Ask an AI assistant to write an Acceptable Use Policy, and it will produce something plausible-looking in seconds: don't share your password, don't click suspicious links, use company devices responsibly. It will also produce almost exactly the same document for a bakery, a bank, and a defence supplier.
That is the problem. Defence Cyber Certification (DCC) governance controls are not looking for a plausible-looking policy; they are looking for evidence that your organisation actually thought about its own risks and wrote the answer down.
Under Objective A (Managing Security Risk), Control 1100 requires documented governance policies to be in place. Using AI to help draft that documentation is entirely permitted; plenty of well-run organisations now start policy drafts this way.
What is not permitted is stopping there. A generic template, AI-generated or otherwise, that has not been actively shaped around how your organisation actually works will not satisfy an assessor, because it does not demonstrate that governance is real rather than decorative.
The distinction matters more than it might sound. An assessor is not grading your prose. They are trying to answer a specific question: if this policy were tested tomorrow by an incident, an audit, or an employee genuinely unsure what to do, would it hold up? A template answers that question with silence.
For HR professionals and compliance writers, the Acceptable Use Policy (AUP) is usually the document that gets the most attention and the one most likely to fall short if it is drafted generically. DCC expects an AUP to enforce restrictions across both the digital and the physical environment, which is a wider brief than most standard templates attempt:
A generic AUP template will typically nod at the first of these and miss the rest completely, simply because they are specific to how defence-adjacent organisations actually operate.
Even a well-tailored policy is only half the evidence an assessor wants. The other half is proof that the policy is a living part of the organisation, not a document written once and filed away. In practice, that means being able to show:
None of this is exotic. It is the same discipline any well-run HR or compliance function should already be applying to its policy library. The difference DCC introduces is that this discipline now needs to be demonstrable, on request, to an external assessor.
For HR teams and compliance writers preparing governance documentation, the highest-value use of time is not agonising over wording, AI tools are genuinely useful for getting a solid first draft down quickly.
The value is in the next step: sitting with someone who actually understands how the organisation works, walking through each policy line by line, and asking "is this actually true for us?" That is the step a generic template, however well-written, cannot do on its own.
If your organisation is reviewing its governance documentation ahead of a DCC submission, speak to Periculo. We help compliance and HR teams turn policy drafts into documentation that stands up to assessment, with the revision history and sign-off evidence to back it up.