Workplace policies (workplace policy): the short set a small company actually needs, and the order to write them in

The instinct when somebody says the company needs policies is to write a handbook, and a handbook written in one sitting is a document nobody reads and nobody maintains. A better approach is to write the four that carry real risk, get them agreed, and add one only when a decision keeps having to be made twice. This page is that order, and why each one is where it is.

First: acceptable use, because it binds everyone

Every employee touches company systems, so acceptable use is the policy with the widest scope and the one worth writing first. It also teaches you the format: a one-sentence scope, a short list of requirements, an owner, a review date, and an acknowledgement. Once one policy exists in that shape, the rest are variations rather than blank pages, which is most of why the order matters at all.

Second: information security and data retention, because they answer questions you will be asked

These two arrive from outside: a customer's security questionnaire, an insurer, a prospective client's procurement team. Having them written before somebody asks is the difference between a same-week answer and a fortnight of drafting under time pressure. Retention in particular is worth settling early because it constrains every system you buy afterwards, and reversing it later means deleting things you have already promised to keep.

Third: the one your industry requires

A safety policy if people work with equipment, a vehicle policy if they drive, a gift acceptance policy if you are a nonprofit taking noncash gifts. This is the slot where a generic handbook is least useful and most likely to be wrong, because the requirement comes from the specific work rather than from a template.

What can wait, and the test for adding one

Everything else. The honest test for a new policy is whether the same decision has been made inconsistently more than once. If it has, write the rule down; if it has not, a policy is a solution looking for a problem and it will dilute the ones that matter. A short set that everybody has read beats a long set that nobody has.

Questions people ask about workplace policies

Handbook or separate documents?

Separate. A handbook has one version and one signature, so changing any rule means re-agreeing all of them. Separate policies change and are re-agreed one at a time.

Do we need a lawyer to write these?

Not to draft them. Have a lawyer read the ones with legal consequences before they go out, which is usually the employment-facing ones.

How often should they be reviewed?

Annually is the common answer and it is a reasonable default. What matters more is that the date is on the document and somebody owns it.

Sources

Related answers

Build the policy freeKeep the record of who agreed