Policy Health & Attestation Reporting Workbook
Reports document currency and acknowledgement coverage in the two forms management actually acts on: what is overdue and who has not signed.
Available soon
- Format
- Excel
- Size
- 95 KB
- Length
- 13 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Register Data
- Acknowledgement Data
- Overdue Acknowledgements
- Metric Definitions
- Quarterly Report
- Trend
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Register Data sheet: in the Policy Register & Review Schedule, copy the register table's rows (sheet Register, columns A to Z, from row 4 down) and paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order. |
| 2 | Acknowledgement Data sheet: in the Policy Attestation & Acknowledgement Tracker, copy the Summary sheet's 'Acknowledgement by policy' rows (columns B to N, one row per policy, not the 'All policies' total) and paste them as values into cell B4. |
| 3 | Overdue Acknowledgements sheet: from the same tracker, copy the Overdue by Manager rows (columns B to J) and paste them as values into cell B4. |
| 4 | Delete the EXAMPLE rows on the three data sheets before you paste, and check that dates are real dates (right-aligned), not text. |
| 5 | Quarterly Report sheet: enter the report date, normally the last day of the quarter. The EXAMPLE uses 2026-09-30; replace it with your quarter end. Document figures are recalculated at this date from the pasted register; acknowledgement figures are as the tracker calculated them at its own As-at date, so set that to the same date before copying. |
| 6 | Read the four headline measures. Each has its target and a status in words; the colour only repeats the word. Add a line of commentary to every measure that missed its target or moved. |
| 7 | Name what is overdue and who has not signed: the report lists the documents past review, triggered or in force without approval, the coverage of each policy, and the overdue acknowledgements by manager. Add the action and date agreed for each document. |
| 8 | Trend sheet: type the previous three quarters' results from the reports you kept (the current quarter fills in). Keep a copy of this workbook for each quarter as the record. |
| 9 | Complete 'What to tell management' and take the report to [[e.g. Executive Committee, or the management body]] every quarter (PF-12). |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The EXAMPLE is a software services company with 240 staff in two offices, an NIS2 important entity, as at 2026-09-30: the same register as the Policy Register & Review Schedule and the same acknowledgement figures as the Policy Attestation & Acknowledgement Tracker. PM-01 is 2 (AUP-001, 91 days past review; BKP-001, 46 days past review); PM-02 is 0; PM-03 is 907 of 960 person-and-policy pairs; PM-04 is 4, counted on the tracker's named sample of 12 people. The previous three quarters on the Trend sheet are EXAMPLE figures typed in, as you would from earlier reports.
PM-03 is counted as: Acknowledged person-and-policy pairs ÷ in-scope pairs, across Policy-tier documents that require acknowledgement. The whole-population totals come from the tracker's Reported columns. PM-04 can only name people listed individually in the tracker; if your tracker holds totals for some policies, say so in the commentary.
Columns used from the register: Document ref, Title, Tier, Owner, Lifecycle status, Approval date, Approved by, Approved at the tier's level, Next review date, Review trigger, Where published. The register's own Status and Days to review are carried across but not used: they were calculated at its as-at date, not your report date.
Tailoring — small organisation: the report can be one page — the four measures, the overdue documents and the names. Take it to whoever approves your policies, every quarter.
Tailoring — regulated entity (NIS2, DORA): take the report to the management body. Documents past review are named with their approval dates (Delegated Regulation (EU) 2024/1774 Art 2(2)(b), (c)); keep each quarter's copy as the record of how the policies' implementation is monitored.
Tailoring — IT run by a service provider: include the provider's documents that carry out your policies in the register you paste, and ask the provider for its staff's acknowledgement figures where they are in scope.
Register Data
Paste the Policy Register & Review Schedule table here as values (columns A–Z, from row 4). Columns AA–AG are calculated at the report date. The 10 EXAMPLE rows are that register's example — delete them first.
| Example | Document ref | Title | Tier | Topic (PT-nn) | Topic | Owner | Approver required | Version | Lifecycle status | Approval date | Approved by | Approved at the tier's level | Review interval (months) | Next review date | Status | Days to review | Review due soon | Review order | Review trigger | Trigger details | Triggered review | Where published | Superseded version archived | Record check | Notes | Next review (calc) | Past review at report date (calc) | Days past review (calc) | In force without approval (calc) | Triggered review (calc) | Why listed (calc) | Listed no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | ISP-001 | Information Security Policy | Policy | PT-01 | Information security policy (the top policy) | Chief Operating Officer | Executive management (the management body, or its delegate for the top policy) | 3.0 | Approved | 12 Mar 2026 | Executive Committee (without the Chief Operating Officer) | Yes | 12 | 12 Mar 2027 | Approved | 163 | 5 | Intranet policy library | Yes | OK | 12 Mar 2027 | |||||||||||
| EXAMPLE | AUP-001 | Acceptable Use Policy | Policy | PT-02 | Acceptable use of information and technology | Head of IT | Executive management (the management body, or its delegate for the top policy) | 2.1 | Approved | 1 Jul 2025 | Executive Committee | Yes | 12 | 1 Jul 2026 | Review overdue | -91 | 1 | Intranet policy library | Yes | Review overdue more than 30 days: escalate (PF-06, PM-01) | Escalated to executive management on 2026-07-31, 30 days overdue. The owner started the review in September; the changes are material, so the next version is 3.0. Version 2.1 stays in force until 3.0 is approved. | 1 Jul 2026 | Yes | 91 | Past review, escalate | 1 | ||||||
| EXAMPLE | ACP-001 | Access Control Policy | Policy | PT-03 | Access control and identity | Head of IT | Executive management (the management body, or its delegate for the top policy) | 2.0 | Approved | 20 Jan 2026 | Executive Committee | Yes | 12 | 20 Jan 2027 | Approved | 112 | 3 | An audit or assessment finding against the document | Internal audit, September 2026: the policy does not cover emergency (break-glass) administrator accounts: who may use them, and how each use is reviewed. | Review now | Intranet policy library | Yes | Triggered review: review now (PF-06) | Review brought forward by the audit finding; the owner is drafting the change to add emergency administrator accounts. | 20 Jan 2027 | Yes | Triggered review | 2 | ||||
| EXAMPLE | INC-001 | Incident Management Policy | Policy | PT-05 | Incident management | Head of Information Security | Executive management (the management body, or its delegate for the top policy) | 1.2 | Approved | 4 May 2026 | Executive Committee | Yes | 12 | 4 May 2027 | Approved | 216 | 6 | Intranet policy library | Yes | OK | 4 May 2027 | |||||||||||
| EXAMPLE | SUP-001 | Supplier Security Policy | Policy | PT-08 | Supplier and third-party security | Head of Procurement | Executive management (the management body, or its delegate for the top policy) | 1.0 | Awaiting approval | 12 | Awaiting approval | Not applicable (first version) | OK | With the Executive Committee for its October meeting. Not published until approved. | ||||||||||||||||||
| EXAMPLE | VMS-001 | Vulnerability & Exposure Management Standard | Standard | PT-07 | Vulnerability and patch management | Head of Information Security | Head of Information Security (the document owner is consulted) | 1.0 | Approved | 10 Sep 2026 | Executive Committee | Yes | 12 | 10 Sep 2027 | Approved | 345 | 7 | Intranet policy library | Not applicable (first version) | OK | 10 Sep 2027 | |||||||||||
| EXAMPLE | BKP-001 | Backup Standard | Standard | PT-06 | Backup and recovery | IT Operations Manager | Head of Information Security (the document owner is consulted) | 1.3 | Approved | 15 Aug 2025 | Head of Information Security | Yes | 12 | 15 Aug 2026 | Review overdue | -46 | 2 | Intranet policy library | Yes | Review overdue more than 30 days: escalate (PF-06, PM-01) | Escalated to executive management on 2026-09-14, 30 days overdue. The owner has not yet started the review. | 15 Aug 2026 | Yes | 46 | Past review, escalate | 3 | ||||||
| EXAMPLE | EXC-STD | Security Exception & Waiver Standard | Standard | PT-15 | Security exceptions and waivers | Head of Information Security | Head of Information Security (the document owner is consulted) | 1.0 | Approved | 10 Sep 2026 | Executive Committee | Yes | 12 | 10 Sep 2027 | Approved | 345 | 8 | Intranet policy library | Not applicable (first version) | OK | 10 Sep 2027 | |||||||||||
| EXAMPLE | JML-PRC | Joiner, Mover, Leaver Procedure | Procedure | PT-14 | People security (joiners, movers, leavers, training) | HR Director | Head of Information Security (the process owner is consulted) | 2.2 | Approved | 3 Feb 2025 | Head of Information Security | Yes | 24 | 3 Feb 2027 | Approved | 126 | 4 | Intranet policy library | Yes | OK | 3 Feb 2027 | |||||||||||
| EXAMPLE | RMT-GDL | Remote Working Guideline | Guideline | PT-09 | Remote working and mobile devices | Head of IT | Information security | 1.1 | Approved | 18 Nov 2025 | Head of Information Security | Yes | 24 | 18 Nov 2027 | Approved | 414 | 9 | Intranet policy library | Yes | OK | 18 Nov 2027 |
Acknowledgement Data
Paste the Policy Attestation & Acknowledgement Tracker's Summary 'Acknowledgement by policy' rows here as values, into B4 (not the total row). EXAMPLE: that tracker's example as at 2026-09-30.
| Example | Document ref | Title | Version | Listed: in scope | Listed: current | Listed: outdated version | Listed: not yet due | Listed: overdue | Listed: overdue more than 30 days | Reported: in scope | Reported: current | Reported: coverage | Status |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | ISP-001 | Information Security Policy | 3.0 | 12 | 11 | 0 | 0 | 1 | 1 | 240 | 231 | 96.3% | Met |
| EXAMPLE | AUP-001 | Acceptable Use Policy | 2.1 | 12 | 8 | 0 | 0 | 4 | 2 | 240 | 214 | 89.2% | Below target |
| EXAMPLE | ACP-001 | Access Control Policy | 2.0 | 12 | 10 | 0 | 1 | 1 | 1 | 240 | 229 | 95.4% | Met |
| EXAMPLE | INC-001 | Incident Management Policy | 1.2 | 12 | 11 | 0 | 1 | 0 | 0 | 240 | 233 | 97.1% | Met |
Overdue Acknowledgements
Paste the Policy Attestation & Acknowledgement Tracker's Overdue by Manager rows here as values, into B4. EXAMPLE: that tracker's example as at 2026-09-30.
| Example | No. | Manager | Name | Role | Policies overdue | Overdue (count) | Longest overdue (days) | Overdue more than 30 days (count) | Manager's people overdue |
|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | 1 | Anna Kowalski | Daniel Reyes | Software Engineer | AUP-001 (annual, 77 days) | 1 | 77 | 1 | 2 |
| EXAMPLE | 2 | Anna Kowalski | Liam O'Connor | DevOps Engineer | ISP-001 (material change, 168 days) | 1 | 168 | 1 | |
| EXAMPLE | 3 | Grace Adeyemi | Oliver Brandt | Accounts Assistant | AUP-001 (annual, 5 days) | 1 | 5 | 0 | 1 |
| EXAMPLE | 4 | Head of Sales | Ravi Menon | Sales Executive | AUP-001 (annual, 120 days) | 1 | 120 | 1 | 1 |
| EXAMPLE | 5 | Mark Ellison | Chloe Martin | Customer Support Agent | ACP-001 (material change, 221 days) | 1 | 221 | 1 | 2 |
| EXAMPLE | 6 | Mark Ellison | Jamal Ahmed | Customer Support Agent | AUP-001 (joiner, 23 days) | 1 | 23 | 0 |
Metric Definitions
Metric definitions
The four headline measures of the Policy Framework Standard, defined once so every quarter is calculated the same way (PF-12).
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| PM-01 Documents past review date | Approved documents whose next review date has passed. | Register rows with Lifecycle status Approved whose next review date is before the report date. Also shown: how many are policies, and the longest, in calendar days past the review date. | Zero policies; no document more than 30 days overdue | Met only when no policy is past review and nothing is more than 30 days past it. A review more than 30 calendar days overdue is escalated to executive management (PF-06). |
| PM-02 Documents in force without approval | Documents people are told to follow that have no recorded approval at the right level. | Register rows, not retired, that are approved or published but have no approval date, no approver recorded, an approval below the tier's level, or approval by the document's own owner. | Zero | Any figure above zero means people are following something nobody with authority approved (each tier is approved at the level set for it; a document is not in force until approved and published.). |
| PM-03 Acknowledgement coverage | People in scope with a current acknowledgement of each policy that applies to them, as a share of all people in scope. | Acknowledged person-and-policy pairs ÷ in-scope pairs, across Policy-tier documents that require acknowledgement. From the Acknowledgement Data: sum of Reported: current divided by sum of Reported: in scope. | ≥ 95% | Read the per-policy coverage too: one policy far below target can hide inside a good total. |
| PM-04 Overdue acknowledgements | People past their joiner, change or annual deadline, named by manager. | From the Acknowledgement Data: the sum of Listed: overdue more than 30 days (the headline) and of Listed: overdue (all). Names come from the Overdue Acknowledgements sheet. | Zero older than 30 days | Old overdue acknowledgements are a management problem, not a reminder problem: each manager named is asked to act. |
Quarterly Report
Policy health and attestation — quarterly report
Yellow cells are yours: the report date, the commentary and the actions. Everything else is calculated. Each figure has a status in words; the colour only repeats it.
Report settings
| Setting | Value | |
|---|---|---|
| Report date (the quarter end) | 30 Sep 2026 | EXAMPLE report date: replace with your quarter end |
| Quarter | Q3 2026 | |
| Quarter start | 1 Jul 2026 |
Headline measures
| Measure | Result | Target | Status | Commentary — what changed, and why | ||||
|---|---|---|---|---|---|---|---|---|
| PM-01 Documents past review date | 2 | Zero policies; no document more than 30 days overdue | Action needed | |||||
| of which policies | 1 | 0 | ||||||
| longest past its review date (days) | 91 | 30 or fewer | ||||||
| PM-02 Documents in force without approval | 0 | Zero | Met | |||||
| PM-03 Acknowledgement coverage | 94.5% | ≥ 95% | Below target | |||||
| PM-04 Overdue acknowledgements: older than 30 days | 4 | Zero older than 30 days | Action needed | |||||
| all overdue acknowledgements | 6 | — | ||||||
Document figures are at the report date; acknowledgement figures are as the tracker calculated them. PM-04 counts the people the tracker lists individually.
What is overdue — documents
| Document | Tier | Owner | Next review date | Days past review | Why listed | Action agreed and date | ||
|---|---|---|---|---|---|---|---|---|
| AUP-001 Acceptable Use Policy | Policy | Head of IT | 1 Jul 2026 | 91 | Past review, escalate | |||
| ACP-001 Access Control Policy | Policy | Head of IT | 20 Jan 2027 | Triggered review | ||||
| BKP-001 Backup Standard | Standard | IT Operations Manager | 15 Aug 2026 | 46 | Past review, escalate | |||
Coming up: 0 approved document(s) due for review by 2026-12-31. Documents more than 30 days past review are escalated to executive management (PF-06).
Who has not signed — coverage by policy
| Policy | In scope | Current | Not current | Coverage | Status | Overdue (listed) | Over 30 days (listed) | |
|---|---|---|---|---|---|---|---|---|
| ISP-001 Information Security Policy | 240 | 231 | 9 | 96.3% | Met | 1 | 1 | |
| AUP-001 Acceptable Use Policy | 240 | 214 | 26 | 89.2% | Below target | 4 | 2 | |
| ACP-001 Access Control Policy | 240 | 229 | 11 | 95.4% | Met | 1 | 1 | |
| INC-001 Incident Management Policy | 240 | 233 | 7 | 97.1% | Met | 0 | 0 | |
| All policies | 960 | 907 | 53 | 94.5% | Below target | 6 | 4 | |
Who has not signed — overdue acknowledgements by manager (first 15)
| Manager | Name | Policies overdue | Longest (days) | Over 30 days | Manager's people overdue | |||
|---|---|---|---|---|---|---|---|---|
| Anna Kowalski | Daniel Reyes | AUP-001 (annual, 77 days) | 77 | 1 | 2 | |||
| Anna Kowalski | Liam O'Connor | ISP-001 (material change, 168 days) | 168 | 1 | ||||
| Grace Adeyemi | Oliver Brandt | AUP-001 (annual, 5 days) | 5 | 1 | ||||
| Head of Sales | Ravi Menon | AUP-001 (annual, 120 days) | 120 | 1 | 1 | |||
| Mark Ellison | Chloe Martin | ACP-001 (material change, 221 days) | 221 | 1 | 2 | |||
| Mark Ellison | Jamal Ahmed | AUP-001 (joiner, 23 days) | 23 | |||||
What to tell management
| Point | What to say | |||||||
|---|---|---|---|---|---|---|---|---|
| The position in one sentence | [[e.g. Two documents are past review, one of them the Acceptable Use Policy; acknowledgement coverage is 94.5%, just below the 95% target.]] | |||||||
| What is overdue and what is being done | [[e.g. AUP-001 is 91 days past review; version 3.0 goes to executive management in November. BKP-001 is 46 days past review; the IT Operations Manager starts the review in October.]] | |||||||
| Who has not signed | [[e.g. Four people are more than 30 days overdue; their managers have been asked to close them by 16 October.]] | |||||||
| Decisions or support needed | [[e.g. Approve SUP-001 at the October meeting; confirm the review plan for AUP-001.]] | |||||||
| What has improved since the last report | [[e.g. No document was in force without approval all year.]] | |||||||
| Prepared by (name, role) and date | [[Name, role, YYYY-MM-DD]] | |||||||
Trend
Trend — the last four quarters
The four headline measures at each of the last four quarter ends. Type the three earlier quarters from the reports you kept; the last row comes from the Quarterly Report. Direction compares each quarter with the one before.
| Quarter end | Quarter | PM-01 past review | PM-01 status | PM-02 without approval | PM-02 status | PM-03 coverage | PM-03 status | PM-04 over 30 days | PM-04 status | PM-03 direction | Commentary |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 31 Dec 2025 | Q4 2025 | 2 | Action needed | 0 | Met | 91.0% | Below target | 3 | Action needed | — | |
| 31 Mar 2026 | Q1 2026 | 1 | Action needed | 0 | Met | 93.2% | Below target | 2 | Action needed | Improving | |
| 30 Jun 2026 | Q2 2026 | 0 | Met | 0 | Met | 95.1% | Met | 2 | Action needed | Improving | |
| 30 Sep 2026 | Q3 2026 | 2 | Action needed | 0 | Met | 94.5% | Below target | 4 | Action needed | Worsening |
EXAMPLE: the three earlier quarters are typed in, as you would from the reports kept for them. PM-01's status is typed too: it depends on which documents were overdue and by how long, which only that quarter's report shows.
Lists
| Tier | LifecycleStatus | MetStatus |
|---|---|---|
| Policy | Draft | Met |
| Standard | In consultation | Action needed |
| Procedure | Awaiting approval | |
| Guideline | Approved |
Retired
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Report date | The quarter end the report is for. Document figures are calculated at this date. |
| Past review | An approved document whose next review date is before the report date (PM-01). |
| Days past review | Calendar days from the next review date to the report date. |
| Escalation | A review more than 30 calendar days past its date is escalated to executive management (PF-06) and named in every quarterly report until approved. |
| In force without approval | An approved or published document with no approval date, no approver recorded, an approval below its tier's level, or approval by its own owner (PF-03, PM-02). |
| Triggered review | An approved document with an event recorded that brings its review forward (PF-06). |
| Policies requiring acknowledgement | Policy-tier documents in force (PF-09). |
| Reported: in scope / current | Per policy, people in scope and people with a current acknowledgement, from the Policy Attestation & Acknowledgement Tracker: whole-population totals where the tracker holds them, otherwise its listed people. |
| Coverage | Current acknowledgements as a share of people in scope. |
| Listed: overdue | People listed individually in the tracker who are past their joiner, change or annual deadline. |
| PM-01 Documents past review date | Approved documents whose next review date has passed. Target: zero policies; no document more than 30 days overdue. |
| PM-02 Documents in force without approval | Documents people are told to follow that have no recorded approval at the right level. Target: zero. |
| PM-03 Acknowledgement coverage | People in scope with a current acknowledgement of each policy that applies to them, as a share of all people in scope. Target: ≥ 95%. |
| PM-04 Overdue acknowledgements | People past their joiner, change or annual deadline, named by manager. Target: zero older than 30 days. |
| (calc) | A column the workbook calculates. Do not type or paste over it. |
| PF-nn, PM-nn | Rule and measure numbers in the Policy Framework Standard. |
| EXAMPLE row | The example organisation's figures as at 2026-09-30. Delete before approval. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | The workbook as a whole: four defined measures, calculated the same way each quarter, with the results evaluated and reported |
| ISO/IEC 27001:2022 | Annex A 5.36 — Compliance with policies, rules and standards for information security | What is overdue and who has not signed: where compliance with policies is not yet achieved |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Headline measures against targets, Trend, and what to tell management |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures” | The quarterly report as a procedure to assess whether the policies are working |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(c) — policies contain indicators to monitor their implementation and record exceptions from it | Headline measures as indicators to monitor the policies' implementation |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774