M.A.I. Consulting
ExplainerAdvanced25 September 20264 min read

Annexes: why casework, fundraising, HR and procurement need their own rules

Keep one shared AI policy core and add short annexes only for casework, fundraising, HR and procurement, where risk genuinely diverges, changing content but never the shared structure.

This series has built one core policy piece by piece: a permitted-use table, a red-line list, an escalation path, a six-month review cycle. That core is meant to be shared across the whole organisation, and for most of it, that is exactly right. It stops being right the moment two departments hit meaningfully different risk from the same underlying structure, because a single document written broad enough to satisfy both ends up either too permissive for the higher-risk one or too restrictive for the lower-risk one. Earlier pieces in this series already found this pattern department by department. This piece is about what to do with it once the core policy is written.

The answer is not a separate policy per department. It is one core policy, unchanged, with a short annex for any department whose risk profile genuinely diverges from the shared default.

Why one policy eventually stops fitting every department

The department playbooks earlier in this series already showed that HR carries more red lines than Finance, that Communications and Advocacy answers to public scrutiny in a way Procurement never does, that donor intelligence crosses into personal data in ways ordinary programme reporting does not. A core policy captures the shared structure well: the shape of the permitted-use table, the test for a red line, the 24-hour escalation rule, the six-month cadence. It cannot also capture every department's specific detail without becoming too long for any one department to actually use, or too generic to help any of them.

What an annex is allowed to change, and what it must never touch

An annex adjusts content, never structure. It can add rows to the permitted-use table specific to that department's tasks, and it can add categories to the red-line list where that department's risk genuinely differs from the shared default. It cannot change the shape of the table, invent a different escalation mechanism, or run its own review cycle on its own schedule. The structure has to stay identical everywhere, because that consistency is exactly what lets a staff member move between departments' documents without relearning how to read a policy each time.

Why these four departments need one

A shared core policy is not one document trying to be everything to everyone. It is the part that never changes, with a short annex for the part that always does.

The trade-off in maintaining annexes alongside the core

Every annex is another document to keep in sync at each review, and that is a real cost, not a hidden one. The honest answer is that the alternative costs more: one document stretched to cover every department's specifics either grows past what anyone will actually read, or gets quietly ignored by the departments it was never really written for. The discipline that keeps annexes worth the overhead is the same one this series has applied throughout: keep each annex short, review it on the same six-month cycle as the core rather than a separate schedule of its own, and resist the pull to let any annex grow into a second full policy.

The practical takeaway

Keep one core policy for the shared structure, permissions table, red-line test, escalation path, review cycle, and let only the departments whose risk genuinely diverges, casework, fundraising, HR, procurement, attach a short annex that adds content without ever changing that shared structure.

No external statistic cited; this article presents an internal explanatory piece rather than third-party evidence.

Series · Writing an AI use policy · part 4 of 6
Keep reading
02 ยท AI Use Policy

What are our people allowed to do, and how?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.