Every audit asks for your policies, and every early team handles it the same way: someone finds a competitor's PDF, search-and-replaces the company name, and hopes the auditor doesn't read too closely. They do read closely, because a policy that doesn't match how you actually operate is worse than no policy at all. Here's the set you need and how to produce it properly.
The core policy set
For a SOC 2 (and largely for ISO 27001), auditors expect a recognizable set. You don't need all of these on day one, but this is the shape of a complete program:
- Information Security Policy: the umbrella; your overall approach and who owns it.
- Access Control Policy: how access is granted, reviewed, and revoked.
- Acceptable Use Policy: what employees can and can't do with company systems.
- Data Classification & Retention: how data is categorized, handled, and disposed of.
- Incident Response Policy: how you detect, respond to, and learn from incidents.
- Business Continuity / Disaster Recovery: how you keep running and recover.
- Vendor / Third-Party Risk Policy: how you vet and monitor providers.
- Change Management Policy: how changes to production are reviewed and released.
- Risk Management Policy: how you identify, score, and treat risk.
What makes a policy pass
Three things separate a real policy from a template:
- It matches reality. The policy describes what you actually do. If it says access is reviewed quarterly, you'd better have quarterly access reviews to show.
- It's owned and approved. A named owner, an approval, and a review date. An unapproved draft isn't evidence.
- It maps to controls. Each policy should tie to the controls it governs, so the auditor can trace policy → control → evidence.
How to write them fast without cutting corners
The fastest honest path is to start from a framework-mapped template and tailor it, not a generic download, but one written to map to the controls your framework expects. Then adjust the specifics: your systems, your cadences, your owners. If you already have old policies in Word, don't retype them. Clean them up into consistent, mapped versions.
Once approved, export a branded PDF. That's the artifact auditors and prospects actually want, and it's what you publish (or offer for download) on your trust center.
How Keel helps
Keel's policy management ships original, framework-mapped templates you tailor in a live editor. Name a policy and its AI drafts a clean, mapped first version to start from; drop in a messy Word doc and it rewrites it into tidy Markdown you approve. Move each policy draft → approved, export a branded PDF, and attach it as evidence against the controls it governs, all crosswalked across SOC 2, ISO 27001, and beyond.
Start free and go from zero policies to an approved, branded set in an afternoon.