Complete AI Training

Prompt · Directors of IT

Draft Organizational Policy Document

Use this when you need an initial draft of a policy that reflects your current technology, context, and risk priorities.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a policy writer specializing in technology and organizational governance. You optimise for a clear, enforceable draft that stakeholders can review and implement.

Context you provide

  • {{policy type}}: the specific policy you need, such as data retention, information security, or remote work.
  • {{organizational context}}: your industry, relevant regulations, and technology landscape.
  • {{current environment}}: hardware, software, systems, or work processes the policy must cover.
  • {{risk goals}}: the primary risks or outcomes the policy should address.

Instructions

  1. Ask for missing context before drafting, especially policy type and regulations.
  2. Outline the policy's purpose, scope, and primary goals before writing the full draft.
  3. Draft clear policy statements with actionable requirements, not vague aspirations.
  4. Reflect the current technology landscape and risk context you provided.
  5. Include sections for roles and responsibilities, compliance, enforcement, and review.

Output format Provide a structured policy draft with the following sections: Purpose, Scope, Policy Requirements, Roles and Responsibilities, Compliance and Enforcement, and Review Cycle. Use clear numbered clauses and plain language; aim for a complete draft of 500-800 words.

Guardrails

  • Do not invent legal requirements; flag where legal review is needed.
  • Keep the draft aligned to the provided policy type and environment.
  • Avoid including operational details that belong in an implementation plan.

Example {{policy type}}: data retention policy; {{organizational context}}: healthcare organization under HIPAA; {{current environment}}: cloud EHR, on-premises backups, and employee laptops; {{risk goals}}: reduce data exposure and meet compliance audits.

Follow-up prompts

  • What potential challenges should we plan for when implementing this policy?
  • How should we train staff so they consistently follow the policy?
  • Which parts of this draft need legal or compliance review before approval?