AI use case

AI for policy drafting and policy gap analysis

An assistant that takes a new or changed obligation, finds every internal policy, standard and procedure it touches, flags clauses that now conflict or are silent, and drafts the updated wording in house style as a redline for the policy owner to approve.

By Len Debets · Last verified 26 September 2026 · 3 public deployments

USD 38,400 to USD 288,000
Indicative value per year
A bank that updates 300 policy and procedure documents a year after regulatory change. Worked example, see how it is calculated.

What problem does it solve?

A bank's policy estate is large and layered: group policies, standards, procedures and desk instructions, written by different teams over many years. When a rule changes, someone has to find every document it touches, work out which clauses now conflict or say nothing, and rewrite them consistently. That work is mostly reading and cross referencing, done under deadline by specialists whose time is better spent on judgement.

The result is predictable: documents that contradict each other, procedures that lag the policy they implement, and wording that differs from team to team. When a supervisor asks how a policy implements a rule, the trail from obligation to clause is often reconstructed after the fact.

How does it work?

  1. Take the obligation. Start from an obligation already mapped by horizon scanning or legal: the new rule text, its effective date and the business it applies to.
  2. Find what it touches. Retrieval over the policy estate returns every policy, standard and procedure that covers the topic, with the relevant clauses.
  3. Flag gaps and conflicts. The assistant compares each clause with the obligation and marks it as compliant, conflicting, silent or unclear, quoting both texts.
  4. Draft the change. For each gap it drafts replacement or new wording using the approved template and style guide, as a redline, never inventing requirements beyond the source.
  5. Owner review. The policy owner edits and approves; legal or compliance signs off where required.
  6. Keep the trail. The link from obligation to clause, the drafts and the approvals are stored with the version history.
Audience
Employee facing
Autonomy
Copilot
Adoption
Emerging
Channels
Internal tools

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

No public deployment has disclosed a measurable outcome yet.

Value drivers: Compliance quality, Employee productivity, Speed and cycle time, Risk and loss reduction.

Indicative value

A bank that updates 300 policy and procedure documents a year after regulatory change

USD 38,400 to USD 288,000

Specialist time released from policy updates per year

How this is calculated

Formula: documents * hoursPerDocument * timeSaved * hourlyCost. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Policy and procedure documents updated per year documents, documents per year300300The reference bank. Replace with your own volume.
Specialist hours per document update (analysis and drafting) hoursPerDocument, hours per document816Editorial assumption, replace with your own time records.
Share of analysis and drafting time saved timeSaved, fraction of time0.20.4Editorial assumption. No public measured benchmark for policy drafting was found; keep this conservative.
Fully loaded cost of a policy or compliance specialist hourlyCost, USD per hour80150Editorial assumption, replace with your own.

What it leaves out: Time only. It leaves out the value of fewer inconsistencies and findings, faster implementation of new rules, and the cost of building and maintaining the policy knowledge base.

Market estimates (analyst estimates, not deployments)

Who already uses it?

3 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Administration for Children and Families

United States · Government and public sector · 2025

ProductionGrade B

In March 2025 the Administration for Children and Families, part of the US Department of Health and Human Services, deployed AI to review its existing grants, new grant applications and position descriptions for alignment with HHS Secretarial Directives related to recent executive orders. The AI produces an initial list of documents that may need revision (for grants, with an initial assessment and example passages); program office staff then review, justify and recommend. For position descriptions the agency states that AI was not used to make any final determinations. It is the gap detection half of policy change work: finding which existing documents a new requirement touches.

No outcome disclosed.

Federal Deposit Insurance Corporation

United States · Government and public sector · 2024

Paused or rolled backGrade B

The FDIC reported in its 2024 AI inventory a planned assistant for its policy writers: it would check a draft policy against the Plain Language Writing Act for clarity, active voice, concision, jargon and acronyms, and redraft selected sections in plain language. In the 2025 inventory the entry is listed as retired. It is a useful signal that style and consistency checking of internal policy is an early candidate, and that not every initiative reaches production.

No outcome disclosed.

Health Resources and Services Administration

United States · Government and public sector · 2024

AnnouncedGrade B

The Health Resources and Services Administration, part of the US Department of Health and Human Services, reported in 2024 a Policy Assistant that uses large language models to generate first drafts of key policy documents, funding notices and budget documents from example documents, style guides, key policy decisions and its internal knowledge base, plus an editing tool that checks drafts for inconsistencies and errors. The goal is less drafting time and better document quality. The entry was at the initiated stage and does not appear in the 2025 inventory; no results are published.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • A current, versioned policy and procedure library with owners
  • An obligation library or the new rule texts with effective dates
  • Approved templates and a style guide
  • Past redlines and approvals to test the assistant against

Systems to integrate

  • Policy management or document management system
  • Regulatory change or obligation management tool
  • Workflow for review and approval
  • Collaboration tools where owners edit drafts

Complexity: Medium

Retrieval and drafting are mature. The effort is in a clean, versioned policy estate with owners, a mapped obligation library and a template the drafts must follow.

  1. 1

    Clean the estate

    Retire duplicates, assign an owner and review date to every document and fix the version history. Retrieval over a messy estate finds the wrong clause confidently.

  2. 2

    Start with gap analysis, then drafting

    First use the assistant to find affected clauses and classify gaps, and measure how many it misses against expert review. Only then let it draft wording.

  3. 3

    Constrain the drafting

    Give the model the template, the style guide and the obligation text, and require every drafted sentence to cite the obligation it implements. Anything without a source is removed.

  4. 4

    Test on past changes

    Replay previous regulatory changes where the final policy text is known and compare the assistant's gaps and drafts with what the experts did.

  5. 5

    Embed in the approval workflow

    Deliver drafts as redlines into the existing review tool, record who approved what, and keep the obligation to clause link after publication.

Guardrails

  • Every drafted clause cites the obligation or source text it implements
  • Drafts follow the approved template; the assistant cannot publish or approve
  • The policy owner approves every change; legal or compliance signs off where required
  • Retrieval is limited to current, approved versions of documents
  • Version history and approval trail retained for supervisors and audit

KPIs to instrument

  • Time from a rule's publication to approved policy updates
  • Recall of affected clauses against expert review on sampled changes
  • Share of drafted text accepted without material edits
  • Inconsistencies found between policy and procedure in periodic reviews
  • Audit and supervisory findings on policy coverage

Human in the loop

The policy owner reviews and approves every change and owns the interpretation of the rule. Compliance or legal signs off material changes. The assistant drafts and flags; it never decides that a policy is compliant.

Common failure modes

Invented obligations
The model adds requirements that are not in the rule. Require a citation per sentence and strip anything unsupported.
Missed documents
A procedure outside the indexed estate never shows up, so the gap persists. Measure recall and keep the estate complete.
Style over substance
Polished drafts get approved without checking the interpretation. Owners must confirm the interpretation separately from the wording.
Stale sources
Retrieval returns a superseded version. Index only current approved versions and show the version in every citation.

What are the risks and rules?

EU AI Act

Minimal risk

Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.

Guidance

Controls to put in place

  • Inventory entry for the assistant with an owner, scope and approved sources
  • Citation requirement and automated check for unsupported text
  • Approval workflow with recorded sign off per change
  • Periodic recall testing against expert gap analysis
  • Retention of the obligation to clause trail and version history

Frequently asked questions

Can AI write our policies?
It can find what a new rule touches and draft consistent wording quickly, but the policy owner must approve every change and own the interpretation. The safe design constrains drafting to approved templates and requires a citation for every clause.
Where do public deployments stand?
Mostly early. The Administration for Children and Families, part of the US Department of Health and Human Services, reported using AI since March 2025 to flag grants and position descriptions that may need revision under new directives, with staff making the final assessments. Policy drafting assistants reported by HRSA (initiated in 2024) and the FDIC (retired by 2025) never reported reaching production.
How is this different from regulatory horizon scanning?
Horizon scanning finds new rules and maps them to obligations. Policy drafting and gap analysis starts from a mapped obligation and changes the bank's own documents to implement it.

How to cite this page

Blits.ai AI Use Case Library, "AI for policy drafting and policy gap analysis", last verified 26 September 2026, https://www.blits.ai/ai-use-cases/policy-drafting-and-gap-analysis. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Cross industryBanking

AI regulatory horizon scanning and obligation mapping

An AI system that continuously reads publications from the regulators and standard setters an organization answers to, classifies each item by relevance and urgency, breaks new rules into individual obligations and maps them to the internal policies and controls that meet them, so compliance owners see what changed and where the gaps are.

Deployments
2 public, best grade B
Autonomy
Assist
Cross industryBanking

AI for continuous controls testing and control self assessment

AI that moves control testing from periodic samples to continuous, full population assurance: it collects evidence from source systems, maps each artefact to the control it supports, tests every transaction or record against the control's rule, flags exceptions for a human to judge and prepares the risk and control self assessment from incident and loss data for the business to review.

Deployments
3 public, best grade B
Autonomy
Supervised agent
BankingInsurance

AI for supervisory exam and information request responses

An assistant for the bank's regulatory affairs team that reads a supervisory information request or exam question, retrieves the relevant evidence, policies and prior correspondence, drafts a response for legal and compliance to approve, and tracks every commitment and remediation action through to closure.

Deployments
3 public, best grade B
Autonomy
Copilot
Cross industryBanking

AI assistant for HR and policy questions

An employee self service assistant that answers questions on leave, pay and tax forms, benefits, expenses, travel and conduct policies from the organization's own HR documents, personalized to the employee's country and role, and starts simple HR transactions such as leave requests or employment letters in the HR system.

Deployments
4 public, best grade B
Reported employee adoption
99%
IBM, organization claim
Cross industryBanking

Generative AI copilot for internal audit

A copilot for internal auditors that drafts planning memos and document request lists from prior audits, summarises large evidence sets, builds risk and control matrices from policies and process documents, and drafts findings and reports, with every statement traceable to its evidence and a qualified auditor accountable for every conclusion.

Deployments
3 public, best grade C
Reported handling time reduction
55%
Banco Bradesco, vendor claim