A rule should not be trusted merely because it is written, approved, or enforced. It should be trusted only to the extent that its authority, meaning, relationships, implementation, and effects can be understood and examined.
Selected references
Sources informing this chapter
- Cornell Law School, Legal Information Institute. “Rule.” General legal definition of a rule as a standard, principle, or norm guiding conduct.
- Stanford Encyclopedia of Philosophy. “Deontic Logic.” Background on the formal study of obligation, permission, prohibition, and related normative concepts.
- International Organization for Standardization. ISO/IEC Directives, Part 2: Principles and rules for the structure and drafting of ISO and IEC documents.
- U.S. Office of the Federal Register. Document Drafting Handbook. Official drafting guidance, including distinctions among requirements, recommendations, options, and capability.
- United Kingdom Office of the Parliamentary Counsel. Drafting Guidance. Guidance emphasizing accurate, effective, and clear legislative drafting.
- U.S. Office of Management and Budget. Circular A-4: Regulatory Analysis. Framework for evaluating need, alternatives, benefits, costs, distributional effects, and uncertainty in regulatory action.
- Organisation for Economic Co-operation and Development. Best Practice Principles for Regulatory Impact Analysis.
- European Commission. Better Regulation Guidelines and Toolbox. Guidance applying analysis, consultation, monitoring, and evaluation throughout the policy cycle.
These references provide established perspectives on legal rules, normative concepts, drafting, and regulatory analysis. The working definition and Rules Integrity framework presented in this chapter are proposed for continued discussion, refinement, and community development.