Before you start
HR hub- Your current handbook section on the topic, if there is one
- The relevant terms from your employment contracts
- The Acas guidance or Code of Practice for the policy area
- The name of the person who approves the policy
AI drafts the structure and plain-English wording from what you already say. The legal minimums come from GOV.UK and Acas, never the AI, and a named person approves the final policy.
The manual
Tick each checkpoint as it passes.
One HR policy, written in plain English, checked against the legal minimums from GOV.UK and Acas, and signed off by a named person with the authority to do it.
The AI does the drafting. It’s good at structure and at turning clunky handbook wording into something a normal person can read. It’s not reliable on what the law says, so you don’t ask it. The legal side comes from the source pages and the sign-off comes from a person. Three hands on one document: you collect, the AI drafts, a named person approves.
Gather four things: your current handbook section on the topic, the relevant terms from your employment contracts, the Acas guidance or Code of Practice that applies, and the name of whoever approves it. “Someone senior” isn’t a name. If nobody knows who signs it off, the policy just sits in a folder, so settle it now.
Pull together everything your organisation currently says about the topic. The handbook is the obvious place, but look at contracts and past staff announcements too, and write down the things people do that aren’t written anywhere. If everyone assumes a rule exists, you need to know before you write anything.
Put it all in one document. Messy is fine. Contradictions are useful, because they show where the policy needs to make a decision.
Checkpoint: everything you currently say on this topic sits in one place, including the unwritten bits.
This is the step people skip, and it matters most. Find the GOV.UK page or Acas guidance for your policy area and copy the requirements into a document of their own. That’s your checklist.
Why not ask the AI? Because it sounds the same whether it’s right or not. It can invent a rule, get a time limit wrong, or slide in something from another country’s law. You can’t tell from the tone.
Some examples of what the sources give you:
Copy what applies to your policy, from the current page, not from this list.
Checkpoint: a separate checklist, copied from the current GOV.UK or Acas page, that you could hand to someone else.
Now the AI earns its keep. Give it what you collected in step 1 and ask for an outline. Tell it to keep your rules and add nothing, because left alone it will helpfully invent a few.
Prompt
Turn the wording below into a policy outline with clear headings for purpose, scope, definitions, procedure and review. Keep all the rules we currently follow, add nothing new, and keep the language simple. [paste your existing wording here]
Read what comes back with the checklist beside you.
Checkpoint: the outline has a home for everything you currently do and for every point on your checklist. A missing heading is a gap you’ve found early.
Work one section at a time. It’s much easier to spot a problem in a few paragraphs than in ten pages.
Prompt
Rewrite this section in plain UK English for a general workforce. Keep every obligation and rule we currently have. Add nothing new. If anything is unclear or could mean two different things, mark it with [CHECK]. [paste the section here]
The [CHECK] instruction gives the AI a way to say “not sure” instead of guessing. Treat every [CHECK] as a question for a person, not something to settle by asking the AI again. Watch the vocabulary too: a term like “at-will employment” comes from US law and has no place in a UK policy.
Checkpoint: someone new to the organisation could read the section and know what to do, and every [CHECK] has been answered by a person.
Comparison is a job AI does reasonably well, as long as you stop it adding anything of its own.
Prompt
Compare the draft policy below with the checklist I've pasted from [Acas / GOV.UK]. List every point on the checklist that the draft does not cover. Do not add any legal content yourself; only flag what is missing. Draft policy: [paste your full draft] Checklist: [paste the requirements from Acas or GOV.UK]
Fill each gap using the wording from the source, not the AI’s version of it.
Then the numbers. Statutory rates change: GOV.UK says National Minimum Wage and National Living Wage rates change on 1 April every year, and it lists the current Statutory Sick Pay rate on its own page. Never let the AI supply a rate, threshold or time limit. If your policy mentions one, check it on the current GOV.UK page yourself, or point staff to the page instead of printing a figure that will go out of date.
Checkpoint: every missing point is filled from the source, and every rate, threshold and time limit has been checked on GOV.UK.
Send the draft to the named approver with the checklist and the gap comparison, so they can see what it was checked against. They’re approving the policy, not the AI’s work.
If you have a trade union or employee representatives, involve them early, not when the thing is finished. For a hybrid working policy, Acas suggests the policy itself says who it was agreed with.
Once it’s approved, tell staff where to find it. And if the change affects anything in people’s written statements, GOV.UK says you must tell them within one month of making the change.
Checkpoint: a named approver, a record of any consultation, and a clear place where staff can find the final version.
Keep it away from live cases about a named person. Don’t ask it how a policy applies to a specific employee, whether a disciplinary outcome is fair, or how to handle a particular grievance. Those need human judgement, knowledge of the individual and a proper process.
The AI is for writing the policy that covers everyone. Applying it to one person is a human job.
Confidentiality and UK GDPR
Before you paste anything, ask two questions: is there personal data in it, and is it confidential to my organisation or a client? If the answer to either is yes, use a tool your organisation has approved, under a business contract, and send only what the task needs.
Codes, headings, layouts, policy wording and your own notes with names taken out are usually enough. Customer names, staff names and bank details almost never are.
Ask for the formula, the template or the draft, not the answer. A formula you can test or a draft you can edit is checkable. A total typed back into a chat window is not.
If it is your organisation's or a client's information, use the tool your organisation has approved, under its contract, not a personal account.
Under a business contract the provider usually acts as your processor. On a personal account you are agreeing to its consumer terms instead.
ICO: The data minimisation principleico.org.uk
ICO: Controllers and processorsico.org.uk
ICO: International transfersico.org.uk
ICO: Guidance on AI and data protectionico.org.uk
ICAEW Code of Ethics (confidentiality is a fundamental principle)www.icaew.com
| Provider | Personal plans | Business and enterprise |
|---|---|---|
| OpenAI (ChatGPT) | Check settingsPersonal plans: conversations can be used to train models unless you turn off "Improve the model for everyone" in Settings > Data controls. | Not trained on by defaultChatGPT Business, Enterprise, Edu and the API: not used to improve models by default.6OpenAI Help Centre: How your data is used to improve model performancehelp.openai.com7 OpenAI: Enterprise privacy at OpenAIopenai.com |
| Anthropic (Claude) | Check settingsFree, Pro and Max: chats are used to train models only when the model-improvement setting is on. With it on, data is kept for up to five years; with it off, the standard is 30 days. | Not trained on by defaultClaude for Work and the API: inputs and outputs are not used to train models by default.8Anthropic: Updates to Consumer Terms and Privacy Policywww.anthropic.com9 Anthropic Privacy Center: Is my data used for model training? (consumer)privacy.claude.com10 Anthropic Privacy Center: Is my data used for model training? (commercial)privacy.claude.com |
| Microsoft (Copilot) | Check settingsPersonal Microsoft accounts are covered by Microsoft's consumer terms, not your organisation's. | Processor under DPACopilot and Copilot Chat used through an organisation: covered by Microsoft's Data Protection Addendum with Microsoft as processor; your data is not used to train foundation models.11Microsoft Learn: Enterprise data protection in Microsoft Copilot and Copilot Chatlearn.microsoft.com12 Microsoft Learn: Data, privacy and security for Microsoft Copilotlearn.microsoft.com |
From the same studio · disclosed
Forematter. In development, not open to customers yet. Once a policy is approved, it is the kind of document Forematter answers staff questions from, showing where each answer came from.
Ours: made by the same studio that runs this site.
Questions
Short answers, drawn from this page. The sources are listed above.