River
Y CombinatorBacked by Y Combinator
FREE TEMPLATE

Compliance Policy and Attestation Template

Three documents and three sheets that tie every attestation to the exact policy version it was given for, not just whether one happened.

Free download  ·  No account needed

Attestation Tracker  ·  Thornwell Retail Group, Inc.  ·  Anti-Harassment Policy, v2 to v3

One reissue. The old tracker kept reporting 100%. The version-locked one showed the real number instead.

Same 64 employees, same reissue date, January 12, 2026. Only the tracker design differs.

EmployeeOld tracker (acknowledged: Y/N)Version-locked tracker
Kevin GradyAcknowledgedv2 stale, v3 due Feb 11
Nicholas VanceAcknowledgedv3 attested Feb 2
Steven IversenAcknowledgedNot yet due, onboarding by Aug 9

58 of 64 on v3, 4 overdue, 2 not yet due. The old column showed 100% the whole time.

One column cannot distinguish the first row from the second. A version field can, and it is the only thing that changed between the two trackers.

Most templates for a compliance policy stop at the acknowledgment form: a signature line stating an employee received the policy, with no field naming which version. The Department of Justice's Evaluation of Corporate Compliance Programs asks a harder question, whether the program is disseminated to, and understood by, employees in practice, not whether a signed form exists somewhere in a file. A generic acknowledgment form's own boilerplate usually answers the wrong way, stating one signature covers every future revision regardless of whether the employee ever saw the revised text.

This pack ties every attestation to the version it was actually given for. The Attestation Tracker records each employee's acknowledgment against the Policy Register's current version, so reissuing a policy stales every existing row for that policy rather than leaving one old signature to stand for whatever text replaces it. A second, independent clock runs alongside it on the Review Calendar: a jurisdiction that mandates retraining on a fixed interval keeps requiring it on that schedule even in a year the underlying policy text never changes at all.

Applied to Thornwell Retail Group, Inc., a 64-employee retailer across nine locations in six states: the Anti-Harassment and Non-Retaliation Policy moves from v2 to v3 on January 12, 2026, inside the company's own 30-day re-attestation window. By the window's close, 58 of 64 employees have attested to v3; four are still on v2 and now overdue; two are new hires not yet due under their own onboarding grace period. The predecessor spreadsheet had one yes-or-no column and had shown 100% straight through the reissue, since it never recorded which version anyone actually signed.

One version field on the register, and every downstream row that depends on it

The Policy Register, the Attestation Tracker, and the Review Calendar behind both.

Policy Register (excerpt)

6 policies, one row each, naming the version in force.

PolicyVersionEffectiveBasis
Code of Conductv42025-01-15U.S.S.G. 8B2.1(b)(4)(A)
Anti-Harassment and Non-Retaliationv32026-01-12Cal. Gov. Code 12950.1; NY Labor Law 201-g
Workplace Safetyv22025-04-0729 C.F.R. 1904.32

1 of 6 policies reissued in the last 60 days

The register is the trigger. The moment this row's version changes, the tracker knows which attestations just went stale.

Attestation Tracker (excerpt)

4 of 64 employees, spanning all three outcomes for the Anti-Harassment reissue.

EmployeeLocationAnti-Harassment Policy
Nicholas VanceSan Diego, CAv3 attested 2026-02-02
Kevin GradyAustin, TXv2 stale, v3 due 2026-02-11
Steven IversenSacramento, CANot yet due, onboarding by 2026-08-09
George XiongAlbany, NYv3 attested 2026-02-09

58 of 64 attested to v3, 4 overdue, 2 not yet due

Every cell names a version. "Acknowledged" alone cannot distinguish the first row from the second.

Review Calendar (excerpt)

The Anti-Harassment Policy's three cadences, run independent of whether the text changes again.

PopulationBasisIntervalIndependent of version?
California (18)Cal. Gov. Code 12950.1Every 24 monthsYes
New York (9)NY Labor Law 201-gEvery 12 monthsYes
All other (37)Company policyNone independent of versionNo

27 of 64 employees sit on a calendar clock that fires even if v3 is never reissued again

Version and calendar are two separate triggers. A tracker with only one can miss whichever one it does not have.

What's in the pack

01

Policy Set

Six policies, one register entry each, naming the version currently in force and the statute or governance basis behind it.

02

Attestation Form

One acknowledgment per employee per policy, worded to name the exact version being signed rather than the policy in general.

03

Training Materials

Delivery notes and talking points for each policy, tied to the same version field the attestation form and tracker both key on.

04

Policy Register

Every policy's current version, effective date, and owner in one place, so a reissue has one row to update, not six documents to hunt through.

05

Attestation Tracker

Every employee's signature logged against the version they actually signed, so a reissue stales the old rows instead of leaving them counted as current.

06

Review Calendar

Each jurisdiction's own mandated interval tracked independently of version, so a state that requires retraining on a schedule gets it even in a year nothing else changed.

How to use it

  1. 1

    Open in River, or take it blank

    Open the pack in River and describe the policies and the roster you already have, or download the Word documents and CSV sheets from the template library and build the register yourself.

  2. 2

    Log every policy's current version first

    Every policy gets one row on the Policy Register naming its current version and effective date, before any attestation is collected against it.

  3. 3

    Tie every signature to that version

    Each signature on the Attestation Tracker ties to the version in force at the time, so a reissue stales the rows it replaces instead of leaving them marked current.

  4. 4

    Let the Review Calendar run its own clock

    A jurisdiction's mandated interval keeps firing on schedule even in a year the policy text does not change, tracked separately from any reissue.

Frequently asked questions

Is this template free?

Yes, no account or card required. The download is Word documents and CSV sheets in a zip. Edit with AI is the second half: the agent builds the Policy Register and Attestation Tracker from the policies and the roster you already have.

What am I actually downloading?

Three Word documents and three CSV sheets, zipped. The registers and calendar open in Excel, Numbers or Google Sheets straight off the download, and the policy set, attestation form and training materials open in Word or Pages.

Why isn't a signed acknowledgment form enough on its own?

A signature proves a copy went out once. It does not say which version was in the copy, or whether a later reissue already made that signature stale. The DOJ's evaluation framework asks whether a policy is disseminated to, and understood by, employees currently, not whether a form with no version field exists somewhere.

What happens when a jurisdiction requires retraining on a schedule even though the policy text hasn't changed?

The Review Calendar tracks that separately from any reissue. California requires the training every two years per employee regardless of version, and New York requires it annually. Both intervals keep running in a year the underlying policy text stays exactly the same.

Who updates the Attestation Tracker when a policy is reissued?

The Policy Register's version field is the trigger. The moment a policy's current version changes there, every existing row for that policy on the Attestation Tracker counts as needing a new signature. The one exception is anyone hired after the new version's effective date, who attests to it directly at onboarding.

How does this fit with the other legal packs?

The compliance program pack sets the Training Plan's cadence by risk tier; this pack turns that cadence into a per-employee attestation record with a version on every row. When an investigation finds a policy existed but nobody had attested to the current version, the internal investigation pack is often what surfaced the gap.

Tie every attestation to the version it was given for

Take the Word documents and CSV sheets blank, or open this exact pack in River and describe the policies you already have.

Edit with AI