My old one simply had an "exclusions" clause where developers could register things that fell outside the 'IP agreement' terms. It wasn't perfect, but that type of thing is a good idea.
Technically, if you're consulting, then any code you produce is the IP of your clients (not you), and your company should be held accountable for any breaches/leaks of IP policy.
I think my old boss had a policy/contract agreement for clients, though, that copyright was owned by the client, and IP was owned by our company unless they specifically asked for it.
I know that this is probably missing the thrust of your question a bit, but aside from just protecting your developer's free time, you have to consider protecting your client's IP. If the IP agreement on that side is between client/company, then you're pretty much free to decide your own policies on your end, but you will have to be vigilant about checking the IP agreements of your clients (if they have them).
#EDIT: It's also a good idea to explain to your employees what exactly you're trying to protect, and let them know that unless they're going into direct competition with you on any systems developed internally, then you probably won't bother perusing any IP breaches. It'd have to be worth your while to waste money/time to chase them, and depending on "right to practice" laws (not sure what the real name is), you may not be able to stop them from building whatever they want anyway.