Policy attestation and acknowledgment tracking: prove who approved each policy and who read which version
Every framework wants written policies. Complies drafts credible starting points from your actual stack, then humans review, approve, and own them, with versions and acknowledgments tracked.
Policy attestation is the recorded proof that a named employee read and accepted a specific version of a policy on a specific date, and it is the policy artifact auditors ask for most often. Complies records both halves of that proof: who approved the document, and who acknowledged it. This page covers the attestation and approval mechanics; the wider category, including how it compares with dedicated policy suites, is covered on our policy management software page. In practice it starts each policy with an AI-drafted starting point tailored to your actual stack: connect AWS and GitHub and your access control and change management drafts reference the tools and practices you really run, not a generic template company. Humans then review, edit, and approve, and nothing becomes an active policy without a named approver, because an auditor will ask who owns each document and when it was last reviewed. Version history records every change with author and date, annual review reminders land on the compliance calendar, and acknowledgment tracking shows exactly which employees have read which version, which is itself evidence auditors routinely request. Each policy is mapped to the controls it supports across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, so one approved document earns credit in every framework that needs it. AI-drafted policy starting points are included from the Starter plan at $79 per month billed yearly. The honest limitation: drafts are starting points, not legal advice, and the review step exists precisely because your company, not the software, is accountable for what its policies say.
It is one capability inside our policy management software. It works alongside compliance tracking software and control mapping software, and plugs straight into iso 27001 compliance software, soc 2 compliance software on every plan from Growth up.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
What changes when it is in place
Drafts from your real stack
AI-drafted starting points reference the tools you actually connected, so the access control policy describes your Okta and GitHub setup instead of a fictional template company.
Human approval, by design
No draft becomes an active policy without a named human approver. Auditors ask who owns each document and when it was reviewed, and Complies always has the answer.
Version history and review cadence
Every edit is recorded with author and date, and annual review reminders land on the compliance calendar, so no policy quietly drifts three years out of date.
Acknowledgment tracking as evidence
See exactly which employees acknowledged which policy version, chase stragglers automatically, and export the record: it is evidence auditors routinely request for security awareness controls.
Common questions
Complies publishes its prices: policy management is included from Starter at $79 per month billed yearly, with Growth at $199 and Scale at $499, and monthly billing available. Most of the category is quote-only. Standalone enterprise policy suites are usually priced per employee per year, and dedicated GRC platforms bundle policy into a larger contract you have to request a quote for.
AI policy management software drafts and maintains written policies with a model instead of a blank template, then routes them through human review. In Complies the draft is generated from your connected stack, so the access control policy describes your actual identity provider and repositories. A named human still edits and approves it, because the company, not the model, is accountable for what a policy says.
It depends on what the policies are for. If you need clinical or manufacturing SOPs with training records, a dedicated document control system fits better. If your policies exist to satisfy SOC 2, ISO 27001, GDPR, HIPAA, or PCI DSS, the deciding feature is whether each policy maps to the controls it supports, so one approved document earns credit in every framework. That mapping is what Complies is built around.
Policy writing software helps you produce the document itself rather than just store it: a structured starting draft, the required sections for your framework, and an editor with version history. The gap most tools leave is what happens after writing, which is approval, distribution, acknowledgment, and annual review. Those are the parts an auditor actually samples.
No, and we built the product so they cannot be. Drafts are starting points generated from your connected stack, and they only become active policies after a named human reviews and approves them. Complies assists with compliance workflows; it is not legal advice. The drafts save you the blank-page week, and the approval step keeps accountability where it belongs, with your company.
It depends on your frameworks. SOC 2 typically expects around a dozen, including information security, access control, change management, incident response, and vendor management. ISO 27001 adds a few of its own. Complies derives the exact list from the frameworks you pick and maps each policy to the controls it supports, so you write what is required and nothing decorative.
Approved policies are distributed to your team, and each person confirms they have read the current version. Complies records who acknowledged what and when, sends automatic reminders to stragglers, and re-runs the cycle when a policy materially changes. The exportable record doubles as audit evidence for security awareness requirements in SOC 2 and ISO 27001.
ISO 27001 Checklist: 13 Steps From Scope to Certification
SOC 2SOC 2 Controls List: All 33 CC1 to CC9 Common Criteria
POLICYAI Policy Management Software: What It Does and Does Not Do
Put policy management on autopilot
All plans include it. Prices are public. Start today.