Skip to content

Revise a policy

Change a document that is already published, without taking it away from your people while you work.

Audience: ISMS Admin.

Where: SharePoint holds the files. The Certaria app holds the records.

Revising a document that is already in force

Section titled “Revising a document that is already in force”

The approved version stays in force until a new approved version replaces it. That is what ISO 27001 Clause 7.5 expects, and it is why setting a document back to Draft or Under Review does not remove it from the Published Policies list. Your people keep reading the version you last approved while you work on the next one.

This only holds if you revise a copy. The Published Policies link points at the file in your policy library root, so anything you type into that file is visible to your whole organisation the moment Word saves it. There is no draft state for a file in the root.

The procedure:

  1. In SharePoint, select the document in the policy library root, choose Copy to, and pick the ISMS Working library.
  2. Set the document record’s status to Under Review in the model driven app. This tells your colleagues a revision is in progress. Your people are unaffected and keep reading the current version.
  3. Revise the copy in ISMS Working. Take as long as you need.
  4. When it is final, copy it back to the policy library root, replacing the file that is there. SharePoint keeps the previous file as a version, so nothing is lost.
  5. Bump the Version on the document record if the change is material enough to need re-acknowledgement. See the next section.
  6. Set the status back to Approved. Certaria stamps a fresh Approved Date, moves the Next Review Date forward twelve months, records you as the approver, and republishes within seconds.


Re-issuance (version aware acknowledgement)

Section titled “Re-issuance (version aware acknowledgement)”

This is the audit critical part. When you bump the version, for example 2.0 to 2.1:

  • Existing acknowledgement rows for that document stay in the register unchanged as historical evidence, recording that a named person acknowledged version 2.0 on a given date.
  • Everyone is then checked against the current version, so prior version acknowledgements no longer satisfy the obligation.
  • Everyone who acknowledged the previous version is flagged outstanding again automatically and is prompted to re-acknowledge.

You do not need to do anything special when re-issuing. The version bump alone creates the new obligation. Do not edit or delete historical acknowledgement rows. They are the audit trail.