A short document that prevents most problems.
WHAT TO COVER
That business mail is a business record, and may be reviewed Acceptable use, and what should not be sent from a business address Password requirements, and that passwords are never shared That nobody, including management and the hosting provider, will ask for a password by email
What to do with a suspicious message: do not click, report it
The rule on payment details: never act on a change of bank details received by email without telephone verification
What happens to the mailbox when someone leaves Whether auto-forwarding to personal addresses is permitted, which it generally should not be
LENGTH
Two pages. A twenty-page policy nobody reads protects nobody.
MAKING IT STICK
Cover it during onboarding rather than emailing it once Repeat the payment-verification rule specifically, because that is where the real money is lost Update it when something goes wrong, and say why
WHY IT MATTERS
Most email compromises begin with one person clicking something. A short, well-understood policy reduces that more than any technical control.