- Documentation
- Run your ISMS
- Document governance
Publish a document
The five step procedure for publishing a new or revised controlled document, and how acknowledgement and re-acknowledgement follow from it.
Purpose: the standard procedure for publishing a new or revised ISMS controlled document (Policy, Procedure, Plan, Guide) so that the acknowledgement loop, the audit register and the notifications all work correctly.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records.
Why this matters: ISO 27001:2022 A.5.1 and Clause 7.5 require controlled documents to be identifiable, available where needed, and traceable through their lifecycle. This procedure ensures every published document carries the metadata Certaria needs to run the acknowledgement cycle without silent drift.
When to follow this procedure
Section titled “When to follow this procedure”- Publishing a brand new policy, procedure, plan or guide.
- Re-issuing an existing document at a new version (any change material enough to bump the version number).
- Migrating an existing document into the Certaria register for the first time.
The one thing that has not changed
Section titled “The one thing that has not changed”Approval is yours and only yours. Certaria will fill in the paperwork, but nothing reaches your people until you set a document to Approved. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to the organisation by accident.
The lifecycle at a glance
Section titled “The lifecycle at a glance”Read this once and the five steps below will make sense as a whole.
You do three things. You adopt a template from the Certaria hub, you personalise the copy it places in Policy Masters, and you set the record to Approved. Everything else is Certaria’s work.
Certaria does the rest. Adopt Policy Template places the file and creates the Draft record
in one action, so there is nothing to wait for. If you add a file to Policy Masters by hand
instead, Register Policy Drafts creates the record within ten minutes. The moment you approve,
Stamp Policy Approval writes the Approved Date, moves the Next Review Date forward, records who
approved it, and publishes straight away: the document reaches the Published Documents list
within seconds, with its link corrected. The Publish Policies to Site sweep runs every
ten minutes: it stays as a safety net, freezes a PDF copy of each published document for your
people, and announces newly published documents once in Teams.
Your people never touch the model-driven app. Notify Policy Acknowledgement puts anything
they still owe on the Certaria card in Microsoft Teams, once a day. They open the document from
the card, read it on your ISMS site, and confirm back on the card. That reaches the register
straight away, and needs no Power Platform licence. Sync Acknowledgements then copies each
confirmation back to the site so they can see their own history.
You do not have to wait for the daily cycle. The page with the Publish now button also carries Notify now: it prepares the acknowledgement records for anything newly published and sends the Microsoft Teams cards immediately. Use it when a document should be in front of people today, a new starter’s first-day pack for example, or an urgent revision.
Every published document gets its own page. Within ten minutes of publication, Certaria
builds a reading page for the document on your ISMS site, under Site Pages in a documents
folder. The page carries the document’s title, reference, category, version, approval date and
owner; your staff summary if you have written one; the document itself, readable in place; and,
beneath it, that person’s own acknowledgement of this document, or a note
that none is recorded yet. Each reader sees only their own acknowledgement there, never anyone
else’s. Confirming is done on the Certaria card in Teams, which is what sent them to the page.
When you publish a new version, the page updates at the same address, so links keep
working.
What your people read on the page is a PDF. Certaria converts the approved Word document into a PDF and shows that on the page. The Word file stays in the library as your editing master for the next revision; the PDF is the frozen copy your people read, so nobody can wander into editing mode on a live policy. If conversion is ever unavailable, the page shows the Word document rather than breaking.
Re-acknowledgement is not a separate process. Bumping the version is the whole of it. A person owes an acknowledgement whenever the document is Approved and they have no acknowledgement row against the current version that has not expired, so a new version reopens the obligation for everybody at once, and the yearly cycle falls out of the same rule.
%%{init: {"theme":"base","themeVariables":{
"fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
"background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
"primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
"secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
"textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
"clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
"edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
"labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
subgraph SP["SharePoint: your ISMS site"]
direction TB
ROOT["Policy Masters<br/><i>your editable masters</i>"]
REPO["Document Repository<br/><i>approved PDFs</i>"]
PUB["Published Documents<br/><i>no licence needed</i>"]
ACK["My Acknowledgements<br/><i>only your own</i>"]
end
subgraph TEAMS["Microsoft Teams: everyone"]
direction TB
CARD["Certaria card<br/><i>no licence needed</i>"]
end
subgraph MDA["Model-driven app: ISMS Admin only"]
direction TB
TPL["Policy Templates<br/><i>38 supplied</i>"]
DRAFT["Document record<br/><b>Draft</b>"]
APPROVED["Document record<br/><b>Approved</b>"]
REGISTER["Acknowledgement register<br/><i>the audit trail</i>"]
end
TPL -->|"YOU: Adopt Policy Template"| ROOT
TPL -.->|"creates the record"| DRAFT
ROOT -.->|"Register Policy Drafts, if added by hand"| DRAFT
DRAFT -->|"YOU: personalise, set Approved"| APPROVED
APPROVED -.->|"published in seconds"| PUB
APPROVED -.->|"Publish Policies to Site, as PDF"| REPO
APPROVED -.->|"Notify Policy Acknowledgement, daily"| CARD
CARD -->|"STAFF: read"| REPO
CARD -->|"STAFF: confirm"| REGISTER
REGISTER -.->|"Sync Acknowledgements"| ACK
classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
class TPL,ROOT,DRAFT,APPROVED you
class PUB,REPO,ACK,REGISTER,CARD auto
Solid arrows are things a person does. Dotted arrows are Certaria, with the flow name and how often it runs.
The only gate is at publication. A document can be Approved and still reach nobody, because Certaria will not publish a document whose file it cannot find in the root of Policy Masters. Step 3 explains why, and where to find the list of anything caught by it.
That picture covers a document’s first trip out to your people. What happens afterwards has a page each: Revise a document when it needs changing, and The annual review cycle when it comes up for review.
Procedure (5 steps)
Section titled “Procedure (5 steps)”Step 1. Adopt the template
Section titled “Step 1. Adopt the template”- In the Certaria hub, switch to the Administration area (the area picker sits at the bottom of the navigation), then open Policy Templates.
- Open the record for the template you want.
- Choose Adopt Policy Template on the command bar, then confirm on the page that opens.
Certaria places the file in the root of Policy Masters, normally <SiteUrl>/Policy Masters/,
creates the Draft document record in the same action, and gives you a link straight to the file.
The record names you, the ISMS administrator, as its Owner. If somebody else owns the
document, change the Owner on the record; nothing else depends on the default.
Adopting the same template twice is safe. If the file is already in Policy Masters, Certaria leaves it exactly as it is and says so. It never overwrites work you have done.
Step 2. Check the document record (Certaria creates it for you)
Section titled “Step 2. Check the document record (Certaria creates it for you)”Within ten minutes, Certaria: Register Policy Drafts notices the new file and creates a Draft record in the document register, filling in:
- Title: taken from the matching Certaria template where it recognises the file, otherwise from the file name.
- Category: taken from the template. Templates, Registers and Reports are excluded from acknowledgement scope.
- Storage Location: the document’s URL, filled in automatically.
- Version: set to
1.0as a starting point.
One field is yours to write, and it is optional: Staff summary. A short paragraph in plain language saying what the document asks of the reader. It appears on the document’s reading page above the document itself. Where you leave it empty the page simply goes without it, but a good summary is the difference between a policy that is read and one that is scrolled past.
Two further fields are yours, and both are safe to ignore. Left alone they give you exactly the behaviour you have always had.
Acknowledgement required decides whether the document asks anything of the reader. It arrives set to Yes. Set it to No for something people should be able to read without being asked to confirm it, a reference guide being the usual case. A document set to No is still approved, still published and still listed; it simply never appears on anyone’s card and its reading page carries no acknowledgement panel, nobody is reminded about it, and no outstanding task is raised against it. This is the fix for attestation fatigue: asking for a formal confirmation on every informational guide teaches people to click through without reading, which costs you the confirmations that actually matter.
Applies to role decides who is asked. Leave it empty and the document applies to everyone. Otherwise pick one or more roles, and only people holding at least one of them are asked to confirm it. Picking Everyone does the same as leaving it empty, and is worth using when you want the intent to be visible on the record rather than inferred from a blank field.
Everyone and Staff are not the same thing, and the difference is easy to miss. Everyone reaches your whole organisation. Staff is one role among several, sitting alongside Director, ISO Manager, Consultant, Contractor and Administrator, so a document scoped to Staff is never asked of anyone whose only role is Director. If you mean the whole company, choose Everyone or leave the field empty. Choose Staff only when you genuinely mean the people holding that role and not your leadership team.
This matters because nothing will look wrong if you get it the wrong way round. A document scoped to Staff shows as fully confirmed as soon as the Staff holders confirm it, because everyone else was never asked. If that document was meant for the whole company, your records will read as complete while your directors have not seen it.
Roles come from the Role field on each person, which also accepts more than one. A document naming Contractor and Administrator is confirmed by anyone holding either, and a person who is both a Director and an ISO Manager is asked for documents naming either.
Both fields change the future, not the past. Acknowledgements already given stay exactly as recorded, including the audience that applied at the time they were given, so narrowing a document’s audience never makes a past confirmation look as though it should not have happened.
Open the Certaria model driven app, go to Documents (Governance, then Documentation), and check the record. Correct the title and version if they are not what you want. You are reviewing, not typing.
Do not want to wait for the ten-minute sweep, or the file is one Certaria did not recognise? You can still create the record by hand with + New. The procedure below is identical from Step 3 onwards.
Step 3. Check the file is in the root of Policy Masters
Section titled “Step 3. Check the file is in the root of Policy Masters”This is the gate, and Certaria enforces it. It is not advice you can skip.
Certaria publishes a document only when it can find its file in the root of Policy Masters. If the file has been moved into a subfolder, renamed or deleted, the document is treated as approved but not published: it does not appear to your people, and it is listed under approvedButNotPublished on the run report of Certaria: Publish Policies to Site.
This is deliberate, and it is there to protect you. Certaria publishes only what it can prove your people would be reading. If it cannot find the file it does not guess, because publishing a document it cannot verify would put something in front of your whole organisation and collect acknowledgements against it. An acknowledgement is evidence that a named person read a specific version of a specific document, so acknowledgements attached to a document nobody can produce are worse at audit than no acknowledgements at all.
If a document is sitting in that list, the fix is to put its file back in the root of Policy Masters. Adopting the template again does this for you, and creates no second record because the register already holds that reference.
Step 4. Approve the document
Section titled “Step 4. Approve the document”Set Status to Approved and save.
Certaria immediately fills in three fields for you:
- Approved Date, set to today. This is what your auditor asks for when they ask “approved when”, and it is what the review cycle counts from.
- Next Review Date, set twelve months out from today. This moves forward every time you approve, so a document you review a second time gets a fresh year rather than staying overdue. To change the interval for every document, set the Document Review Months setting.
- Approver, matched from the account that set the status to Approved.
Then, within seconds:
- The document appears in the Published Documents list on your SharePoint site, where your people read and acknowledge it. They need no Power Platform licence to do so.
- Its Storage Location is corrected to the live document, so every link your people follow resolves to the file you actually published.
- Anyone who has not acknowledged it starts appearing in the daily reminder.
Then, at the next sweep: the document’s reading page is created (or refreshed, for a new version), the PDF copy is frozen, and every active person receives one Microsoft Teams message telling them what is newly published, listing everything approved since the last run rather than one message per document.
Withdrawing a document is deliberate and separate. Set the status to Superseded or Archived and it is removed from the Published Documents list, and its reading page taken down, at the next run. Setting it back to Draft or Under Review does not withdraw it, because a document being revised is still the version in force. A file leaving the root of Policy Masters does withdraw it. Move it into a subfolder and Certaria stops showing it to your people, because it can no longer prove what they would be reading.
Step 5. Verify (one minute)
Section titled “Step 5. Verify (one minute)”- Open the Published Documents list on your SharePoint site and confirm the document is there with the right title and version.
- Once the ten-minute sweep has passed, or sooner if you press Publish to site, follow the Read the document link: it opens the document’s reading page. Confirm the banner shows the right version and the document renders (the frozen PDF copy, not a template). Before the first sweep the link serves the document file directly, so a page arriving within ten minutes is normal.
- Confirm Approved Date is set on the document record.
- Confirm you received the Teams message yourself. If nobody received one, see the failure table below.
Publishing without waiting
Section titled “Publishing without waiting”Publishing happens on its own. Approving a document publishes it within seconds, and
Publish Policies to Site sweeps everything again every ten minutes as a safety net. In normal
use there is nothing for you to press.
Publish to site on the command bar runs that sweep immediately. It sits on the Policies, Procedures, Guides, Plans and All Documents lists, and it acts on every approved document rather than the row you have selected.
Reach for it when you have corrected something and would rather not wait: you have put a missing file back in the root of Policy Masters, personalised a document that published with placeholders still in it, or fixed a category. It does exactly what the sweep does, brought forward.
It answers “Publishing started” and returns straight away rather than holding you while the run finishes, because a full sweep takes longer than a button should. Give it a minute, then verify as in Step 5.
How your people acknowledge
Section titled “How your people acknowledge”Through the Certaria card in Teams. The card links each document they owe to its own reading page on your SharePoint site. They read there, return to the card, tick what they have read, and press Confirm. The card also carries an Open all my documents button, which opens the Published Documents list on the same site.
Confirmation happens on the Certaria card in Microsoft Teams, and only there. The card lists the documents a person still owes, links each one to its own reading page, and takes the confirmation when they come back. Sites set up before August 2026 may still show a confirm link in the Published Documents list; it no longer records anything, and it is removed when the site is next updated.
Only the people a document applies to are asked, and only where the document asks for a confirmation at all. Someone outside a document’s audience can still open it and read it, and is simply never asked to confirm it, because narrowing an audience narrows who is asked and never who may read.
The reading page answers “have I done this?” in place. Beneath the document, the page shows that person’s own acknowledgement of it, with the version and date, or a note that none is recorded for the current version yet. Each person sees only their own entry there.
The card is the core route and every customer has it. It needs no add-on and no Power Platform licence, only Microsoft Teams, which your people already have. Acknowledgements reach the register immediately, and the person’s own copy appears on the site shortly afterwards.
Nobody chooses which document they are confirming. The card carries the document with it, so a confirmation can only ever attach to the document the person was sent to read. There is no list to pick from and no way to confirm one document while believing you confirmed another.
Where they see what they have already confirmed. The site navigation carries My Acknowledgements, beneath My Compliance, which opens their own acknowledgement history: the document with its reference, the version, and the date it was acknowledged. Each person sees only their own entries, and nobody else’s.
Through the AI Agent, if you have bought that add-on. Staff can say “acknowledge a document” to the Certaria agent in Teams instead. The two routes record the same thing, and an acknowledgement made either way stops the reminders.
If you do not have the agent add-on, the card is the route, and it is complete on its own.
What a recorded acknowledgement tells you
Section titled “What a recorded acknowledgement tells you”Each confirmation is a record of a moment, not a tick against a name. Open Acknowledgements in the admin app and every row carries what was true when the person confirmed:
- Document Version. An acknowledgement is evidence that a named person read a specific version. Publish a new version and the obligation resets, which is why the version sits on the row rather than being looked up from the document.
- Applied audience. The roles the document applied to at that moment. Retarget a document later and this does not move, so the record still shows who was required to confirm it then rather than who would be required now.
- Expiry Date. Acknowledgements do not last forever. Each one expires after the period set in Document Validity Months, and when it does the person returns to outstanding and starts appearing in the daily reminder again. Nobody has to do anything for this to happen. This is the column to sort by if you want to know what is about to lapse.
Rows recorded before your ISMS started scoping audiences carry no Applied audience. That is correct rather than missing: no audience was in force to record.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| The document record never appeared | The file was added by hand and fewer than ten minutes have passed, or it sits in a subfolder rather than the root of Policy Masters | Move the file to the root and wait for the next sweep, or create the record by hand |
| The document published, but nobody was asked to acknowledge it | Its Applies to role names a role none of your people hold, so the audience is empty. A document with no roles named applies to everyone; one naming a role nobody has is addressed to nobody, silently | Clear Applies to role on the document, or give at least one person that role on their own record. See Import your people |
| The link opens a document with the approver or the dates still in square brackets | The document was open in Word when it published, so SharePoint had it locked and the values could not be written | Close the document everywhere, including any browser tab showing it, then press Publish to site |
| The link opens a document with your organisation name or the owner still in square brackets | It was adopted before those details were available | Delete the file from Policy Masters and adopt the template again, then approve and publish it |
| Nobody received a Teams message at all | The people register is empty, or the person has no email address recorded against their identity, so there is nobody to message | Import your people during onboarding and confirm each active person has an email address |
| The document is approved but is not in Published Documents | The file is not in the root of Policy Masters, or the category is an excluded type (Template, Register, Report) | Check approvedButNotPublished on the last run of Certaria: Publish Policies to Site. If the document is listed there, put its file back in the root |
| A document I set back to Under Review is still visible to staff | This is deliberate. The approved version stays in force until a new approved version replaces it | To withdraw it, set the status to Superseded or Archived |
| Approving a document a second time did nothing at all | Certaria was unable to record a second approval on the same document before 3 August 2026 | Set the status away from Approved and back again. If the dates still do not move, confirm Certaria: Stamp Policy Approval is switched on |
| The same document keeps appearing in the Monday review email | Its Next Review Date is in the past and nothing has re-approved it | Set the status to Under Review and back to Approved. That is the record of review, and it moves the date on |
| A new version was published, but people who acknowledged the old version are not prompted | The version field was not bumped, or person rows are missing the user link | Confirm the version changed, then check the person links |
| Somebody confirmed from the card but it is not in the register | The card submission did not complete. Confirmations are written to the register at the moment the person presses Confirm in Teams, so a missing row means that write failed | Check the run history of Certaria: Notify Policy Acknowledgement for the day they confirmed. The person stays on the daily reminder until a confirmation is recorded, so nothing is silently lost |
| A confirmation is in the register but the person cannot see it under My Acknowledgements | The site copy could not be projected, usually because the person could not be resolved to a signed-in account. It is counted and named under unresolved on the run report, never skipped in silence | Check unresolved on the last run of Certaria: Sync Acknowledgements. Confirm the person is in the people register with an email address that matches their Microsoft 365 sign-in |
| An acknowledgement was deleted from the register by mistake | The register is the record. Deleting a row deletes the evidence, and nothing rebuilds it. The copy on the SharePoint site is a display of the register, not a backup of it | Treat register rows as audit records and do not delete them. If one has been lost, the person will return to outstanding on the next reminder and can confirm again, which creates a new record with today’s date rather than restoring the old one |
| Two records share one Doc Ref | Releases before August 2026 could register the same file twice. Adopting no longer creates a second record for a reference the register already holds | Decide which record is right, set the other to Archived, and check the acknowledgements are attached to the one you keep |
| Duplicate document records for the same file | The file was renamed after its record was created | Delete the surplus Draft record. Certaria matches on the file name, so copying or moving a file between folders is safe; renaming it is not |
| A published document has no reading page | Fewer than ten minutes have passed since approval, or the page sweep failed on its last run | Wait for the next run of Certaria: Publish Policies to Site, then check that run’s history if the page is still missing |
| The reading page shows an old version in its banner | The document record changed after the page was last built, and the next sweep has not run yet | The page refreshes on the next run. If it never does, confirm the document’s Modified date actually moved |
Related references
Section titled “Related references”- ISO 27001:2022 A.5.1: policies communicated to and acknowledged by relevant personnel.
- ISO 27001:2022 Clause 7.5: documented information: identification, distribution, version control.
Certaria: Stamp Policy Approval: on approval. Sets Approved Date, moves Next Review Date forward, records the Approver, and publishes straight away.Certaria: Register Policy Drafts: every ten minutes. Creates the Draft document record from a file added to the root of Policy Masters by hand. Adopting a template creates the record directly and does not wait for this.Certaria: Publish Policies to Site: every ten minutes. The safety net behind immediate publication. Freezes a PDF copy of each published document, builds and refreshes each document’s reading page, publishes documents whose file is in the root of Policy Masters, corrects their Storage Location, removes superseded and archived ones together with their pages, announces newly published policies in Teams, and reports anything approved but not publishable.ISMS Policy Review Date Alert: Monday mornings. Emails the ISMS administrator every document due for review within 30 days.Document Review Months: how far ahead the Next Review Date is set on approval. Defaults to 12.Certaria: Sync Acknowledgements: hourly. Projects each person’s confirmations from the register to the SharePoint site and grants each row to that person alone, so My Acknowledgements stays current and private. Anything it cannot project is counted and named underunresolvedon its run report.Certaria: Notify Policy Acknowledgement: daily. Reminds people who still have documents outstanding, and maintains the one task per document that the home page and the morning email read.Certaria: Check Daily Health: daily, after the reminder has run. Emails the ISMS administrator whenever anyone is outstanding, naming each person per document with days outstanding, and calls out any document that applies to a role nobody currently holds.isms-site-access-model.md: who can see and do what on the ISMS site.