Skip to content
complianceofficer

Policy attestation software and policy acknowledgement tracking that proves who read which version, and when

Policy attestation software proves that a named person read a named version of a named policy on a named date. That is the whole job, and it is narrower than policy management: the library, the drafting and the approval workflow are a different problem. What an examiner, an auditor or an employment lawyer asks for is the receipt, and specifically a receipt that survives the document having changed three times since.

Most programs fail that test in the same place. The acknowledgement was captured against a policy title rather than a policy version, so a year later nobody can reconstruct what the employee actually saw. Version binding is what turns an acknowledgement into evidence, and it is the first thing to check in any demo.

Complianceofficer sits underneath this. We keep the obligations that apply to your entities identified and current, and we tell you the day a rule moves so you know which policies need a new version and therefore a fresh round of attestation. Below: what the evidence has to contain, where the rules actually require it, the denominator error that makes most attestation rates wrong, and what the platforms cost.

Last updated September 2026. Every vendor pricing page and contract figure on this page was read first hand on 6 September 2026 and is dated where it appears.

Find out which policies you are required to hold, before you buy a tool to distribute them

Pick your industry and size, then the regimes you operate under. The scan returns the obligations that apply to an organization like yours, which of them name a written policy requirement, and the primary source behind each line. No signup, nothing stored.

§ Live · Compliance scan

No signup. Nothing you pick is stored.

Frameworks you answer to

Sample register · fintech, US · what a scan returns

  • § 01 Written AML program with a named officer
  • § 02 KYC and customer due diligence
  • § 03 Sanctions screening lists Changed
  • § 04 PCI DSS v4.0 validation
§ 190 What counts as evidence

What a policy attestation record has to contain to be worth anything

An attestation is a claim about the past, and its value is entirely a function of whether you can reconstruct that past on demand. The failure is almost never that the acknowledgement was not collected. It is that the record does not tie back to a fixed artifact. Here is the difference between a record that holds up and one that does not.

Weak versus defensible policy attestation evidence
Element What most programs capture What survives a challenge
The document Policy title, current file Version number plus an immutable copy of that exact version
The person Name or email address Identity plus the role and entity they held on that date
The time Date the record was exported Timestamp of the acknowledgement itself, not of the report
The population "All employees" The named in-scope list as it stood on the assignment date
The revision Latest version inherits old acknowledgements New version resets status and creates a new assignment
The history Current status only As-of reporting that reproduces last year's number unchanged

The last row is the one buyers almost never test and the one that causes the most damage. Many systems recalculate historical coverage against the current roster and the current document. That means the completion rate you reported to your board in March quietly changes by September, and when someone asks why, there is no answer. Ask a vendor to show you a report as of a date twelve months ago and watch what happens.

§ 191 Where it is required

Is policy attestation legally required?

No US regulation uses the word attestation for this activity, which is why vendor pages tend to gesture vaguely at "compliance requirements" instead of citing anything. The obligations are real, but they arrive as written policy requirements plus an expectation of communication, and the acknowledgement record is how you evidence the second half. These are the ones that come up most often for US teams.

Sources of policy and communication obligations for US organizations
Source Who it reaches What it requires that attestation evidences
45 CFR 164.316 HIPAA covered entities and business associates Written policies and procedures, retained six years from creation or last effective date, whichever is later
21 CFR 11.10(j) FDA regulated life sciences Written policies holding individuals accountable for actions taken under their electronic signatures
31 CFR 1020.210 Banks and other covered financial institutions A system of internal controls within the AML program, which examiners read as including communicated policy
COSO entity level controls SOX filers A code of conduct that is written, communicated and acknowledged, tested by asking who acknowledged which version and when
17 CFR 275.206(4)-7 SEC registered investment advisers Written policies and procedures, reviewed for adequacy and effectiveness no less frequently than annually
FINRA Rule 3110 Broker dealers Written supervisory procedures, with offices of supervisory jurisdiction inspected at least annually on a calendar-year basis

One correction worth making, because a lot of live content still gets it wrong. Rule 206(4)-7 does not currently require the adviser's annual review to be documented in writing. That requirement was added by the Private Fund Adviser Rules in September 2023, the Fifth Circuit vacated those rules in their entirety in June 2024, and the SEC removed the amendment by technical amendments in November 2024. Documenting the review is still the right practice, because exam staff ask for evidence of it, but it is not rule text and you should not let a vendor tell you otherwise.

§ 192 The denominator

How do you calculate a policy attestation rate accurately?

Attestation rate is a fraction, and nearly all the error lives in the denominator rather than the numerator. Counting signatures is easy. Knowing who was supposed to sign is the hard part, and it is where reported coverage detaches from reality.

If the in-scope population comes from a quarterly HR export, every person hired since that export is invisible to the calculation. They are missing from both the numerator and the denominator, so the rate does not drop, it just silently describes a smaller company than the one you run. A program with steady hiring can sit at a reported 98 percent while a tenth of the workforce has never been assigned anything.

Three fixes, in order of how much they buy you. Join the policy system to a live HR feed so joiners appear within a day. Handle leavers by excluding them as of the measurement date rather than deleting the record, because deleting people who left mid-cycle retroactively improves last year's number and destroys your ability to reproduce it. Then stamp every report with an as-of date, so a number that gets challenged in an examination can be reconstructed rather than defended from memory.

The cut that finds real problems is coverage by population, not coverage overall. An aggregate of 96 percent is comfortable. The same data sliced by department routinely shows one team at 40 percent, and if that team is the one the policy governs, the aggregate was hiding the only finding that mattered. Report by policy, by population and by entity separately, and never let a single blended percentage stand in for all three.

§ 193 Cost

How much does policy attestation software cost?

Standalone policy and attestation platforms are one of the cheaper things a compliance function buys, and materially cheaper than the GRC suites they are often shortlisted against. On 6 September 2026 we opened thirteen vendor pricing URLs in this market and pulled aggregated contract data for the vendors that have it. Seven of the thirteen pricing pages returned a 404: PowerDMS, NAVEX, ConvergePoint, Mitratech, Ideagen, DocTract and RLDatix. Five resolved but displayed no dollar figure at all. Exactly one published a price.

Policy management and attestation platform contract data, read 6 September 2026
Vendor Median annual contract Recorded range Public pricing page, 6 Sep 2026
PowerDMS $7,233 $619 to $18,423 404
NAVEX $7,851 $1,535 to $28,553 404
Mitratech $10,386 $6,475 to $18,907 404
VComply Not recorded Not recorded Modules start at $1,000/mo
ComplianceBridge Not recorded Not recorded Silver, Gold, Platinum, quote only
SAI360 Not recorded Not recorded Essentials, Professional, Enterprise, quote only
Onspring $33,808 $9,972 to $55,810 Licensing model only, no figure
Diligent $25,335 $5,500 to $48,323 Request form, no figure

The gap in that table is the useful part. A dedicated policy and attestation tool lands somewhere around $7,000 to $10,400 at the median. The GRC suites that also contain a policy module sit three to five times higher: Diligent at $25,335, Onspring at $33,808, and further up the market Hyperproof at $41,400 and Workiva at $49,420. If attestation is the actual requirement, buying it inside a suite means paying suite money for a feature that a $7,000 product does at least as well. The suite is worth it when you need the control testing and audit workflow too, and not otherwise.

VComply is worth calling out because it was the only vendor of the thirteen that published a number, and because its unit is unusual. It prices by module with unlimited users, invoices annually, and states a twelve month minimum contract period. Almost everyone assumes policy software is priced per employee, and per employee pricing is what makes it expensive to roll out to a large frontline workforce who each need to acknowledge two documents a year. If that is your shape, a per-module vendor changes the arithmetic completely, and it is worth asking every shortlisted vendor to quote both ways.

NAVEX's average discount off first quote came in at 14.83 percent across 73 recorded purchases, which is thin for a market with this many alternatives. The pattern we keep seeing holds: discount tracks substitutability, and NAVEX bundles ethics hotline and case management where there is no easy drop-in. Buying attestation alone from a vendor whose leverage comes from the hotline is how you end up paying hotline prices. The full breakdown is in policy management software pricing.

§ 194 Buying

What are alternatives to manual policy tracking?

There are four routes and only three of them work. A dedicated policy and attestation platform is the cleanest fit if attestation is the requirement you are solving. The policy module of a broader GRC suite makes sense when you also need control testing and issue management, and you should expect to pay three to five times more for the privilege. A learning management system is a real option that plenty of mid-sized companies use successfully, with one caveat covered below. Spreadsheets and email receipts are the fourth, and they fail audits for a structural reason rather than a tidiness one: they cannot prove which version a person saw.

Can you use an LMS for policy attestation?

You can, and the assignment and completion tracking is genuinely similar. The gap is version control of the document itself. An LMS tracks completion of a course, so when someone swaps the attached PDF for an updated one, the completion records usually survive unchanged and every historical attestation now points at a document the signer never saw. If you take this route, keep the authoritative versioned document in a system that enforces versioning and put the version number in the course title, so the two records can be tied back together later.

How often should employees re-attest to policies?

Annually for a code of conduct, plus on hire, plus on every material revision. Event driven re-attestation matters more than the calendar, because a rule change that forces a policy edit should reach the people it governs within days rather than at the next annual cycle. The case most programs miss is the role change: someone promoted into a position carrying extra obligations frequently never gets assigned the policies that come with it, because assignment was done once by department and never re-evaluated.

What is the difference between policy attestation and policy acknowledgement?

Vendors use the two words interchangeably and no US regulation defines either. Where teams do draw a line, acknowledgement means the person confirms they received and read the document, while attestation means they additionally affirm something about their own conduct, such as having no undisclosed conflict of interest or no outside business activity. The second is more useful in an investigation because it is a statement of fact by the employee rather than a receipt, and a false one is a disciplinary matter on its own.

§ 195 Where this fits

Attestation is the last step, and it is only as good as the policy behind it

Collecting a signature against a policy that no longer reflects the rule is a well evidenced way of proving your whole workforce read something wrong. That is the failure mode attestation tooling cannot see, because it measures distribution rather than correctness, and it is the reason we built the obligations layer first.

The full document lifecycle, from drafting through approval to scheduled review, is covered on policy compliance software, which is the parent page for this one. If the trigger for re-attestation is what you care about, that is regulatory change management software. For SOX filers, the code of conduct attestation is an entity level control tested every year, which sits inside SOX compliance software, and the electronic signature control set for FDA regulated teams is on 21 CFR Part 11 compliant software.