SOC 2 policy acknowledgment: why auditors ask for it and how to collect it
A policy nobody has read is a document, not a control. Acknowledgment is how you show the auditor that the people in scope know what the policies say and have agreed to follow them. This guide covers why it is requested, which criteria it supports, how to collect it without a compliance platform, and a form you can copy today.
Why auditors ask
Several of the common criteria in the 2017 Trust Services Criteria are about people rather than technology. In our own words: CC1.1 expects a commitment to integrity and ethical values that is communicated and enforced; CC1.4 expects that people are competent for their roles; CC1.5 expects that people are held accountable for their responsibilities; CC2.2 expects that objectives and responsibilities are communicated internally; and CC5.3 expects that control activities are deployed through policies and procedures. For each of these the auditor needs evidence that the policies reached the people they apply to. A signed, dated acknowledgment that lists the policies and their versions is the simplest evidence that satisfies all five.
Two policies in the Policyseed set make acknowledgment an explicit requirement. The Human Resources Security Policy requires acknowledgment of the full pack at onboarding and after every review, and the Acceptable Use Policy requires its own signed acknowledgment because it is the document that sets out personal obligations. The Information Security Policy states that all personnel must comply with the policy set, which is what the acknowledgment confirms.
What counts as evidence
An acknowledgment record needs to show four things:
- Who: the person’s name, and ideally their role, matched to an entry in the personnel list the auditor will sample from.
- What: which policies, at which version and effective date. “I have read the security policies” without a list is routinely rejected because the auditor cannot tell whether the current versions were covered.
- When: a date that is on or after the effective date of the policies listed, and before the person was granted access (for onboarding) or within the review cycle (for re-acknowledgment).
- Assent: a signature, an e-signature record, an authenticated click, or an approval in a system that identifies the user. The record must not be editable by the person after the fact.
When to collect it
- Onboarding, before access to production, source code or customer data is granted. Most companies put it in the first-day checklist alongside the equipment form.
- After a material revision. If a policy changes in a way that alters what is expected of people (a new MFA requirement, a new data-handling rule), re-issue it. Typo fixes do not require a new round; record them as a minor version.
- At least annually, usually in the same month as the policy review so the revision history and the acknowledgments line up. Semi-annual and quarterly cadences are chosen in the intake and appear in section 8 of every policy.
- For contractors and vendors with access, at engagement start, covering at least the Acceptable Use, Information Security and Data Classification policies. See the Vendor and Third-Party Risk Management Policy.
Five ways to run it at a startup
| Method | Evidence produced | Good for | Watch out for |
|---|---|---|---|
| Printed or PDF form (below), signed and scanned | Signed document per person | Under 20 people, first examination | Chasing signatures; store scans in one folder by name |
| E-signature platform | Audit trail with timestamps and IP | Remote teams, contractors | Include the policy list and versions in the envelope, not just a link |
| HR platform attestation | Completion report per employee | Companies already on an HRIS | Contractors are often outside the HRIS; cover them separately |
| Pull request approval in a policy repository | Git history with authenticated approvals | Engineering-heavy teams keeping policies as Markdown | Non-engineers need a path too; auditors accept it but ask for an export |
| Authenticated form (SSO-gated) | Response sheet with login identity and timestamp | Fast annual re-acknowledgment | Lock the response sheet; export it with the date visible |
Free acknowledgment form
Copy the text below into a document, fill in the company and version details, and use it as-is or as the body of an e-signature envelope. It lists all 22 Policyseed policies; delete rows for policies you have not adopted. The Audit Kit produces the same form as a Word document with your company name, versions and effective date filled in.
POLICY ACKNOWLEDGMENT FORM
Company: ______________________________
Employee / contractor name: ______________________________
Role: ______________________________
Start date (if onboarding): ____ / ____ / ________
I confirm that I have received, read and understood the following policies,
at the version and effective date shown, and that I agree to comply with them
for as long as I work with the company:
[ ] P01 Information Security Policy v____ effective ____-__-__
[ ] P02 Acceptable Use Policy v____ effective ____-__-__
[ ] P03 Access Control Policy v____ effective ____-__-__
[ ] P04 Authentication and Password Policy v____ effective ____-__-__
[ ] P05 Asset Management Policy v____ effective ____-__-__
[ ] P06 Data Classification and Handling Policy v____ effective ____-__-__
[ ] P07 Data Retention and Disposal Policy v____ effective ____-__-__
[ ] P08 Encryption and Key Management Policy v____ effective ____-__-__
[ ] P09 Change Management Policy v____ effective ____-__-__
[ ] P10 Secure Software Development Policy v____ effective ____-__-__
[ ] P11 Vulnerability and Patch Management Policy v____ effective ____-__-__
[ ] P12 Logging and Monitoring Policy v____ effective ____-__-__
[ ] P13 Incident Response Policy v____ effective ____-__-__
[ ] P14 Business Continuity and Disaster Recovery Policy v____ effective ____-__-__
[ ] P15 Backup and Recovery Policy v____ effective ____-__-__
[ ] P16 Vendor and Third-Party Risk Management Policy v____ effective ____-__-__
[ ] P17 Risk Assessment and Management Policy v____ effective ____-__-__
[ ] P18 Human Resources Security Policy v____ effective ____-__-__
[ ] P19 Endpoint and Workstation Security Policy v____ effective ____-__-__
[ ] P20 Network and Infrastructure Security Policy v____ effective ____-__-__
[ ] P21 Physical and Remote Work Security Policy v____ effective ____-__-__
[ ] P22 Privacy and Data Protection Policy v____ effective ____-__-__
I understand that:
- questions about these policies should go to the Security Owner named in the
Information Security Policy;
- security incidents and suspected policy violations must be reported using
the contact in the Incident Response Policy;
- exceptions must be requested in writing as described in section 6 of the
relevant policy and are not valid until approved;
- failure to comply may result in the actions described in section 7
(Enforcement) of each policy, up to and including termination of employment
or contract, subject to applicable law.
Signature: ______________________________ Date: ____ / ____ / ________
For the company
Witnessed by (People/HR Lead or Security Owner): ______________________________
Signature: ______________________________ Date: ____ / ____ / ________
Retention: keep this form for the duration of employment plus the current
examination period and one year. Store with personnel records.Mistakes that turn into findings
- Acknowledging a folder. “I have read the policies in the shared drive” with no versions. The auditor cannot tie it to the policies they examined.
- Not re-collecting after revisions. The pack was revised in March; the acknowledgments are from the previous year. The revision history says v1.1; the signatures say v1.0.
- Missing contractors. The auditor samples from the identity provider’s user list, and three of the names have no acknowledgment because they are not employees.
- No tracker. You cannot say who has not signed. Keep a one-page list: name, role, date signed, version. The Audit Kit’s evidence checklist has a row for it.
- Acceptable Use only. The AUP acknowledgment does not cover the other 21 policies. Use the full list.
Related reading: what auditors ask about policies (question 3 is this topic), the 22 policies and their owners, and the template index. Pricing for the Audit Kit is on the pricing page.
Frequently asked questions
- Is a signed acknowledgment required by the SOC 2 criteria?
- The criteria do not name a document, but they expect that personnel know their responsibilities and that policies are communicated. A dated acknowledgment is the evidence auditors accept most readily, and almost every request list asks for it. An alternative such as an LMS completion record works if it names the policies and versions.
- Do contractors need to sign?
- Anyone with access to in-scope systems or data should acknowledge the policies that apply to them, at minimum the Acceptable Use, Information Security and Data Classification policies. Auditors sample from the full list of people with access, which includes contractors.
- How often should people re-acknowledge?
- At onboarding, after every material revision to a policy, and at least annually. If your review cadence is annual and you re-issue the pack after the review, an annual re-acknowledgment lines up with it naturally.
- Can acknowledgment be electronic?
- Yes. E-signature platforms, HR systems, a form with an authenticated login, or a pull request approval in a policy repository all produce acceptable evidence as long as the record shows who, when and which versions. A shared spreadsheet where people type their own names is weak because anyone can edit it.
- Does the free acknowledgment form on this page cover the Audit Kit policies?
- Yes. The form lists all 22 Policyseed policies. The Audit Kit generates the same form as a Word document with your company name, policy versions and effective date already filled in.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.