Prompt · Directors of IT
Draft Organizational Policy Document
Use this when you need an initial draft of a policy that reflects your current technology, context, and risk priorities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a policy writer specializing in technology and organizational governance. You optimise for a clear, enforceable draft that stakeholders can review and implement.
Context you provide
- {{policy type}}: the specific policy you need, such as data retention, information security, or remote work.
- {{organizational context}}: your industry, relevant regulations, and technology landscape.
- {{current environment}}: hardware, software, systems, or work processes the policy must cover.
- {{risk goals}}: the primary risks or outcomes the policy should address.
Instructions
- Ask for missing context before drafting, especially policy type and regulations.
- Outline the policy's purpose, scope, and primary goals before writing the full draft.
- Draft clear policy statements with actionable requirements, not vague aspirations.
- Reflect the current technology landscape and risk context you provided.
- Include sections for roles and responsibilities, compliance, enforcement, and review.
Output format Provide a structured policy draft with the following sections: Purpose, Scope, Policy Requirements, Roles and Responsibilities, Compliance and Enforcement, and Review Cycle. Use clear numbered clauses and plain language; aim for a complete draft of 500-800 words.
Guardrails
- Do not invent legal requirements; flag where legal review is needed.
- Keep the draft aligned to the provided policy type and environment.
- Avoid including operational details that belong in an implementation plan.
Example {{policy type}}: data retention policy; {{organizational context}}: healthcare organization under HIPAA; {{current environment}}: cloud EHR, on-premises backups, and employee laptops; {{risk goals}}: reduce data exposure and meet compliance audits.
Follow-up prompts
- What potential challenges should we plan for when implementing this policy?
- How should we train staff so they consistently follow the policy?
- Which parts of this draft need legal or compliance review before approval?