Glossary

What is policy attestation?

Policy attestation is an employee’s recorded confirmation that they have read, understood and agree to follow a specific version of an organisational policy, such as an acceptable use or information security policy.

Also known as
Policy acknowledgement, policy sign-off
Who attests
Employees, contractors and new joiners
Typical goal
A dated record of who accepted which policy version
Related term
Security awareness training

How it works

Publish, acknowledge,
chase, record.

  1. 01

    Publish

    A policy version is shared with the people who must follow it.

  2. 02

    Acknowledge

    Each person reads it and confirms acceptance, sometimes after a short check of understanding.

  3. 03

    Chase

    Reminders go to people who haven’t responded, with escalation to managers if needed.

  4. 04

    Record

    Every attestation is stored with the person, version and date, and repeats when the policy changes.

What makes it useful

A signature is as good
as its record.

An email with an attachment and a spreadsheet of replies rarely holds up well. Useful attestation ties each person to a specific version and date.

CHECKLIST

A strong attestation record

  • Person, policy and version for each entry
  • Date and time of acknowledgement
  • Reminder and escalation history
  • Re-attestation when a policy changes
  • Easy export for auditors

General good practice.

Questions buyers ask

Frequently asked questions.

What is the difference between attestation and acknowledgement?

The terms are often used interchangeably. Both mean an employee confirming they have read and accept a policy; attestation sometimes implies a more formal, recorded declaration.

How often should employees attest to policies?

Commonly at joining, when a policy changes, and at a regular interval such as annually. Your own governance and audit requirements set the rhythm.

Is policy attestation the same as data protection consent?

No. Policy attestation records that employees accept internal policies. Consent from customers or other data subjects is a separate process with its own requirements.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo