Policy Evidence Readiness Check

Could you prove who acknowledged which policy version and when? Take the 2-minute assessment.

The readiness check

8 questions · about 2 minutes

Eight questions about how your acknowledgement records actually work, and a score out of 100 with the gaps your answers point to.

Your score appears on screen as soon as you finish. No email address, no signup, and your answers are not stored.

What is policy acknowledgement evidence?

Policy acknowledgement evidence is a record showing which recipient acknowledged a policy, which policy version the acknowledgement related to, and when the acknowledgement occurred.

The distinction that matters in practice is not whether the acknowledgement happened, which it usually did, but whether you can show it afterwards, for a named person and a specific version, without reconstructing it from memory or from several files. That is what this check measures.

What should policy acknowledgement evidence contain?

Eight fields cover most of what a request asks for:

FieldWhy it matters
RecipientIdentifies who acknowledged
PolicyIdentifies what was acknowledged
Policy versionShows which version applied
Distribution dateShows when the policy was issued
Due dateSupports follow-up
Acknowledgement dateShows when acknowledgement occurred
StatusShows acknowledged, pending or overdue
Historical recordPreserves evidence when policies change

Why evidence becomes difficult to retrieve

Records are rarely lost deliberately. They become hard to retrieve through ordinary operational drift:

  • Acknowledgement replies sit in individual inboxes, so the record is only as durable as one mailbox.
  • Spreadsheets are kept without consistent versioning, and two copies drift apart.
  • A revised policy file replaces the old one, and the version people acknowledged no longer exists.
  • Employees leave, and their account, mailbox and records go with them.
  • Reminders are sent by hand, so completion depends on who had time.
  • New joiners arrive between rollout cycles and are not picked up by the closed cycle.
  • Historical records live in a different place from current ones, so a request spans both.

None of these is a rule violation in itself. They are the reasons an acknowledgement that genuinely happened can be hard to demonstrate two years later.

Can Excel be used to track policy acknowledgements?

Yes. For a smaller number of recipients and policies, a spreadsheet is a perfectly reasonable record.

It becomes harder to maintain as recipient counts increase, more policies are distributed, policies are revised, acknowledgement cycles repeat, reminders become frequent, and historical evidence starts being requested, because each of those steps stays manual.

If a spreadsheet is where you are, start from a structured one: download the free Policy Acknowledgement Tracker for recipients, policy versions, due dates and calculated status, with no signup.

Policy acknowledgement evidence and audits

What you need to be able to show depends on the framework in scope, your contractual commitments, your own internal controls and the scope of the particular review. Organisations may need to demonstrate that relevant policies were communicated, applied or understood, and those are three different requirements, satisfied by different evidence.

It is worth separating three things that often get merged: a legal or contractual requirement to obtain a signature, which is specific to the document and the jurisdiction; a framework requirement, which is usually written in terms of an outcome such as personnel awareness rather than a named mechanism; and common governance practice, which is where explicit acknowledgement mostly comes from. Different auditors ask for different depth within the same framework.

For the framework detail, see ISO 27001 acknowledgement requirements and SOC 2 policy acknowledgement requirements. For what a defensible record looks like in practice, proving policy acknowledgement to auditors goes step by step.

What the check asks

Eight questions about how your acknowledgement records work in practice. Each one is answerable from memory by whoever owns the process, which is what keeps it to two minutes. The strongest answer is shown after each question, as an indication of what a well structured process looks like.

  1. Can you identify exactly which version of a policy each employee or recipient acknowledged?

    Strongest answer: Yes, immediately

    If that is not you: Create a new acknowledgement record whenever a policy version changes, and never overwrite the historical record. The version belongs in the record itself, not in the file name of the document.

  2. Can you immediately see who has not yet acknowledged a policy?

    Strongest answer: Yes, in one place

    If that is not you: Maintain one central view of acknowledged, pending and overdue recipients, so the outstanding list is a filter rather than a reconciliation job.

  3. Could you retrieve acknowledgement evidence for an employee who left 12 months ago?

    Strongest answer: Yes, immediately

    If that is not you: Retain acknowledgement date, policy name, policy version and recipient identity together, in a record that outlives the individual's account.

  4. What happens when a policy version changes?

    Strongest answer: A new acknowledgement record is created for the new version

    If that is not you: Treat each version as its own acknowledgement cycle. Add records for the new version rather than editing the ones already there.

  5. How are new employees or recipients handled between policy rollout cycles?

    Strongest answer: They are automatically or consistently added to the relevant process

    If that is not you: Define how new joiners are added to policies already in force, and who owns that step. Onboarding is usually the natural place for it.

  6. How are overdue acknowledgements followed up?

    Strongest answer: Automatically

    If that is not you: Use a consistent reminder schedule and a defined escalation point, so follow-up does not rely on someone noticing.

  7. If someone asked for acknowledgement evidence for five random employees, how long would it take you to produce it?

    Strongest answer: Under 5 minutes

    If that is not you: Store records so evidence for any recipient can be retrieved directly, without searching through old email threads or rebuilding it from several files.

  8. Do you maintain a consistent historical record of policy acknowledgements?

    Strongest answer: Yes, including policy version and acknowledgement date

    If that is not you: Keep one authoritative record of acknowledgements. Other systems can hold copies, but one place should be the one you would produce.

Take the check to get these scored, with findings drawn from your own answers.

How the check is scored

8 questions, each worth up to 12.5 points, for a maximum of 100. The strongest answer scores 12.5, the second 8, the third 4 and the weakest 0. Findings come only from questions you did not answer with the strongest option.

  • 80–100 · Strong evidence readiness
  • 60–79 · Generally structured, with evidence gaps
  • 40–59 · Significant manual dependency
  • 0–39 · Evidence is difficult to verify

The score describes how retrievable your records are. It is not an audit outcome and does not establish whether your organisation meets any framework.

Frequently asked questions

Policy acknowledgement evidence is a record showing which recipient acknowledged a policy, which policy version the acknowledgement related to, and when the acknowledgement occurred. It is the difference between believing a policy was communicated and being able to show it.

In common practice: the recipient, the policy, the policy version, the distribution date, the due date, the acknowledgement date, the current status, and a reference to any supporting evidence. The version and the acknowledgement date are the fields most often missing and the ones most often asked about later.

Record the version in the acknowledgement record itself, and create a new record when a new version is issued rather than editing the existing one. If the old record is overwritten, it now says the person acknowledged a version that did not exist at the time they acknowledged it.

They can form part of a record, and many organisations rely on them. The practical limits are retrieval and durability: replies are spread across individual mailboxes, they usually do not state which version was attached, and they leave with the employee. A read receipt is weaker still, because it reports delivery rather than agreement.

Yes. For a smaller number of recipients and policies a spreadsheet is a perfectly reasonable record. It gets harder to maintain as recipient counts grow, policies are revised, acknowledgement cycles repeat, reminders become frequent and historical evidence starts being requested, because each of those steps stays manual.

There is no single answer. Retention depends on legal, contractual, regulatory and internal policy requirements, and on the kind of policy involved. Set a retention period deliberately against those inputs rather than keeping records for as long as the tool happens to keep them.

It depends on the policy and the jurisdiction. Some documents carry a specific signing or notification requirement in employment law or sector regulation; many internal policies do not. Acknowledgement is widely used as governance practice because it shows a policy was communicated and received, which is a separate question from whether a signature is legally required.

When the manual work around the record starts costing more than the record saves. In practice that means frequent policy revisions, many recipients across several teams or locations, recurring acknowledgement cycles, people joining throughout the year, and evidence requests you cannot answer quickly.

When the record has to be retrievable

Policy Confirm distributes policies, collects acknowledgements against a specific version, follows up the people who have not responded, and exports the record as PDF or CSV.

Get started
Try with up to 10 recipientsNo credit card
Get started in secondsMagic link access
Choose between EU or US hosting
See how it works