Skip to the content
Forematter

Policy acknowledgement forms: how to show staff have read a policy

Someone has asked you to "get everyone to sign the policies". Fine. Before you build a form, it helps to be honest about what a signature on a policy actually tells you, because it's less than most people assume, and a bit more than nothing.

It tells you that a person was given a document and said they'd read it. That's it. It's a receipt. It doesn't prove they understood the policy, it doesn't prove they agree with it, and it definitely doesn't prove they remember a word of it three months later. A receipt is still worth having. But only if it's a good one, and most of the acknowledgement forms doing the rounds are pretty weak receipts.

If you just want the form, there's a free policy acknowledgement form template with a record log. The rest of this is why it's built the way it is.

What a policy acknowledgement actually proves

Start with the legal position, because it's short. No law requires a handbook or a policy acknowledgement form as such. GOV.UK lists the places contract terms can sit, and one of them is "in an employee handbook or on a company notice board". A handbook is a place terms can live, not a thing you're obliged to have signed. (There's more on this in do you need an employee handbook?)

What some rules do ask for is that people genuinely know them. The Acas Code of Practice on disciplinary and grievance procedures says those rules should "be set down in writing, be specific and clear", and that "it is also important to help employees and managers understand what the rules and procedures are, where they can be found and how they are to be used." For health and safety, the HSE is blunter: "You must share the policy, and any changes to it, with your employees."

So an acknowledgement is a practice choice. A sensible one, mostly. It's your record that you shared something and gave people the chance to understand it. Keep that in mind and the rest of the design falls out of it.

Why one signature on day one is weak

Picture the usual setup. A new starter turns up, there's a lot going on, and somewhere in the first week they're handed a 60-page PDF and asked to sign at the bottom to say they've read the lot.

What does that record? That a file was handed over. Nothing more.

Hardly anyone reads 60 pages in the middle of learning where the kettle is, who their manager is and how to log in to anything. So the signature says "read" while the reality says "skimmed, or not at all". And you, the person who might have to rely on that record later, know it.

There are other problems hiding in that one signature. You often can't show which version of the handbook they saw, because it's been edited since. You usually haven't recorded how it reached them, or whether they had any real time to read it. And if someone did have a question, there's no trace of it.

The point isn't that acknowledging things on day one is bad. It's that a single bundled signature for everything is the weakest version of it.

What a good acknowledgement records

Think of it as a small record with a few things in it, kept together.

The exact wording and version. Either the text itself or a fixed copy of the version the person saw, with a version number and date on it. "Signed the handbook" is useless if you can't show which handbook. This is the difference between a record and a shrug.

The name and the date. Simple, but people forget the date, or keep it somewhere separate from the name.

How it was delivered. Email, a shared drive, a printed copy, a system they logged in to? Did they get a proper chance to read it before being asked to confirm? Where the document lives matters too. For some of the day-one details in the written statement, GOV.UK says a separate document is fine if it's something the employee "has reasonable access to, such as on the employer’s intranet". Reasonable access is a good standard for every policy you ask people to acknowledge.

Questions. A way to ask them, and a note of any that came up. If someone queries the acceptable use policy and you answer, write down that it happened. It shows the process was a conversation, not a tick.

The statement itself. Write out exactly what the person is confirming. "I have received this policy, had time to read it, know where to find it and know who to ask" is honest. "I have read, understood and agree to all company policies" is asking one signature to carry far more than it can.

Split it instead of bundling it

So what do you do instead of the one big signature? Split it. Pick the policies that genuinely matter for the role and acknowledge them one at a time, paced over the first weeks. Conduct, disciplinary, grievance, health and safety, data protection, IT and acceptable use is a decent starting list, though yours may differ.

Each one is short enough to actually read. Each one gets its own record, with its own version and date. And the person isn't being asked to swallow everything in one sitting, which is, you know, how people end up reading none of it. Someone who's had a few days with the grievance policy and a named person to ask is far more likely to have read it than someone told to sign before lunch.

Re-acknowledging when a policy changes

Policies change. Someone updates the remote working rules, or the acceptable use policy gets a new section, and suddenly the version people acknowledged isn't the version in force.

This is where a fresh acknowledgement earns its keep. After a meaningful change, ask for a new one, tied to the new version. And here's the bit people get wrong: don't re-send the whole handbook and hope. Say what changed. A few lines on what's different, a link to the new version, and a request to confirm. That's readable, and it means the record points at a specific version at a specific time.

Annual re-acknowledgement of everything is a habit some organisations like. That's fine, but it's a practice choice, not a legal duty, and a change-triggered acknowledgement with a short summary usually tells you more than a yearly blanket one.

There's a useful habit from the data protection side too. On privacy information, the ICO says "You should make sure you periodically remind existing workers", and suggests larger organisations check with a random sample of workers that they "are aware of the privacy information; received it; and know how to find it." That's about privacy information specifically, but it transfers nicely. Ask a few people where a policy lives. If they can't say, the signatures aren't doing their job.

Acknowledgement isn't agreement

Now the trap. A "read and understood" form is not someone agreeing to change their contract. Keep the two apart.

The employment contract can be broader than people think. Acas says it might include "the organisation's code of conduct" and "policies – for example on social media or data protection (GDPR)". GOV.UK says "An employer should make clear which parts of a contract are legally binding." So label each policy as contractual or not, on the policy and on the acknowledgement.

When a change touches contractual terms, different rules apply. Acas puts it plainly: "You must both agree to the changes. This is unless there's a clause in the contract that allows you to make a change without agreement." A tick on "I've read the new policy" isn't that agreement. And if the change affects the written statement, GOV.UK says employers must tell people about it: "They must do this within one month of making the change."

So run them as two processes. A policy acknowledgement is a receipt. A contract change is a proper conversation, with notice, and agreement where it's needed. If you're unsure which one you're in, check before you send anything round.

Keeping the records: data protection

Acknowledgement records have names and dates on them, so they're personal information and part of your employment records. Treat them like the rest.

The ICO's keeping employment records guidance covers what that means:

  • Retention. "The storage limitation principle says you can only keep personal information for as long as you need it." The ICO says you should set up a retention policy or schedule. It doesn't give a number for acknowledgement records, so you decide one that fits your reasons, write it down and stick to it.
  • Security. Records should be kept so they "can only be accessed, altered, disclosed or deleted by those who are authorised to do so", and they must "remain accessible and usable". An acknowledgement that anyone can quietly edit isn't much of a record.
  • Subject access. Workers can ask for a copy of their personal information, and "You must respond to a SAR from a worker without delay and within one month of receiving the request." Acknowledgement records should turn up in that search. If they're scattered across inboxes and a folder called "misc", you'll feel it.

On format, you don't need wet ink to have a usable record. Under the Electronic Communications Act 2000, an electronic signature "shall each be admissible in evidence" in legal proceedings, alongside any certification of it. That's about admissibility, nothing broader, so don't read it as "e-signatures settle everything".

Whatever tool you use, the test is the same: can you show, for one named person, the exact text they acknowledged, which version it was, when, and how it reached them? Forematter, onboarding software for UK companies, records the exact wording and version each person acknowledged, and the record can't be edited afterwards. A spreadsheet log plus fixed PDF copies of each version can do the same job if you're disciplined about it.

Questions people ask

Is a policy acknowledgement form a legal requirement?

No law requires a handbook or an acknowledgement form as such. Some rules do require you to share things, such as your health and safety policy and any changes to it, and an acknowledgement is a tidy way to record that you did.

What should an employee policy acknowledgement form say?

The policy name, its version and date, where the full text lives, whether it's contractual, the exact statement being confirmed (received, had time to read, know where to find it, know who to ask), how it was delivered, any questions raised, and the person's name and date.

Does a signed acknowledgement prove someone understood the policy?

No. It records that they were given the policy and said they'd read it. It's stronger if you can show the exact version, that they had time to read it, and that they had a way to ask questions.

Do staff need to re-sign when a policy changes?

It's good practice after a meaningful change, tied to the new version, with a short note on what changed. For contractual terms, reading isn't agreeing: Acas says changes must be agreed unless the contract allows otherwise.

How long should we keep policy acknowledgement records?

The ICO doesn't give a set period. It says to keep personal information only as long as you need it and to set a retention schedule, so decide a period that fits your reasons and write it down.

Are electronic signatures OK for policy acknowledgements?

An electronic signature is admissible in evidence in UK legal proceedings under the Electronic Communications Act 2000. What makes the record useful is keeping the exact version, date and delivery method alongside it.

Sources

The pages this guide quotes and links, checked on 29 September 2026.

  1. gov.uk/employment-contracts-and-conditions/contract-terms
  2. acas.org.uk/acas-code-of-practice-on-disciplinary-and-grievance-procedures/html
  3. hse.gov.uk/simple-health-safety/policy/index.htm
  4. gov.uk/employment-contracts-and-conditions/written-statement-of-employment-particulars
  5. ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/employment/employment-practices-and-data-protection-keeping-employment-records/collecting-and-keeping-employment-records
  6. acas.org.uk/employment-contracts-and-the-law
  7. acas.org.uk/changing-an-employment-contract/employer-responsibilities
  8. legislation.gov.uk/ukpga/2000/7/section/7

We're building Forematter now.

It answers new starters' questions from your own documents, sends the gaps to the people who can fill them, and paces their first weeks. Leave your email and we'll tell you when it opens.