I agree, and have seen many banks where their POLICY is how the bank is going to handle the regulation. (Why it's done) "ABC Bank will ensure that the tenets of XYZ regulation are met, including training, etc.." and is usually 1 to 2 pages long. This is generally approved by the Board. It is short, because the details go in the procedures, and changes there do not need a Board re-approval.
Procedures - the How, When and Where it's done is significantly more detailed, is flexible for persons, core systems, etc. and can run 20-pages plus. This is the management part.
Integrity. With it, nothing else matters. Without it, nothing else matters.