Compliance Policy and Attestation Template
Three documents and three sheets that tie every attestation to the exact policy version it was given for, not just whether one happened.
Free download · No account needed
Attestation Tracker · Thornwell Retail Group, Inc. · Anti-Harassment Policy, v2 to v3
One reissue. The old tracker kept reporting 100%. The version-locked one showed the real number instead.
Same 64 employees, same reissue date, January 12, 2026. Only the tracker design differs.
| Employee | Old tracker (acknowledged: Y/N) | Version-locked tracker |
|---|---|---|
| Kevin Grady | Acknowledged | v2 stale, v3 due Feb 11 |
| Nicholas Vance | Acknowledged | v3 attested Feb 2 |
| Steven Iversen | Acknowledged | Not yet due, onboarding by Aug 9 |
58 of 64 on v3, 4 overdue, 2 not yet due. The old column showed 100% the whole time.
One column cannot distinguish the first row from the second. A version field can, and it is the only thing that changed between the two trackers.
Most templates for a compliance policy stop at the acknowledgment form: a signature line stating an employee received the policy, with no field naming which version. The Department of Justice's Evaluation of Corporate Compliance Programs asks a harder question, whether the program is disseminated to, and understood by, employees in practice, not whether a signed form exists somewhere in a file. A generic acknowledgment form's own boilerplate usually answers the wrong way, stating one signature covers every future revision regardless of whether the employee ever saw the revised text.
This pack ties every attestation to the version it was actually given for. The Attestation Tracker records each employee's acknowledgment against the Policy Register's current version, so reissuing a policy stales every existing row for that policy rather than leaving one old signature to stand for whatever text replaces it. A second, independent clock runs alongside it on the Review Calendar: a jurisdiction that mandates retraining on a fixed interval keeps requiring it on that schedule even in a year the underlying policy text never changes at all.
Applied to Thornwell Retail Group, Inc., a 64-employee retailer across nine locations in six states: the Anti-Harassment and Non-Retaliation Policy moves from v2 to v3 on January 12, 2026, inside the company's own 30-day re-attestation window. By the window's close, 58 of 64 employees have attested to v3; four are still on v2 and now overdue; two are new hires not yet due under their own onboarding grace period. The predecessor spreadsheet had one yes-or-no column and had shown 100% straight through the reissue, since it never recorded which version anyone actually signed.
What's in the pack
Policy Set
Six policies, one register entry each, naming the version currently in force and the statute or governance basis behind it.
Attestation Form
One acknowledgment per employee per policy, worded to name the exact version being signed rather than the policy in general.
Training Materials
Delivery notes and talking points for each policy, tied to the same version field the attestation form and tracker both key on.
Policy Register
Every policy's current version, effective date, and owner in one place, so a reissue has one row to update, not six documents to hunt through.
Attestation Tracker
Every employee's signature logged against the version they actually signed, so a reissue stales the old rows instead of leaving them counted as current.
Review Calendar
Each jurisdiction's own mandated interval tracked independently of version, so a state that requires retraining on a schedule gets it even in a year nothing else changed.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and describe the policies and the roster you already have, or download the Word documents and CSV sheets from the template library and build the register yourself.
- 2
Log every policy's current version first
Every policy gets one row on the Policy Register naming its current version and effective date, before any attestation is collected against it.
- 3
Tie every signature to that version
Each signature on the Attestation Tracker ties to the version in force at the time, so a reissue stales the rows it replaces instead of leaving them marked current.
- 4
Let the Review Calendar run its own clock
A jurisdiction's mandated interval keeps firing on schedule even in a year the policy text does not change, tracked separately from any reissue.
Frequently asked questions
Is this template free?
Yes, no account or card required. The download is Word documents and CSV sheets in a zip. Edit with AI is the second half: the agent builds the Policy Register and Attestation Tracker from the policies and the roster you already have.
What am I actually downloading?
Three Word documents and three CSV sheets, zipped. The registers and calendar open in Excel, Numbers or Google Sheets straight off the download, and the policy set, attestation form and training materials open in Word or Pages.
Why isn't a signed acknowledgment form enough on its own?
A signature proves a copy went out once. It does not say which version was in the copy, or whether a later reissue already made that signature stale. The DOJ's evaluation framework asks whether a policy is disseminated to, and understood by, employees currently, not whether a form with no version field exists somewhere.
What happens when a jurisdiction requires retraining on a schedule even though the policy text hasn't changed?
The Review Calendar tracks that separately from any reissue. California requires the training every two years per employee regardless of version, and New York requires it annually. Both intervals keep running in a year the underlying policy text stays exactly the same.
Who updates the Attestation Tracker when a policy is reissued?
The Policy Register's version field is the trigger. The moment a policy's current version changes there, every existing row for that policy on the Attestation Tracker counts as needing a new signature. The one exception is anyone hired after the new version's effective date, who attests to it directly at onboarding.
How does this fit with the other legal packs?
The compliance program pack sets the Training Plan's cadence by risk tier; this pack turns that cadence into a per-employee attestation record with a version on every row. When an investigation finds a policy existed but nobody had attested to the current version, the internal investigation pack is often what surfaced the gap.
Tie every attestation to the version it was given for
Take the Word documents and CSV sheets blank, or open this exact pack in River and describe the policies you already have.
Edit with AI