Policy template library
Choose a starting configuration
Search by name, requirement or region. Use the filters to narrow the results.
Compliance & Audit
Find a starter for an audit, standard or regulatory program. Use it to plan controls and evidence, not to claim compliance.
SOC 2 Type I
Map point-in-time control design to the AICPA Trust Services Criteria with this SOC 2 starter.
SOC 2 Type II
Map controls and evidence for a SOC 2 Type II review period with this starter.
ISO/IEC 27001
Map information security management, supplier, continuity and cloud privacy controls to ISO/IEC 27001.
ISO/IEC 42001
Map AI management, risk treatment, human oversight and data quality controls to ISO/IEC 42001.
GDPR (Data Controller)
Map GDPR controller duties for lawful processing, transparency, individual rights, impact assessments and breach handling.
GDPR (Data Processor)
Map GDPR processor duties for agreements, subprocessors, security, confidentiality, incidents and audit support.
UK GDPR
Map UK GDPR controls for lawful processing, transparency, individual rights, impact assessments and breach reporting.
CCPA / CPRA
Map California privacy notices, consumer rights, opt-outs and automated decision-making requirements.
LGPD (Brazil)
Map Brazilian privacy controls for lawful processing, individual rights, data protection officers and incident reporting.
HIPAA (Covered Entity)
Map HIPAA covered-entity controls for protected health information, access, audits, transmission security and breach response.
HIPAA (Business Associate)
Map HIPAA business-associate controls for agreements, subcontractors, protected health information, security and breach response.
HITECH
Map HITECH controls for protected health information, breach notices, business-associate liability, encryption and audit evidence.
PCI DSS v4.0.1
Map PCI DSS v4.0.1 controls for cardholder data, testing, change management, encryption and logs.
GLBA (Gramm-Leach-Bliley)
Map Gramm-Leach-Bliley Act controls for privacy notices, safeguards, risk management, incidents and provider oversight.
SOX ITGC
Map Sarbanes-Oxley technology controls for access, change management, operations, backup and segregation of duties.
SEC/FINRA Books & Records
Map SEC and FINRA controls for supervision, access, and write-once, read-many records retention.
FedRAMP Moderate
Map the FedRAMP Moderate baseline to access, monitoring, remediation, audit and system-protection controls.
FedRAMP High
Map the FedRAMP High baseline to access, audit, encryption, configuration, media and physical controls.
NIST SP 800-53 Moderate
Map moderate-impact federal security controls and assessment evidence to NIST Special Publication 800-53.
NIST AI RMF
Map AI governance, transparency, data quality, human oversight and risk treatment to the NIST AI Risk Management Framework.
CJIS Security Policy
Map criminal justice information controls for authentication, personnel, facilities, media, encryption, audits and incidents.
NIS2 Directive
Map NIS2 controls for cyber risk, incidents, supply chains, continuity, crises and vulnerability management.
DORA
Map EU financial technology risk, resilience testing, continuity, incidents and third-party oversight to DORA.
FDA 21 CFR Part 11
Map FDA 21 CFR Part 11 controls for validation, audit trails, access, retention and electronic signatures.
GxP / GMP Annex 11
Map GxP and GMP Annex 11 controls for computerized-system validation, data integrity, backups, changes and suppliers.
TISAX
Map TISAX controls for automotive information security, prototype protection, data classification, access and incidents.
ISO 26262
Map ISO 26262 controls for automotive functional safety, verification, validation, safety analysis, changes and evidence.
NERC CIP
Map bulk electric system controls for cyber access, configuration, incidents, recovery, vulnerabilities and supply-chain security.
MAS TRM
Map Singapore financial technology risk, cyber hygiene, continuity, data, incidents, providers and AI risk controls.
APRA CPS 234
Map APRA CPS 234 controls for information security, asset classification, testing, incidents, third parties and risk management.
Industry-Specific
Choose a starter for the data, decisions and review points in a regulated or high-risk industry workflow.
Finance
Protect financial data, flag material nonpublic information, add supervisory notices and retain audit evidence with this starter.
Healthcare (U.S. — HIPAA)
Start with selected HIPAA controls for protected health information, minimum-necessary access, retention and clinical review.
Healthcare (EU — GDPR)
Map European health-data controls for GDPR Article 9 and EU AI Act risk management with this starter.
Healthcare
Start with health-data protection, clinical safety and cross-border control mapping for AI workflows.
Legal
Protect privileged matters, limit unauthorized legal practice, check citations and retain defensible audit records.
Defense (U.S.)
Map controls for export-regulated and controlled defense data, access, human review and retention.
Defense (EU)
Start with controls for dual-use content, sanctions screening, classified data and human review in EU defense workflows.
China Export Controls
Start with controls for export-regulated content, data sovereignty, state secrets and sensitive AI interactions in China.
Government
Map U.S. federal AI controls for access, sensitive records, citations, human review and evidence.
EU AI Act Control Mapping
Map EU AI Act risk, transparency, conformity-assessment and human-oversight controls without implying compliance.
Education
Protect student data, screen age-sensitive content, check sources and review decisions with this education starter.
Human Resources and Recruitment
Add privacy, fairness checks and accountable human review to AI-assisted hiring workflows.
Justice System
Protect sealed records, check sources, escalate bias risks and require human approval in justice workflows.
Law Enforcement
Protect criminal justice records, constrain tools, flag bias risks and require human review in investigative workflows.
Consumer
Protect customer data, deter abuse, screen content and verify consent in public-facing AI services.
Startups
Give your startup a practical starting point for data protection, abuse prevention and audit evidence.
Small and Midsize Business
Start with practical controls for confidential data, employee information, attributable access and human review.
Critical Infrastructure
Control access to operational technology and industrial control systems while keeping people responsible for high-impact actions.
Automotive
Protect connected-vehicle data, preserve functional-safety evidence and restrict AI-assisted engineering actions.
Zero-Retention Routing
Route requests only to targets that operators mark as zero retention, with local privacy safeguards.
Finance & Professional Services
Protect client and financial data while keeping advice, reports and sensitive decisions under accountable review.
Accounting and Audit
Control sensitive financial data, review AI-assisted findings and retain evidence for accounting and audit work.
Asset Management
Protect client data, flag market-sensitive content, review financial output and keep records during AI-assisted investment research.
Insurance Claims
Protect claimant data, control financial output, require review and record decisions in AI-assisted claims workflows.
Insurance Underwriting
Protect applicant data, route underwriting recommendations for human review and retain decision evidence.
Mortgage Processing
Protect borrower data and documents, require review of financial output and retain evidence during mortgage processing.
Regulatory Reporting
Protect records, review AI-assisted financial output and retain evidence during regulatory report preparation.
Wealth Management
Protect client data, flag market-sensitive content, review advice-related output and retain wealth-management records.
Open Banking
Filter credentials and payment data, review sensitive instructions and retain evidence for open-banking workflows.
Attorney-Client Privilege
Protect confidential matters, check citations, limit unauthorized legal practice and review AI output before use.
Contract Review
Protect confidential contract terms, check cited sources, require legal review and retain policy evidence.
eDiscovery
Protect privileged material and sealed records, check citations, review evidence and retain metadata-only audit history.
Consulting Firm
Protect client data, limit access, check output quality, require review and retain consulting-workflow records.
Patent Research
Protect confidential inventions, check patent citations, require legal review and retain limited evidence.
Architecture and Engineering Intellectual Property
Protect restricted designs and client data, limit access, review output and retain engineering-workflow evidence.
Management Consulting
Protect confidential engagements, limit access, check output quality, require review and retain consulting records.
Forensic Accounting
Protect sensitive evidence, flag financial-data risks, review findings and retain records during forensic accounting work.
Compliance Advisory
Protect client material, limit access, review compliance guidance and retain evidence for advisory work.
Healthcare & Life Sciences
Protect health and research data while keeping clinical, scientific and safety decisions with qualified people.
Clinical Decision Support
Redact protected health information, check sources and output quality, require clinical review and keep limited evidence.
Telehealth
Protect telehealth data, limit access, check sources and output quality and require human review.
Medical Records Summarization
Redact protected health information, check source records, require review and keep limited history for medical summaries.
Mental Health
Protect sensitive behavioral health records, check sources and output quality, require review and retain evidence.
Clinical Trials
Protect participant data, check research sources, require qualified review and retain clinical trial records.
Genomics Research
Protect genomic and participant data, limit access, check sources, require review and keep metadata-only logs.
Medical Device
Protect medical device data, check sources and output quality, require review and record policy outcomes.
Radiology
Protect imaging-related health information, check sources and output quality, require radiology review and retain evidence.
Laboratory Diagnostics
Protect laboratory health data, check sources and output quality, require diagnostic review and keep limited records.
Pharmaceutical Research and Development
Protect pharmaceutical research data, limit access, check sources and output quality, require review and retain evidence.
Education
Protect student data and keep assessment, access and learning decisions under responsible human review.
University
Protect student records, limit access, screen content, check sources, review bias risks and retain university audit evidence.
Student Assessment
Redact student data, check sources and output quality, review bias risks and record AI-assisted assessment decisions.
Public Sector & Security
Protect public and mission-sensitive data while keeping access, evidence and consequential decisions under authorized review.
Public Sector Procurement
Protect procurement data, check vendor sources, review bias risks and recommendations and retain redacted history.
Citizen Services
Protect resident records, check sources, review bias risks and service decisions and retain redacted history.
Enterprise Data Compartmentalization
Limit access to compartmented data, redact restricted content, check sources, require review and retain audit history.
Cybersecurity Operations
Protect security data, limit access, check sources, require responder review and retain incident evidence.
Social Services
Protect beneficiary data, check sources, review bias risks and case decisions and retain redacted history.
Emergency Management
Protect incident data, limit access, check sources and output quality and keep emergency decisions under human command.
Technology & Platforms
Protect customer data, secrets, code and tools while keeping high-risk actions under human control.
Software as a Service Platforms
Protect customer data and secrets, constrain agent tools, require review and retain evidence for software-as-a-service workflows.
Developer Tools
Protect credentials, sanitize generated code, constrain tools, require review and retain evidence in AI-assisted development.
Cloud Providers
Filter cloud secrets, constrain agent actions, require operator review and record outcomes for high-risk work.
Cybersecurity Products
Protect credentials, sanitize code, analyze tool use, require review and retain security-product records.
Data Analytics
Protect personal data and secrets, constrain analytics tools, check output quality, require review and retain evidence.
Gaming
Protect player data and unreleased content, check sources, screen configured terms, require review and retain evidence.
Education Technology
Protect student data, limit access, screen content, check sources, review bias risks and retain education-technology evidence.
Marketing Technology
Protect audience data and credentials, constrain marketing tools, check output quality, require review and retain evidence.
Enterprise Copilot
Protect internal data, restrict agent actions, require human review and retain evidence for enterprise assistants.
Internet of Things Platform
Protect device data and credentials, constrain agent tools, check output quality, require review and retain records.
Media & Creative
Protect sources, rights and personal data while keeping publication and release decisions with accountable editors and creators.
Publishing
Protect personal data and rights-sensitive material, check citations, require editorial review and retain evidence.
Film and TV Production
Protect confidential productions and rights material, check sources, require review and retain policy records.
News Media
Protect sources, check citations and output quality, require editorial review and retain correction evidence.
Advertising
Protect audience data and rights material, check sources, review disclosures and retain advertising-workflow evidence.
Streaming Platform
Protect subscriber data and media rights, check sources, require review and retain streaming-workflow records.
Music Industry
Protect personal data and rights agreements, check sources, require review and retain music-workflow evidence.
Event Management
Protect attendee and rights-sensitive data, check sources, require review and retain event-workflow records.
Governance & Operations
Build clear review paths for AI inventory, vendors, disclosures, access, procurement and evidence.
Third-Party AI Risk
Protect internal data, check vendor evidence, require risk-owner review and retain third-party AI assessment records.
Model Governance Registry
Protect model records, limit access, check supporting sources, require review and retain registry evidence.
AI Disclosure and Transparency
Protect personal data, check disclosure sources, require approval and retain evidence for AI transparency workflows.
Shadow AI Discovery
Protect shadow AI findings, check sources, require governance review and retain investigation evidence.
AI Procurement Review Board
Protect vendor evidence, limit access, check recommendations, require board review and retain AI procurement records.
Acceptable Use and Model Access
Protect data, limit model access by role, check sources, require approval and retain acceptable-use evidence.
Record Retention and Audit Evidence
Protect governance records, limit access, check sources, require review and collect audit events for a separate retention policy.
Industrial & Manufacturing
Protect designs and operational data while keeping engineering, quality and safety decisions with qualified teams.
Aerospace Manufacturing
Protect aerospace designs, limit access, screen configured terms, require engineering review and retain limited production evidence.
Chemical Industry
Protect plant and interlock data, limit access, screen configured terms, require review and retain limited evidence.
Electronics Manufacturing
Protect electronics designs, limit access, screen configured terms, check output quality, require review and keep limited records.
Food and Beverage
Protect food-production data, limit access, screen configured terms, check output quality, require review and retain evidence.
Energy Sector
Protect energy operations data, limit access, screen configured terms, require operator review and retain limited evidence.
Construction
Protect construction plans and credentials, screen configured terms, check output quality, require review and keep limited records.
Precision Agriculture
Protect agricultural operations data, screen configured terms, check output quality, review actions and retain limited evidence.
Mining Operations
Protect mining site and interlock data, screen configured terms, require operational review and retain records.
Industrial Robotics
Protect robotics data and blueprints, screen configured terms, check output quality, require review and keep limited logs.
Transportation & Logistics
Protect route, vehicle, facility and cargo data while keeping operational and safety decisions with qualified teams.
Supply Chain
Protect logistics data, limit access, screen configured terms, require supply-chain review and retain limited evidence.
Aviation
Protect aviation operations data, limit access, screen configured terms, require qualified review and retain limited evidence.
Maritime
Protect vessel and port data, screen configured terms, check output quality, require review and keep limited records.
Rail Operations
Protect rail operations data, screen configured terms, check output quality, require review and retain records.
Last-Mile Delivery
Protect route and logistics data, screen configured terms, require dispatcher review and retain delivery evidence.
Fleet Management
Protect fleet and vehicle data, check configured terms and output quality, require review and retain limited history.
Warehouse Automation
Protect warehouse and interlock data, screen configured terms, check output quality, require review and retain logs.
Public Transit
Protect public transit data, screen configured terms, require operational review and retain limited evidence.
Multimodal Freight
Protect multimodal logistics data, screen configured terms, check output quality, require review and keep limited logs.
Retail & Commerce
Protect customer and payment data while keeping pricing, service, fraud and transaction controls in place.
E-commerce
Redact customer and payment data, block risky exports, screen configured terms, check output quality and retain logs.
Retail Customer Service
Redact customer and payment data, block risky exports, screen configured terms, check output quality and record outcomes.
Dynamic Pricing
Redact personal data, check sources and output quality, review bias risks, require approval and retain pricing evidence.
Luxury Retail
Redact client and payment data, block risky exports, screen configured terms, check output quality and retain logs.
Marketplace
Redact marketplace and payment data, block bulk exports, screen configured terms, check output quality and retain evidence.
Property & Hospitality
Protect tenant, guest, property and payment data while keeping fairness-sensitive and operational decisions under review.
Commercial Real Estate
Protect tenant and lease data, review bias risks and property decisions, check output quality and retain evidence.
Property Technology
Protect tenant and property data, review bias risks, check output quality, require approval and retain audit logs.
Property Management
Protect tenant records and access data, review bias risks and leasing decisions and retain audit evidence.
Hotel Chain
Redact guest and payment data, block risky exports, screen configured terms, check output quality and retain hotel records.
Travel Booking
Redact traveler and payment data, block booking exports, screen configured terms, check output quality and retain evidence.
Nonprofit & Humanitarian
Protect donor and beneficiary data while keeping fundraising, aid and protection decisions with responsible people.
Nonprofit Donor Data
Protect donor identities, limit access and exports, check output quality and retain nonprofit audit records.
Humanitarian Aid
Protect beneficiary data, check sources, review bias and protection risks, require approval and retain redacted history.
Regional & Privacy
Map jurisdiction-specific privacy and routing controls, then validate legal duties and provider claims before deployment.
Colorado AI Act
Map Colorado AI Act controls for personal data, bias risks, source quality, human review and decision evidence.
NYC AEDT
Map New York City hiring-tool controls for candidate privacy, bias monitoring, source quality, review and evidence.
India DPDP
Map India privacy controls for personal data, declared provider practices, source checks, human review and evidence.
Singapore PDPA
Map Singapore privacy controls for identity data, declared provider practices, source checks, review and routing evidence.
Japan APPI
Map Japan privacy controls for personal data, declared provider practices, source quality, human review and evidence.
Cross-Border Data Transfer
Redact personal data, route by declared provider practices, check sources, require review and record cross-border decisions.
No templates match your search or filters. Change your search or clear all fields.