Every CISO and GRC manager has had the same thought recently: “Could ChatGPT write my ISO 27001 policies?” AI can already generate clean templates, structured paragraphs, and even full ISMS documents in minutes. The question isn’t can it? The question is: should you trust it?
Most organisations are testing AI the wrong way. They throw a prompt at ChatGPT ; “Write an Access Control Policy!” ; and expect magic. Instead, they get:
- generic text
- missing controls
- auditor-unfriendly phrasing
- over-promised responsibilities
- and zero alignment to their actual reality
Here’s the truth from the field:AI can absolutely draft your ISMS policies ; but only if you treat it as a co-pilot, not a replacement. The “real test” isn’t whether ChatGPT can generate text. It’s whether the output stands up to evidence, auditors, and operational reality.
Let’s break down what AI can (and cannot) do for your ISMS.
1. AI Is Excellent at Structure ; and Can Be Terrible at Context
ChatGPT is a master at structure. It can instantly produce:
- headings
- clauses
- definitions
- tables
- scope statements
- responsibilities
- policy outlines
Anecdote: I once tested ChatGPT by asking for a full ISMS policy suite. In 5 seconds, it produced 14 policies that looked clean and complete.
But:
ChatGPT doesn’t know:
- your risk profile
- your actual tools
- what you’ve implemented
- who owns what
- your exceptions
- your evidence reality
Fix: Use AI to generate the skeleton, not the substance.
2. AI Writes Policies That Say Too Much ; and That’s Dangerous
ChatGPT loves strong wording: “Access reviews shall be performed monthly.” “All incidents shall be resolved within 24 hours.” “Encryption is mandatory for all data.”
Looks professional. Fails the audit instantly.
Because auditors don’t check what you wrote. They check what you promised vs. what you prove.
A story from the field: A company copy-pasted an AI-generated access policy that required monthly reviews. In reality, they did quarterly reviews. The auditor scored a nonconformity because the organisation didn’t follow its own policy.
Fix: Always rewrite requirements to match your actual operating reality not AI’s perfection.
3. AI Still Gets ISO 27001 Wrong (Especially the Annex A Controls)
ChatGPT often:
- mixes versions (2013 vs 2022)
- misinterprets controls
- confuses guidance with requirements
- invents obligations that don’t exist
- omits mandatory clauses
- misaligns PDCA with documentation
Example: Ask ChatGPT for a “Supplier Security Policy” based on ISO 27001. It will produce a decent narrative ; but miss the core requirement:supplier agreements must define the security expectations, not just assess them.
AI knows the words, not the nuance.
Fix: Let AI draft text, but validate content against the real Annex A.
4. AI Cannot Align Policies With Your Actual ISMS Scope
Scope is the heart of your ISMS. And ChatGPT cannot:
- interpret your organisational structure
- define your boundaries
- integrate your asset inventory
- map your processes
- reflect your real architecture
- understand shared responsibilities
If you ask it to draft a policy without feeding context, it writes for a fictional organisation.
Anecdote: A client used AI to generate a “Backup Policy.” It referenced systems they didn’t have and responsibilities that didn’t exist.
Fix: Give AI the real scope and environment ; or you’ll get a policy for someone else’s company.
5. AI Can Help With Consistency ; if You Feed It Your Voice
One huge win with ChatGPT: tone consistency.
If you have:
- an existing policy
- a preferred style
- a compliance language
- specific phrasing
- a writing standard
AI can replicate it across your entire ISMS.
Anecdote: We once fed ChatGPT a single “master policy style.” It produced six other policies with the same tone, formatting, and structure ; saving hours of manual editing.
Fix: Provide examples before asking it to generate new documents.
6. AI Is Amazing at First Drafts ; But Cannot Produce Audit-Ready Final Versions
ChatGPT can give you 80% of a policy’s text. What it cannot do is the last mile:
- alignment with your actual processes
- legal validation
- technical feasibility checks
- cross-functional responsibilities
- audit defensibility
- evidence consistency
- operational clarity
Humans still handle the governance. AI handles the grunt work.
This is the correct balance.
7. AI Can Accelerate ISMS Implementation ; Dramatically
With good prompts, AI can:
- draft your policy suite
- outline your risk methodology
- produce SoA drafts
- generate training content
- rewrite technical processes into plain English
- convert engineer notes into policies
- create templates (e.g., incident reports, vendor assessments)
- summarise audit requirements
- compare frameworks (ISO vs SOC vs NIS2 vs DORA)
One CISO told me: “What used to take two months of writing now takes a week.”
AI doesn’t make the ISMS mature. It makes the documentation painless.
8. The Real Test: Can ChatGPT Handle an Auditor?
Short answer: no. Not yet. Maybe not ever.
Auditors ask: “Show me the evidence behind this statement.” ChatGPT can’t do that. Only your environment can.
Auditors check:
- traceability
- implementation
- ownership
- last updated date
- proven workflows
- logs
- approvals
AI can generate explanations ; but not evidence.
Fix: Use AI for drafting. Use humans for validation and proof.
9. The Magic Formula: Human Governance + AI Drafting
This is the model that actually works:
- Human defines: scope, responsibilities, frequency, evidence reality.
- AI drafts: structure, language, formatting, alignment.
- Human edits: accuracy, feasibility, compliance alignment.
- AI refines: clarity, consistency, tone.
- Human approves: final governance and evidence traceability.
This hybrid approach cuts ISMS documentation time by 50–70% while improving clarity.
10. So… Can ChatGPT Draft Your ISMS Policy?
Yes. But only if you understand what AI is ; and what it isn’t.
AI is a writing engine.It is not a governance engine.
It can:
- speed up
- simplify
- standardise
- inspire
- clarify
It cannot:
- own controls
- validate evidence
- interpret ISO requirements
- reflect your organisational reality
- survive an audit alone
AI is the best junior GRC assistant you will ever have ; but it still needs a senior human to lead.
Final Thought
ChatGPT won’t replace your ISMS. It will replace the slow, painful drafting phase that everyone hates.
The organisations that win the AI transition aren’t the ones who let AI write everything. They are the ones who use AI to remove friction while keeping governance strong.
AI accelerates. Humans validate. Together, they transform how ISMS documentation gets done.
If you want to learn how to use AI safely and effectively to build or upgrade your ISMS ; ISO 27001, NIS2, DORA, SOC 2 and more ; that’s exactly what we teach inside the Cyber Academy AI for GRC & Compliance Programs. Join the next session and build a modern, intelligent ISMS that works.
