Skip to content

Publish a policy

The five step procedure for publishing a new or revised controlled document, and how acknowledgement and re-acknowledgement follow from it.

Purpose: the standard procedure for publishing a new or revised ISMS controlled document (Policy, Procedure, Plan, Guide) so that the acknowledgement loop, the audit register and the notifications all work correctly.

Audience: ISMS Admin.

Where: SharePoint holds the files. The Certaria app holds the records.

Why this matters: ISO 27001:2022 A.5.1 and Clause 7.5 require controlled documents to be identifiable, available where needed, and traceable through their lifecycle. This procedure ensures every published document carries the metadata Certaria needs to run the acknowledgement cycle without silent drift.


  • Publishing a brand new policy, procedure, plan or guide.
  • Re-issuing an existing document at a new version (any change material enough to bump the version number).
  • Migrating an existing document into the Certaria register for the first time.

Approval is yours and only yours. Certaria will fill in the paperwork, but nothing reaches your people until you set a document to Approved. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to the organisation by accident.


Read this once and the five steps below will make sense as a whole.

You do four things. You copy a template out of Pending Applicability into the library root, you personalise the copy, you check the record Certaria created for it, and you set the status to Approved. Everything else is Certaria’s work.

Certaria does the rest. Within an hour of a file arriving in the library root, Register Policy Drafts creates a Draft record for it. The moment you approve, Stamp Policy Approval writes the Approved Date, moves the Next Review Date forward, records who approved it, and publishes straight away: the document reaches the Published Policies list within seconds, with its link corrected. The hourly Publish Policies to Site run stays as a safety net and announces newly published policies once in Teams.

Your people never touch the model-driven app. They read the document from the Published Policies list and acknowledge it there, needing no Power Platform licence. Sync Policy Acknowledgements writes what they did into the register within the hour, and Notify Policy Acknowledgement reminds anyone still outstanding, once a day.

Re-acknowledgement is not a separate process. Bumping the version is the whole of it. A person owes an acknowledgement whenever the document is Approved and they have no acknowledgement row against the current version that has not expired, so a new version reopens the obligation for everybody at once, and the yearly cycle falls out of the same rule.

%%{init: {"theme":"base","themeVariables":{
  "fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
  "background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
  "primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
  "secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
  "textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
  "clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
  "edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
  "labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
  subgraph SP["SharePoint: your ISMS site"]
    direction TB
    T["Pending Applicability<br/><i>blank templates</i>"]
    ROOT["Policy library root<br/><i>your live policies</i>"]
    PUB["Published Policies<br/><i>no licence needed</i>"]
    ACK["What I have confirmed<br/><i>only your own</i>"]
  end

  subgraph MDA["Model-driven app: ISMS Admin only"]
    direction TB
    DRAFT["Document record<br/><b>Draft</b>"]
    APPROVED["Document record<br/><b>Approved</b>"]
    REGISTER["Acknowledgement register<br/><i>the audit trail</i>"]
  end

  T -->|"YOU: copy, personalise"| ROOT
  ROOT -.->|"Register Policy Drafts"| DRAFT
  DRAFT -->|"YOU: set Approved"| APPROVED
  APPROVED -.->|"published in seconds"| PUB
  PUB -->|"STAFF: read, confirm"| ACK
  ACK -.->|"Sync Acknowledgements"| REGISTER

  classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
  classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
  class T,ROOT,DRAFT,APPROVED you
  class PUB,ACK,REGISTER auto

Solid arrows are things a person does. Dotted arrows are Certaria, with the flow name and how often it runs.

The only gate is at publication. A document can be Approved and still reach nobody, because Certaria will not publish a file that is still sitting in Pending Applicability. Step 3 explains why, and where to find the list of anything caught by it.

That picture covers a document’s first trip out to your people. What happens afterwards has a page each: Revise a policy when it needs changing, and The annual review cycle when it comes up for review.


Step 1. Save the document to the policy library

Section titled “Step 1. Save the document to the policy library”
  1. Save the final document to the root of your policy library, normally <SiteUrl>/ISMS Policies/.
  2. The Pending Applicability folder inside that library is a staging area for templates you have not yet adopted. A file there is not a policy. The root holds your live policies.
  3. If you are adopting one of Certaria’s 34 templates, copy it to the library root first, and personalise the copy.

Step 2. Check the document record (Certaria creates it for you)

Section titled “Step 2. Check the document record (Certaria creates it for you)”

Within an hour, Certaria: Register Policy Drafts notices the new file and creates a Draft record in the document register, filling in:

  • Title: taken from the matching Certaria template where it recognises the file, otherwise from the file name.
  • Category: taken from the template. Templates, Registers and Reports are excluded from acknowledgement scope.
  • Storage Location: the document’s URL, filled in automatically.
  • Version: set to 1.0 as a starting point.

Open the Certaria model driven app, go to Documents (Governance, then Documentation), and check the record. Correct the title and version if they are not what you want. You are reviewing, not typing.

Do not want to wait for the hourly run, or the file is one Certaria did not recognise? You can still create the record by hand with + New. The procedure below is identical from Step 3 onwards.

Step 3. Check the file is out of Pending Applicability

Section titled “Step 3. Check the file is out of Pending Applicability”

This is the gate, and Certaria enforces it. It is not advice you can skip.

Certaria publishes a document only when it can find the file in the root of your policy library. If the file is still in Pending Applicability, the document is treated as approved but not published: it does not appear to your people, and it is listed under approvedButNotPublished on the run report of Certaria: Publish Policies to Site.

This is deliberate, and it is there to protect you. Pending Applicability holds Certaria’s unpersonalised templates. Publishing one would put a document in front of your whole organisation with the placeholders still in it, and would collect acknowledgements against it. An acknowledgement is evidence that a named person read a specific version of a specific document, so a blank document with acknowledgements attached is worse at audit than no acknowledgements at all.

If a document is sitting in that list, the fix is always the same: copy the file to the library root and personalise the copy.

Set Status to Approved and save.

Certaria immediately fills in three fields for you:

  • Approved Date, set to today. This is what your auditor asks for when they ask “approved when”, and it is what the review cycle counts from.
  • Next Review Date, set twelve months out from today. This moves forward every time you approve, so a document you review a second time gets a fresh year rather than staying overdue. To change the interval for every document, set the Document Review Months setting.
  • Approver, matched from the account that set the status to Approved.

Then, within seconds:

  • The policy appears in the Published Policies list on your SharePoint site, where your people read and acknowledge it. They need no Power Platform licence to do so.
  • Its Storage Location is corrected to the live document, so every link your people follow resolves to the file you actually published.
  • Anyone who has not acknowledged it starts appearing in the daily reminder.

Then, at the next hourly run, every active person receives one Microsoft Teams message telling them what is newly published, listing everything approved since the last run rather than one message per policy.

Withdrawing a policy is deliberate and separate. Set the status to Superseded or Archived and it is removed from the Published Policies list at the next run. Setting it back to Draft or Under Review does not withdraw it, because a document being revised is still the version in force. A file leaving the library root does withdraw it. Move it back to Pending Applicability and Certaria stops showing it to your people, because it can no longer prove what they would be reading.

  1. Open the Published Policies list on your SharePoint site and confirm the document is there with the right title and version.
  2. Follow the Read the document link and confirm it opens the document you actually published, not a template.
  3. Confirm Approved Date is set on the document record.
  4. Confirm you received the Teams message yourself. If nobody received one, see the failure table below.

Through SharePoint. They open the Published Policies list, read the document, and use the Confirm I have read and understood link beside it. This is the core route and every customer has it. Acknowledgements are written to the register within the hour.

The link opens a short form with one field: the policy they are confirming. That field is required, so the form cannot be submitted without it. Ask your people to pick the policy whose row they clicked from, because the form has no way of knowing which one they came from.

Where they see what they have already confirmed. The site navigation carries What I have confirmed, which opens their own acknowledgement history: the policy, the version, and the date. Each person sees only their own entries, and nobody else’s.

Through the AI Agent, if you have bought that add-on. Staff can say “acknowledge a policy” to the Certaria agent in Teams instead. The two routes record the same thing, and an acknowledgement made either way stops the reminders.

If you do not have the agent add-on, SharePoint is the route, and it is complete on its own.


SymptomCauseFix
The document record never appearedThe file is in Pending Applicability rather than the library root, or fewer than 60 minutes have passedCopy the file to the root and wait for the next run, or create the record by hand
The link opens a template with placeholders still in itThe document was approved while its file was still in Pending Applicability, before Certaria enforced the gateCopy the file to the library root, personalise the copy, and let the next run correct the link
Nobody received a Teams message at allThe people register is empty, or the person has no email address recorded against their identity, so there is nobody to messageImport your people during onboarding and confirm each active person has an email address
The policy is approved but is not in Published PoliciesThe file is still in Pending Applicability, or the category is an excluded type (Template, Register, Report)Check approvedButNotPublished on the last run of Certaria: Publish Policies to Site. If the document is listed there, move the personalised file to the library root
A document I set back to Under Review is still visible to staffThis is deliberate. The approved version stays in force until a new approved version replaces itTo withdraw it, set the status to Superseded or Archived
Approving a document a second time did nothing at allCertaria was unable to record a second approval on the same document before 3 August 2026Set the status away from Approved and back again. If the dates still do not move, confirm Certaria: Stamp Policy Approval is switched on
The same document keeps appearing in the Monday review emailIts Next Review Date is in the past and nothing has re-approved itSet the status to Under Review and back to Approved. That is the record of review, and it moves the date on
A new version was published, but people who acknowledged the old version are not promptedThe version field was not bumped, or person rows are missing the user linkConfirm the version changed, then check the person links
Somebody confirmed a policy but it is not in the registerTheir confirmation could not be matched to a policy, or to a person. It is counted and named under unresolved on the run report, never skipped in silenceCheck unresolved on the last run of Certaria: Sync Policy Acknowledgements. If the person is new, confirm they are in the people register with an email address
An acknowledgement was deleted from the register by mistakeDeleting the record does not delete the person’s confirmation on the SharePoint siteNothing to do. The next run notices the record is missing and writes it again from the confirmation, which is still there
A template in Pending Applicability is no longer cleanIt was opened and edited where it sat, and Word AutoSave overwrote it. This happens silently and without warningCopy the edited file to the root to keep your work, then restore the earlier version from Version history on the original
Duplicate document records for the same fileThe file was renamed after its record was createdDelete the surplus Draft record. Certaria matches on the file name, so copying or moving a file between folders is safe; renaming it is not

  • ISO 27001:2022 A.5.1: policies communicated to and acknowledged by relevant personnel.
  • ISO 27001:2022 Clause 7.5: documented information: identification, distribution, version control.
  • Certaria: Stamp Policy Approval: on approval. Sets Approved Date, moves Next Review Date forward, records the Approver, and publishes straight away.
  • Certaria: Register Policy Drafts: hourly. Creates the Draft document record from a file in the policy library root.
  • Certaria: Publish Policies to Site: hourly. The safety net behind immediate publication. Publishes documents whose file is in the library root, corrects their Storage Location, removes superseded and archived ones, announces newly published policies in Teams, and reports anything approved but not publishable.
  • ISMS Policy Review Date Alert: Monday mornings. Emails the ISMS administrator every document due for review within 30 days.
  • Document Review Months: how far ahead the Next Review Date is set on approval. Defaults to 12.
  • Certaria: Sync Policy Acknowledgements: hourly. Writes SharePoint acknowledgements into the register.
  • Certaria: Notify Policy Acknowledgement: daily. Reminds people who still have documents outstanding.
  • isms-site-access-model.md: who can see and do what on the ISMS site.