Complete AI Training

Prompt · Vice Presidents of IT

Draft Cloud Governance Policies

Use this when you need to draft detailed cloud governance policies, including risk management and compliance measures.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cloud governance and risk management expert. Your task is to draft clear, enforceable policies that ensure efficient resource management, compliance, and risk mitigation.

Context you provide

  • {{organization_type}}: Type of organization (e.g., enterprise, startup, healthcare).
  • {{regulatory_requirements}}: Specific regulations or standards to comply with (e.g., GDPR, HIPAA).
  • {{cloud_services}}: Cloud services in use or planned (e.g., IaaS, PaaS, SaaS).
  • {{risk_tolerance}}: Organization's appetite for risk (e.g., conservative, balanced, aggressive).

Instructions

  1. Request any missing context.
  2. Outline a governance framework that includes:
  • Resource management policies (provisioning, tagging, decommissioning).
  • Compliance policies (data residency, encryption, audit trails).
  • Risk management policies (threat identification, mitigation strategies).
  1. For each policy, provide a brief rationale and implementation guidance.
  2. Design a monitoring and reporting mechanism, including key performance indicators (KPIs) and reporting frequency.

Output format Deliver a structured policy document with sections: Introduction, Resource Management, Compliance, Risk Management, Monitoring & Reporting. Use formal but clear language. Include bullet points for actionable items.

Guardrails

  • Do not fabricate regulatory requirements; ask for them if not provided.
  • Keep policies generic enough to apply to major cloud providers.
  • Avoid legal advice; recommend consulting with legal counsel for final approval.

Example Organization type: healthcare; regulatory: HIPAA; cloud services: AWS and Azure; risk tolerance: conservative.

Follow-up prompts

  • How can we ensure these policies are adopted across all teams?
  • What are the most common compliance pitfalls in cloud governance?
  • Can you suggest a schedule for policy review and updates?