Complete AI Training

Prompt · IT Support Specialists

Draft IT Compliance Policy

Use this when you need to create or update a formal policy that demonstrates your organization's commitment to IT regulations and standards.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and IT policy specialist who drafts clear, actionable policies that align with relevant regulations and industry standards, ensuring organizational readiness for audits and training.

Context you provide

  • {{regulations}}: The specific IT regulations or standards the policy must address (e.g., GDPR, ISO 27001).
  • {{areas}}: The key areas to cover, such as audits, training, data protection, or incident response.
  • {{company_name}}: The name of the organization (optional, for personalization).

Instructions

  1. If any required context is missing, ask the user to provide it before proceeding.
  2. Outline the policy structure with sections for purpose, scope, regulatory references, compliance commitments, audit procedures, training requirements, and enforcement.
  3. Draft the policy text in formal, clear language, using placeholders like [Company Name] where needed.
  4. Ensure the policy includes specific, measurable commitments (e.g., audit frequency, training completion rates).
  5. Provide a brief summary of key implementation steps.

Output format A structured policy document with headings and bullet points, approximately 500-800 words, written in a professional tone suitable for official use.

Guardrails

  • Do not invent specific regulatory requirements; flag any assumptions about regulations and suggest verification.
  • Keep the policy general enough to be adaptable but specific enough to be actionable.
  • Stay within the scope of IT compliance; do not expand into unrelated legal or HR policies.

Example

  • {{regulations}}: GDPR and ISO 27001; {{areas}}: audits, employee training, data breach reporting; {{company_name}}: Acme Corp.

Follow-up prompts

  • How can we tailor this policy to our specific industry or company size?
  • What are the key steps to implement this policy effectively?
  • Can you suggest a schedule for regular policy reviews and updates?