Forty-five policy and standard templates, ready to adopt in your organization.

These are templates for your own programme, not the Association's rules: a complete baseline library of security, privacy, data and operations documents with merge tokens, so you fill in your organization's names and adopt them as yours. Five are free with a free membership. Preview any of them; download what your tier includes.

Policy · AcceptableUseFree

Acceptable Use Policy

[POLICY] [SME] Personnel-facing rules of acceptable system, data, and resource use; includes GenAI use boundaries.

Version 2026.07 · updated Jul 2026

Preview
Policy · AcceptableUseFree

Artificial Intelligence Acceptable Use Policy

[POLICY] [SME] Responsible use of AI/ML and generative tools: approved use, data-handling limits, human accountability. NIST AI RMF, ISO 42001, EU AI Act.

Version 2026.07 · updated Jul 2026

Preview
Policy · HumanResourcesFree

Code of Conduct

[POLICY] [SME] FCPA, UK Bribery Act, SOX, Dodd-Frank, EU Whistleblower Directive; ethics and compliance framework.

Version 2026.07 · updated Jul 2026

Preview
Standard · AccessControlFree

Password Standard

[STANDARD] [SME] Modern NIST SP 800-63B guidance; length over complexity; breach-corpus checking; no forced rotation.

Version 2026.07 · updated Jul 2026

Preview
Standard · InformationSecurityFree

Email and Instant Messaging Standard

[STANDARD] [SME] SPF/DKIM/DMARC p=reject, MTA-STS, DANE, BIMI, secure email practices.

Version 2026.07 · updated Jul 2026

Preview

Policy templates provided by a sponsor of the association.