PlaybookTemplates← Back to library
Risk, compliance & governance · AI playbook 03

AI Policy
Review

A controlled first-pass comparison workflow that helps qualified teams locate possible gaps, inconsistencies, stale references, evidence issues, and review questions in policy documents.

The outcome

A preliminary issue log with source citations and clearly labeled uncertainty, ready for review by the appropriate legal, compliance, privacy, security, or subject-matter professional.

01 · Workflow

Use AI to prepare review, not provide approval.

The reference framework must be current, authorized, and selected by a qualified person. AI should never be represented as counsel, an auditor, a compliance authority, or the final policy approver.

01

Scope

Define the policy, framework, jurisdiction, owner, and review question.

02

Map

Connect policy passages to relevant framework provisions and evidence.

03

Flag

Identify omissions, ambiguity, contradictions, stale references, and owner questions.

04

Escalate

Qualified reviewers assess every flag and determine remediation.

02 · Prompt example

Explicit limits produce safer outputs.

The prompt asks for review questions, not unsupported declarations of compliance.

Comparison prompt

Policy issue finder

Compare the supplied policy only against the supplied reference. Identify passages that may warrant expert review. For each, provide the policy citation, reference citation, reason for review, and uncertainty. Do not state that the policy is compliant or noncompliant.
Expert review

Required checks

  • Confirm the reference is current and applicable
  • Verify every policy and framework citation
  • Discard interpretations outside the stated scope
  • Assign each issue to a qualified owner
03 · Example output

An issue log, not a legal conclusion.

Review questionSource basisStatus
Is the named owner still the accountable role?Policy section 2.1; org model changedOwner verification needed
Does the retention period match the approved schedule?Policy section 6; schedule reference suppliedExpert comparison needed
Is the exception process sufficiently defined?Policy section 8 contains no approval pathDrafting review needed
04 · What's included

What this playbook includes.

A product-ready structure for an AI prompt governance template, policy comparison workflow, and compliance review checklist.

ComponentIncluded detailPurpose
Use caseAI-assisted policy comparison and issue spottingPrepare qualified review without claiming approval
Intended userPolicy owner, compliance, privacy, security, governanceSupport controlled escalation
Required inputsApproved policy, reference framework, scope, reviewer ownerLimit the model to authorized sources
Output artifactsIssue log, evidence register, escalation trackerCreate reviewable compliance materials
Review controlsFramework validation, citation checks, qualified-owner reviewAvoid false compliance conclusions
Common failure modesStale references, unsupported interpretations, broad hallucinationKeep uncertainty visible
Related playbooksHealthcare/HIPAA, NDA review, procurement, executive briefingConnect governance to operating workflows
05 · Guardrails

Designed around escalation.

01

No legal conclusions

Outputs are review aids and must not be described as legal or regulatory advice.

02

Current references

A qualified owner confirms applicability and version before analysis begins.

03

Mandatory expert review

No flagged issue is accepted, rejected, or remediated solely on model output.

Controlled governance workflow

Make responsible AI adoption tangible and reviewable.

Licensing & partners ↗

Illustrative concept content only and not legal, regulatory, compliance, privacy, security, or audit advice.