Scope
Define the policy, framework, jurisdiction, owner, and review question.
A controlled first-pass comparison workflow that helps qualified teams locate possible gaps, inconsistencies, and review questions in policy documents.
A preliminary issue log with source citations and clearly labeled uncertainty, ready for review by the appropriate legal, compliance, privacy, security, or subject-matter professional.
The reference framework must be current, authorized, and selected by a qualified person. AI should never be represented as counsel, an auditor, or the final policy approver.
Define the policy, framework, jurisdiction, owner, and review question.
Connect policy passages to relevant framework provisions.
Identify omissions, ambiguity, contradictions, and stale references.
Qualified reviewers assess every flag and determine remediation.
The prompt asks for review questions, not unsupported declarations of compliance.
| Review question | Source basis | Status |
|---|---|---|
| Is the named owner still the accountable role? | Policy §2.1; org model changed | Owner verification needed |
| Does the retention period match the approved schedule? | Policy §6; schedule reference supplied | Expert comparison needed |
| Is the exception process sufficiently defined? | Policy §8 contains no approval path | Drafting review needed |
Outputs are review aids and must not be described as legal or regulatory advice.
A qualified owner confirms applicability and version before analysis begins.
No flagged issue is accepted, rejected, or remediated solely on model output.
Illustrative concept content only and not legal, regulatory, compliance, privacy, security, or audit advice.