TechRam For Operations and HR

How do you prove your staff have read a policy?

Policy acknowledgement needs three things an email can't provide: one current version of the document, a per-person record of who opened which version and when, and an export an auditor can read without your help. Attachments prove a policy was sent, which is a different claim.

Scattered shapes settling into one solid block, like loose acknowledgements becoming a single complete record

What an auditor actually asks for

Not “do you have a policy”. They will ask for the current version of one named policy, the list of people it applies to, and evidence that each of them acknowledged that version.

The third one is where it comes apart. Most organisations can produce the policy and the staff list within minutes, and then spend a week reconstructing the acknowledgements from sent items.

Why email can’t answer it

An email attachment proves the policy was sent. It doesn’t prove it was opened, it doesn’t tie the recipient to a version, and it creates a second copy of the document that will still be in somebody’s inbox after the policy is superseded.

Three specific failures, in the order they usually bite:

Version drift. The policy is updated. The old attachment is still sitting in two hundred inboxes, and it’s indistinguishable from the new one.

No per-person record. A distribution list proves a group was addressed. Nobody can tell you whether a specific person opened it.

Starters and movers. Somebody who joined last month wasn’t on the distribution list. Nobody notices until they’re the person who needed to know.

The three things a working system has

One current version, with an owner and a review date. Not the most recent attachment — one document, in one place, that’s authoritative by definition. Everything else is a link to it.

An acknowledgement record per person, per version. Who, which version, what date and time. When the policy is revised, the previous acknowledgements remain true about the previous version rather than being silently invalidated.

An export nobody needs to explain. The evidence has to be readable by somebody outside the organisation, on demand, without your quality manager building a spreadsheet from three sources.

What this looks like built

A SharePoint list as the register, the policy library as the single source, a flow that assigns an acknowledgement task on publication and on the start date of anyone who joins afterwards, and a report that shows outstanding acknowledgements by team.

None of that’s new software. It’s the licences you already hold, arranged so the record is written as the work happens rather than assembled at audit. That arrangement is what Custom Operational Apps means in practice.

Where to start

The Policy Acknowledgement Centre does the narrow version: publish a policy, track who has read it, export the evidence. Ask for it on the page and we’ll send the package and the setup notes.

If your problem is that the policies themselves exist in three versions across four locations, that’s the structural problem underneath, and it’s the Intranet & Knowledge Layer rather than a register.

The tool this article is about Policy Acknowledgement Centre Publish a policy, track who has read it, and export the evidence at audit time. Request access →

The service behind this: Custom Operational Apps →

Common questions

01. What does an auditor actually ask for?

Not whether you have a policy. The current version of one named policy, the list of people it applies to, and evidence that each of them acknowledged that version. The third one is where it comes apart.

02. Why is an email attachment not evidence?

It proves the policy was sent. It doesn't prove it was opened, it does not tie the recipient to a version, and it leaves a second copy of the document in somebody's inbox after the policy is superseded.

03. What happens to old acknowledgements when a policy is revised?

In a working system the record is per person and per version, so the previous acknowledgements stay true about the previous version rather than being silently invalidated.

04. Does this need new software?

No. A SharePoint list as the register, the policy library as the single source, a flow that assigns the acknowledgement task on publication and on the start date of anyone who joins afterwards, and a report showing what is outstanding by team.

Rami Younes

Co-founder — Director of Engagement & Strategy

LinkedIn

Run the Policy Acknowledgement Centre on your own tenant first.

It deploys into the Microsoft 365 tenant you already pay for, on the licences you already hold, and nothing leaves your environment.

Request access →