New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Governance & evidence

Policy versioning and staff acknowledgment

Every generated policy keeps its full version history: each regeneration records a new version rather than replacing the previous one, so you can show exactly what a policy said on the day someone was asked to follow it. Any policy can be marked as requiring staff acknowledgment of the current version specifically. You can also author your own corporate governance policies directly in the platform. They get the same versioning and staff sign-off as generated ones.

Transcript

Every regenerated policy keeps its full version history, so you can prove exactly what a policy said on the day an employee signed off on it, not just what it says today.

That distinction matters under ISO 27001 A.6.3: awareness training and policy sign-off are only meaningful if you can show which version someone actually read.

Any policy can be marked as requiring sign-off. Once it is, staff need to actively confirm they have read the current version before it counts as acknowledged.

You can also author your own corporate governance policies here. The New Policy button takes a title, a category, a short summary, and your policy text, and the result joins the same list, version history and acknowledgment matrix as generated policies.

A policy doesn't have to go to the whole company. When you require acknowledgment, you can target it at specific departments or groups: engineering-only standards stay engineering-only. Staff outside the audience never see the policy in My Compliance and are never emailed a request, and the acknowledgment matrix reflects exactly who was actually asked.

The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately rather than discovered at audit time.

Regenerate the policy after a real change, and a new version is created rather than the old one being erased. Anyone who already acknowledged the previous version is automatically asked to review the new one.

Why this is required

ISO 27001 A.6.3 covers information security awareness, education and training. That control is only meaningful if it is possible to show which version of a policy a given person actually read and confirmed, not just that a policy exists somewhere.

A policy that silently changed after someone signed off on it is a real gap: if the version they acknowledged is gone, there is nothing to compare against when something goes wrong.

Not every policy you need is one the platform can generate for you. An HR handbook, a remote-working rule, a bespoke engineering standard: authoring these in the same place that tracks versioning and sign-off keeps every policy you ask staff to follow in one auditable register instead of a documents folder.

What EuroCompliant does

Every time a policy document is generated, a new version is recorded rather than the previous one being erased, together with who generated it and when.

Any policy can be marked as requiring sign-off. Once marked, staff are asked to actively confirm they have read the current version; that confirmation is recorded against the specific version, not the policy in general.

The acknowledgment matrix shows exactly who has signed off on the current version and who has not, per policy, so a gap is visible immediately. Regenerating the policy after a real change creates a new version and reopens acknowledgment for anyone who already signed off on the old one.

Custom policies are authored with the + New Policy button: a title, a category (information security, data privacy, HR, engineering, operations), a short summary, and the full policy text. Saving the text creates version 1; editing the content later pushes a new version with the previous one kept in history, and toggling attestation hooks the policy into the same staff acknowledgment matrix and My Compliance page.

Acknowledgment requests can be targeted instead of company-wide. On any policy that requires sign-off you can pick specific departments and/or groups as the audience: only those members are emailed a request, see it in My Compliance, and appear in the matrix. Useful when a policy genuinely only applies to one team (an engineering standard, an HR handbook) and you want the sign-off evidence scoped to exactly the people it applies to.

Walking through it

1

Generate or regenerate a policy

Each generation is kept as its own version rather than overwriting the last one.

Open /compliance-docs →
2

Author a custom policy

Use + New Policy to write your own corporate governance document, with a category and your policy text. It appears in the same list as generated policies.

Open /compliance-docs →
3

Require staff acknowledgment

Mark the policy as requiring sign-off, then request acknowledgment from your team.

Open /compliance-docs →
4

Check the acknowledgment matrix

See who has confirmed the current version and remind anyone still pending.

Open /compliance-docs →
5

Target the policy at a department or group

When requiring acknowledgment, choose the departments or groups that actually need to read it. Staff outside the audience never see it and are never asked to sign.

Open /compliance-docs →

The law

Frequently asked

Does regenerating a policy lose the old version?

No. The previous version is kept in full, alongside who published it and when, so you can always show what a policy said on any given date.

Can I write my own policies, or only use the generated ones?

Both. The platform generates the documents it can (risk reports, technical documentation, records of processing), and the + New Policy button lets you author your own corporate governance documents. Custom policies get the same version history, staff acknowledgment and audit matrix as generated ones.

What happens to existing acknowledgments when a policy is regenerated?

They stay attached to the version they were given against. Anyone who acknowledged the previous version is asked to review and acknowledge the new one separately.

Do staff need an emailed link to acknowledge a policy?

No, that is one option. Any logged-in team member can also review and acknowledge pending policies directly from their own My Compliance page. Both routes record the same acknowledgment, just tagged with how it was given.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial