Governance & evidence
Policy versioning and staff acknowledgment
Regenerating a generated policy used to overwrite it outright, so there was no way to show what a policy actually said on the day someone was asked to follow it. Every version is now kept, and any policy can be marked as requiring staff acknowledgment of the current version specifically.
Transcript
Regenerating a policy used to overwrite it. Every version is now kept, so you can prove exactly what a policy said on the day an employee signed off on it, not just what it says today.
That distinction matters under ISO 27001 A.6.3: awareness training and policy sign-off are only meaningful if you can show which version someone actually read.
Any policy can be marked as requiring sign-off. Once it is, staff need to actively confirm they have read the current version before it counts as acknowledged.
The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately rather than discovered at audit time.
Regenerate the policy after a real change, and a new version is created rather than the old one being erased. Anyone who already acknowledged the previous version is automatically asked to review the new one.
Why this is required
ISO 27001 A.6.3 covers information security awareness, education and training. That control is only meaningful if it is possible to show which version of a policy a given person actually read and confirmed, not just that a policy exists somewhere.
A policy that silently changed after someone signed off on it is a real gap: if the version they acknowledged is gone, there is nothing to compare against when something goes wrong.
What EuroCompliant does
Every time a policy document is generated, a new version is recorded rather than the previous one being erased, together with who generated it and when.
Any policy can be marked as requiring sign-off. Once marked, staff are asked to actively confirm they have read the current version; that confirmation is recorded against the specific version, not the policy in general.
The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately. Regenerating the policy after a real change creates a new version and reopens acknowledgment for anyone who already signed off on the old one.
Walking through it
Generate or regenerate a policy
Each generation is kept as its own version rather than overwriting the last one.
Open /compliance-docs →Require staff acknowledgment
Mark the policy as requiring sign-off, then request acknowledgment from your team.
Open /policies →Check the acknowledgment matrix
See who has confirmed the current version and remind anyone still pending.
Open /policies →The law
Frequently asked
Does regenerating a policy lose the old version?
No. The previous version is kept in full, alongside who published it and when, so you can always show what a policy said on any given date.
What happens to existing acknowledgments when a policy is regenerated?
They stay attached to the version they were given against. Anyone who acknowledged the previous version is asked to review and acknowledge the new one separately.
Related guides
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial