Keep one shared AI policy core and add short annexes only for casework, fundraising, HR and procurement, where risk genuinely diverges, changing content but never the shared structure.
This series has built one core policy piece by piece: a permitted-use table, a red-line list, an escalation path, a six-month review cycle. That core is meant to be shared across the whole organisation, and for most of it, that is exactly right. It stops being right the moment two departments hit meaningfully different risk from the same underlying structure, because a single document written broad enough to satisfy both ends up either too permissive for the higher-risk one or too restrictive for the lower-risk one. Earlier pieces in this series already found this pattern department by department. This piece is about what to do with it once the core policy is written.
The answer is not a separate policy per department. It is one core policy, unchanged, with a short annex for any department whose risk profile genuinely diverges from the shared default.
The department playbooks earlier in this series already showed that HR carries more red lines than Finance, that Communications and Advocacy answers to public scrutiny in a way Procurement never does, that donor intelligence crosses into personal data in ways ordinary programme reporting does not. A core policy captures the shared structure well: the shape of the permitted-use table, the test for a red line, the 24-hour escalation rule, the six-month cadence. It cannot also capture every department's specific detail without becoming too long for any one department to actually use, or too generic to help any of them.
An annex adjusts content, never structure. It can add rows to the permitted-use table specific to that department's tasks, and it can add categories to the red-line list where that department's risk genuinely differs from the shared default. It cannot change the shape of the table, invent a different escalation mechanism, or run its own review cycle on its own schedule. The structure has to stay identical everywhere, because that consistency is exactly what lets a staff member move between departments' documents without relearning how to read a policy each time.
A shared core policy is not one document trying to be everything to everyone. It is the part that never changes, with a short annex for the part that always does.
Every annex is another document to keep in sync at each review, and that is a real cost, not a hidden one. The honest answer is that the alternative costs more: one document stretched to cover every department's specifics either grows past what anyone will actually read, or gets quietly ignored by the departments it was never really written for. The discipline that keeps annexes worth the overhead is the same one this series has applied throughout: keep each annex short, review it on the same six-month cycle as the core rather than a separate schedule of its own, and resist the pull to let any annex grow into a second full policy.
Keep one core policy for the shared structure, permissions table, red-line test, escalation path, review cycle, and let only the departments whose risk genuinely diverges, casework, fundraising, HR, procurement, attach a short annex that adds content without ever changing that shared structure.
No external statistic cited; this article presents an internal explanatory piece rather than third-party evidence.
Why an AI policy needs a fixed six-month review against four specific questions, plus four yes-or-no triggers (departed contact, changed tool, repeated escalation, changed law) that force an earlier one.
AI Use Policy · 4 minGuide · 17 September 2026Five Programmes and Monitoring tasks worth delegating to AI, including survey summaries and indicator cross-referencing, and three that never should be, including interpreting beneficiary feedback and signing off outcomes.
Team AI Training · 3 minGuide · 18 September 2026Which HR tasks can be delegated to AI, such as scheduling, job posting drafts and aggregated survey themes, and why hiring, discipline, grievances and individual personal data stay with named humans.
Team AI Training · 4 minIf this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.