IT governance that protects your business
Policy & Documentation
IT policy and documentation services are the writing of the disaster recovery plans, incident response playbooks, AI usage policies and POPIA records your organisation needs to stay compliant. When things go wrong, you need a plan. When auditors come knocking, you need proof. We write the documentation that keeps your organisation compliant, secure, and prepared for anything, tailored to your business rather than pulled from a generic template.
Why does IT documentation matter?
IT documentation matters because it reduces mistakes, proves POPIA and ISO 27001 compliance, tells staff what is allowed, and is the difference between recovering from an incident in hours and in weeks.
How does documentation reduce risk?
Risk is reduced because documented procedures mean fewer mistakes; when everyone knows the process, human error drops and incident response times improve.
Is documentation required for compliance?
Yes, POPIA, ISO 27001 and industry audit standards all require formal IT governance documentation, and AMEA makes sure you can prove compliance at any time.
How do policies help staff?
Clear policies are how staff know what is allowed, what is not, and exactly what to do when problems crop up.
How does documentation protect continuity?
Business continuity is protected because organisations with documented recovery plans are back on their feet in hours, while those without can take weeks.
Which IT policies and plans does AMEA write?
AMEA writes disaster recovery plans, IT policy frameworks, incident response plans, AI acceptable use policies, POPIA compliance frameworks and password and access policies, each written around your organisation rather than a generic template.
What is a Disaster Recovery Plan (DRP)?
A DRP is the step-by-step guide to restoring IT systems after a major incident.
A step-by-step guide for recovering your IT systems after a major incident, whether that is ransomware, hardware failure, or a natural disaster. We document your critical systems, recovery priorities, RTO/RPO targets, and communication protocols.
- Business impact analysis (BIA)
- Recovery time & recovery point objectives
- Vendor and supplier contact lists
- System restoration runbooks
- Tabletop exercise scenarios
- Annual testing and review schedule
What is an IT Policy Framework?
An IT policy framework is the set of enforceable rules that govern how your organisation uses technology.
A comprehensive set of enforceable policies covering how your organisation uses technology. Clear, practical, and tailored to your size and industry, never generic templates.
- Acceptable use policy (AUP)
- Data classification and handling standards
- Access control and privilege management
- Password and authentication requirements
- BYOD and remote work guidelines
- Software and hardware procurement rules
What is an Incident Response Plan (IRP)?
An IRP is the procedure your team follows the moment a breach or IT incident is detected.
When a security breach or IT incident occurs, every minute counts. We create detailed response procedures so your team acts decisively, minimising damage, preserving evidence, and meeting your notification obligations.
- Incident severity classification matrix
- Escalation paths and responsibilities
- Evidence preservation procedures
- Regulatory notification timelines (POPIA)
- Communication templates for stakeholders
- Post-incident review and lessons learned
What is an AI Acceptable Use Policy?
An AI acceptable use policy is the rule set for which AI tools staff may use and what data may go into them.
As AI tools become standard in the workplace, clear guidelines are non-negotiable. We help you define which tools are approved, what data can be shared with them, and how to maintain quality and legal compliance.
- Approved AI tools and platforms list
- Data sensitivity and privacy rules
- Intellectual property considerations
- Quality control and review obligations
- AI output disclosure requirements
- Staff training and acknowledgement process
What is a POPIA Compliance Framework?
A POPIA compliance framework is the documentation package that evidences how personal information is collected, stored and protected.
The Protection of Personal Information Act (POPIA) requires organisations to formalise how they collect, store, and process personal data. We create the full documentation package your Information Officer needs.
- PAIA/POPIA manual
- Data processing register
- Consent management procedures
- Data breach notification protocol
- Supplier and third-party data agreements
- Annual compliance review checklist
What is a Password & Access Policy?
A password and access policy is the enforceable standard for credentials, MFA and privileged access.
Weak credentials are the number-one attack vector. We create enforceable password and access management policies aligned with NIST best practices and your specific technology environment.
- Password complexity and rotation standards
- Multi-factor authentication requirements
- Privileged access management rules
- Joiner / mover / leaver procedures
- Service account governance
- Third-party and contractor access rules
How does the documentation process work?
The process runs in five steps: discovery interviews, a gap analysis against compliance requirements, drafting, review with your team, and implementation with staff training and a review schedule.
What happens in discovery?
Discovery is where AMEA learns your systems, processes and business priorities through structured interviews and a technical environment review.
What is the gap analysis?
Gap analysis is a comparison of your current documentation against compliance requirements and security best practice to identify exactly what is missing.
How is drafting done?
Drafting is clear, practical, business-specific writing with no copy-paste templates; every document is tailored to your organisation and signed off by you.
How does the review work?
Review is where your team reads the drafts and AMEA refines them until the documentation is accurate, actionable and fits the way your business works.
What does implementation involve?
Implementation is the rollout: AMEA helps you publish policies, train staff and establish review schedules so documentation stays current.
Which standards are the policies aligned to?
All documentation is aligned to POPIA, ISO 27001, the CIS Controls and NIST guidance where relevant, so it holds up in audits and customer due diligence.
Start with the free POPIA compliance guide, which covers what every policy set has to say about personal information.
POPIA
Protection of Personal Information Act
ISO 27001
Information Security Management
NIST CSF
Cybersecurity Framework
CIS Controls
Center for Internet Security
PAIA
Promotion of Access to Information
GDPR
EU Data Protection (where applicable)
Which IT policy covers what, and who requires it?
Six documents cover most of what a South African business is asked for by regulators, auditors, insurers and enterprise customers.
| Document | What it covers | Who requires it |
|---|---|---|
| Disaster Recovery Plan | Restoring systems after a major outage: priorities, RTO and RPO, runbooks | Auditors, insurers, enterprise customers, boards |
| Incident Response Plan | Detecting, containing and reporting a security incident | POPIA (breach notification), cyber insurers, ISO 27001 |
| IT Policy Framework | Acceptable use, data handling, access, passwords, BYOD, procurement | ISO 27001, customer due diligence, HR |
| POPIA Compliance Framework | PAIA manual, processing register, consent, breach protocol, supplier agreements | Information Regulator, every organisation under POPIA |
| AI Acceptable Use Policy | Approved AI tools, permitted data, review and disclosure rules | Boards, clients, professional bodies, cyber insurers |
| Password and Access Policy | Credential standards, MFA, privileged access, joiner and leaver process | Cyber insurers, CIS Controls, ISO 27001 |
IT policy & documentation questions
Most South African businesses need seven core documents at a minimum. An acceptable use policy, a password and access control policy, a data classification and handling standard, an incident response plan, a disaster recovery plan, a POPIA compliance framework including a PAIA/POPIA manual, and, if staff use AI tools, an AI acceptable use policy. AMEA writes all of these as business-specific documents rather than generic templates.
A disaster recovery plan (DRP) describes how to restore IT systems after a major outage, with recovery priorities, recovery time and recovery point objectives and step-by-step restoration runbooks. An incident response plan (IRP) describes how to detect, contain and report a security incident such as a breach or ransomware attack, including POPIA notification timelines. Most businesses need both, and they reference each other.
Yes. POPIA requires responsible parties to take reasonable, documented measures to secure personal information, to appoint an Information Officer, to maintain a PAIA manual, and to be able to demonstrate compliance to the Information Regulator. Written policies, a data processing register and a breach notification protocol are how that compliance is evidenced.
A typical engagement runs four to eight weeks: discovery interviews and an environment review in week one, a gap analysis against POPIA and security best practice, drafting, one or two review rounds with your team, and then rollout with staff training and a review schedule.
Not sure what you're missing?
We'll run a free policy gap analysis to identify exactly what documentation your organisation needs to be compliant and protected.
