Only if you write a bad policy, so don't do that.

The better way is that for each policy you look at what do you actually want to do and how you want to do it, and then write that down as the policy. Now the policy makes sense because it's how you wanted to do it anyway.

I've set up policies and processes from the ground up for SOC2 audits in startups, that's how I do it.