Skip to content

Advisory

IT Policies and Procedures

Policy documents that are specific enough to be testable, short enough to be read, and traceable to the framework or regulation that requires them.

Why most policy sets fail an audit

The typical policy suite we inherit was downloaded, lightly renamed, and approved without anyone checking whether the organisation could actually comply with it. It fails on audit for predictable reasons: it commits to controls that do not exist, it contradicts itself between documents, it has no version control or review evidence, and no one below the CIO has read it.

A policy you cannot evidence compliance with is worse than no policy — it converts an operational gap into a documented control failure.

What we produce

  • Policy — the board-approved statement of intent and mandatory requirement. Short. Rarely changes.
  • Standards — the specific, measurable technical requirements. Testable. Changes with technology.
  • Procedures — the step-by-step operational instructions for the people doing the work.
  • Records and templates — the forms and registers that generate the evidence an auditor will ask for.

Four document types, four audiences

Policy Board-approved intent Standards Specific, measurable, testable Procedures Step-by-step, for the people doing the work Records The registers and forms an auditor will ask to see
A policy you cannot evidence compliance with converts an operational gap into a documented control failure.

Typical policy suite

Scoped to your regulatory obligations, but usually covering: information security policy; acceptable use; access control and identity management; change management; asset management and classification; cryptography and key management; physical and environmental security; operations security including backup, logging and malware; network security; secure development; supplier and third-party security; incident management; business continuity; data protection and privacy; and human resources security.

Traceability

Every requirement in the suite is mapped back to its source — an ISO 27001 Annex A control, a COBIT objective, a regulatory clause, or an internal risk decision. When an auditor asks why a control exists, the answer is in the document. When a framework changes, you can see exactly which policies are affected.

How the engagement runs

  1. 1

    Obligation mapping

    Establish every framework, regulation and contractual commitment the policy set must satisfy.

  2. 2

    Gap review

    Review existing documentation against those obligations. We reuse what works rather than starting from zero.

  3. 3

    Architecture

    Design the document hierarchy, ownership model, numbering and review cycle.

  4. 4

    Drafting

    Write to your actual operating reality, validated with the people who will have to comply.

  5. 5

    Review and approval

    Support the governance passage through to board or committee approval.

  6. 6

    Rollout

    Awareness material, acknowledgement tracking and the evidence trail that shows the policy landed.

What you receive

Complete, version-controlled policy suite in your own document template
Supporting standards and operational procedures
Traceability matrix mapping every requirement to its framework source
Registers and record templates that generate audit evidence
Defined review cycle, ownership and change control
Staff awareness material and acknowledgement tracking approach

Frequently asked questions

We can, but you should understand the limitation. A template that has not been reconciled to how your organisation actually operates will commit you to controls you do not have — which is exactly what auditors find. If budget is tight, a better use of it is tailoring a small core set properly rather than adopting forty generic documents.

You do, entirely, including the source files. We build in a defined ownership model and review cycle so the suite does not go stale the day we leave.

No. Same independence principle that applies across our practice — we do not audit our own work.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top