Policy Templates

54 pre-built governance configurations for every industry and compliance framework. Pick a template, customize it, and deploy in minutes.

Canonical Frameworks

ISO 27001, SOC 2, HIPAA, GDPR, and other regulation-specific compliance frameworks with structured evidence, control domains, and assurance levels.

SOC 2 Type I

Point-in-time SOC 2 readiness with Trust Services Criteria controls.

Global Framework Type 1
View details

SOC 2 Type II

Continuous SOC 2 compliance with change management and risk controls.

Global Framework Type 2
View details

ISO/IEC 27001

International information security management system standard.

Global Framework Certified
View details

ISO/IEC 42001

AI management system standard for responsible AI governance.

Global Framework Certified
View details

GDPR (Data Controller)

EU data-controller obligations — consent, data rights, and breach notification.

EU Framework
View details

GDPR (Data Processor)

EU data-processor obligations — DPAs, subprocessor management, and logging.

EU Framework
View details

UK GDPR

UK data-protection framework post-Brexit — ICO-aligned.

UK Framework
View details

CCPA / CPRA

California consumer privacy rights — opt-out, data-sale restrictions, and ADMT.

US Framework
View details

LGPD (Brazil)

Brazil's General Data Protection Law — ANPD-aligned.

BR Framework
View details

HIPAA (Covered Entity)

HIPAA compliance for healthcare providers and health plans.

US Framework
View details

HIPAA (Business Associate)

HIPAA compliance for business associates and subcontractors.

US Framework
View details

HITECH

HITECH Act breach notification and enhanced enforcement for health IT.

US Framework
View details

PCI DSS v4.0

Payment card industry security for AI systems handling cardholder data.

Global Framework Level 1
View details

GLBA (Gramm-Leach-Bliley)

Financial privacy and safeguards for banks, insurers, and securities firms.

US Framework
View details

SOX ITGC

Sarbanes-Oxley IT general controls for financial reporting systems.

US Framework
View details

SEC/FINRA Books & Records

Securities communication archiving and supervision requirements.

US Framework
View details

FedRAMP Moderate

FedRAMP Moderate authorization for cloud AI serving federal agencies.

US Framework Moderate
View details

FedRAMP High

FedRAMP High authorization for sensitive government AI workloads.

US Framework High
View details

NIST SP 800-53 Moderate

Federal information system security controls at the Moderate impact level.

US Framework Moderate
View details

NIST AI RMF

AI risk management framework for trustworthy and responsible AI.

Global Framework
View details

CJIS Security Policy

FBI CJIS security controls for criminal justice information systems.

US Framework
View details

NIS2 Directive

EU network and information security for essential and important entities.

EU Framework
View details

DORA

EU digital operational resilience for financial institutions.

EU Framework
View details

FDA 21 CFR Part 11

FDA electronic records and signatures for life-sciences AI.

US Framework
View details

GxP / GMP Annex 11

EU pharmaceutical and life-sciences computerized system validation.

EUGlobal Framework
View details

TISAX

Automotive information security assessment for supply-chain partners.

EUGlobal Framework
View details

ISO 26262

Automotive functional safety for AI in safety-critical vehicle systems.

Global Framework Asil D
View details

NERC CIP

Critical infrastructure protection for the North American bulk electric system.

US Framework
View details

MAS TRM

Singapore financial technology risk management guidelines.

SG Framework
View details

APRA CPS 234

Australian prudential information security for regulated financial entities.

AU Framework
View details

Industry-Specific

Finance, healthcare, legal, defense, and more — with domain-tailored policy rules and guardrails.

Finance

Pre-configured guardrails for financial services AI, covering SOX, PCI-DSS, and Basel III.

USEUGlobal
View details

Healthcare (US — HIPAA)

HIPAA-aligned AI policy for US healthcare providers and covered entities.

US
View details

Healthcare (EU — GDPR)

GDPR-compliant healthcare AI with Article 9 special-category data protections.

EUEEAUK
View details

Healthcare

Global healthcare AI governance aligned to WHO and ICD-11 standards.

GlobalUSEU +3
View details

Legal

AI policy for law firms — privilege detection, ethical guardrails, and audit trails.

USEUGlobal
View details

Defense (US)

ITAR/EAR-compliant AI controls for US defense and national security organizations.

US
View details

Defense (EU)

EU defense AI governance with dual-use export controls and NATO alignment.

EU
View details

Government

FedRAMP and FISMA-aligned AI policy for US federal agencies.

US
View details

Education

FERPA and COPPA-compliant AI policy for K-12 and higher education.

USEUGlobal
View details

HR / Recruitment

Anti-bias and EEOC-aligned AI controls for hiring and workforce management.

USEUGlobal
View details

Justice System

Due-process-aligned AI governance for courts, corrections, and judicial analytics.

USEUGlobal
View details

Law Enforcement

CJIS-aligned AI policy for police departments and public-safety agencies.

USEUGlobal
View details

Consumer

FTC-aligned AI safety controls for consumer-facing applications.

USEUGlobal
View details

Critical Infrastructure

NIST CSF 2.0 and NIS2-aligned AI controls for utilities, energy, and transport.

USEU
View details

Automotive

ISO 26262 and UNECE WP.29-aligned AI governance for vehicle systems.

EUUSGlobal
View details

Can't find the right template?

Start from any template and customize it, or build a policy from scratch in the configuration editor.