1. Purpose
The Security Policy Acknowledgement Register provides a structured method for recording whether personnel have received, reviewed, understood, and acknowledged applicable information-security policies.
The register helps demonstrate that security policies are not merely published but are:
- Communicated to relevant personnel
- Made available in an accessible form
- Acknowledged where required
- Tracked
- Re-acknowledged after significant changes where appropriate
- Followed up when acknowledgement is overdue
- Supported by security awareness activities
Core Principle
Publish → Communicate → Review → Acknowledge → Track → Remind → Reassess → Evidence
2. When to Use
Use this register for:
- Employees
- Contractors
- Interns
- Temporary personnel
- Consultants
- Relevant third-party personnel
- Privileged users
- Personnel with access to sensitive information
- Personnel subject to specific customer or contractual requirements
Use it for policies where acknowledgement is required by the organization’s security, HR, contractual, legal, or compliance process.
Not every policy necessarily requires individual acknowledgement. The organization should define which policies require acknowledgement based on risk and applicability.
3. Policy Acknowledgement Register
| Record ID | Person | Employee/Contractor ID | Department | Policy | Version | Published Date | Acknowledged Date | Due Date | Status | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|
Status Options
☐ Not Assigned
☐ Assigned
☐ Pending
☐ Acknowledged
☐ Overdue
☐ Declined
☐ Exempted
☐ Superseded
☐ Re-acknowledgement Required
4. Personnel Information
Record ID: ______________________________
Name: __________________________________
Employee / Contractor ID: _______________
Employment Type:
☐ Employee
☐ Contractor
☐ Consultant
☐ Intern
☐ Temporary Worker
☐ Third Party
☐ Other: __________________
Department: _____________________________
Job Title: _______________________________
Manager: ________________________________
Location: ________________________________
Start Date: ______________________________
End Date: _______________________________
5. Policy Information
Policy Name: _____________________________
Policy ID: _______________________________
Policy Version: __________________________
Policy Owner: ____________________________
Approval Date: ___________________________
Effective Date: ___________________________
Publication Date: ________________________
Review Date: _____________________________
Policy Category
☐ Information Security
☐ Acceptable Use
☐ Access Control
☐ Password/Authentication
☐ Data Protection
☐ Privacy
☐ Remote Access
☐ Cloud Security
☐ Incident Management
☐ Business Continuity
☐ Supplier Security
☐ AI Security
☐ Physical Security
☐ Other: __________________
6. Applicability
Determine why the person is required to acknowledge the policy.
☐ Applies to all personnel
☐ Applies to specific department
☐ Applies to specific role
☐ Applies to privileged users
☐ Applies to system administrators
☐ Applies to personnel handling sensitive information
☐ Applies to contractors
☐ Applies to third parties
☐ Customer requirement
☐ Contractual requirement
☐ Regulatory requirement
☐ Other: __________________
Applicability Rationale
7. Acknowledgement Requirement
Acknowledgement Required?
☐ Yes
☐ No
Reason: __________________________________
Acknowledgement Frequency:
☐ Once
☐ On joining
☐ Annually
☐ After material policy change
☐ Role change
☐ Other: __________________
8. Policy Distribution
Record how the policy was made available.
☐ ISMS portal
☐ Employee portal
☐ Document management system
☐ Email
☐ Security awareness platform
☐ HR platform
☐ Training platform
☐ Other: __________________
Policy Location: __________________________
Distribution Date: ________________________
9. Policy Review
Personnel should have an opportunity to review the applicable policy before acknowledgement.
Policy Provided: ☐ Yes ☐ No
Access Confirmed: ☐ Yes ☐ No
Review Completed: ☐ Yes ☐ No
Review Date: ______________________________
10. Acknowledgement Statement
The organization may use a statement such as:
I confirm that I have received access to the applicable information-security policy, have had an opportunity to review it, understand that I am responsible for complying with the requirements applicable to my role, and understand where to obtain clarification or assistance.
Acknowledgement Method
☐ Electronic acknowledgement
☐ Written acknowledgement
☐ Training-platform acknowledgement
☐ HR-system acknowledgement
☐ Email confirmation
☐ Other approved method
11. Acknowledgement Record
Person: __________________________________
Policy: __________________________________
Policy Version: ___________________________
Acknowledged: ☐ Yes ☐ No
Acknowledgement Date: ____________________
Acknowledgement Method: ___________________
Evidence Reference: _______________________
Recorded By/System: _______________________
12. Electronic Acknowledgement
Where electronic acknowledgement is used, retain sufficient evidence to demonstrate:
☐ Identity of person
☐ Policy acknowledged
☐ Policy version
☐ Date/time
☐ Acknowledgement status
☐ Relevant system/platform
☐ Record integrity
Electronic Evidence Reference
13. Training-Linked Acknowledgement
Where acknowledgement forms part of security awareness training:
Training Name: ____________________________
Training Version: _________________________
Training Date: ____________________________
Completion Status: ________________________
Assessment Score: _________________________
Policy Acknowledged: ☐ Yes ☐ No
Evidence Reference: _______________________
14. New Joiner Acknowledgement
New personnel should complete applicable policy acknowledgement as part of onboarding.
☐ Information-security policy provided
☐ Acceptable-use policy provided
☐ Access policy provided
☐ Data-protection requirements provided
☐ Incident-reporting requirements provided
☐ Confidentiality requirements provided
☐ Relevant role-specific policies provided
☐ Security awareness completed
☐ Required acknowledgements completed
☐ Evidence recorded
Onboarding Completion
Joiner: _________________________________
Manager: ________________________________
Completion Date: ________________________
15. Role Change
When a person changes roles, reassess policy applicability.
☐ Existing policies remain applicable
☐ New policies assigned
☐ Previous policies no longer applicable
☐ Additional acknowledgement required
☐ Privileged-access policies assigned
☐ Sensitive-information requirements assigned
Role Change Date
Review Completed By
16. Policy Change
When a policy is materially changed:
Previous Version: ________________________
New Version: _____________________________
Change Date: _____________________________
Change Description: ______________________
Re-Acknowledgement Required?
☐ Yes
☐ No
Reason
17. Material Policy Changes
Examples of changes that may require re-acknowledgement:
- New security responsibilities
- New access requirements
- New authentication requirements
- New data-handling requirements
- Significant acceptable-use changes
- New incident-reporting requirements
- New AI-security requirements
- Significant privacy requirements
- New customer obligations
- Major changes to employee responsibilities
The organization should define what constitutes a material change.
18. Annual Re-Acknowledgement
Where annual acknowledgement is required:
Review Year: ______________________________
Policy Version: ___________________________
Acknowledgement Due Date: _________________
Completion Date: __________________________
Status: ___________________________________
Annual Review Result
☐ Acknowledged
☐ Pending
☐ Overdue
☐ Reassigned
☐ Exempted
19. Overdue Acknowledgements
Track overdue records.
| Person | Policy | Version | Due Date | Days Overdue | Manager | Follow-Up | Status |
|---|---|---|---|---|---|---|---|
Escalation
☐ Reminder issued
☐ Manager notified
☐ Security team notified
☐ HR notified where appropriate
☐ Access restriction considered
☐ Management escalation required
Actions should be proportionate to the policy and organizational process.
20. Declined Acknowledgement
If a person declines to acknowledge a policy:
Person: _________________________________
Policy: _________________________________
Date: __________________________________
Reason Provided: ________________________
Manager Notified: ☐ Yes ☐ No
Security Review: ☐ Yes ☐ No
HR Review: ☐ Yes ☐ No
Risk Assessment Required: ☐ Yes ☐ No
Action Taken
A refusal to acknowledge should not automatically be treated as acceptance of non-compliance. The organization should follow its defined personnel, security, and escalation processes.
21. Exemption
Where acknowledgement is genuinely not applicable:
Person: _________________________________
Policy: _________________________________
Exemption Reason: _______________________
Approved By: ____________________________
Approval Date: __________________________
Expiry Date: ____________________________
Evidence: _______________________________
22. Third-Party Acknowledgement
Where relevant, third-party personnel may be required to acknowledge applicable requirements.
Organization: ____________________________
Person: __________________________________
Contract: ________________________________
Applicable Requirement: ___________________
Acknowledgement Required: ☐ Yes ☐ No
Acknowledgement Date: ____________________
Evidence: ________________________________
23. Privileged User Acknowledgement
Personnel with privileged access may require additional acknowledgement.
☐ Privileged access responsibilities
☐ Administrator security requirements
☐ MFA requirements
☐ Credential protection
☐ Logging and monitoring
☐ Change-management requirements
☐ Emergency-access requirements
☐ Incident-reporting requirements
☐ Acceptable-use requirements
Privileged User
Name: ___________________________________
Role: ____________________________________
System: __________________________________
Acknowledgement Date: ____________________
24. Sensitive Information Acknowledgement
Personnel handling sensitive information may require acknowledgement of specific requirements.
☐ Confidential information
☐ Restricted information
☐ Customer information
☐ Personal data
☐ Financial information
☐ Source code
☐ Security information
☐ Credentials/secrets
☐ Other: __________________
Additional Requirements
25. Policy Communication Evidence
Evidence may include:
☐ Email distribution
☐ Portal publication
☐ Training completion
☐ Electronic acknowledgement
☐ Meeting record
☐ Security awareness platform record
☐ HR system record
☐ Policy access log
☐ Other: __________________
26. Policy Understanding
Acknowledgement does not necessarily prove that personnel understand every policy requirement.
Where appropriate, supplement acknowledgement with:
☐ Security awareness training
☐ Knowledge assessment
☐ Role-based training
☐ Security briefing
☐ Practical exercise
☐ Manager communication
☐ Policy FAQ
☐ Other: __________________
Understanding Assessment
27. Policy Compliance
Acknowledgement should not be treated as proof that a person actually follows the policy.
Where appropriate, verify actual compliance through:
- Access reviews
- Security monitoring
- Internal audits
- Control testing
- Policy compliance reviews
- Incident investigations
- Security assessments
- Management reviews
Compliance Verification
28. Acknowledgement Dashboard
| Metric | Current | Previous | Target | Status |
|---|---|---|---|---|
| Applicable Personnel | ||||
| Policies Requiring Acknowledgement | ||||
| Acknowledged | ||||
| Pending | ||||
| Overdue | ||||
| Exempted | ||||
| Declined | ||||
| Re-Acknowledgement Required |
29. Policy Coverage
Track whether required policies have been assigned to the appropriate population.
| Policy | Applicable Population | Assigned | Acknowledged | Overdue | Coverage % |
|---|---|---|---|---|---|
Coverage Target
Target: __________________ %
30. Policy Acknowledgement by Department
| Department | Applicable Personnel | Acknowledged | Pending | Overdue | Coverage |
|---|---|---|---|---|---|
31. Policy Acknowledgement by Role
| Role | Applicable Personnel | Acknowledged | Pending | Overdue | Coverage |
|---|---|---|---|---|---|
32. Evidence Integrity
Acknowledgement records should be protected against:
☐ Unauthorized modification
☐ Unauthorized deletion
☐ Loss
☐ Incorrect version association
☐ Duplicate records
☐ Identity mismatch
Where appropriate, retain system-generated timestamps and audit trails.
33. Record Retention
Define the retention period according to the organization’s records-retention requirements.
Retention Period: _________________________
Record Owner: ____________________________
Storage Location: _________________________
Deletion/Disposal Requirement: ____________
34. Privacy Considerations
The register may contain personnel information.
Apply appropriate controls for:
- Access
- Confidentiality
- Retention
- Data minimization
- Accuracy
- Secure disposal
Do not collect unnecessary personal information merely for policy acknowledgement tracking.
35. Exceptions
Where acknowledgement cannot be completed within the required timeframe:
☐ Exception raised
☐ Reason documented
☐ Risk assessed where required
☐ Temporary action defined
☐ Owner assigned
☐ Expiry date defined
☐ Approval obtained
Exception Reference
36. Findings
Identify problems with policy acknowledgement.
| Finding ID | Policy | Area | Finding | Risk | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|---|---|
Examples:
- High number of overdue acknowledgements
- Incorrect policy version assigned
- Personnel missing required policy
- Evidence unavailable
- Departed employees still active
- Third-party acknowledgement not tracked
- Re-acknowledgement not completed after material change
37. Corrective Action
For significant gaps:
| Action ID | Finding | Root Cause | Corrective Action | Owner | Due Date | Evidence | Status |
|---|---|---|---|---|---|---|---|
Corrective action should address the underlying reason for repeated acknowledgement failures rather than simply sending another reminder.
38. Management Reporting
Report relevant metrics to management where appropriate.
Examples:
- Overall acknowledgement percentage
- Overdue acknowledgements
- High-risk populations with overdue policies
- Material policy changes awaiting acknowledgement
- Repeated acknowledgement failures
- Department-level compliance
- Third-party acknowledgement status
Management Summary
39. Review Frequency
Review the register:
☐ Monthly
☐ Quarterly
☐ Semi-annually
☐ Annually
☐ After material policy changes
☐ After significant organizational changes
The frequency should be based on organizational risk and policy requirements.
40. Roles and Responsibilities
| Role | Responsibility |
|---|---|
| Policy Owner | Maintains policy and identifies applicable population |
| Information Security | Defines security acknowledgement requirements |
| HR | Supports personnel onboarding and personnel records where applicable |
| Manager | Ensures applicable personnel complete requirements |
| Personnel | Reviews and acknowledges applicable policies |
| System Administrator | Maintains acknowledgement platform where applicable |
| Compliance | Monitors completion and evidence |
| Internal Audit | Independently tests the process where applicable |
| Management | Reviews significant compliance gaps |
41. AWS SaaS Startup Example
A SaaS startup has 35 employees and operates its production environment on AWS.
The following policies require acknowledgement:
- Information Security Policy
- Acceptable Use Policy
- Access Control Policy
- Incident Management Policy
- Data Protection Policy
- Remote Working Policy
- AI Security Policy
Example Register
| Person | Policy | Version | Assigned | Acknowledged | Status |
|---|---|---|---|---|---|
| Employee A | Information Security Policy | 2.1 | 01-Jan | 02-Jan | Acknowledged |
| Employee A | Acceptable Use Policy | 3.0 | 01-Jan | 02-Jan | Acknowledged |
| Employee B | Information Security Policy | 2.1 | 01-Jan | Pending | |
| Employee B | AI Security Policy | 1.0 | 01-Jan | Overdue |
Process
Policy Approved → Published → Assigned → Personnel Reviews → Acknowledgement → Evidence Recorded → Dashboard → Reminder → Escalation → Re-Acknowledgement After Material Change
42. Startup-Friendly Model
A startup can keep the process simple.
New Joiner
Day 1–7
- Information Security Policy
- Acceptable Use
- Confidentiality requirements
- Access/security responsibilities
- Relevant role-specific policies
Annual
Review and re-acknowledge policies where required.
Material Change
Re-acknowledge affected policies.
Role Change
Review policy applicability and assign additional policies where necessary.
High-Risk Roles
Provide additional role-specific security training and acknowledgement.
43. Common Mistakes
Avoid:
- Treating acknowledgement as proof of compliance
- Assigning every policy to every person
- Failing to track policy versions
- Keeping only a generic acknowledgement without identifying the policy version
- Failing to re-acknowledge material policy changes
- Ignoring contractors and relevant third parties
- Allowing large numbers of overdue records
- Failing to follow up with managers
- Collecting unnecessary personal information
- Keeping acknowledgement records without appropriate access controls
- Deleting evidence before the required retention period
- Using acknowledgement instead of security awareness training
- Assuming an acknowledgement means personnel understood every requirement
44. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Information Security Policy | Defines overarching security requirements |
| Security Awareness Program | Builds security knowledge |
| Security Training Register | Records training completion |
| Policy Compliance Review Checklist | Verifies policies are actually followed |
| Policy Management Procedure | Controls policy creation and review |
| Access Control Policy | Defines access responsibilities |
| Acceptable Use Policy | Defines acceptable technology use |
| Incident Management Policy | Defines incident responsibilities |
| HR Onboarding Checklist | Supports new-joiner acknowledgement |
| Employee Offboarding Checklist | Handles departing personnel |
| Internal Audit Checklist | Tests policy and evidence effectiveness |
| Information Security Compliance Monitoring | Monitors ongoing compliance |
| Security Findings Register | Records identified gaps |
| Corrective Action Tracker | Tracks remediation |
45. ISO/IEC 27001 Connection
Policy acknowledgement supports the organization’s ability to demonstrate that applicable information-security policies and requirements have been communicated to relevant personnel.
However, a policy acknowledgement register is not itself a universally prescribed ISO/IEC 27001 form.
The organization should determine:
- Which policies require acknowledgement
- Which personnel are in scope
- When acknowledgement is required
- Whether annual re-acknowledgement is necessary
- Which changes trigger re-acknowledgement
- What evidence must be retained
- How overdue acknowledgements are handled
Acknowledgement should also be distinguished from security awareness, competence, and actual compliance. A signed or electronic acknowledgement demonstrates that a person received/reviewed the applicable requirement; it does not by itself demonstrate that the requirement is understood or consistently followed.
46. Audit Evidence Checklist
For sampled personnel and policies, the organization should be able to demonstrate:
☐ Applicable policy identified
☐ Correct policy version
☐ Policy approved
☐ Policy published
☐ Person identified
☐ Applicability established
☐ Policy distributed
☐ Acknowledgement completed
☐ Date/time recorded
☐ Evidence retained
☐ Overdue records followed up
☐ Material changes reassessed
☐ Re-acknowledgement completed where required
☐ Exceptions documented
☐ Actual policy compliance tested separately where appropriate
47. Final Audit Trail
For every applicable policy, the organization should be able to demonstrate:
Which policy applies?
Which version was provided?
Who was required to acknowledge it?
Why was it applicable to them?
When was it provided?
Did the person acknowledge it?
When did they acknowledge it?
What evidence supports the acknowledgement?
What happens if acknowledgement is overdue?
What happens when the policy changes?
How is actual compliance verified?
Final Principle
Policy acknowledgement is evidence of communication and receipt—not proof of compliance. An effective ISMS connects policy publication, awareness, acknowledgement, actual implementation, compliance monitoring, and continual improvement into one controlled process.
