Policy & Document Drafting

Missing a policy? Draft it via chat. Track every version through maker-checker approval.

ICMS AI drafts compliance documents on request (policies, procedures, manuals, work instructions), grounded in your organisation and mapped to the clauses they satisfy. Every version tracks through maker-checker-approver.

policy · assistant
Draft an Access Control Policy aligned with A.5.15 & A.8.2.
drafting
Access Control Policy
1. Purpose & Scope
2. Roles & Responsibilities
3. Access Provisioning
4. Privileged Accounts
5. Review & Revocation
6. Audit & Evidence
streaming
Regenerate / Improve
Access Control Policy
v0.1 · ISO/IEC 27001:2022
A.5.15A.8.2A.8.3A.5.18
1. Purpose & Scope
3. Access Provisioning · Matrix
RoleAccess LevelReview
AdminPrivilegedQuarterly
AnalystRead/WriteBi-annual
AuditorRead-onlyAnnual
Mapped:ISO A.5.15 · A.8.2 · NIST AC-2 · SOC2 CC6.1
maker → checker → approver
AR
MAKER09:14
A. Rao
Compliance Analyst
Drafted
SI
CHECKER10:02
S. Iyer
Security Lead
Reviewed
KM
APPROVER10:47
K. Menon
CISO
Approved & Signed
AU
PUBLISHER10:48
Auto
Policy Publisher
Published to library
audit trail · immutable live

Traditional ICMS is a workflow. ICMS AI is a conversation.

Traditional workflow

You navigate the app.

  • Policies drafted in Word, reviewed over email
  • Version control by filename ("_v3_FINAL_reviewed_2.docx")
  • No mapping between a policy and the clauses it satisfies
  • Renewals slip because nobody owns the calendar

ICMS AI · agentic

You just ask.

  • Ask: "Draft an Access Control Policy aligned with A.5.15 and A.8.2"
  • The assistant drafts a policy specific to your organisation
  • The document goes through maker → checker → approver in-app
  • Every clause the policy satisfies is mapped and tracked

How it works.

  1. 01

    Ask for what you need

    Request a policy, procedure, manual, work instruction, form, or register. Name the clauses it should satisfy.

  2. 02

    Draft grounded in your organisation

    The assistant drafts against your industry, size, structure, and existing policies. You get a real first draft, not a template.

  3. 03

    Maker → checker → approver

    The draft moves through your approval chain in-app. Every reviewer sees the same document, comments, and version history.

  4. 04

    Publish and map

    On approval, the document publishes to your policy library and its clause map updates. Renewals are calendared automatically.

What you get.

Turns "we need a policy for that" into a signed, mapped, published document by end of week.

  • Document types: policy, procedure, manual, work instruction, form, checklist, register
  • Grounded drafting: uses your organisation, industry, and existing docs
  • Split-pane editing: markdown preview + iterative AI edits
  • Maker-Checker-Approver workflow with immutable audit trail
  • Automatic mapping to standards clauses
  • Renewal calendar and expiry alerts

See it on your standards.

Talk to us about running this on your compliance programme.