- Documentation
- Run your ISMS
- Policies
Publish a policy
The five step procedure for publishing a new or revised controlled document, and how acknowledgement and re-acknowledgement follow from it.
Purpose: the standard procedure for publishing a new or revised ISMS controlled document (Policy, Procedure, Plan, Guide) so that the acknowledgement loop, the audit register and the notifications all work correctly.
Audience: ISMS Admin.
Where: SharePoint holds the files. The Certaria app holds the records.
Why this matters: ISO 27001:2022 A.5.1 and Clause 7.5 require controlled documents to be identifiable, available where needed, and traceable through their lifecycle. This procedure ensures every published document carries the metadata Certaria needs to run the acknowledgement cycle without silent drift.
When to follow this procedure
Section titled “When to follow this procedure”- Publishing a brand new policy, procedure, plan or guide.
- Re-issuing an existing document at a new version (any change material enough to bump the version number).
- Migrating an existing document into the Certaria register for the first time.
The one thing that has not changed
Section titled “The one thing that has not changed”Approval is yours and only yours. Certaria will fill in the paperwork, but nothing reaches your people until you set a document to Approved. Every record Certaria creates arrives as Draft, deliberately, so that putting a file in a folder can never publish it to the organisation by accident.
The lifecycle at a glance
Section titled “The lifecycle at a glance”Read this once and the five steps below will make sense as a whole.
You do four things. You copy a template out of Pending Applicability into the library root,
you personalise the copy, you check the record Certaria created for it, and you set the status to
Approved. Everything else is Certaria’s work.
Certaria does the rest. Within an hour of a file arriving in the library root,
Register Policy Drafts creates a Draft record for it. The moment you approve,
Stamp Policy Approval writes the Approved Date, moves the Next Review Date forward, records who
approved it, and publishes straight away: the document reaches the Published Policies list
within seconds, with its link corrected. The hourly Publish Policies to Site run stays as a
safety net and announces newly published policies once in Teams.
Your people never touch the model-driven app. They read the document from the Published
Policies list and acknowledge it there, needing no Power Platform licence.
Sync Policy Acknowledgements writes what they did into the register within the hour, and
Notify Policy Acknowledgement reminds anyone still outstanding, once a day.
Re-acknowledgement is not a separate process. Bumping the version is the whole of it. A person owes an acknowledgement whenever the document is Approved and they have no acknowledgement row against the current version that has not expired, so a new version reopens the obligation for everybody at once, and the yearly cycle falls out of the same rule.
%%{init: {"theme":"base","themeVariables":{
"fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
"background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
"primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
"secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
"textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
"clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
"edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
"labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
subgraph SP["SharePoint: your ISMS site"]
direction TB
T["Pending Applicability<br/><i>blank templates</i>"]
ROOT["Policy library root<br/><i>your live policies</i>"]
PUB["Published Policies<br/><i>no licence needed</i>"]
ACK["What I have confirmed<br/><i>only your own</i>"]
end
subgraph MDA["Model-driven app: ISMS Admin only"]
direction TB
DRAFT["Document record<br/><b>Draft</b>"]
APPROVED["Document record<br/><b>Approved</b>"]
REGISTER["Acknowledgement register<br/><i>the audit trail</i>"]
end
T -->|"YOU: copy, personalise"| ROOT
ROOT -.->|"Register Policy Drafts"| DRAFT
DRAFT -->|"YOU: set Approved"| APPROVED
APPROVED -.->|"published in seconds"| PUB
PUB -->|"STAFF: read, confirm"| ACK
ACK -.->|"Sync Acknowledgements"| REGISTER
classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
class T,ROOT,DRAFT,APPROVED you
class PUB,ACK,REGISTER auto
Solid arrows are things a person does. Dotted arrows are Certaria, with the flow name and how often it runs.
The only gate is at publication. A document can be Approved and still reach nobody, because
Certaria will not publish a file that is still sitting in Pending Applicability. Step 3 explains
why, and where to find the list of anything caught by it.
That picture covers a document’s first trip out to your people. What happens afterwards has a page each: Revise a policy when it needs changing, and The annual review cycle when it comes up for review.
Procedure (5 steps)
Section titled “Procedure (5 steps)”Step 1. Save the document to the policy library
Section titled “Step 1. Save the document to the policy library”- Save the final document to the root of your policy library, normally
<SiteUrl>/ISMS Policies/. - The
Pending Applicabilityfolder inside that library is a staging area for templates you have not yet adopted. A file there is not a policy. The root holds your live policies. - If you are adopting one of Certaria’s 34 templates, copy it to the library root first, and personalise the copy.
Step 2. Check the document record (Certaria creates it for you)
Section titled “Step 2. Check the document record (Certaria creates it for you)”Within an hour, Certaria: Register Policy Drafts notices the new file and creates a Draft record in the document register, filling in:
- Title: taken from the matching Certaria template where it recognises the file, otherwise from the file name.
- Category: taken from the template. Templates, Registers and Reports are excluded from acknowledgement scope.
- Storage Location: the document’s URL, filled in automatically.
- Version: set to
1.0as a starting point.
Open the Certaria model driven app, go to Documents (Governance, then Documentation), and check the record. Correct the title and version if they are not what you want. You are reviewing, not typing.
Do not want to wait for the hourly run, or the file is one Certaria did not recognise? You can still create the record by hand with + New. The procedure below is identical from Step 3 onwards.
Step 3. Check the file is out of Pending Applicability
Section titled “Step 3. Check the file is out of Pending Applicability”This is the gate, and Certaria enforces it. It is not advice you can skip.
Certaria publishes a document only when it can find the file in the root of your policy library. If the file is still in Pending Applicability, the document is treated as approved but not published: it does not appear to your people, and it is listed under approvedButNotPublished on the run report of Certaria: Publish Policies to Site.
This is deliberate, and it is there to protect you. Pending Applicability holds Certaria’s unpersonalised templates. Publishing one would put a document in front of your whole organisation with the placeholders still in it, and would collect acknowledgements against it. An acknowledgement is evidence that a named person read a specific version of a specific document, so a blank document with acknowledgements attached is worse at audit than no acknowledgements at all.
If a document is sitting in that list, the fix is always the same: copy the file to the library root and personalise the copy.
Step 4. Approve the document
Section titled “Step 4. Approve the document”Set Status to Approved and save.
Certaria immediately fills in three fields for you:
- Approved Date, set to today. This is what your auditor asks for when they ask “approved when”, and it is what the review cycle counts from.
- Next Review Date, set twelve months out from today. This moves forward every time you approve, so a document you review a second time gets a fresh year rather than staying overdue. To change the interval for every document, set the Document Review Months setting.
- Approver, matched from the account that set the status to Approved.
Then, within seconds:
- The policy appears in the Published Policies list on your SharePoint site, where your people read and acknowledge it. They need no Power Platform licence to do so.
- Its Storage Location is corrected to the live document, so every link your people follow resolves to the file you actually published.
- Anyone who has not acknowledged it starts appearing in the daily reminder.
Then, at the next hourly run, every active person receives one Microsoft Teams message telling them what is newly published, listing everything approved since the last run rather than one message per policy.
Withdrawing a policy is deliberate and separate. Set the status to Superseded or Archived and it is removed from the Published Policies list at the next run. Setting it back to Draft or Under Review does not withdraw it, because a document being revised is still the version in force. A file leaving the library root does withdraw it. Move it back to Pending Applicability and Certaria stops showing it to your people, because it can no longer prove what they would be reading.
Step 5. Verify (one minute)
Section titled “Step 5. Verify (one minute)”- Open the Published Policies list on your SharePoint site and confirm the document is there with the right title and version.
- Follow the Read the document link and confirm it opens the document you actually published, not a template.
- Confirm Approved Date is set on the document record.
- Confirm you received the Teams message yourself. If nobody received one, see the failure table below.
How your people acknowledge
Section titled “How your people acknowledge”Through SharePoint. They open the Published Policies list, read the document, and use the Confirm I have read and understood link beside it. This is the core route and every customer has it. Acknowledgements are written to the register within the hour.
The link opens a short form with one field: the policy they are confirming. That field is required, so the form cannot be submitted without it. Ask your people to pick the policy whose row they clicked from, because the form has no way of knowing which one they came from.
Where they see what they have already confirmed. The site navigation carries What I have confirmed, which opens their own acknowledgement history: the policy, the version, and the date. Each person sees only their own entries, and nobody else’s.
Through the AI Agent, if you have bought that add-on. Staff can say “acknowledge a policy” to the Certaria agent in Teams instead. The two routes record the same thing, and an acknowledgement made either way stops the reminders.
If you do not have the agent add-on, SharePoint is the route, and it is complete on its own.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| The document record never appeared | The file is in Pending Applicability rather than the library root, or fewer than 60 minutes have passed | Copy the file to the root and wait for the next run, or create the record by hand |
| The link opens a template with placeholders still in it | The document was approved while its file was still in Pending Applicability, before Certaria enforced the gate | Copy the file to the library root, personalise the copy, and let the next run correct the link |
| Nobody received a Teams message at all | The people register is empty, or the person has no email address recorded against their identity, so there is nobody to message | Import your people during onboarding and confirm each active person has an email address |
| The policy is approved but is not in Published Policies | The file is still in Pending Applicability, or the category is an excluded type (Template, Register, Report) | Check approvedButNotPublished on the last run of Certaria: Publish Policies to Site. If the document is listed there, move the personalised file to the library root |
| A document I set back to Under Review is still visible to staff | This is deliberate. The approved version stays in force until a new approved version replaces it | To withdraw it, set the status to Superseded or Archived |
| Approving a document a second time did nothing at all | Certaria was unable to record a second approval on the same document before 3 August 2026 | Set the status away from Approved and back again. If the dates still do not move, confirm Certaria: Stamp Policy Approval is switched on |
| The same document keeps appearing in the Monday review email | Its Next Review Date is in the past and nothing has re-approved it | Set the status to Under Review and back to Approved. That is the record of review, and it moves the date on |
| A new version was published, but people who acknowledged the old version are not prompted | The version field was not bumped, or person rows are missing the user link | Confirm the version changed, then check the person links |
| Somebody confirmed a policy but it is not in the register | Their confirmation could not be matched to a policy, or to a person. It is counted and named under unresolved on the run report, never skipped in silence | Check unresolved on the last run of Certaria: Sync Policy Acknowledgements. If the person is new, confirm they are in the people register with an email address |
| An acknowledgement was deleted from the register by mistake | Deleting the record does not delete the person’s confirmation on the SharePoint site | Nothing to do. The next run notices the record is missing and writes it again from the confirmation, which is still there |
A template in Pending Applicability is no longer clean | It was opened and edited where it sat, and Word AutoSave overwrote it. This happens silently and without warning | Copy the edited file to the root to keep your work, then restore the earlier version from Version history on the original |
| Duplicate document records for the same file | The file was renamed after its record was created | Delete the surplus Draft record. Certaria matches on the file name, so copying or moving a file between folders is safe; renaming it is not |
Related references
Section titled “Related references”- ISO 27001:2022 A.5.1: policies communicated to and acknowledged by relevant personnel.
- ISO 27001:2022 Clause 7.5: documented information: identification, distribution, version control.
Certaria: Stamp Policy Approval: on approval. Sets Approved Date, moves Next Review Date forward, records the Approver, and publishes straight away.Certaria: Register Policy Drafts: hourly. Creates the Draft document record from a file in the policy library root.Certaria: Publish Policies to Site: hourly. The safety net behind immediate publication. Publishes documents whose file is in the library root, corrects their Storage Location, removes superseded and archived ones, announces newly published policies in Teams, and reports anything approved but not publishable.ISMS Policy Review Date Alert: Monday mornings. Emails the ISMS administrator every document due for review within 30 days.Document Review Months: how far ahead the Next Review Date is set on approval. Defaults to 12.Certaria: Sync Policy Acknowledgements: hourly. Writes SharePoint acknowledgements into the register.Certaria: Notify Policy Acknowledgement: daily. Reminds people who still have documents outstanding.isms-site-access-model.md: who can see and do what on the ISMS site.