Skip to main content
    Technical

    What Counts as Proof That Someone Read a Policy?

    PM
    Pete Murr
    Founder & CEO, CourseAgent - 20+ years in L&D··6 min read

    What counts as proof that someone read a policy?

    Proof means a record that names the individual, stores the exact wording they agreed to, and fixes the moment they agreed with a timestamp they could not set themselves. It should also show which version of the policy they saw and which language they read it in. A completion record from a learning platform does none of that - it only says a course was finished.

    That distinction matters the day an auditor, an insurer, a regulator or a tribunal asks the question. "Everyone completed the code of conduct module in March" is an assertion. "Here is the named list, the statement each person confirmed, the version, the language and the timestamp" is evidence.

    Why a completion tick is weaker than it looks

    Most compliance teams already collect something. The usual options all have the same hole in them.

    • A spreadsheet. Maintained by hand, edited by anyone, and it records a name and a date but never the wording.
    • A signed paper form. Genuinely strong evidence, until you have to find 400 of them across six sites.
    • An email chain. You own a mailbox, not a report. No chase list, no percentage, no export.
    • An LMS acknowledgement tick. The most common answer, and the most misleading. It records that a box was ticked. Ask it to reproduce the wording that box sat next to on the day, in the language the learner read, for the version of the policy that was live at the time. Usually it cannot.

    The policy document itself has almost certainly been edited since. Once that happens, a completion record points to a statement nobody can now reconstruct.

    What a defensible record contains

    If you are specifying this for your own organisation, these are the eight fields worth insisting on.

    FieldWhy it matters
    Who signedThe individual, by name and email or by learner id
    The exact wordingThe evidence itself, stored in full - not a link to a document that may have changed
    The sign-off labelThe policy name as it will appear in your audit report
    The timestampSet server-side, not by the learner's device
    The course versionProves which edition of the policy they actually saw
    The languageProves they read it in a language they understand
    Delivery routePortal, shared link or their own LMS
    Typed name, if requiredAn extra deliberate act on top of the tick

    Two properties matter as much as the fields. The record should be insert-only - nobody, including the account owner, should be able to edit or delete it through the product. And it should outlive the content: if the course is later deleted or rebuilt, the evidence must remain.

    Be honest about what it is not

    An acknowledgement record is not a qualified electronic signature. There is no certificate authority and no eIDAS or ESIGN cryptographic signing. For a contract, use an e-signature product.

    For internal policy attestation, health and safety inductions, SOP acknowledgements and annual code-of-conduct cycles, an authenticated acknowledgement with a tamper-resistant server-side audit trail is normally exactly what is being asked for. Overstating it is what creates problems later.

    How CourseAgent does it

    CourseAgent's Compliance Sign-off is a section you drop onto any page of any course. You write the confirmation statement yourself, link out to the full policy document, give it a reporting label such as "Code of conduct 2026", and choose whether the learner must also type their first and last name.

    It is always mandatory. Continue is blocked, every later page is locked in the navigation menu with the reason shown, the course cannot be completed and no certificate is issued until the learner confirms. They can always move backwards to re-read.

    Insights then gives you a Sign-offs report: Expected, Signed, Outstanding, a compliance percentage and average time to sign, filtered by course, sign-off, status, date range, delivery method and academy group. Choose your columns, export the lot to CSV, and send one reminder email per outstanding person listing everything they still owe.

    Sign-off works in the Academy portal, on assigned and sign-up links, when a course is launched from your own application, and inside your own LMS through dynamic SCORM. It does not work on anonymous open links or static SCORM packages, because there is no identified learner to attribute a record to - and in those cases we say so rather than recording something meaningless.

    The test to run this week

    Pick the policy you would least like to be asked about. Then ask your current system for three things: the named list of everyone who accepted it this year, the exact wording each of them saw, and the version and language for each. If you cannot produce all three inside ten minutes, you have a reporting problem rather than a training problem - and that is the gap a sign-off record closes.

    Try the approach in CourseAgent

    Every guide works faster when you can test it. Start a 14-day free trial of Professional - no credit card, no time limit if you stay on Free.

    Start free trial →

    Frequently asked questions

    Share

    Ready to build better courses?

    Free to start. No credit card. No technical skills required. Just describe what you want to teach.