AI-Based Compliance Policy Recommender

  • Unique Paper ID: 200638
  • Volume: 12
  • Issue: 12
  • PageNo: 2285-2290
  • Abstract:
  • In the current digital landscape, organizations are required to implement structured information security policies to protect sensitive data and comply with international standards such as ISO 27001. However, developing these policies manually is a complex, time-consuming process that requires domain expertise and a deep understanding of regulatory frameworks. Many small and medium-sized organizations struggle to create and maintain proper compliance documentation due to a lack of resources and technical knowledge. This paper presents an AI-Based ISO 27001 Compliance Policy Generation System that automates the creation of information security policies based on organizational inputs. The system collects key details such as industry type, system environment, data storage methods, and sensitivity level, and dynamically maps them to relevant ISO 27001 controls. A structured policy engine is designed using predefined rule-based logic and control mappings to generate context-aware and standardized policy documents. The proposed system is implemented using a Flask-based backend, a MySQL database for data management, and a responsive web interface for user interaction. It also includes automated PDF generation for producing professionally formatted policy documents. By reducing manual effort and ensuring consistency with ISO standards, the system improves compliance readiness and simplifies the policy creation process. The results demonstrate that the system can generate accurate, structured, and industry-relevant policy documents dynamically, making it a practical solution for organizations seeking efficient and reliable compliance management.

Copyright & License

Copyright © 2026 Authors retain the copyright of this article. This article is an open access article distributed under the Creative Commons Attribution License which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.

BibTeX

@article{200638,
        author = {Aditya Ranaware and Nandkumar Aniruddha Kaldhone and Sahil Nitin Shinde and Pranjal Dattatray Sahane and Prof. Saba Chaugule},
        title = {AI-Based Compliance Policy Recommender},
        journal = {International Journal of Innovative Research in Technology},
        year = {2026},
        volume = {12},
        number = {12},
        pages = {2285-2290},
        issn = {2349-6002},
        url = {https://ijirt.org/article?manuscript=200638},
        abstract = {In the current digital landscape, organizations are required to implement structured information security policies to protect sensitive data and comply with international standards such as ISO 27001. However, developing these policies manually is a complex, time-consuming process that requires domain expertise and a deep understanding of regulatory frameworks. Many small and medium-sized organizations struggle to create and maintain proper compliance documentation due to a lack of resources and technical knowledge.
This paper presents an AI-Based ISO 27001 Compliance Policy Generation System that automates the creation of information security policies based on organizational inputs. The system collects key details such as industry type, system environment, data storage methods, and sensitivity level, and dynamically maps them to relevant ISO 27001 controls. A structured policy engine is designed using predefined rule-based logic and control mappings to generate context-aware and standardized policy documents.
The proposed system is implemented using a Flask-based backend, a MySQL database for data management, and a responsive web interface for user interaction. It also includes automated PDF generation for producing professionally formatted policy documents. By reducing manual effort and ensuring consistency with ISO standards, the system improves compliance readiness and simplifies the policy creation process.
The results demonstrate that the system can generate accurate, structured, and industry-relevant policy documents dynamically, making it a practical solution for organizations seeking efficient and reliable compliance management.},
        keywords = {Artificial Intelligence (AI), ISO 27001, Information Security Policy, Compliance Automation, Policy Generation System, Information Security Management System (ISMS), Rule-Based System, Data Security.},
        month = {May},
        }

Cite This Article

Ranaware, A., & Kaldhone, N. A., & Shinde, S. N., & Sahane, P. D., & Chaugule, P. S. (2026). AI-Based Compliance Policy Recommender. International Journal of Innovative Research in Technology (IJIRT), 12(12), 2285–2290.

Related Articles