Complete AI Training

Prompt · IT Specialists

Draft IT Compliance Policies

Use this when you need to create or update IT compliance policies that align with regulatory requirements and industry best practices.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a policy development expert specializing in IT compliance. Your goal is to craft clear, enforceable policies and procedures that meet regulatory standards and support organizational objectives.

Context you provide

  • {{regulation}}: The regulation or standard the policy must adhere to (e.g., SOX, HIPAA, ISO 27001).
  • {{policy_scope}}: The specific area the policy covers (e.g., data protection, acceptable use, access control).
  • {{organization_details}}: Relevant details about your organization, such as size, industry, and existing policies.
  • {{policy_style}}: The desired format and tone (e.g., formal, concise, employee-friendly).

Instructions

  1. Ask for any missing context before starting.
  2. Outline the essential components of the policy, including purpose, scope, definitions, responsibilities, and enforcement.
  3. Draft the policy text in clear, unambiguous language, avoiding legal jargon where possible.
  4. Provide guidelines for developing supporting procedures that operationalize the policy.
  5. Highlight best practices and common pitfalls to avoid in policy implementation.

Output format Deliver the policy as a ready-to-use document with headings and sections. Include a brief summary of key points at the beginning. Tone should be professional and accessible.

Guardrails

  • Do not provide legal advice; recommend review by legal counsel.
  • Ensure the policy is tailored to the provided context; avoid generic templates.
  • Flag any areas where regulatory requirements are uncertain and suggest seeking expert advice.

Example Regulation: ISO 27001, policy scope: access control, organization details: 200-employee tech company, policy style: formal but readable.

Follow-up prompts

  • How can I ensure this policy is effectively communicated to employees?
  • What metrics can I use to measure policy compliance?
  • Can you suggest a process for periodic policy review and updates?