The Policies Your HRIS Assumes You Already Have

Every HR platform on the market is built on a quiet assumption: that the foundational policies already exist somewhere. The onboarding flow asks you to upload your attendance policy. The compliance module asks you to attach your accommodation procedure. The offboarding checklist asks you to link your access-revocation steps. None of them ask whether those documents exist — because the software was designed for a company that already had an HR function before it had an HRIS.

If you're the first HR hire at a startup, or the one person holding people operations together at a company that grew faster than its infrastructure, you know the truth the platform politely ignores: half of those documents don't exist. Not because anyone was careless. Because the day each policy becomes necessary is almost always the first day you go looking for it.

That's the pattern worth naming. Foundational policy is invisible right up until the moment it isn't — and the moment it isn't is rarely convenient.

The policies only become visible the day you need them

Consider how each gap actually surfaces.

You don't miss an attendance policy until you're managing your first pattern of absence and realize you have no documented standard to point to — no distinction between innocent and culpable absence, no escalation path, nothing that makes the conversation defensible rather than personal.

You don't miss an accommodation procedure until an employee discloses a condition and asks for an adjustment, and you're improvising a legally significant process in real time, under pressure, with someone's trust and your company's exposure both on the line.

You don't miss an access-revocation checklist until someone leaves on bad terms and, three weeks later, you discover they still have credentials to a system nobody remembered to close.

In each case the cost of the gap isn't abstract. It lands on a specific day, in a specific conversation, and it lands on you.

Why "we'll write it when we need it" fails

The instinct is understandable: don't build infrastructure you're not using yet. But policy is the one area where writing it when you need it means writing it too late. A policy drafted mid-incident is a policy drafted defensively, and it shows. It also can't be applied to the situation that triggered it — you can't retroactively hold someone to a standard you hadn't set.

There's a second trap, subtler than the empty file: the draft. The half-finished attendance policy someone started in a Google Doc eighteen months ago. The accommodation process that lives in one senior person's head. These feel like coverage. They aren't. An unapproved, uncommunicated, inconsistently applied document offers almost none of the protection a real policy does, and it carries a particular risk of its own — the appearance of a standard you're not actually meeting.

Where the exposure actually sits — Canada, the US, and the UK

If you operate across borders, the gaps don't just multiply — they change shape. The same missing policy carries a different flavour of risk depending on the jurisdiction, and the assumptions that hold in one country quietly fail in another. A few of the load-bearing examples:

Termination and separation. In the US, the at-will default tempts people into believing separation is simple. It isn't — at-will has never meant consequence-free, and discrimination, retaliation, and wrongful-termination claims all live in that gap. In Canada, there's no at-will equivalent at all: common-law reasonable notice can far exceed the statutory minimums in the employment standards legislation, and a poorly documented termination gets expensive quickly. In the UK, unfair-dismissal protection and statutory process attach once an employee has the qualifying service, which makes a documented, followed procedure the difference between a clean exit and a tribunal. One "termination policy" written for a US mindset will not protect you in London or London, Ontario.

Accommodation. The US frames this around the ADA and the interactive process. Canada frames it as a duty to accommodate to the point of undue hardship under human rights legislation — a genuinely demanding standard. The UK frames it as reasonable adjustments under the Equality Act. The underlying humanity is the same; the procedural obligations, triggers, and thresholds are not. A single generic process will under-serve at least two of the three.

Employee data privacy. This is where a lot of lean teams are most exposed and least aware of it. The UK runs on UK GDPR and the Data Protection Act — a comprehensive regime with real obligations around employee data. Canada layers federal and provincial rules, with Quebec's requirements notably strict. The US has no single federal equivalent and instead a widening patchwork of state law. If your HRIS is collecting, storing, and moving employee data across these lines — and it is — the policy governing that flow is not optional infrastructure.

The point isn't that you need to become a three-country employment lawyer. It's that a policy is only as good as the jurisdiction it was written for, and "we have a handbook" is not the same as "we have coverage where we operate."

How to triage when you can't do everything at once

You won't close every gap this quarter, and you shouldn't try to. Sequence by exposure, not by convenience.

Start with the policies where the cost of not having one is a legal claim rather than an awkward conversation: anything touching accommodation, harassment and investigations, termination, and employee data handling. These are the items where improvisation is most expensive and least forgivable.

Then move to the operational backbone — attendance, hours and overtime, remote and on-call — where a documented standard is what lets you manage consistently and fairly, and what keeps a management decision from looking arbitrary after the fact.

Then the exit layer — final pay, benefits continuation, access revocation, knowledge transfer — the steps that quietly protect you on the way out.

The goal isn't a binder nobody reads. It's making sure that the day a policy becomes visible, it already exists, it's already approved, and you can produce it without a scramble.

Find your gaps before they find you

The hardest part is seeing your own gaps clearly — the missing policy is, by definition, the one you're not thinking about. That's exactly what the HR Policy Gap Audit is built to fix: a ten-minute, self-scoring diagnostic that walks you through the eighteen foundational policies lean teams most often lack, flags the ones that carry the greatest legal exposure, and tells you where your risk sits today.

It's the honest version of the checklist your HRIS assumed you'd already completed.

Download the HR Policy Gap Audit at people-stack-now.comand if it surfaces a gap, the template that closes it is already built.

Next
Next

Germany Just Ended the Phone-In Sick Note. Here's What It Reveals About How Differently Countries Handle Absence