Placement and consistency
Keep headers and footers inside the page margin rather than encroaching on the text block. Documents produced by merging or scanning frequently have less margin than you expect, and content stamped over the first line of body text is worse than no header at all.
Be consistent across the document. If a header appears on some pages and not others, readers assume the missing ones are a different document or a later insertion. The usual deliberate exception is the cover page, which conventionally carries neither.
Match the document's typeface at a smaller size, and use a lighter weight or a grey tone so the running text stays dominant. A header set at body size in the same weight reads as content and interrupts every page.
Adding them to documents that were not designed for them
The common case is a document assembled from parts — a scanned bundle, a merged submission, an export from a system that produced bare pages. These have no headers of their own, and adding a consistent one is often what makes the collection read as a single document rather than a stack.
Check a representative sample of pages afterwards rather than only the first. Merged documents contain pages of different sizes and orientations, and a header positioned correctly on A4 portrait can land in the middle of a landscape page or off the edge of a smaller one.
Do it after the pages are final and in their final order, for the same reason page numbers come last. Adding a header, then inserting pages, gives you a document where some pages carry it and some do not, and fixing that is more work than doing it in the right order.
Classification markings and regulated documents
In organisations that handle sensitive material, the header and footer often carry a classification: INTERNAL, CONFIDENTIAL, RESTRICTED, or a client-specific marking. The convention exists because a page's status has to be obvious to whoever picks it up, not inferred from where it was found.
Where markings are mandated, they usually have to appear on every page including annexes and blank pages, and often at both top and bottom. Applying them after a document is assembled is far more reliable than trusting that each contributing part carried the right marking already.
It is worth reviewing markings before a document is released externally rather than only when it is created. Documents frequently outlive the sensitivity that justified their marking, and a report still stamped CONFIDENTIAL two years after publication creates unnecessary friction for everyone who has to handle it.