Governance & evidence
Policy versioning and staff acknowledgment
Every generated policy keeps its full version history: each regeneration records a new version rather than replacing the previous one, so you can show exactly what a policy said on the day someone was asked to follow it. Any policy can be marked as requiring staff acknowledgment of the current version specifically. You can also author your own corporate governance policies directly in the platform. They get the same versioning and staff sign-off as generated ones.
Transcript
Every regenerated policy keeps its full version history, so you can prove exactly what a policy said on the day an employee signed off on it, not just what it says today.
That distinction matters under ISO 27001 A.6.3: awareness training and policy sign-off are only meaningful if you can show which version someone actually read.
Any policy can be marked as requiring sign-off. Once it is, staff need to actively confirm they have read the current version before it counts as acknowledged.
You can also author your own corporate governance policies here. The New Policy button takes a title, a category, a short summary, and your policy text, and the result joins the same list, version history and acknowledgment matrix as generated policies.
A policy doesn't have to go to the whole company. When you require acknowledgment, you can target it at specific departments or groups: engineering-only standards stay engineering-only. Staff outside the audience never see the policy in My Compliance and are never emailed a request, and the acknowledgment matrix reflects exactly who was actually asked.
The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately rather than discovered at audit time.
Regenerate the policy after a real change, and a new version is created rather than the old one being erased. Anyone who already acknowledged the previous version is automatically asked to review the new one.
Why this is required
ISO 27001 A.6.3 covers information security awareness, education and training. That control is only meaningful if it is possible to show which version of a policy a given person actually read and confirmed, not just that a policy exists somewhere.
A policy that silently changed after someone signed off on it is a real gap: if the version they acknowledged is gone, there is nothing to compare against when something goes wrong.
Not every policy you need is one the platform can generate for you. An HR handbook, a remote-working rule, a bespoke engineering standard: authoring these in the same place that tracks versioning and sign-off keeps every policy you ask staff to follow in one auditable register instead of a documents folder.
What EuroCompliant does
Every time a policy document is generated, a new version is recorded rather than the previous one being erased, together with who generated it and when.
Any policy can be marked as requiring sign-off. Once marked, staff are asked to actively confirm they have read the current version; that confirmation is recorded against the specific version, not the policy in general.
The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately. Regenerating the policy after a real change creates a new version and reopens acknowledgment for anyone who already signed off on the old one.
Custom policies are authored with the + New Policy button: a title, a category (information security, data privacy, HR, engineering, operations), a short summary, and the full policy text. Saving the text creates version 1; editing the content later pushes a new version with the previous one kept in history, and toggling attestation hooks the policy into the same staff acknowledgment matrix and My Compliance page.
Acknowledgment requests can be targeted instead of company-wide. On any policy that requires sign-off you can pick specific departments and/or groups as the audience: only those members are emailed a request, see it in My Compliance, and appear in the matrix. Useful when a policy genuinely only applies to one team (an engineering standard, an HR handbook) and you want the sign-off evidence scoped to exactly the people it applies to.
Walking through it
Generate or regenerate a policy
Each generation is kept as its own version rather than overwriting the last one.
Open /compliance-docs →Author a custom policy
Use + New Policy to write your own corporate governance document, with a category and your policy text. It appears in the same list as generated policies.
Open /compliance-docs →Require staff acknowledgment
Mark the policy as requiring sign-off, then request acknowledgment from your team.
Open /compliance-docs →Check the acknowledgment matrix
See who has confirmed the current version and remind anyone still pending.
Open /compliance-docs →Target the policy at a department or group
When requiring acknowledgment, choose the departments or groups that actually need to read it. Staff outside the audience never see it and are never asked to sign.
Open /compliance-docs →The law
Information security awareness, education and training
Staff must receive appropriate awareness education and training, and updates, relevant to their job function.
Policies for information security
A set of policies for information security must be defined, approved by management, published and communicated to employees.
Frequently asked
Does regenerating a policy lose the old version?
No. The previous version is kept in full, alongside who published it and when, so you can always show what a policy said on any given date.
Can I write my own policies, or only use the generated ones?
Both. The platform generates the documents it can (risk reports, technical documentation, records of processing), and the + New Policy button lets you author your own corporate governance documents. Custom policies get the same version history, staff acknowledgment and audit matrix as generated ones.
What happens to existing acknowledgments when a policy is regenerated?
They stay attached to the version they were given against. Anyone who acknowledged the previous version is asked to review and acknowledge the new one separately.
Do staff need an emailed link to acknowledge a policy?
No, that is one option. Any logged-in team member can also review and acknowledge pending policies directly from their own My Compliance page. Both routes record the same acknowledgment, just tagged with how it was given.
Related guides
Team, roles and access control
Inviting your team, assigning roles, organising departments, and locking down accounts with 2FA and SSO.
Evidence vault & audit trail
Turning completed checklist items into artefacts a regulator can inspect, and the logging duties behind Articles 12 and 26.
ISO 27001: information security management
The international standard for an information security management system, and how EuroCompliant tracks your Annex A controls.
My Compliance: the employee self-service page
Where any team member, not just admins, signs off on required policies and completes their own AI literacy check.
Automated document generation and cryptographic signing
Generate regulator-ready documents from your own data, then download a signed PDF an auditor can verify independently.
Publishing a trust center
A public page, at your own address, answering the security questions a prospect would otherwise ask by email.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial