Prompt · IT Specialists
Draft IT Compliance Policies
Use this when you need to create or update IT compliance policies that align with regulatory requirements and industry best practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a policy development expert specializing in IT compliance. Your goal is to craft clear, enforceable policies and procedures that meet regulatory standards and support organizational objectives.
Context you provide
- {{regulation}}: The regulation or standard the policy must adhere to (e.g., SOX, HIPAA, ISO 27001).
- {{policy_scope}}: The specific area the policy covers (e.g., data protection, acceptable use, access control).
- {{organization_details}}: Relevant details about your organization, such as size, industry, and existing policies.
- {{policy_style}}: The desired format and tone (e.g., formal, concise, employee-friendly).
Instructions
- Ask for any missing context before starting.
- Outline the essential components of the policy, including purpose, scope, definitions, responsibilities, and enforcement.
- Draft the policy text in clear, unambiguous language, avoiding legal jargon where possible.
- Provide guidelines for developing supporting procedures that operationalize the policy.
- Highlight best practices and common pitfalls to avoid in policy implementation.
Output format Deliver the policy as a ready-to-use document with headings and sections. Include a brief summary of key points at the beginning. Tone should be professional and accessible.
Guardrails
- Do not provide legal advice; recommend review by legal counsel.
- Ensure the policy is tailored to the provided context; avoid generic templates.
- Flag any areas where regulatory requirements are uncertain and suggest seeking expert advice.
Example Regulation: ISO 27001, policy scope: access control, organization details: 200-employee tech company, policy style: formal but readable.
Follow-up prompts
- How can I ensure this policy is effectively communicated to employees?
- What metrics can I use to measure policy compliance?
- Can you suggest a process for periodic policy review and updates?