Skip to content

Policies

How a policy gets written, approved, published, confirmed and kept current in Certaria, and which page covers each part.

Audience: ISMS Admin.

Where: SharePoint holds the files. The Certaria app holds the records. Your people only ever see SharePoint, and need no licence to do so.

Policies are the part of an ISMS your whole organisation meets. ISO 27001:2022 A.5.1 asks that they are approved, communicated, acknowledged and reviewed, and Clause 7.5 asks that you can show which version is in force and when it was approved. Certaria does the paperwork around all of that. It never decides for you.

A policy moves through four stages, and each has a page of its own.

StageWhat you doPage
AdoptDecide whether a control applies to you, then copy a template and personalise itThe policy templates
PublishCheck the record Certaria created and set it to ApprovedPublish a policy
ReviseChange a document that is already in force, without withdrawing itRevise a policy
ReviewConfirm each year that it still stands, whether or not it changesThe annual review cycle

Four things worth knowing before you start

Section titled “Four things worth knowing before you start”

Approval is yours and only yours. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to your organisation by accident.

Nothing publishes from the staging folder. Certaria will not publish a document whose file is still in Pending Applicability, because that folder holds unpersonalised templates and publishing one would put a blank document in front of everybody.

A document being revised stays in force. Setting it back to Draft or Under Review does not take it off the site. Only Superseded or Archived does that, because until a new approved version replaces it, the last approved version is still the one that applies.

Review and acknowledgement are two separate clocks. Reviewing a document does not by itself ask anyone to confirm it again. People are asked when the version changes, or when their own confirmation passes its expiry, whichever comes first. So a yearly review that changes nothing does not create work for your whole organisation.

They read policies from the Published Policies list on your SharePoint site and confirm them there. They never open the Certaria app and need no Power Platform licence.

Each person can see what they have already confirmed under What I have confirmed, which shows their own entries and nobody else’s. Published Policies is a list of what applies to everyone, not a personal to-do list.