Policy Studio · in the Company Vault

Asked for a policy your business doesn't have yet?

A customer's questionnaire wants your incident response plan. An insurer wants your information security policy. You don't have them — most growing businesses don't. Audit and Comply writes the policy for your company, tells you how to implement it, keeps it reviewed and current, and files the approved version as audit-ready evidence you can attach to any assessment.

Part of the Pro plan. AI-drafted, human-approved — every document needs your recorded sign-off before it counts. The gap check — lite self-assessment plus the full gap report — is free for every account.

Why this matters

Good policies aren't paperwork.
They're how small companies survive.

Whether or not anyone ever audits you: an incident response plan is the difference between a bad day and a business-ending one. Cybersecurity, POPIA, backup discipline — these protect you first. And when the questionnaire does land (they always do — South African insurers now assess every provider under Joint Standards 1 and 2), you'll answer "yes, attached" instead of scrambling.

TODAY

The questionnaire moment

You see the requirement the moment a customer asks for it. Generate the policy right there — grounded in your business, not a generic template.

WEEK 1

Implemented, not shelved

Every policy ships with a first-30-days guide a non-specialist can follow, and its commitments become tracked obligations with reminders.

EVERY YEAR

Still true, still evidence

Review cycles nudge you before policies go stale. Assessors see the governance state — approved, review current — right on your evidence.

How it works

From "we don't have that"
to filed evidence, in four steps.

STEP 01

Tell us about your business

A five-minute company profile — industry, headcount, the systems you run, the data you handle — plus two or three questions specific to the policy. Filled in once, used for every policy you generate.

STEP 02

The AI drafts it for YOUR company

Not a template with blanks. A complete policy written around your actual setup — your systems, your Information Officer, your notification duties — with a plain-language implementation guide: first 30 days, who does what.

STEP 03

You review, edit and approve

The draft lands in your Company Vault as exactly that — a draft. Edit every line in the built-in editor or export to Word. Approval requires a recorded sign-off (a second person where your team has one) and an explicit acknowledgement that a human reviewed the AI’s work.

STEP 04

It becomes evidence — and stays alive

On approval a Word version is filed in your document library, ready to attach to any assessment. The policy’s own commitments — access reviews, plan tests, backup drills — install as tracked obligations with reminders. Review cycles keep it current.

Straight talk about the AI: the draft is a strong, personalised starting point — not legal advice, and never auto-approved. You (and a second approver where your team has one) must read it, edit it, and sign it off; the acknowledgement is recorded in an immutable audit trail. That's the same evidence discipline the rest of the platform runs on.
The catalog

Eight policies. The ones assessments actually ask for.

Curated from what South African questionnaires demand — POPIA, Joint Standard 2 cybersecurity, ISO-style controls — each with its own intake questions, structure, and suggested recurring obligations.

Information Security PolicyThe umbrella document every assessment asks for first.
Incident Response PlanDetection to regulator notification (POPIA s 22), with your contacts in it.
Access Control & Password PolicyLeast privilege, MFA, joiner/mover/leaver, access reviews.
Data Retention & Destruction ScheduleWhat you keep, how long, on what basis (POPIA s 14).
Business Continuity & DR PlanRPO/RTO, backups, tested restoration.
Acceptable Use PolicyDevices, email, BYOD — and rules for staff using AI tools.
POPIA Privacy PolicyLawful processing, data subject rights, your Information Officer.
Patch & Vulnerability ManagementUpdate timeframes by severity, compensating controls.

The next questionnaire is coming. Answer it with attachments.

Create your account, fill in your company profile, and generate your first policy today — Policy Studio is part of the Pro plan.

Generate your first policy

See what's in each plan →

Occasional, useful, unsubscribe in one click. Double opt-in — we practise the POPIA we preach.