In many SMEs, IT rules exist, but only inside the owner’s head. Everyone more or less guesses what is done and what is not. As long as nothing goes wrong, this holds up.

The problem appears the day an employee installs free software that opens a door, sends a client file to their private address, or leaves with a copy of the database. The question then becomes: what exactly had you forbidden them from doing, and can you prove it?

This is what an IT charter is for.

What is an IT charter actually for?

An IT charter is an internal document that describes the expected use of company tools: computers, phones, e-mail, remote access, storage spaces. It fulfils two distinct functions, and both matter.

It gives staff a clear framework. Most breaches are not malicious, they come from ignorance. No one ever told your accountant that a payroll file should not be forwarded to their personal e-mail to finish over the weekend. They think they are doing the right thing, they are working. A written rule removes this grey area.

It allows the employer to act in the event of a breach. This is the point owners tend to underestimate. Holding someone accountable for breaking a rule assumes that the rule existed, that it was clearly stated, and that the person was aware of it. Without a written document that staff have been made aware of, the discussion quickly turns into a misunderstanding, and the company’s position is weak.

An unwritten rule is a rule that does not exist

Typical scenario: an employee leaves the company and takes the file of their business contacts, "like everyone does here". No document had ever forbidden it, and the practice tolerated until then works against the employer. The time to set the rules is not when the problem occurs.

What does a charter actually contain?

An SME charter does not need to be long. It must cover the situations your staff actually encounter.

TopicWhat the charter specifies
Personal use of toolsWhether reasonable personal use is tolerated, and within what limits
PasswordsBan on sharing access credentials, use of the company’s password tool
Personal devicesWhether a private phone or computer may access business data
Remote workNetwork used, screen locking, paper documents, connection conditions
Software installationWho is allowed to install what, and the procedure for requesting a tool
Cloud storageAuthorised services, and the ban on personal accounts for company data
Social mediaWhat may be said about the company, its clients and its projects
Employee departureReturn of equipment, access and data, deletion of accounts
Incident reportingWho to contact, within what timeframe, and the guarantee that no one will be punished for reporting

Two points on this list deserve particular attention.

Personal cloud storage has become the most common workaround. An employee in a hurry drops a folder onto their own file-sharing account to access it from home. Company data then leaves all control, and no one knows it. Explicitly authorise a usable solution, or your teams will find one themselves. The same reasoning now applies to artificial intelligence tools, which we cover in can I use ChatGPT with my company’s data.

Incident reporting is the single most valuable clause in the entire charter. An employee who clicked on a phishing link and fears being punished sometimes waits several days. That delay is exactly what an attacker needs. Write in black and white that reporting a mistake promptly carries no sanction.

The tone: realistic, or worked around

A charter that bans everything is not applied, it is ignored. Banning all personal browsing, all private devices, all unapproved tools produces a document that no one follows, and a rule no one follows no longer protects anything at all. Worse: it discredits the important rules, which end up buried among the rest.

Always explain the reason why. “Do not reuse your work password on private sites” is not enough on its own. Add the reason: when a third-party site is hacked, stolen credentials are tried elsewhere, including on your business e-mail. A rule that is understood gets followed, a rule that is merely imposed gets worked around.

Aim for the principle rather than the list. “Company data does not leave the tools provided by the company” covers more situations, and ages better, than a list of banned services you will have to update every six months.

How do you get it adopted?

A charter drafted and then forgotten on the shared server fulfils neither its educational function nor its evidentiary one. Three simple steps make the difference.

Have it formally accepted. A paper signature, an electronic signature, or validation through an internal tool: the method does not matter, as long as it leaves a dated record. That record is what establishes that the rule was known.

Hand it over on arrival. Include it in the onboarding pack, alongside the contract and equipment access. A new employee who receives the charter on day one understands that it is part of how the company works, not a constraint bolted on afterwards.

Bring it back up. Once a year, in ten minutes of a team meeting, revisit two or three points. Use the opportunity to flag what has changed. It is also a chance to talk about current threats, such as CEO fraud, which relies entirely on bypassing internal procedures.

The read-it-aloud test

Before distributing your charter, read it aloud in front of two employees who did not draft it. Whenever a sentence triggers a "yes, but in practice, how does that work?", you are holding an unworkable rule. Fix it before distribution, not after the first incident.

Monitoring: an area to handle with care

Many business owners see the charter as a way to authorise staff monitoring. That is the wrong approach, and it can be costly.

In Switzerland, employee monitoring is governed by both employment law and data protection law. These frameworks set limits that an internal document cannot override: a charter announcing a control does not make that control admissible. Conversely, certain normal technical measures, such as access logging or message filtering, require that the people concerned be informed of their existence and their purpose.

Keep two ideas in mind, and do not go further without advice. First, informing staff is generally necessary, but informing them does not make everything possible. Second, the line between a legitimate technical control, aimed at the security of the system, and surveillance of people’s behaviour, is precisely the delicate point.

Do not draft the monitoring section on your own

The clause describing what the company consults, records or analyses is the most sensitive part of the entire charter. An approximate drafting exposes the employer instead of protecting them. Have this section reviewed by a lawyer specialised in employment law, describing precisely the technical tools you have in place.

Why a template found online is not enough

A charter template downloaded from the internet was written for a different company. It knows nothing about your tools, your organisation, or your employment contracts.

It will mention rules for a server you do not have, stay silent on the collaboration tool your entire team uses every day, or impose an approval procedure that assumes an internal IT department you do not have. It can also contradict your employment contracts or a company policy already in force.

An ill-fitting charter is at best useless, because no one recognises themselves in it. At worst it is unworkable, and in that case the document itself weakens your position: invoking a rule that is clearly out of step with how the company actually works can easily backfire on the person invoking it.

The useful work, therefore, is not the drafting, it is the adaptation. Start from an inventory of your actual tools and your teams’ actual practices, including the ones you do not officially approve. Then write the rules that match this landscape, and this landscape alone.

This documentary foundation works hand in hand with the technical measures described in the 10 essential measures and with two-factor authentication. To gauge your overall level, the cyber check-up gives a quick overview, and the full set of priority measures is grouped in the Best practices pillar.

These measures form a foundation, they do not replace an assessment of your own situation. A charter that is consistent with your contracts, your sector obligations and your actual tools requires an eye that knows both your organisation and the applicable legal framework.