Unit 8 / 12

Policy and Procedure Writing

Gains:

  • Ability to draft an institution-specific policy/procedure document with a structured prompt
  • Ability to match policies with role and responsibility (RACI) and make them auditable
  • Ability to apply style and formatting standards for understandable, applicable and consistent policy language.

An institution's policies are its written memory and decision discipline: from anti-bribery to information security, from remote working to data storage, it is the formal version of the phrase "this is how we do it". A good policy is clear, enforceable and auditable; A bad policy is either a pile of jargon that no one reads or a collection of good intentions that remain void in practice. Artificial intelligence (AI) quickly produces the first draft of policy and procedure documents, keeps language consistent, and structures role-responsibility mappings. In this unit, we will learn how to create organization-specific, RACI-auditable and understandable policies — always maintaining human approval.

Let's clarify the terms. A policy is a high-level document ("what and why") that establishes the organization's stance and rules on an issue. A procedure is a document that explains step by step how to implement that policy ("how"). RACI is a matrix that clarifies the roles of Responsible, Accountable, Consulted and Informed for each task. Scope is who and what the policy binds. Effectiveness and review is when the policy is valid and how often it will be updated.

Skeleton of the Policy Document

Consistent policies share a common framework. If you give AI this skeleton, all your documents will have the same structure and readability. Step by step:

  1. Purpose and scope. What, who, and what situations does the policy cover?
  2. Definitions. Critical terms are defined once, clearly.
  3. Principles/rules. The main stance and binding rules of the institution.
  4. Roles and responsibilities (RACI). Who does what, who approves it, who is consulted.
  5. Procedure/steps. The concrete flow of the application.
  6. Exceptions, violation and enforcement. How to manage breaking the rules.
  7. Enforcement, review and related documents.

Your role: an experienced expert in corporate policy writing.Prepare a policy draft for the following topic.Structure: 1) Purpose and scope 2) Definitions 3) Principles and rules4) Roles and responsibilities 5) Procedure steps 6) Exception/violation/sanction7) Enforcement and review.Rules:- Leave institution-specific blanks as [TO BE FILLED: ...]; apocryphal.- If legal attribution is required, add note "legal approval required — must be verified"; Do not give your own article/decision number. - Keep the language clear, short-sentenced and applicable.<topic>[basic information about the policy issue and institution]</topic>

Attention: Policies have legal consequences; A disciplinary, data or security policy must comply with applicable legislation. The draft produced by AI must be reviewed and approved by a lawyer/expert in accordance with the applicable law before it is published.

Making it Auditable with RACI

Clarity on “who will do what” is what makes policy feasible. A roleless policy is a document for which everyone is responsible but no one is held accountable. AI is powerful in matching every liability with RACI.

Produce a RACItable for each concrete obligation in the following policy draft:| Activity/liability | Responsible (R) | Approved by (A) | Consulted (C) | Informed (I) |Rules:- Have a SINGLE "Approver (A)" on each activity.- Mark activities whose role remains unclear in the policy as "no role assigned".- Leave a [ROLE: ...] placeholder if you do not know the actual titles.

There is also the consistency and readability aspect. All policies of the institution should be written in the same style and in the same terms. AI standardizes text according to a style guide.

Organize this policy according to these stylistic standards:- Short sentences; one rule in each sentence. - Possessive expressions such as "It is the responsibility of unit Define it where it is first mentioned. - Clause by clause, numbered structure. Show the expressions you changed with a short table (before/after).

Weak Prompt / Strong Prompt

Weak prompt:Write us an information security policy.

Result: A generic text derived from the internet average, not relevant to your organization, with unclear roles, and whose legal compliance has not been verified. If published, it cannot be implemented and remains idle in audit.

Powerful prompt: [expert role + 7-part skeleton + [TO BE FILLED] institution-specific gaps + "legal approval for legal attribution" note + RACI matching + style standards]

Result: A draft policy that is adaptable to your institution, embraces every obligation, has consistent language and is ready for legal approval.

Testing the Policy: Applicability Check

Even a seemingly well-written policy may not be implemented in the field: it may contain unrealistic deadlines, non-existent roles, or conflicting rules. You can use AI to put the policy through a “feasibility test” before publishing it. This reads the text from an employee's perspective and finds the points where they might get stuck.

Test the following policy for applicability before publishing:1) Question whether each rule can be implemented by a real role; mark those that seem vague or impossible.2) Find out if there are any contradictions or duplication of rules.3) Evaluate whether the specified times and frequencies are realistic.4) When an employee asks "how exactly am I going to do this?" List the points where you will get stuck. Give a short correction suggestion for each finding; imposition of final judgment.

Tip: Think of the policy as "will an employee read this and know what to do?" Testing with a question catches the most common flaw (abstract and unenforceable rules). A policy that cannot be implemented is riskier than a policy that does not exist; because it creates the illusion of harmony.

Policy or Procedure?

Size

Politics

Procedure

Question

what and why

How

Level

upper, principle

Operational, step by step

change

rare

Updated when the process changes

example

"Personal data is protected"

"Data deletion request within 30 days with these steps"

Approval

Senior management/legal

Process owner + compliance

Three Mini Cases

Case 1 — Derelict policy. A company's data retention policy has been in place for years, but "who deletes data and when?" The answer to the question was not in the document. When a customer request for deletion came in, no one took ownership and the request was delayed by 40 days. Added RACI to policy with AI; A single approver and responsible person was assigned to each storage and deletion activity. Subsequent requests were closed in an average of 9 days and the process became auditable.

Case 2 — Unreadable document. An institution's ethics policy was a 14-page text with heavy jargon; the survey showed that only 12% of employees read. Stylistic standardization with AI: short sentences, appropriate expressions, defined terms. The document was reduced to 6 pages and the reading rate increased to 57% in three months. The content remained the same; intelligibility increased tenfold.

Case 3 — The value of legal approval. One team was about to directly publish the AI-generated draft disciplinary policy. The draft contained a statement of "unilateral termination", which did not comply with applicable labor legislation; AI had flagged it as "legal approval required". The legal review corrected the wording. If the sign were ignored, an unenforceable and litigation-risky policy would be enacted.

Common mistakes

  • Producing general policy without an institution. Text produced without context and [TO BE FILLED] spaces will not fit your institution.
  • Not being able to assign roles. Without RACI, politics remains derelict; no one is held accountable.
  • Confusing policy with procedure. If "what/why" and "how" are not separated, the document will be both abstract and incomplete.
  • Bypassing legal approval. Policies that have legal consequences must be reviewed in accordance with the legislation.
  • Jargon and long sentences. An unread policy is not enforced; Stylistic standard is essential.
  • Not setting a review date. Policies become obsolete; enforcement and periodic review should be defined.

In summary

Policy and procedure writing is the task of translating the organization's stance into clear, proprietary and auditable rules. AI produces a good first draft, keeps the language consistent and matches each obligation to RACI; But you must fill in the gaps specific to the institution, pass the legal content through legal approval, and keep the document readable. Separate policy from procedure, assign a single approver to each activity, and establish a review cycle. AI produces blueprints and structure; The authorized professional decides on the legality and validity of the policy.

Application task

Select a policy topic (e.g. acceptable use, data retention). (1) Have an outline produced with the 7-part skeleton prompt; inspect all [TO BE FILLED] and “legal approval required” markings. (2) Assign roles to each obligation with the RACI prompt; Verify that there is only one approver for each activity. (3) Run style standardization and improve readability. (4) Close the document with the status “pending legal/expert approval” and a review date.

checklist

  • [ ] Is the policy written with a coherent 7-part framework?
  • [ ] Have the institution-specific gaps been left as [TO BE FILLED]?
  • [ ] Each obligation mapped to RACI, single approver appointed?
  • [ ] Is the distinction between policy and procedure clear?
  • [ ] Is legal/expert approval planned for legal content?
  • [ ] Has the language been made short-sentenced, idiosyncratic and jargon-free?
  • [ ] Have the effective and review dates been defined?