- Documentation
- Run your ISMS
- Document governance
Retire or replace a document
How to take a policy out of force, how replacing one differs from withdrawing it, what happens to the acknowledgements, and why Delete is not the way to do any of it.
Audience: ISMS Admin.
Before this: Publish a document covers getting a document into force. This page covers taking one out, which is the part most organisations get wrong and auditors ask about.
There are two situations and they are not the same thing. Replacing a document means a newer version takes over and the subject stays covered. Retiring one means the organisation stops having a policy on that subject at all. Replacing is routine. Retiring is a governance decision, and it needs a reason you would be willing to say out loud in an audit.
The document lifecycle, and what moves a document between stages
Section titled “The document lifecycle, and what moves a document between stages”Every controlled document in Certaria sits at one of five statuses. Status is the control that matters: it decides what staff see, what the Statement of Applicability counts, and what an auditor is shown as being in force.
| Status | What it means | Who sees it |
|---|---|---|
| Draft | Registered from your library, not yet in force | Admins only |
| Under Review | Being worked on or reviewed | Admins only |
| Approved | In force. This is your ISMS | Staff, on the published list, and asked to acknowledge |
| Superseded | A newer version took over | Nobody, but retained as evidence |
| Archived | Withdrawn. The organisation no longer has this policy | Nobody, but retained as evidence |
Only Approved documents reach staff. Moving a document to Superseded or Archived removes it from the staff-facing list automatically, within about ten minutes. Moving it back to Approved puts it back.
Replacing a document with a newer version
Section titled “Replacing a document with a newer version”This is the common case, and you do not need anything on this page for it. Publish the new version through the normal procedure. The previous version stops being the one in force, staff are asked to acknowledge the new one, and the old version stays in the record as evidence of what applied before.
Do not delete the previous version. An auditor may reasonably ask what your Acceptable Use Policy said in March, and the honest answer requires the March version still to exist. Superseded is not the same as gone.
Retiring a document properly
Section titled “Retiring a document properly”Set the document’s status to Archived. Open the document record in the management hub, change Status to Archived, and save. That is the whole action.
Within about ten minutes Certaria removes the document from the staff-facing Published Documents list on your SharePoint site. Staff stop seeing it, and it stops appearing in the list they are asked to acknowledge from. You do not have to tell anyone to stop acknowledging it, and you do not have to tidy SharePoint by hand.
Use Superseded instead when a newer version takes over, so the record says why it left rather than merely that it did. Both statuses have the same effect on the staff surface; they differ in what they tell an auditor.
Before you archive, satisfy yourself on three points.
- No control depends on it alone. If the document was the only thing covering an Annex A control you have marked applicable, retiring it opens a gap. Either accept the gap and record why, or publish something in its place first.
- The reason is recorded. “We no longer offer that service” is a reason. “It was out of date” is not, because that is an argument for revising it rather than withdrawing it.
- Anyone who needs to know, knows. Staff will stop seeing the document. If they were relying on it, tell them what replaces it.
Do not use Delete
Section titled “Do not use Delete”Delete appears on the toolbar and its confirmation says the document cannot be recovered. Neither part of that is a good guide to what will happen.
Deleting the record does not remove the document from your SharePoint library, because the library is where the document actually lives. The management hub record is a view onto it. Certaria checks the library regularly for documents it has not seen before, so a record you delete while the file remains will be recreated as a new draft within a few minutes, and you will have lost the version history and the acknowledgement links that were attached to the record you deleted.
Removing a document from the library altogether
Section titled “Removing a document from the library altogether”Archiving withdraws a document from staff, but the original file stays in the library you adopted it into. That is usually right: the file is the evidence. Occasionally, though, a file genuinely does not belong at all, such as a duplicate, a draft saved to the wrong folder, or something uploaded by mistake.
That is a library operation, not a hub operation. Remove the file in SharePoint first, then remove the matching record in the hub. In that order the record stays gone. In the other order it returns within ten minutes, because Certaria checks the library regularly for documents it has not seen and will register the file again as a fresh draft.
For a document that was ever approved and acknowledged, prefer moving it to an archive location over deleting it. Storage is cheap and reconstructing a controlled document you cannot produce is not possible.
After you retire a document: what Certaria does, and what you must do
Section titled “After you retire a document: what Certaria does, and what you must do”Two of these are automatic and two are not. The two that are not will not remind you, so treat them as part of the retirement rather than as follow-up.
| Happens automatically | |
|---|---|
| The document leaves the staff-facing list | Yes, within about ten minutes |
| Staff stop being asked to acknowledge it | Yes, it leaves the list they acknowledge from |
| You must do this yourself | |
|---|---|
| Close any open review task for the document | Certaria closes policy review tasks when a document is approved. Nothing closes them when it is retired, so a review task for a withdrawn policy stays open and will go overdue. Find it under Tasks and close it. |
| Re-read the Statement of Applicability | If the document was the only thing covering a control you have marked applicable, you now have a gap. Nothing announces this. |
Neither omission breaks anything, and both look bad in an audit. A permanently overdue task to review a policy you withdrew months ago is exactly the kind of detail an assessor notices, and an applicable control with nothing behind it is a finding.
What happens to the acknowledgements
Section titled “What happens to the acknowledgements”Acknowledgements are recorded against the version that was acknowledged, so they are unaffected by what happens to the document afterwards. Retiring a document does not invalidate the fact that twelve people read it in June, and nothing about a retirement asks anyone to acknowledge anything.
This is worth understanding because it is what makes retirement safe. You are changing what applies from now on, not editing the past.
What an auditor asks, and where the answer is
Section titled “What an auditor asks, and where the answer is”| Question | Where it is answered |
|---|---|
| What policies are in force today? | Documents with status Approved in the hub, which are exactly the ones on the staff facing list |
| What applied before the current version? | The superseded versions, retained |
| Why did you withdraw that policy? | The status you set, Superseded or Archived, and the reason recorded with it |
| Did anyone acknowledge the old one? | The acknowledgement records, which survive retirement |
| Is any applicable control now uncovered? | The Statement of Applicability, read after the retirement |
Related controls
Section titled “Related controls”- A.5.1 Policies for information security, which requires that policies are reviewed and remain adequate
- A.5.37 Documented operating procedures
- Clause 7.5.3 Control of documented information, which covers availability, retention and disposition
- Publish a document, for getting the replacement into force
- The Statement of Applicability, to confirm nothing is left uncovered
- Your SharePoint site, for how the library and the hub relate