Most organisations arrive with a policy set that already exists: a folder of Word and PDF files named like "POL-007_access-control_v3_final (2).docx". Import policies takes that folder as it is. Your own AI reads every document, gives it a clean title, sorts it into a category, works out which framework it serves and which controls it satisfies, and shows you the result in one table before anything is created.

What you need

  • The policies.edit permission (editors and administrators).
  • Your documents as PDF, Word (.docx), text or Markdown, up to 40 files of 25 MB each per import. A scanned PDF without a text layer is named from its file name only.
  • Optionally, an AI connected under Settings, AI (Claude, OpenAI or DeepSeek, with your own key). Without it the import still works: titles come from file names, categories from a keyword heuristic, and the control mapping from the deterministic passes.

How it works

1. Add the documents

Open Policies, choose Import policies, and drop the files in. Each file uploads on its own, so a slow connection or one bad file never blocks the rest.

2. The analysis runs in the background

Each document is read in turn. The AI proposes the formal title, a category, the framework the document most directly serves, the language, a two-sentence summary and, where the document states them, its version, effective date and owner. The policy-to-control matcher then runs for that framework: an AI pass, a keyword pass and the crosswalk fan-out to equivalent controls in your other frameworks. You can leave the page; a notification tells you when the batch is ready.

3. Review

One row per document: edit the title, change the category or framework, open the list of mapped controls with their confidence, and untick anything that should not become a policy. A document the AI considers not to be a governing document (an invoice, a contract) is unticked by default.

4. Create

Choose whether the imported policies are created as approved and in force (the default, since these are your existing documents) or as drafts for review, then create them. The original file is attached to each policy, the control mappings are saved, and the batch is closed.

Where the import lands

ResultWhere to find it
The policy record with its category chipPolicies; the uploaded file is in the policy's documents panel
The mapped controlsThe policy's Controls tab, and the Policies tab of each control
Evidence on the mapped controlsAn approved policy mapped to a control fills that control's policy-type evidence slot through detected evidence; the refresh is queued at once and otherwise runs daily

Categories

Governance, Risk management, Access control, People and HR security, Asset management, Cryptography, Physical security, Operations security, Network security, Secure development, Suppliers and third parties, Incident management, Business continuity, Compliance and privacy, AI governance, Other. The category is a sorting aid for your library; it does not change how controls are mapped.

Good to know

  • Changing a document's framework at review recomputes its mapping with the keyword and crosswalk passes only; run Match controls on the policy afterwards to add the AI pass for the new framework.
  • Mappings you confirmed or dismissed by hand on a policy are never overwritten by a later re-match.
  • Documents left out at review are deleted from storage. Cancelling an import removes every staged file.
  • The AI reads the document text only. It never follows instructions found inside a document.