- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2024 05:39 PM
Can you give us a specific example of how Policy Acknowledgement is used in a real business use case?
My understanding is that it is a questionnaire used to confirm policy compliance with each company's employees.
(Do you mean whether they are actually compliant with what the policy says? Is that what you mean?
In that case, I don't see a clear difference between this and Attestation in terms of business operations.
Please could you please enlighten us?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-13-2024 12:56 AM
Hi @Ohki_Yamamoto1 ,
Policy acknowledgment forms are more than just a bureaucratic requirement; they are a strategic tool for bridging the gap between communication and compliance.
As your business operations and the regulatory landscape evolve, so will your policies. It’s essential employees are kept up-to-date. But communicating new policies isn’t enough; you have to make sure they’re read, understood, and accepted.
They fulfil several useful functions, including:
● Evidence of Communication: Provides a tangible record that the employee has been informed of the new policy.
● Accountability: Ensures employees understand their responsibilities and can be held accountable for adhering to company policies.
● Legal Protection: Serves as evidence in legal or regulatory scenarios to prove the company informed employees of specific policies or procedures.
● Promotes Compliance: Emphasizes the importance of the policy, encouraging employees to comply.
● Feedback Loop: Allows employees to ask questions or seek clarifications before signing, ensuring they fully understand the policy.
● Standardized Process: Provides a consistent approach to policy dissemination and acknowledgment across an organization.
● Audit Trail: Assists in internal and external audits by providing a paper trail of policy awareness and acceptance.
Now, Let's undestand by an example:
We have Policy called "Facility Management policy" which needs to be Read and Acknowledged by a set of "Audience" ( which is nothing but a user criteria) .
Now you have a option to run a policy acknowledgement campaign such that this policy can be rolled out for the employees who needs to acknowledge that they have read and abide by it.
Product Document : Acknowledge a policy
For the policy to be rolled out it has to be in Published state:
You have option to give the employee/user a ability to decline the policy and raise a exception request or this policy needs to be adhered.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-13-2024 12:56 AM
Hi @Ohki_Yamamoto1 ,
Policy acknowledgment forms are more than just a bureaucratic requirement; they are a strategic tool for bridging the gap between communication and compliance.
As your business operations and the regulatory landscape evolve, so will your policies. It’s essential employees are kept up-to-date. But communicating new policies isn’t enough; you have to make sure they’re read, understood, and accepted.
They fulfil several useful functions, including:
● Evidence of Communication: Provides a tangible record that the employee has been informed of the new policy.
● Accountability: Ensures employees understand their responsibilities and can be held accountable for adhering to company policies.
● Legal Protection: Serves as evidence in legal or regulatory scenarios to prove the company informed employees of specific policies or procedures.
● Promotes Compliance: Emphasizes the importance of the policy, encouraging employees to comply.
● Feedback Loop: Allows employees to ask questions or seek clarifications before signing, ensuring they fully understand the policy.
● Standardized Process: Provides a consistent approach to policy dissemination and acknowledgment across an organization.
● Audit Trail: Assists in internal and external audits by providing a paper trail of policy awareness and acceptance.
Now, Let's undestand by an example:
We have Policy called "Facility Management policy" which needs to be Read and Acknowledged by a set of "Audience" ( which is nothing but a user criteria) .
Now you have a option to run a policy acknowledgement campaign such that this policy can be rolled out for the employees who needs to acknowledge that they have read and abide by it.
Product Document : Acknowledge a policy
For the policy to be rolled out it has to be in Published state:
You have option to give the employee/user a ability to decline the policy and raise a exception request or this policy needs to be adhered.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-13-2024 03:10 AM
Thank you for the detailed explanation. I now have a better understanding of the use case for policy acknowledgments!
By the way, what are the use cases for control attestations? I am particularly interested in knowing who the actor is for responding to control attestations.
Since control attestations are surveys that collect evidence proving that controls are implemented, I assume that the actors answering them would be each employee, similar to policy acknowledgements. Is this correct?
According to the description of the newly added "GRC employee" user role in Xanadu, it seems they can respond to policy acknowledgements. However, there was no mention of whether they can respond to control attestations, so I am confirming this point.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-13-2024 03:26 AM
Hi @Ohki_Yamamoto1 ,
Good to hear i could help you 🙂
Your Original qustion has been answered, you can raise another question for your second question Control Attestations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-13-2024 03:43 AM
Hi @Community Alums ,
Thank you. I have marked it as Correct.
Additionally, I have posted a new question regarding control attestations below. I would appreciate it if you could provide an answer.