Policy compliance software publishes a policy, gets it in front of the people it binds, records that each of them accepted a specific version, and produces that evidence on demand. Writing policies is the part organisations do; the part they fail is proving three years later that a named employee had accepted the current version on the date something went wrong. A folder of PDFs cannot do that, and neither can an email announcing a new policy.
What policy compliance software must handle
- Version control with effective dates, so the question "which version applied in March" has an answer.
- Audience rules by role, location or entity, rather than sending every policy to everyone.
- Attestation capture per person per version, with a timestamp.
- Review cycles with an owner, so policies are re-approved rather than silently ageing.
- Reminders and escalation for outstanding attestations.
- Translations where the workforce needs them, tied to the same version.
- Reporting: who has not attested, by manager, so chasing is somebody's specific job.
Publication is not the same as acceptance
Regulators and tribunals ask two things about a policy: was it communicated, and was it applied. Communication means a record that the person received and acknowledged it, not that it existed on an intranet they had access to. Application is harder still — a policy attested by everyone and contradicted by normal practice is worse than no policy, because it evidences that the organisation knew the standard and did not meet it.
Re-attest on material change only, not on every typo. Organisations that re-issue everything annually teach people to click through without reading, which destroys the value of the attestation they are collecting.
Doing it before you buy a platform
- List every policy with its owner, approval date and next review date.
- Define the audience for each one, and stop sending policies to people they do not bind.
- Version each document explicitly, with an effective date on the face of it.
- Record attestations in a register: person, policy, version, date.
- Chase outstanding attestations through managers rather than through a group email.
- Diary reviews and treat a missed review as a finding, not as housekeeping.
Ettex Records covers the register: policies with owner, version, effective and review dates, plus an attestation row per person and version. Filtering by missing attestations gives the chase list, and filtering by review date shows which documents are about to go stale — the two reports anyone assessing policy compliance software will want to see first.
Frequently asked
How long should policy attestations be kept?
At least as long as the limitation period for the claims the policy is meant to defend against, which in employment matters often means several years after the person leaves.
Does an intranet posting count as communication?
Usually not on its own. Evidence of communication means an acknowledgement from the individual, tied to a version and a date, rather than proof that the document was available somewhere.
How often should policies be reviewed?
Annually for high-risk areas, every two to three years otherwise, plus immediately on a relevant legal or organisational change. The review matters more than the frequency — an unchanged policy re-approved deliberately is fine.