Policy updates
Publishes the revised version from the approved source, retires the copy before it, and records who has read the version that is actually current.
Tools
Hyperion, LawToolBox, OneTrust, Vanta
Outcomes
Retired versions withdrawn, not just ignored • Covered staff list read from the system • Each acknowledgment tied to a version • Outstanding acknowledgments listed weekly
Documentation
Instruction-ready detail below
What breaks: the current policy version lives in one shared drive, and the version people actually read is whichever copy a manager forwarded six months ago. The compliance lead emails every department chasing acknowledgments because the acknowledgment record was never kept, and headcount changes mean the covered list is stale before the campaign even starts. What the workflow does: it publishes the revised policy from the approved source, retires the previous version instead of leaving it in place, and lists everyone the policy covers from the system of record rather than from a list someone last edited. Each person receives the change with the sections that changed to them, and their acknowledgment is recorded against that version with a date. Staff who have not acknowledged are listed weekly to their manager instead of to a shared inbox nobody owns. A policy with no acknowledgment from the whole covered group escalates to the compliance lead rather than being treated as done. What a person still approves: the compliance lead approves the revised wording before publication, and the business owner decides whether a late acknowledgment is a real gap.