Glossary
What is policy attestation?
Policy attestation is an employee’s recorded confirmation that they have read, understood and agree to follow a specific version of an organisational policy, such as an acceptable use or information security policy.
- Also known as
- Policy acknowledgement, policy sign-off
- Who attests
- Employees, contractors and new joiners
- Typical goal
- A dated record of who accepted which policy version
- Related term
- Security awareness training
How it works
Publish, acknowledge,
chase, record.
- 01
Publish
A policy version is shared with the people who must follow it.
- 02
Acknowledge
Each person reads it and confirms acceptance, sometimes after a short check of understanding.
- 03
Chase
Reminders go to people who haven’t responded, with escalation to managers if needed.
- 04
Record
Every attestation is stored with the person, version and date, and repeats when the policy changes.
What makes it useful
A signature is as good
as its record.
An email with an attachment and a spreadsheet of replies rarely holds up well. Useful attestation ties each person to a specific version and date.
A strong attestation record
- Person, policy and version for each entry
- Date and time of acknowledgement
- Reminder and escalation history
- Re-attestation when a policy changes
- Easy export for auditors
General good practice.
Questions buyers ask
Frequently asked questions.
What is the difference between attestation and acknowledgement?
The terms are often used interchangeably. Both mean an employee confirming they have read and accept a policy; attestation sometimes implies a more formal, recorded declaration.
How often should employees attest to policies?
Commonly at joining, when a policy changes, and at a regular interval such as annually. Your own governance and audit requirements set the rhythm.
Is policy attestation the same as data protection consent?
No. Policy attestation records that employees accept internal policies. Consent from customers or other data subjects is a separate process with its own requirements.
Let’s connect the dots
See the human risk.
Change what happens next.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo