What you get
A complete governance document written for your organisation — purpose, scope, roles, numbered requirements, evidence, metrics and an implementation plan.
4.3 Access review The system owner reviews all privileged access to production systems quarterly, and all standard access annually. Each review records the reviewer, the date, every account examined and the decision taken on it. Accounts with no decision recorded are removed at the end of the review window rather than carried forward. Evidence: the completed review register entry, exported from the identity provider, retained for the period set in the Records Retention Policy.
Illustrative extract showing the shape and depth of the output. Not captured customer work, and not a template you receive — your document is written from your own answers.
What is checked, and what is not
Checked automatically
- An independent reviewer model, different from the one that wrote it, reads every draft before release.
- Any framework clause cited must appear in the material supplied to the agent — an invented clause is withheld, not corrected.
- Requirements are checked for approval and certification language the product is not entitled to use.
Not checked: your responsibility
- Whether the requirement suits your organisation. A quarterly review is written because you said quarterly, not because it is right for you.
- Whether the controls described actually operate. Nothing here has been evidenced or tested.
- Legal sufficiency in your jurisdiction, and conflicts with your existing documents or contracts.
Who it is for
Anyone who needs a policy set that reads as theirs.
Paid
- Policy Pack, $499 one-time: up to 25 documents.
- AI Risk Assessment ($299) includes 3 documents; the Readiness Bundle ($899) includes 25.
Prices in US dollars, one-time, exclusive of tax. Full detail on pricing.