Skip to content

Retire or replace a document

How to take a policy out of force, how replacing one differs from withdrawing it, what happens to the acknowledgements, and why Delete is not the way to do any of it.

Audience: ISMS Admin.

Before this: Publish a document covers getting a document into force. This page covers taking one out, which is the part most organisations get wrong and auditors ask about.

There are two situations and they are not the same thing. Replacing a document means a newer version takes over and the subject stays covered. Retiring one means the organisation stops having a policy on that subject at all. Replacing is routine. Retiring is a governance decision, and it needs a reason you would be willing to say out loud in an audit.

The document lifecycle, and what moves a document between stages

Section titled “The document lifecycle, and what moves a document between stages”

Every controlled document in Certaria sits at one of five statuses. Status is the control that matters: it decides what staff see, what the Statement of Applicability counts, and what an auditor is shown as being in force.

StatusWhat it meansWho sees it
DraftRegistered from your library, not yet in forceAdmins only
Under ReviewBeing worked on or reviewedAdmins only
ApprovedIn force. This is your ISMSStaff, on the published list, and asked to acknowledge
SupersededA newer version took overNobody, but retained as evidence
ArchivedWithdrawn. The organisation no longer has this policyNobody, but retained as evidence

Only Approved documents reach staff. Moving a document to Superseded or Archived removes it from the staff-facing list automatically, within about ten minutes. Moving it back to Approved puts it back.

This is the common case, and you do not need anything on this page for it. Publish the new version through the normal procedure. The previous version stops being the one in force, staff are asked to acknowledge the new one, and the old version stays in the record as evidence of what applied before.

Do not delete the previous version. An auditor may reasonably ask what your Acceptable Use Policy said in March, and the honest answer requires the March version still to exist. Superseded is not the same as gone.

Set the document’s status to Archived. Open the document record in the management hub, change Status to Archived, and save. That is the whole action.

Within about ten minutes Certaria removes the document from the staff-facing Published Documents list on your SharePoint site. Staff stop seeing it, and it stops appearing in the list they are asked to acknowledge from. You do not have to tell anyone to stop acknowledging it, and you do not have to tidy SharePoint by hand.

Use Superseded instead when a newer version takes over, so the record says why it left rather than merely that it did. Both statuses have the same effect on the staff surface; they differ in what they tell an auditor.

Before you archive, satisfy yourself on three points.

  1. No control depends on it alone. If the document was the only thing covering an Annex A control you have marked applicable, retiring it opens a gap. Either accept the gap and record why, or publish something in its place first.
  2. The reason is recorded. “We no longer offer that service” is a reason. “It was out of date” is not, because that is an argument for revising it rather than withdrawing it.
  3. Anyone who needs to know, knows. Staff will stop seeing the document. If they were relying on it, tell them what replaces it.

Delete appears on the toolbar and its confirmation says the document cannot be recovered. Neither part of that is a good guide to what will happen.

Deleting the record does not remove the document from your SharePoint library, because the library is where the document actually lives. The management hub record is a view onto it. Certaria checks the library regularly for documents it has not seen before, so a record you delete while the file remains will be recreated as a new draft within a few minutes, and you will have lost the version history and the acknowledgement links that were attached to the record you deleted.

Removing a document from the library altogether

Section titled “Removing a document from the library altogether”

Archiving withdraws a document from staff, but the original file stays in the library you adopted it into. That is usually right: the file is the evidence. Occasionally, though, a file genuinely does not belong at all, such as a duplicate, a draft saved to the wrong folder, or something uploaded by mistake.

That is a library operation, not a hub operation. Remove the file in SharePoint first, then remove the matching record in the hub. In that order the record stays gone. In the other order it returns within ten minutes, because Certaria checks the library regularly for documents it has not seen and will register the file again as a fresh draft.

For a document that was ever approved and acknowledged, prefer moving it to an archive location over deleting it. Storage is cheap and reconstructing a controlled document you cannot produce is not possible.

After you retire a document: what Certaria does, and what you must do

Section titled “After you retire a document: what Certaria does, and what you must do”

Two of these are automatic and two are not. The two that are not will not remind you, so treat them as part of the retirement rather than as follow-up.

Happens automatically
The document leaves the staff-facing listYes, within about ten minutes
Staff stop being asked to acknowledge itYes, it leaves the list they acknowledge from
You must do this yourself
Close any open review task for the documentCertaria closes policy review tasks when a document is approved. Nothing closes them when it is retired, so a review task for a withdrawn policy stays open and will go overdue. Find it under Tasks and close it.
Re-read the Statement of ApplicabilityIf the document was the only thing covering a control you have marked applicable, you now have a gap. Nothing announces this.

Neither omission breaks anything, and both look bad in an audit. A permanently overdue task to review a policy you withdrew months ago is exactly the kind of detail an assessor notices, and an applicable control with nothing behind it is a finding.

Acknowledgements are recorded against the version that was acknowledged, so they are unaffected by what happens to the document afterwards. Retiring a document does not invalidate the fact that twelve people read it in June, and nothing about a retirement asks anyone to acknowledge anything.

This is worth understanding because it is what makes retirement safe. You are changing what applies from now on, not editing the past.

What an auditor asks, and where the answer is

Section titled “What an auditor asks, and where the answer is”
QuestionWhere it is answered
What policies are in force today?Documents with status Approved in the hub, which are exactly the ones on the staff facing list
What applied before the current version?The superseded versions, retained
Why did you withdraw that policy?The status you set, Superseded or Archived, and the reason recorded with it
Did anyone acknowledge the old one?The acknowledgement records, which survive retirement
Is any applicable control now uncovered?The Statement of Applicability, read after the retirement
  • A.5.1 Policies for information security, which requires that policies are reviewed and remain adequate
  • A.5.37 Documented operating procedures
  • Clause 7.5.3 Control of documented information, which covers availability, retention and disposition