Before you start
HR hub- Your dated evidence notes from the review period
- The objectives agreed at the start of the period
- The employee's self-appraisal, if there is one
- Your organisation's review form, or an Acas appraisal template
Use AI to turn a manager's own anonymised notes into a balanced review, check the language and tighten SMART objectives. The rating and any decision stay with the manager.
The manual
Tick each checkpoint as it passes.
A review write-up that’s fair, specific and tied to what the person actually did in the period: strengths, areas to develop, support needed. No guesswork, no personality verdicts.
The rating stays with you. So does any decision that follows from it. The AI helps with the writing; you do the judging.
Acas describes a performance review as a chance to discuss what someone is doing well, any areas for improvement, whether they need more support or training, and their career and development objectives. Some places call it an appraisal. The write-up is the record of that conversation, and it needs to be worth reading.
Get your raw materials together: your dated evidence notes from the period, the objectives you both agreed at the start, the employee’s self-appraisal if there is one, and your organisation’s review form. If you’re short of a form, Acas publishes free appraisal templates, including one based on job objectives and a self-appraisal form.
Then do the bit people skip. Decide the rating yourself, before you open any AI tool, and write it down somewhere the AI will never see. Decide afterwards and you’ll drift towards whatever the draft makes sound reasonable. That’s backwards.
Go through your notes and pull out what happened, when, and what came of it. Facts and dates, not adjectives. “Lazy”, “difficult” and “natural leader” are impressions, and none of them would survive the employee asking “what do you mean?”
Acas says reviews might be based on whether the employee is meeting agreed objectives, demonstrating the right behaviours, and following any agreed development plan. Sort your notes against those three. Anything that doesn’t fit, ask yourself why it’s there.
There’s no prompt for this step. It’s all you.
Checkpoint: every item in your notes has a date and an observable outcome, and none of it describes the person’s character.
Before anything goes near an AI tool, take out names and anything that points to a specific person. Use “the employee” or “Employee A”.
Then take out the sensitive material: anything about health, disability, family circumstances or age, and anything touching the protected characteristics in the Equality Act 2010. The ICO treats health data as special category data, along with some protected characteristics. If a detail matters for support or adjustments, it belongs in a separate confidential record, not in the write-up and not in a prompt.
Checkpoint: read your cleaned notes once more, slowly, looking for a name, a health reference or a family mention you’ve missed.
You’re asking the AI to organise and phrase, not to evaluate. Paste only the cleaned notes.
Prompt
Here are my dated notes about [Employee A] for the review period [start date to end date]. Write a balanced review with three sections: strengths, areas to develop, and support needed. Use only these notes. Do not add examples, dates or outcomes that aren't in them. If any claim you write has no example behind it in my notes, flag it in [square brackets] so I can remove it or find the evidence. Do not give a rating or an overall performance level. Notes: [paste dated notes here]
Read what comes back against your notes, line by line. The tool will sometimes smooth over a gap by inventing something plausible. If a claim has no evidence behind it, cut it.
Checkpoint: every sentence in the draft traces back to a line in your notes, and the draft contains no rating.
A draft can be accurate and still read badly: vague words, loaded words, small personality judgements that slipped in.
Prompt
Check this review write-up for three things: (1) vague, personality-based or loaded words; (2) anything that comments on age, health, family or other personal circumstances; (3) anything an employee could fairly ask "what do you mean by that?" about. Quote each problem phrase exactly, then suggest replacement wording tied to observable work: what the person did, when, and with what result. Write-up: [paste draft here]
“Attitude” and “engagement” are the usual culprits. They feel like they say something but don’t point at anything. “Missed three agreed deadlines” does. “Asked for help early when a task slipped” does. Don’t accept every suggestion blindly: some replacements are tidier than they are true, so check each against your notes.
Checkpoint: no phrase left in the draft describes who the person is rather than what they did.
Acas says objectives should be fair and reflect the employee’s usual tasks and workload, though they might also stretch them, and suggests making them SMART: specific, measurable, achievable, relevant and time-bound. Loose goals usually miss at least one.
Prompt
Turn these goals into SMART objectives. For each one, say which parts of SMART it is missing (specific, measurable, achievable, relevant, time-bound) and what information I'd need to add. Do not invent figures, deadlines or targets; leave a placeholder in [square brackets] where I need to supply one. Role and usual workload: [describe the role and typical tasks] Goals: [paste goals here]
The placeholders matter. Any number or date in an objective has to come from you and the person’s actual workload. The AI doesn’t know what’s achievable for this person in this role, and if it guesses, you’ll be holding someone to a target nobody checked. Agree the objectives with the employee rather than handing them over finished.
Checkpoint: each objective has a clear measure and a date, and you can explain why it’s achievable given the person’s normal workload.
Restore the names and anything you swapped out. Then read the whole thing as the employee would: cold, with no context about what you meant. Does anything sting without a reason behind it? Is anything a surprise? Acas says managers should also talk to people informally through regular feedback, coaching and one-to-ones, so nothing in the write-up should be the first time they’ve heard it.
Fill in your organisation’s form with the rating you decided at the start. Acas says to keep a written record of what is discussed and share it with the employee afterwards.
Checkpoint: the rating on the form is the one you decided before using AI, and nothing in the write-up would be news to the person reading it.
Some situations aren’t for this. Acas says that when there’s a problem with performance, employers should work out whether it’s capability (ability) or conduct (behaviour), and the two can overlap. Regular lateness, for example, could be down to an impairment or condition; if that’s a disability, the employer must consider reasonable adjustments before any disciplinary action.
So keep AI out of capability processes, disciplinary processes, anything involving health or disability, and anything that could lead to dismissal. Those need careful handling and a clear written record, kept confidential.
The write-up is the easy bit. The judging stays yours.
Confidentiality and UK GDPR
Before you paste anything, ask two questions: is there personal data in it, and is it confidential to my organisation or a client? If the answer to either is yes, use a tool your organisation has approved, under a business contract, and send only what the task needs.
Codes, headings, layouts, policy wording and your own notes with names taken out are usually enough. Customer names, staff names and bank details almost never are.
Ask for the formula, the template or the draft, not the answer. A formula you can test or a draft you can edit is checkable. A total typed back into a chat window is not.
If it is your organisation's or a client's information, use the tool your organisation has approved, under its contract, not a personal account.
Under a business contract the provider usually acts as your processor. On a personal account you are agreeing to its consumer terms instead.
ICO: The data minimisation principleico.org.uk
ICO: Controllers and processorsico.org.uk
ICO: International transfersico.org.uk
ICO: Guidance on AI and data protectionico.org.uk
ICAEW Code of Ethics (confidentiality is a fundamental principle)www.icaew.com
| Provider | Personal plans | Business and enterprise |
|---|---|---|
| OpenAI (ChatGPT) | Check settingsPersonal plans: conversations can be used to train models unless you turn off "Improve the model for everyone" in Settings > Data controls. | Not trained on by defaultChatGPT Business, Enterprise, Edu and the API: not used to improve models by default.6OpenAI Help Centre: How your data is used to improve model performancehelp.openai.com7 OpenAI: Enterprise privacy at OpenAIopenai.com |
| Anthropic (Claude) | Check settingsFree, Pro and Max: chats are used to train models only when the model-improvement setting is on. With it on, data is kept for up to five years; with it off, the standard is 30 days. | Not trained on by defaultClaude for Work and the API: inputs and outputs are not used to train models by default.8Anthropic: Updates to Consumer Terms and Privacy Policywww.anthropic.com9 Anthropic Privacy Center: Is my data used for model training? (consumer)privacy.claude.com10 Anthropic Privacy Center: Is my data used for model training? (commercial)privacy.claude.com |
| Microsoft (Copilot) | Check settingsPersonal Microsoft accounts are covered by Microsoft's consumer terms, not your organisation's. | Processor under DPACopilot and Copilot Chat used through an organisation: covered by Microsoft's Data Protection Addendum with Microsoft as processor; your data is not used to train foundation models.11Microsoft Learn: Enterprise data protection in Microsoft Copilot and Copilot Chatlearn.microsoft.com12 Microsoft Learn: Data, privacy and security for Microsoft Copilotlearn.microsoft.com |
Questions
Short answers, drawn from this page. The sources are listed above.