FREE TOOL 06 / Policies

Policy builder

Build editable written information security, business continuity, incident response and AI policy drafts with an actual-practice review. For RIA operations, compliance and technology teams.

Text · PDF · Editable copyRead the guide ↗
Inputs stay in this browser tab

No automatic saving. Download a copy or choose Save to free account to keep your work. Avoid client details, credentials and confidential evidence.

A CLEAR RECORD, FROM SCOPE TO NEXT STEPS

Policy builder

Choose a policy, write procedures that reflect your firm and record the changes needed before adoption.

  1. Define the firm, period and information in scope.
  2. Record judgments with evidence and rationale.
  3. Export a complete draft and continue from your saved copy.

No account required. Download your work or explicitly save it to a free account. Use categories and fictional labels; avoid sensitive records.

Sources, assumptions & limits

Template 1.1.0 · Sources checked October 2, 2026. A planning aid, not legal advice, a system assessment or a compliance determination. User-recorded statuses are not independently verified.

SEC-SP-2024: Regulation S-P amendments, release 34-100155 and correction 34-100155A ↗ — Applies according to the rule's institution and information scope; this initial worksheet does not determine applicability, calculate incident deadlines or provide an exhaustive legal assessment. Qualified regulatory content review remains pending.

NIST-1305: CSF 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management ↗ — Voluntary guidance; review depth, evidence and reassessment timing depend on the service and firm's exposure.

NIST-34: SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems ↗ — Federal contingency guidance used as planning background, not a specific RIA legal mandate.

NIST-AI: AI Risk Management Framework 1.0 ↗ — Voluntary framework. This release uses version 1.0; NIST indicates revision work is underway. The policy builder is not a complete AI governance system.

NIST-1300: Cybersecurity Framework 2.0: Small Business Quick-Start Guide ↗ — Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.

NIST-84: Guide to Test, Training, and Exercise Programs for IT Plans and Capabilities ↗ — Exercise methodology background, originally in a federal context. Our fictional scenarios and minute allocations are product-authored suggestions.

Read our methodology