Skip to main content

Governance

POLICYFORGE

Policy Automation

Stop writing policy by hand. Generate the set, find the gaps, fix them.

PolicyForge drafts the whole governance set against a control baseline: the policy, the technical standard, the procedure and the compliance requirements. It runs gap analysis over the documents you already have and drafts the language that closes what is missing. Reviewers approve. Models inside your boundary do the writing.

Gap analysis, NIST SP 800-53 Moderate Example Agency
ControlVerdictBest match
AC-2 Covered Account Management Policy, 4.2
AC-2(3) Partial Account Management Policy, 4.5
AC-6(9) Gap No passage above threshold
AU-6 Covered Audit Procedures, 3.1
CM-3 Partial Change Control SOP, 2
IR-8 Gap No passage above threshold

42 of 61 covered, 11 partial, 8 gaps

Illustrative run. Controls real, documents and scores invented.

Cross framework mapping

Working with multiple frameworks? Generate one doc-bundle that fits them all.

PolicyForge includes built-in cross-framework mappings for multiple compliance frameworks including NIST SP 800‑53, NIST CSF 2.0, and CMMC 2.0. Pick out your applicable frameworks when setting up your organization and create one set of documents. Still specific to your organization, each generated document now provides you the list of controls across other selected frameworks that are satisfied by each text section.

Frameworks

We currently support the following frameworks. Can't find what you need? Reach out to the team to add your preferred frameworks to the list.

NIST 800-53 R5NIST CSF 2.0ISO 27001 2022NIST AI RMF 1.0CMMC 2.0

How it works

Profile, ingest, analyze, generate

01

Profile the organization

Name, mission, framework and impact level. Policies, documents and gap results are all stored against the profile, so one instance serves many organizations.

Organization profile
Organization profile Example Agency
Mission Benefits administration for 1.2 million members
Framework NIST SP 800-53 Rev 5
Impact level Moderate
Documents 12 ingested
Gap runs kept 3 of 10

Illustrative profile. Everything invented.

02

Ingest what you have

Upload the existing policy set. Each document is chunked and embedded into a searchable corpus. A chunk that fails to embed is counted and reported, never silently scored as a gap.

Indexed policy corpus
Indexed corpus 12 documents
Account Management Policy, 38 chunksAudit Procedures, 22 chunksChange Control SOP, 17 chunksIncident Response Plan, 41 chunksMedia Protection Policy, 12 chunksAccess Review Standard, 9 chunks

0 chunks failed to embed. A failure is counted and reported, never scored as a gap.

03

Run gap analysis

Every required control is embedded and searched against your documents, so coverage written in different words still counts. Each control comes back covered, partial or gap with the passage it matched. Runs in the background, scoped to the controls you choose, and every run is kept with its history.

Scored coverage, per control Local model
Gap analysis history Moderate baseline
RunWhenScopeCovered / partial / gap
3Today61 controls42 / 11 / 8
26 days ago61 controls39 / 13 / 9
13 weeks ago61 controls31 / 14 / 16

Every run kept, ten deep. Invented figures.

04

Generate and fix

Generate a policy against the baseline, prefilled from any gap you click. Or take a typed gap from evidence analysis in the ATO workflow and have the missing language drafted: one section per gap, a placement hint, bracketed parameters for your choices. Review, approve, export.

Drafts ready for review Local model
AV-POL-0007 In review

Account Management Policy, amendment

4.6 Privileged account review

Privileged accounts shall be reviewed every [review period] by the [reviewing role], and each review shall be recorded.

Place after 4.5 Periodic account review

Drafted from an evidence gap. Copy it, or save it to the library.

What it writes

Four documents per control set, not one

A policy alone does not pass an assessment. PolicyForge generates the full chain from what is required to how it is done to what proves it, each document numbered and exportable to DOCX or PDF.

POL

Policy

The shall statements. What the organization requires, scoped to the controls and the impact level in the profile.

STD

Technical standard

The specific settings, thresholds and configurations the policy demands, written so an engineer can implement them.

PROC

Procedure

Step by step operational instructions for the people who carry the policy out, in the order they do it.

COMP

Compliance requirements

The evidence artifacts required per control, so the ISSO knows what to collect before an assessor asks.

Generate one type or all four in a single run. Each lands in the library with its own review state and a document number.

Why it matters

The same control, two ways to get to a document

Without PolicyForge

Copy a template, find and replace the agency name, hope the procedure matches what the team actually does, and learn at the assessment which controls the document never mentioned.

With PolicyForge

Profile the organization once, generate the policy, standard, procedure and compliance requirements against the baseline, run gap analysis on what you already had, and fix the misses with drafted language before the assessor arrives.

Where it connects

Built into the authorization, not beside it

ATO workflow

Policy and procedure gaps found during evidence analysis hand straight to PolicyForge with a Draft the missing language button. The draft lands in the library as an amendment drafted from evidence gaps.

AVISSAA

Evidence and technical gaps go the other way: AVISSAA says what artifact would close them.

The library

Generated policies, ingested documents and evidence driven amendments live together, filterable by type, each with a review state.

Review

Approve, hold in review or reject with notes. Nothing is published on a model's say so.

Six tabs

One workspace with the status, KPIs and recent documents up front, and a hand-off from every tab into Generate.

OverviewGenerateGap AnalysisLibraryControlsOrganizations

What you can do

  • Set up an organization profile first, since policies, documents and gap results are stored against it

  • Generate the policy, the technical standard, the procedure and the compliance requirements for a control set in one run

  • Upload your existing policy set so gap analysis has a corpus to search

  • Run gap analysis to see each control scored as covered, partial or gap, with the matching passage

  • Read the matched passage before accepting a control as covered

  • Generate a policy from a gap, or draft the missing language from an evidence gap in the ATO workflow

  • Export a generated policy when you are ready to take it into review

Straight answers

What does it actually produce?

Four document types per control set: the policy statements, a technical standard with the settings the policy demands, a step by step procedure, and the compliance requirements listing the evidence each control needs. Any of them exports to DOCX or PDF.

How does it decide a control is covered?

It embeds the control statement, searches your document collection, and scores the best semantic match. High similarity reads as covered, middling as partial, low as a gap. Every result shows the text it matched so you can judge whether the match is legitimate.

Does it replace legal or leadership review?

No. It produces drafts and scored findings. A human still reviews and approves anything published, and the coverage scores are decision support rather than an assessment result.

Does it edit my existing policies?

No. A fix drafted from an evidence gap is a new section you copy or save as its own draft. The document you uploaded is never changed.

What frameworks does it cover?

NIST control content today, with additional frameworks as they are added.

Does my policy text leave the environment?

No. Drafting and matching run on models inside your own boundary.

Bring a policy. Leave with its gaps and the language that closes them.

Ask for a demo and we will run one of your documents, or a synthetic one, against a baseline in front of you.