Documentation

Governance & evidence

Policy versioning and staff acknowledgment

Regenerating a generated policy used to overwrite it outright, so there was no way to show what a policy actually said on the day someone was asked to follow it. Every version is now kept, and any policy can be marked as requiring staff acknowledgment of the current version specifically.

Transcript

Regenerating a policy used to overwrite it. Every version is now kept, so you can prove exactly what a policy said on the day an employee signed off on it, not just what it says today.

That distinction matters under ISO 27001 A.6.3: awareness training and policy sign-off are only meaningful if you can show which version someone actually read.

Any policy can be marked as requiring sign-off. Once it is, staff need to actively confirm they have read the current version before it counts as acknowledged.

The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately rather than discovered at audit time.

Regenerate the policy after a real change, and a new version is created rather than the old one being erased. Anyone who already acknowledged the previous version is automatically asked to review the new one.

Why this is required

ISO 27001 A.6.3 covers information security awareness, education and training. That control is only meaningful if it is possible to show which version of a policy a given person actually read and confirmed, not just that a policy exists somewhere.

A policy that silently changed after someone signed off on it is a real gap: if the version they acknowledged is gone, there is nothing to compare against when something goes wrong.

What EuroCompliant does

Every time a policy document is generated, a new version is recorded rather than the previous one being erased, together with who generated it and when.

Any policy can be marked as requiring sign-off. Once marked, staff are asked to actively confirm they have read the current version; that confirmation is recorded against the specific version, not the policy in general.

The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately. Regenerating the policy after a real change creates a new version and reopens acknowledgment for anyone who already signed off on the old one.

Walking through it

1

Generate or regenerate a policy

Each generation is kept as its own version rather than overwriting the last one.

Open /compliance-docs →
2

Require staff acknowledgment

Mark the policy as requiring sign-off, then request acknowledgment from your team.

Open /policies →
3

Check the acknowledgment matrix

See who has confirmed the current version and remind anyone still pending.

Open /policies →

The law

Frequently asked

Does regenerating a policy lose the old version?

No. The previous version is kept in full, alongside who published it and when, so you can always show what a policy said on any given date.

What happens to existing acknowledgments when a policy is regenerated?

They stay attached to the version they were given against. Anyone who acknowledged the previous version is asked to review and acknowledge the new one separately.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial