SOC 2 policy acknowledgment: why auditors ask for it and how to collect it

A policy nobody has read is a document, not a control. Acknowledgment is how you show the auditor that the people in scope know what the policies say and have agreed to follow them. This guide covers why it is requested, which criteria it supports, how to collect it without a compliance platform, and a form you can copy today.

Why auditors ask

Several of the common criteria in the 2017 Trust Services Criteria are about people rather than technology. In our own words: CC1.1 expects a commitment to integrity and ethical values that is communicated and enforced; CC1.4 expects that people are competent for their roles; CC1.5 expects that people are held accountable for their responsibilities; CC2.2 expects that objectives and responsibilities are communicated internally; and CC5.3 expects that control activities are deployed through policies and procedures. For each of these the auditor needs evidence that the policies reached the people they apply to. A signed, dated acknowledgment that lists the policies and their versions is the simplest evidence that satisfies all five.

Two policies in the Policyseed set make acknowledgment an explicit requirement. The Human Resources Security Policy requires acknowledgment of the full pack at onboarding and after every review, and the Acceptable Use Policy requires its own signed acknowledgment because it is the document that sets out personal obligations. The Information Security Policy states that all personnel must comply with the policy set, which is what the acknowledgment confirms.

What counts as evidence

An acknowledgment record needs to show four things:

  • Who: the person’s name, and ideally their role, matched to an entry in the personnel list the auditor will sample from.
  • What: which policies, at which version and effective date. “I have read the security policies” without a list is routinely rejected because the auditor cannot tell whether the current versions were covered.
  • When: a date that is on or after the effective date of the policies listed, and before the person was granted access (for onboarding) or within the review cycle (for re-acknowledgment).
  • Assent: a signature, an e-signature record, an authenticated click, or an approval in a system that identifies the user. The record must not be editable by the person after the fact.

When to collect it

  1. Onboarding, before access to production, source code or customer data is granted. Most companies put it in the first-day checklist alongside the equipment form.
  2. After a material revision. If a policy changes in a way that alters what is expected of people (a new MFA requirement, a new data-handling rule), re-issue it. Typo fixes do not require a new round; record them as a minor version.
  3. At least annually, usually in the same month as the policy review so the revision history and the acknowledgments line up. Semi-annual and quarterly cadences are chosen in the intake and appear in section 8 of every policy.
  4. For contractors and vendors with access, at engagement start, covering at least the Acceptable Use, Information Security and Data Classification policies. See the Vendor and Third-Party Risk Management Policy.

Five ways to run it at a startup

MethodEvidence producedGood forWatch out for
Printed or PDF form (below), signed and scannedSigned document per personUnder 20 people, first examinationChasing signatures; store scans in one folder by name
E-signature platformAudit trail with timestamps and IPRemote teams, contractorsInclude the policy list and versions in the envelope, not just a link
HR platform attestationCompletion report per employeeCompanies already on an HRISContractors are often outside the HRIS; cover them separately
Pull request approval in a policy repositoryGit history with authenticated approvalsEngineering-heavy teams keeping policies as MarkdownNon-engineers need a path too; auditors accept it but ask for an export
Authenticated form (SSO-gated)Response sheet with login identity and timestampFast annual re-acknowledgmentLock the response sheet; export it with the date visible

Free acknowledgment form

Copy the text below into a document, fill in the company and version details, and use it as-is or as the body of an e-signature envelope. It lists all 22 Policyseed policies; delete rows for policies you have not adopted. The Audit Kit produces the same form as a Word document with your company name, versions and effective date filled in.

POLICY ACKNOWLEDGMENT FORM

Company: ______________________________
Employee / contractor name: ______________________________
Role: ______________________________
Start date (if onboarding): ____ / ____ / ________

I confirm that I have received, read and understood the following policies,
at the version and effective date shown, and that I agree to comply with them
for as long as I work with the company:

  [ ] P01  Information Security Policy                          v____  effective ____-__-__
  [ ] P02  Acceptable Use Policy                                v____  effective ____-__-__
  [ ] P03  Access Control Policy                                v____  effective ____-__-__
  [ ] P04  Authentication and Password Policy                   v____  effective ____-__-__
  [ ] P05  Asset Management Policy                              v____  effective ____-__-__
  [ ] P06  Data Classification and Handling Policy              v____  effective ____-__-__
  [ ] P07  Data Retention and Disposal Policy                   v____  effective ____-__-__
  [ ] P08  Encryption and Key Management Policy                 v____  effective ____-__-__
  [ ] P09  Change Management Policy                             v____  effective ____-__-__
  [ ] P10  Secure Software Development Policy                   v____  effective ____-__-__
  [ ] P11  Vulnerability and Patch Management Policy            v____  effective ____-__-__
  [ ] P12  Logging and Monitoring Policy                        v____  effective ____-__-__
  [ ] P13  Incident Response Policy                             v____  effective ____-__-__
  [ ] P14  Business Continuity and Disaster Recovery Policy     v____  effective ____-__-__
  [ ] P15  Backup and Recovery Policy                           v____  effective ____-__-__
  [ ] P16  Vendor and Third-Party Risk Management Policy        v____  effective ____-__-__
  [ ] P17  Risk Assessment and Management Policy                v____  effective ____-__-__
  [ ] P18  Human Resources Security Policy                      v____  effective ____-__-__
  [ ] P19  Endpoint and Workstation Security Policy             v____  effective ____-__-__
  [ ] P20  Network and Infrastructure Security Policy           v____  effective ____-__-__
  [ ] P21  Physical and Remote Work Security Policy             v____  effective ____-__-__
  [ ] P22  Privacy and Data Protection Policy                   v____  effective ____-__-__

I understand that:
  - questions about these policies should go to the Security Owner named in the
    Information Security Policy;
  - security incidents and suspected policy violations must be reported using
    the contact in the Incident Response Policy;
  - exceptions must be requested in writing as described in section 6 of the
    relevant policy and are not valid until approved;
  - failure to comply may result in the actions described in section 7
    (Enforcement) of each policy, up to and including termination of employment
    or contract, subject to applicable law.

Signature: ______________________________   Date: ____ / ____ / ________

For the company
Witnessed by (People/HR Lead or Security Owner): ______________________________
Signature: ______________________________   Date: ____ / ____ / ________

Retention: keep this form for the duration of employment plus the current
examination period and one year. Store with personnel records.

Mistakes that turn into findings

  • Acknowledging a folder. “I have read the policies in the shared drive” with no versions. The auditor cannot tie it to the policies they examined.
  • Not re-collecting after revisions. The pack was revised in March; the acknowledgments are from the previous year. The revision history says v1.1; the signatures say v1.0.
  • Missing contractors. The auditor samples from the identity provider’s user list, and three of the names have no acknowledgment because they are not employees.
  • No tracker. You cannot say who has not signed. Keep a one-page list: name, role, date signed, version. The Audit Kit’s evidence checklist has a row for it.
  • Acceptable Use only. The AUP acknowledgment does not cover the other 21 policies. Use the full list.

Related reading: what auditors ask about policies (question 3 is this topic), the 22 policies and their owners, and the template index. Pricing for the Audit Kit is on the pricing page.

Frequently asked questions

Is a signed acknowledgment required by the SOC 2 criteria?
The criteria do not name a document, but they expect that personnel know their responsibilities and that policies are communicated. A dated acknowledgment is the evidence auditors accept most readily, and almost every request list asks for it. An alternative such as an LMS completion record works if it names the policies and versions.
Do contractors need to sign?
Anyone with access to in-scope systems or data should acknowledge the policies that apply to them, at minimum the Acceptable Use, Information Security and Data Classification policies. Auditors sample from the full list of people with access, which includes contractors.
How often should people re-acknowledge?
At onboarding, after every material revision to a policy, and at least annually. If your review cadence is annual and you re-issue the pack after the review, an annual re-acknowledgment lines up with it naturally.
Can acknowledgment be electronic?
Yes. E-signature platforms, HR systems, a form with an authenticated login, or a pull request approval in a policy repository all produce acceptable evidence as long as the record shows who, when and which versions. A shared spreadsheet where people type their own names is weak because anyone can edit it.
Does the free acknowledgment form on this page cover the Audit Kit policies?
Yes. The form lists all 22 Policyseed policies. The Audit Kit generates the same form as a Word document with your company name, policy versions and effective date already filled in.

Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.