Browse our library of 113 compliance policy templates covering SOC 2, GDPR, HIPAA, ISO 27001, PCI DSS, CCPA/CPRA, and NIST CSF 2.0. Each template outlines required sections and structure to help you understand what auditors expect.
Generate customized versions with AIService Organization Control 2 - Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Requires an observation period of 3-12 months demonstrating controls operate effectively over time.
Establishes the overarching information security program and governance structure.
Defines requirements for managing user access based on least privilege.
Establishes password creation, management, and rotation requirements.
Defines data classification levels and handling requirements.
Defines acceptable and prohibited uses of company systems and data.
Structured approach for detecting, responding to, and recovering from security incidents.
Ensures critical business functions continue during and after disruptions.
Procedures for recovering IT infrastructure after catastrophic events.
Procedures for requesting, reviewing, approving, and deploying changes.
Methodology for identifying, assessing, and managing security risks.
Procedures for evaluating, onboarding, and monitoring third-party vendors.
Defines retention periods and secure disposal requirements.
Describes how the organization handles personal information.
Procedures for securely onboarding and offboarding employees.
Physical access controls and environmental protections.
Controls for securing network infrastructure and communications.
Encryption standards and key management practices.
Requirements for logging events and maintaining audit trails.
Procedures for inventorying, tracking, and disposing of assets.
Expected standards of behavior and ethics for all employees.
Section 3 of SOC 2 Type 2 report — mandatory narrative describing infrastructure, software, people, procedures, and data per AICPA Description Criteria DC 200 (2018 revision).
Section 2 of SOC 2 Type 2 report — formal management attestation of control effectiveness per AICPA AT-C 205.
General Data Protection Regulation - EU data protection and privacy regulation.
Comprehensive GDPR data protection policy.
External GDPR privacy notice.
Data Subject Access Request handling procedure.
Maintains records of all data processing activities as required by GDPR Article 30.
Framework for conducting DPIAs on high-risk processing activities per GDPR Article 35.
Governs cross-border transfers of personal data per GDPR Articles 44-49.
Defines retention periods and erasure procedures aligned with GDPR Articles 5(1)(e) and 17.
Procedures for detecting, assessing, and notifying personal data breaches per GDPR Articles 33 and 34.
Procedures for obtaining, recording, and managing consent per GDPR Articles 6 and 7.
Detailed procedure for handling all data subject rights requests under GDPR Articles 15-22.
Health Insurance Portability and Accountability Act - US healthcare data protection.
Administrative, physical, and technical safeguards.
PHI use and disclosure requirements.
Breach identification and reporting procedures.
Technical policies for controlling access to ePHI per §164.312(a).
Mechanisms for recording and examining access to ePHI per §164.312(b).
Policies to protect ePHI from improper alteration or destruction per §164.312(c).
Technical safeguards for protecting ePHI during electronic transmission per §164.312(e).
Establishes procedures for responding to emergencies affecting ePHI systems per §164.308(a)(7).
Security awareness and training program for all workforce members per §164.308(a)(5).
Requirements for establishing and managing Business Associate Agreements per §164.308(b).
Completed Security Risk Analysis artifact required by 45 CFR §164.308(a)(1)(ii)(A) — the most frequently cited deficiency in OCR HIPAA investigations.
Workforce sanction policy explicitly required by 45 CFR §164.308(a)(1)(ii)(C) and §164.530(e)(1).
International standard for information security management systems (ISMS).
Top-level information security management system policy.
Risk management methodology aligned with ISO 27005.
Mandatory ISMS document per ISO/IEC 27001:2022 Clause 6.1.3(d) — exhaustive table of all 93 Annex A controls with applicability, justification, implementation status, and exclusion rationale.
Defines access control requirements aligned with ISO 27001 Annex A controls A.5.15 and A.8.2.
Information asset inventory and classification aligned with ISO 27001 controls A.5.9 and A.5.10.
Information security incident management aligned with ISO 27001 controls A.5.24 and A.5.25.
Information security aspects of business continuity aligned with ISO 27001 controls A.5.29 and A.5.30.
Managing information security risks in supplier relationships per ISO 27001 controls A.5.19 and A.5.20.
Cryptographic controls and key management aligned with ISO 27001 control A.8.24.
Security responsibilities throughout the employment lifecycle per ISO 27001 controls A.6.1-A.6.5.
Secure development lifecycle aligned with ISO/IEC 27001:2022 Annex A controls A.8.25 through A.8.31.
Payment Card Industry Data Security Standard — security controls for organizations that store, process, or transmit payment cardholder data.
Controls for network security including firewall configuration, DMZ setup, and cardholder data environment segmentation.
Policy governing storage, transmission, and protection of cardholder data and sensitive authentication data.
Processes for identifying, prioritizing, and remediating security vulnerabilities across system components.
Restricting access to cardholder data system components on a business need-to-know basis.
Logging, monitoring, and testing of all network resources and cardholder data access.
Overarching information security policy addressing all PCI DSS program requirements and security governance.
Incident response plan for suspected or confirmed cardholder data breaches and security events.
Physical access controls for cardholder data environments, media handling, and device security.
Management of third-party service providers with access to or impact on cardholder data and the CDE.
Cryptographic controls for protecting cardholder data in transit and at rest, including key management.
Password complexity, authentication requirements, and account management for all CDE system components.
Formal change control process for system components in the cardholder data environment.
California Consumer Privacy Act / California Privacy Rights Act — grants California consumers rights over their personal information collected by businesses.
Consumer-facing privacy notice disclosing data collection, use, sharing practices, and consumer rights under CCPA/CPRA.
Internal procedures for handling consumer rights requests including access, deletion, correction, opt-out, and portability.
Policy for maintaining an inventory of personal information collected, used, shared, and deleted across the organization.
Procedures for honoring consumer opt-out requests from sale and sharing of personal information under CCPA/CPRA.
Retention schedules and secure deletion procedures for personal information under CCPA/CPRA data minimization principles.
Requirements for data processing agreements and service provider contracts to comply with CCPA/CPRA third-party requirements.
Reasonable security measures required to protect personal information and avoid CCPA private right of action for data breaches.
Training requirements for employees who handle consumer personal information or process consumer rights requests.
NIST Cybersecurity Framework — voluntary guidance for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
Identifying and managing organizational assets within the context of their relative importance to business objectives. (NIST CSF 2.0: IDENTIFY — ID.AM)
Process for understanding cybersecurity risks to assets, systems, and operations to inform risk response decisions. (NIST CSF 2.0: IDENTIFY — ID.RA)
Access to assets and associated facilities is limited to authorized users and processes. (NIST CSF 2.0: PROTECT — PR.AA)
Personnel and partners are provided with cybersecurity awareness education. (NIST CSF 2.0: PROTECT — PR.AT)
Data is managed consistent with risk strategy to protect confidentiality, integrity, and availability. (NIST CSF 2.0: PROTECT — PR.DS)
Anomalies and events are detected and their potential impact understood. (NIST CSF 2.0: DETECT — DE.AE)
Systems and assets are monitored to identify cybersecurity events and verify protective measure effectiveness. (NIST CSF 2.0: DETECT — DE.CM)
Responses to detected cybersecurity incidents are managed and executed effectively. (NIST CSF 2.0: RESPOND — RS.MA, RS.AN, RS.CO)
Recovery processes ensure restoration of systems or assets affected by cybersecurity incidents. (NIST CSF 2.0: RECOVER — RC.RP)
Response and recovery activities are coordinated with internal and external stakeholders. (NIST CSF 2.0: RESPOND — RS.CO / RECOVER — RC.CO)
SOC 2 Type I — Point-in-time assessment of your security controls design. Ideal for first-time certification before progressing to Type II.
Establishes the overarching information security program and governance structure.
Defines requirements for managing user access based on least privilege.
Establishes password creation, management, and rotation requirements.
Defines data classification levels and handling requirements.
Defines acceptable and prohibited uses of company systems and data.
Structured approach for detecting, responding to, and recovering from security incidents.
Ensures critical business functions continue during and after disruptions.
Procedures for recovering IT infrastructure after catastrophic events.
Procedures for requesting, reviewing, approving, and deploying changes.
Methodology for identifying, assessing, and managing security risks.
Procedures for evaluating, onboarding, and monitoring third-party vendors.
Defines retention periods and secure disposal requirements.
Describes how the organization handles personal information.
Procedures for securely onboarding and offboarding employees.
Physical access controls and environmental protections.
Controls for securing network infrastructure and communications.
Encryption standards and key management practices.
Requirements for logging events and maintaining audit trails.
Procedures for inventorying, tracking, and disposing of assets.
Expected standards of behavior and ethics for all employees.
Section 3 of SOC 2 Type 2 report — mandatory narrative describing infrastructure, software, people, procedures, and data per AICPA Description Criteria DC 200 (2018 revision).
Section 2 of SOC 2 Type 2 report — formal management attestation of control effectiveness per AICPA AT-C 205.
ISO/IEC 42001 — International standard for Artificial Intelligence Management Systems (AIMS), covering responsible AI development, deployment, and governance.
Establishes the overall AI management system (AIMS) including leadership commitment, AI principles, and organizational context for responsible AI development and deployment. (ISO/IEC 42001: Clause 5 — Leadership)
Defines the risk management framework for identifying, assessing, treating, and monitoring risks associated with AI systems throughout their lifecycle. (ISO/IEC 42001: Clause 6.1 — Actions to address risks and opportunities)
Governs the acquisition, preparation, quality, lineage, and lifecycle management of data used in AI systems to ensure trustworthy AI outcomes. (ISO/IEC 42001: Annex A — A.10 Data for AI Systems)
Establishes the process for conducting impact assessments on AI systems to evaluate potential effects on individuals, groups, and society. (ISO/IEC 42001: Annex A — A.3 AI System Impact Assessment)
Ensures AI systems operate transparently with appropriate levels of explainability for stakeholders, regulators, and affected individuals. (ISO/IEC 42001: Annex A — A.5 Transparency and Explainability)
Defines requirements for human oversight, intervention capabilities, and accountability structures for AI system operations. (ISO/IEC 42001: Annex A — A.7 Human Oversight)
Defines requirements for continuous monitoring, performance evaluation, and periodic auditing of AI systems in production. (ISO/IEC 42001: Clause 9 — Performance Evaluation)
Establishes procedures for detecting, reporting, investigating, and remediating incidents related to AI system failures, unintended behaviors, or harmful outcomes. (ISO/IEC 42001: Clause 10 — Improvement)
NIS 2 Directive (EU 2022/2555) — EU-wide cybersecurity legislation requiring essential and important entities to implement comprehensive risk management and incident reporting.
Establishes a systematic approach to identifying, analyzing, and treating cybersecurity risks in accordance with NIS 2 Directive Article 21.
Defines procedures for detecting, managing, and reporting significant cybersecurity incidents, including the mandatory 24-hour early warning to the CSIRT under NIS 2 Article 23.
Ensures continuity of essential or important services during and after cybersecurity incidents, aligned with NIS 2 Article 21(2)(c).
Addresses security requirements for direct suppliers and service providers, aligned with NIS 2 Article 21(2)(d).
Establishes security controls for network and information systems acquisition, development, and maintenance, aligned with NIS 2 Article 21(2)(e).
Establishes procedures for vulnerability disclosure and coordinated handling of vulnerabilities, aligned with NIS 2 Article 21(2)(e) and Article 12.
Defines policies and procedures for the use of cryptography and encryption to protect network and information systems, aligned with NIS 2 Article 21(2)(h).
Establishes access control policies and asset management requirements for network and information systems, aligned with NIS 2 Article 21(2)(i).
Defines requirements for multi-factor authentication and continuous authentication solutions, aligned with NIS 2 Article 21(2)(j).
Establishes governance structures and management body responsibilities for cybersecurity oversight, aligned with NIS 2 Article 20.
NIST SP 800-53 — Comprehensive catalog of security and privacy controls for federal information systems, widely adopted by private sector organizations.
Establishes access control requirements covering account management, access enforcement, separation of duties, and least privilege, aligned with NIST SP 800-53 AC control family.
Defines audit logging, monitoring, and accountability requirements aligned with NIST SP 800-53 AU control family.
Establishes requirements for security assessments, system authorization, and continuous monitoring, aligned with NIST SP 800-53 CA control family.
Defines configuration management requirements including baseline configurations, change control, and configuration monitoring, aligned with NIST SP 800-53 CM control family.
Establishes contingency planning requirements including backup, recovery, and continuity of operations, aligned with NIST SP 800-53 CP control family.
Defines requirements for identifying and authenticating users, devices, and services, aligned with NIST SP 800-53 IA control family.
Establishes an incident response capability including preparation, detection, analysis, containment, recovery, and post-incident activities, aligned with NIST SP 800-53 IR control family.
Defines requirements for protecting system communications and data, including boundary protection, cryptography, and denial-of-service protection, aligned with NIST SP 800-53 SC control family.
Establishes requirements for assessing security risks including vulnerability scanning, threat analysis, and privacy impact assessments, aligned with NIST SP 800-53 RA control family.
Defines personnel security requirements including screening, termination, transfer, and access agreements, aligned with NIST SP 800-53 PS control family.
These templates show the structure. PoliWriter generates fully customized policies that reference your actual infrastructure, tools, and team practices.
Get Started FreeNo credit card required. 3 documents free.
Service Organization Control 2 - Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy. Requires an observation period of 3-12 months demonstrating controls operate effectively over time.
22 templates availableGeneral Data Protection Regulation - EU data protection and privacy regulation.
10 templates availableHealth Insurance Portability and Accountability Act - US healthcare data protection.
12 templates availableInternational standard for information security management systems (ISMS).
11 templates availablePayment Card Industry Data Security Standard — security controls for organizations that store, process, or transmit payment cardholder data.
12 templates availableCalifornia Consumer Privacy Act / California Privacy Rights Act — grants California consumers rights over their personal information collected by businesses.
8 templates availableNIST Cybersecurity Framework — voluntary guidance for managing cybersecurity risk across five core functions: Identify, Protect, Detect, Respond, and Recover.
10 templates availableSOC 2 Type I — Point-in-time assessment of your security controls design. Ideal for first-time certification before progressing to Type II.
22 templates availableISO/IEC 42001 — International standard for Artificial Intelligence Management Systems (AIMS), covering responsible AI development, deployment, and governance.
8 templates availableNIS 2 Directive (EU 2022/2555) — EU-wide cybersecurity legislation requiring essential and important entities to implement comprehensive risk management and incident reporting.
10 templates availableNIST SP 800-53 — Comprehensive catalog of security and privacy controls for federal information systems, widely adopted by private sector organizations.
10 templates available