ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Security Policy Acknowledgement Register

Security Policy Acknowledgement Register

1. Purpose

The Security Policy Acknowledgement Register provides a structured method for recording whether personnel have received, reviewed, understood, and acknowledged applicable information-security policies.

The register helps demonstrate that security policies are not merely published but are:

  • Communicated to relevant personnel
  • Made available in an accessible form
  • Acknowledged where required
  • Tracked
  • Re-acknowledged after significant changes where appropriate
  • Followed up when acknowledgement is overdue
  • Supported by security awareness activities

Core Principle

Publish → Communicate → Review → Acknowledge → Track → Remind → Reassess → Evidence


2. When to Use

Use this register for:

  • Employees
  • Contractors
  • Interns
  • Temporary personnel
  • Consultants
  • Relevant third-party personnel
  • Privileged users
  • Personnel with access to sensitive information
  • Personnel subject to specific customer or contractual requirements

Use it for policies where acknowledgement is required by the organization’s security, HR, contractual, legal, or compliance process.

Not every policy necessarily requires individual acknowledgement. The organization should define which policies require acknowledgement based on risk and applicability.


3. Policy Acknowledgement Register

Record IDPersonEmployee/Contractor IDDepartmentPolicyVersionPublished DateAcknowledged DateDue DateStatusEvidence

Status Options

☐ Not Assigned
☐ Assigned
☐ Pending
☐ Acknowledged
☐ Overdue
☐ Declined
☐ Exempted
☐ Superseded
☐ Re-acknowledgement Required


4. Personnel Information

Record ID: ______________________________

Name: __________________________________

Employee / Contractor ID: _______________

Employment Type:

☐ Employee
☐ Contractor
☐ Consultant
☐ Intern
☐ Temporary Worker
☐ Third Party
☐ Other: __________________

Department: _____________________________

Job Title: _______________________________

Manager: ________________________________

Location: ________________________________

Start Date: ______________________________

End Date: _______________________________


5. Policy Information

Policy Name: _____________________________

Policy ID: _______________________________

Policy Version: __________________________

Policy Owner: ____________________________

Approval Date: ___________________________

Effective Date: ___________________________

Publication Date: ________________________

Review Date: _____________________________

Policy Category

☐ Information Security
☐ Acceptable Use
☐ Access Control
☐ Password/Authentication
☐ Data Protection
☐ Privacy
☐ Remote Access
☐ Cloud Security
☐ Incident Management
☐ Business Continuity
☐ Supplier Security
☐ AI Security
☐ Physical Security
☐ Other: __________________


6. Applicability

Determine why the person is required to acknowledge the policy.

☐ Applies to all personnel
☐ Applies to specific department
☐ Applies to specific role
☐ Applies to privileged users
☐ Applies to system administrators
☐ Applies to personnel handling sensitive information
☐ Applies to contractors
☐ Applies to third parties
☐ Customer requirement
☐ Contractual requirement
☐ Regulatory requirement
☐ Other: __________________

Applicability Rationale


7. Acknowledgement Requirement

Acknowledgement Required?

☐ Yes
☐ No

Reason: __________________________________

Acknowledgement Frequency:

☐ Once
☐ On joining
☐ Annually
☐ After material policy change
☐ Role change
☐ Other: __________________


8. Policy Distribution

Record how the policy was made available.

☐ ISMS portal
☐ Employee portal
☐ Document management system
☐ Email
☐ Security awareness platform
☐ HR platform
☐ Training platform
☐ Other: __________________

Policy Location: __________________________

Distribution Date: ________________________


9. Policy Review

Personnel should have an opportunity to review the applicable policy before acknowledgement.

Policy Provided: ☐ Yes ☐ No

Access Confirmed: ☐ Yes ☐ No

Review Completed: ☐ Yes ☐ No

Review Date: ______________________________


10. Acknowledgement Statement

The organization may use a statement such as:

I confirm that I have received access to the applicable information-security policy, have had an opportunity to review it, understand that I am responsible for complying with the requirements applicable to my role, and understand where to obtain clarification or assistance.

Acknowledgement Method

☐ Electronic acknowledgement
☐ Written acknowledgement
☐ Training-platform acknowledgement
☐ HR-system acknowledgement
☐ Email confirmation
☐ Other approved method


11. Acknowledgement Record

Person: __________________________________

Policy: __________________________________

Policy Version: ___________________________

Acknowledged: ☐ Yes ☐ No

Acknowledgement Date: ____________________

Acknowledgement Method: ___________________

Evidence Reference: _______________________

Recorded By/System: _______________________


12. Electronic Acknowledgement

Where electronic acknowledgement is used, retain sufficient evidence to demonstrate:

☐ Identity of person
☐ Policy acknowledged
☐ Policy version
☐ Date/time
☐ Acknowledgement status
☐ Relevant system/platform
☐ Record integrity

Electronic Evidence Reference


13. Training-Linked Acknowledgement

Where acknowledgement forms part of security awareness training:

Training Name: ____________________________

Training Version: _________________________

Training Date: ____________________________

Completion Status: ________________________

Assessment Score: _________________________

Policy Acknowledged: ☐ Yes ☐ No

Evidence Reference: _______________________


14. New Joiner Acknowledgement

New personnel should complete applicable policy acknowledgement as part of onboarding.

☐ Information-security policy provided
☐ Acceptable-use policy provided
☐ Access policy provided
☐ Data-protection requirements provided
☐ Incident-reporting requirements provided
☐ Confidentiality requirements provided
☐ Relevant role-specific policies provided
☐ Security awareness completed
☐ Required acknowledgements completed
☐ Evidence recorded

Onboarding Completion

Joiner: _________________________________

Manager: ________________________________

Completion Date: ________________________


15. Role Change

When a person changes roles, reassess policy applicability.

☐ Existing policies remain applicable
☐ New policies assigned
☐ Previous policies no longer applicable
☐ Additional acknowledgement required
☐ Privileged-access policies assigned
☐ Sensitive-information requirements assigned

Role Change Date


Review Completed By



16. Policy Change

When a policy is materially changed:

Previous Version: ________________________

New Version: _____________________________

Change Date: _____________________________

Change Description: ______________________

Re-Acknowledgement Required?

☐ Yes
☐ No

Reason


17. Material Policy Changes

Examples of changes that may require re-acknowledgement:

  • New security responsibilities
  • New access requirements
  • New authentication requirements
  • New data-handling requirements
  • Significant acceptable-use changes
  • New incident-reporting requirements
  • New AI-security requirements
  • Significant privacy requirements
  • New customer obligations
  • Major changes to employee responsibilities

The organization should define what constitutes a material change.


18. Annual Re-Acknowledgement

Where annual acknowledgement is required:

Review Year: ______________________________

Policy Version: ___________________________

Acknowledgement Due Date: _________________

Completion Date: __________________________

Status: ___________________________________

Annual Review Result

☐ Acknowledged
☐ Pending
☐ Overdue
☐ Reassigned
☐ Exempted


19. Overdue Acknowledgements

Track overdue records.

PersonPolicyVersionDue DateDays OverdueManagerFollow-UpStatus

Escalation

☐ Reminder issued
☐ Manager notified
☐ Security team notified
☐ HR notified where appropriate
☐ Access restriction considered
☐ Management escalation required

Actions should be proportionate to the policy and organizational process.


20. Declined Acknowledgement

If a person declines to acknowledge a policy:

Person: _________________________________

Policy: _________________________________

Date: __________________________________

Reason Provided: ________________________

Manager Notified: ☐ Yes ☐ No

Security Review: ☐ Yes ☐ No

HR Review: ☐ Yes ☐ No

Risk Assessment Required: ☐ Yes ☐ No

Action Taken

A refusal to acknowledge should not automatically be treated as acceptance of non-compliance. The organization should follow its defined personnel, security, and escalation processes.


21. Exemption

Where acknowledgement is genuinely not applicable:

Person: _________________________________

Policy: _________________________________

Exemption Reason: _______________________

Approved By: ____________________________

Approval Date: __________________________

Expiry Date: ____________________________

Evidence: _______________________________


22. Third-Party Acknowledgement

Where relevant, third-party personnel may be required to acknowledge applicable requirements.

Organization: ____________________________

Person: __________________________________

Contract: ________________________________

Applicable Requirement: ___________________

Acknowledgement Required: ☐ Yes ☐ No

Acknowledgement Date: ____________________

Evidence: ________________________________


23. Privileged User Acknowledgement

Personnel with privileged access may require additional acknowledgement.

☐ Privileged access responsibilities
☐ Administrator security requirements
☐ MFA requirements
☐ Credential protection
☐ Logging and monitoring
☐ Change-management requirements
☐ Emergency-access requirements
☐ Incident-reporting requirements
☐ Acceptable-use requirements

Privileged User

Name: ___________________________________

Role: ____________________________________

System: __________________________________

Acknowledgement Date: ____________________


24. Sensitive Information Acknowledgement

Personnel handling sensitive information may require acknowledgement of specific requirements.

☐ Confidential information
☐ Restricted information
☐ Customer information
☐ Personal data
☐ Financial information
☐ Source code
☐ Security information
☐ Credentials/secrets
☐ Other: __________________

Additional Requirements


25. Policy Communication Evidence

Evidence may include:

☐ Email distribution
☐ Portal publication
☐ Training completion
☐ Electronic acknowledgement
☐ Meeting record
☐ Security awareness platform record
☐ HR system record
☐ Policy access log
☐ Other: __________________


26. Policy Understanding

Acknowledgement does not necessarily prove that personnel understand every policy requirement.

Where appropriate, supplement acknowledgement with:

☐ Security awareness training
☐ Knowledge assessment
☐ Role-based training
☐ Security briefing
☐ Practical exercise
☐ Manager communication
☐ Policy FAQ
☐ Other: __________________

Understanding Assessment


27. Policy Compliance

Acknowledgement should not be treated as proof that a person actually follows the policy.

Where appropriate, verify actual compliance through:

  • Access reviews
  • Security monitoring
  • Internal audits
  • Control testing
  • Policy compliance reviews
  • Incident investigations
  • Security assessments
  • Management reviews

Compliance Verification


28. Acknowledgement Dashboard

MetricCurrentPreviousTargetStatus
Applicable Personnel
Policies Requiring Acknowledgement
Acknowledged
Pending
Overdue
Exempted
Declined
Re-Acknowledgement Required

29. Policy Coverage

Track whether required policies have been assigned to the appropriate population.

PolicyApplicable PopulationAssignedAcknowledgedOverdueCoverage %

Coverage Target

Target: __________________ %


30. Policy Acknowledgement by Department

DepartmentApplicable PersonnelAcknowledgedPendingOverdueCoverage

31. Policy Acknowledgement by Role

RoleApplicable PersonnelAcknowledgedPendingOverdueCoverage

32. Evidence Integrity

Acknowledgement records should be protected against:

☐ Unauthorized modification
☐ Unauthorized deletion
☐ Loss
☐ Incorrect version association
☐ Duplicate records
☐ Identity mismatch

Where appropriate, retain system-generated timestamps and audit trails.


33. Record Retention

Define the retention period according to the organization’s records-retention requirements.

Retention Period: _________________________

Record Owner: ____________________________

Storage Location: _________________________

Deletion/Disposal Requirement: ____________


34. Privacy Considerations

The register may contain personnel information.

Apply appropriate controls for:

  • Access
  • Confidentiality
  • Retention
  • Data minimization
  • Accuracy
  • Secure disposal

Do not collect unnecessary personal information merely for policy acknowledgement tracking.


35. Exceptions

Where acknowledgement cannot be completed within the required timeframe:

☐ Exception raised
☐ Reason documented
☐ Risk assessed where required
☐ Temporary action defined
☐ Owner assigned
☐ Expiry date defined
☐ Approval obtained

Exception Reference



36. Findings

Identify problems with policy acknowledgement.

Finding IDPolicyAreaFindingRiskActionOwnerDue DateStatus

Examples:

  • High number of overdue acknowledgements
  • Incorrect policy version assigned
  • Personnel missing required policy
  • Evidence unavailable
  • Departed employees still active
  • Third-party acknowledgement not tracked
  • Re-acknowledgement not completed after material change

37. Corrective Action

For significant gaps:

Action IDFindingRoot CauseCorrective ActionOwnerDue DateEvidenceStatus

Corrective action should address the underlying reason for repeated acknowledgement failures rather than simply sending another reminder.


38. Management Reporting

Report relevant metrics to management where appropriate.

Examples:

  • Overall acknowledgement percentage
  • Overdue acknowledgements
  • High-risk populations with overdue policies
  • Material policy changes awaiting acknowledgement
  • Repeated acknowledgement failures
  • Department-level compliance
  • Third-party acknowledgement status

Management Summary


39. Review Frequency

Review the register:

☐ Monthly
☐ Quarterly
☐ Semi-annually
☐ Annually
☐ After material policy changes
☐ After significant organizational changes

The frequency should be based on organizational risk and policy requirements.


40. Roles and Responsibilities

RoleResponsibility
Policy OwnerMaintains policy and identifies applicable population
Information SecurityDefines security acknowledgement requirements
HRSupports personnel onboarding and personnel records where applicable
ManagerEnsures applicable personnel complete requirements
PersonnelReviews and acknowledges applicable policies
System AdministratorMaintains acknowledgement platform where applicable
ComplianceMonitors completion and evidence
Internal AuditIndependently tests the process where applicable
ManagementReviews significant compliance gaps

41. AWS SaaS Startup Example

A SaaS startup has 35 employees and operates its production environment on AWS.

The following policies require acknowledgement:

  • Information Security Policy
  • Acceptable Use Policy
  • Access Control Policy
  • Incident Management Policy
  • Data Protection Policy
  • Remote Working Policy
  • AI Security Policy

Example Register

PersonPolicyVersionAssignedAcknowledgedStatus
Employee AInformation Security Policy2.101-Jan02-JanAcknowledged
Employee AAcceptable Use Policy3.001-Jan02-JanAcknowledged
Employee BInformation Security Policy2.101-JanPending
Employee BAI Security Policy1.001-JanOverdue

Process

Policy Approved → Published → Assigned → Personnel Reviews → Acknowledgement → Evidence Recorded → Dashboard → Reminder → Escalation → Re-Acknowledgement After Material Change


42. Startup-Friendly Model

A startup can keep the process simple.

New Joiner

Day 1–7

  • Information Security Policy
  • Acceptable Use
  • Confidentiality requirements
  • Access/security responsibilities
  • Relevant role-specific policies

Annual

Review and re-acknowledge policies where required.

Material Change

Re-acknowledge affected policies.

Role Change

Review policy applicability and assign additional policies where necessary.

High-Risk Roles

Provide additional role-specific security training and acknowledgement.


43. Common Mistakes

Avoid:

  • Treating acknowledgement as proof of compliance
  • Assigning every policy to every person
  • Failing to track policy versions
  • Keeping only a generic acknowledgement without identifying the policy version
  • Failing to re-acknowledge material policy changes
  • Ignoring contractors and relevant third parties
  • Allowing large numbers of overdue records
  • Failing to follow up with managers
  • Collecting unnecessary personal information
  • Keeping acknowledgement records without appropriate access controls
  • Deleting evidence before the required retention period
  • Using acknowledgement instead of security awareness training
  • Assuming an acknowledgement means personnel understood every requirement

44. Relationship With Other ISMS Documents

DocumentRelationship
Information Security PolicyDefines overarching security requirements
Security Awareness ProgramBuilds security knowledge
Security Training RegisterRecords training completion
Policy Compliance Review ChecklistVerifies policies are actually followed
Policy Management ProcedureControls policy creation and review
Access Control PolicyDefines access responsibilities
Acceptable Use PolicyDefines acceptable technology use
Incident Management PolicyDefines incident responsibilities
HR Onboarding ChecklistSupports new-joiner acknowledgement
Employee Offboarding ChecklistHandles departing personnel
Internal Audit ChecklistTests policy and evidence effectiveness
Information Security Compliance MonitoringMonitors ongoing compliance
Security Findings RegisterRecords identified gaps
Corrective Action TrackerTracks remediation

45. ISO/IEC 27001 Connection

Policy acknowledgement supports the organization’s ability to demonstrate that applicable information-security policies and requirements have been communicated to relevant personnel.

However, a policy acknowledgement register is not itself a universally prescribed ISO/IEC 27001 form.

The organization should determine:

  • Which policies require acknowledgement
  • Which personnel are in scope
  • When acknowledgement is required
  • Whether annual re-acknowledgement is necessary
  • Which changes trigger re-acknowledgement
  • What evidence must be retained
  • How overdue acknowledgements are handled

Acknowledgement should also be distinguished from security awareness, competence, and actual compliance. A signed or electronic acknowledgement demonstrates that a person received/reviewed the applicable requirement; it does not by itself demonstrate that the requirement is understood or consistently followed.


46. Audit Evidence Checklist

For sampled personnel and policies, the organization should be able to demonstrate:

☐ Applicable policy identified
☐ Correct policy version
☐ Policy approved
☐ Policy published
☐ Person identified
☐ Applicability established
☐ Policy distributed
☐ Acknowledgement completed
☐ Date/time recorded
☐ Evidence retained
☐ Overdue records followed up
☐ Material changes reassessed
☐ Re-acknowledgement completed where required
☐ Exceptions documented
☐ Actual policy compliance tested separately where appropriate


47. Final Audit Trail

For every applicable policy, the organization should be able to demonstrate:

Which policy applies?
Which version was provided?
Who was required to acknowledge it?
Why was it applicable to them?
When was it provided?
Did the person acknowledge it?
When did they acknowledge it?
What evidence supports the acknowledgement?
What happens if acknowledgement is overdue?
What happens when the policy changes?
How is actual compliance verified?

Final Principle

Policy acknowledgement is evidence of communication and receipt—not proof of compliance. An effective ISMS connects policy publication, awareness, acknowledgement, actual implementation, compliance monitoring, and continual improvement into one controlled process.