Skip to main content

FAQs: Policies and acknowledgments: templates, mappings, and workflows

Written by Brady Price

Acknowledgments and training

This article brings together common customer questions and practical answers based on typical Secureframe workflows, compliance situations and unique tech stacks.

It is meant as quick reference material for day-to-day use of the product.

All my acknowledgment tests are passing, as they should since everyone has accepted them according to them, but the tests themselves show up as "none" for accepted.

  • This is typically because the "require employee acceptance" button is NOT selected while publishing the policies. once you check that box in policy, data will backfill correctly.

Does the Workday integration support compliance with SecureFrame's policy acknowledgment training?

How can I verify the completion status of Security Awareness training and policy acknowledgement?

  • You can verify completion by navigating to the relevant Security Awareness training or policy acknowledgement test. If you are checking completion for a specific user, you can also review their status directly from the Personnel page.

How can policy acknowledgement or any tests be re-enabled after being disabled?

  • If you've previously disabled Policy Acknowledgement tests or any tests in Secureframe, you can re-enable them from the Test Library.

  • Steps to re-enable Policy Acknowledgement tests:

  • Go to the Tests page in Secureframe.

  • In the top-right corner, click Test Library.

  • Use the search bar to search for “acknowledgement” or any keyword related to the test you are looking for.

  • Select the tests you want to re-enable using the checkboxes.

  • Once selected, a bulk action bar will appear, click Enable.

  • This will return the tests to your active test list.

Tip: If you don’t see the Test Library, make sure you're on the main Tests tab (not Frameworks or another section).

How long is policy acknowledgement information stored in Secureframe?

  • Secureframe retains policy acknowledgment records for the lifetime of your active subscription. As long as you remain a customer, all historical policy acceptance data is preserved and available for audit and reporting purposes.

  • If your contract is terminated and the account is deprovisioned, policy acknowledgment records are typically deleted as part of the account cleanup process. Once removed, this historical acknowledgment data can no longer be recovered.

  • At any time while your account is active, you can export a complete history of policy acknowledgments from the Data Room by using the export option in the Accepted Policies section.

How do I get historical policy acceptance records for offboarded or inactive employees?

  • Standard Data Room exports typically show active or latest acceptance data. They may not include everything you need for archived policies or offboarded employees.

  • For a full historical export (including offboarded users and older policy versions), contact [email protected] and ask for a backend CSV of policy acceptances. Include the company name, date range, and whether you need archived policies, inactive users, or both.

  • Keep exported files in a secure location. Policy acceptance data can include personal information.

How should the method by which the TPSP provides written acknowledgment be determined?

  • The method by which the TPSP provides written acknowledgment should be agreed between the provider and its customers.

Our vendor is a third party that has access to sensitive data, but they are already being treated as a vendor in Secureframe. Do we also need to add their personnel to the platform to complete onboarding (e.g., security training, policy acknowledgment), or is a risk assessment enough?

  • If the third party is being treated as a vendor, and you’ve completed an appropriate vendor risk assessment with supporting documentation, you do not need to add their individuals to the Personnel page for onboarding. This includes cases where the vendor’s employees have access to sensitive data, as long as:

  • The vendor is classified correctly in your Vendor Access module

  • A risk assessment has been completed

  • The vendor’s handling of sensitive data is covered in contracts or due diligence documentation

  • If you instead treat them as part of your internal team (e.g., employees or direct contractors), then onboarding through the Personnel module would be required.

What acknowledgments must written agreements with TPSPs include?

  • Written agreements must include acknowledgments from TPSPs that TPSPs are responsible for the security of account data the TPSPs possess or otherwise store, process, or transmit on behalf of the entity, or to the extent that the TPSP could impact the security of the entity’s cardholder data and/or sensitive authentication data.

What does the acknowledgment from the TPSP evidence?

  • The acknowledgment from the TPSP evidences the TPSP’s commitment to maintaining proper security of the account data that it obtains from its customers.

What does the TPSP's written acknowledgment confirm?

  • The TPSP’s written acknowledgment is a confirmation that states the TPSP is responsible for the security of the account data it may store, process, or transmit on behalf of the customer or to the extent the TPSP may impact the security of a customer’s cardholder data and/or sensitive authentication data.

What is not considered a written acknowledgment from a TPSP?

  • Evidence that a TPSP is meeting PCI DSS requirements (is not the same as a written acknowledgment specified in this requirement. For example, a PCI DSS Attestation of Compliance (AOC), a declaration on a company’s website, a policy statement, a responsibility matrix, or other evidence not included in a written agreement is not a written acknowledgment.

What is the purpose of a written acknowledgment from a TPSP?

  • The written acknowledgment from a TPSP demonstrates its commitment to maintaining proper security of account data that it obtains from its customers and that the TPSP is fully aware of the assets that could be affected during the provisioning of the TPSP’s service.

Can an admin accept policies on behalf of other employees?

  • No. Policy acceptance must be completed by each in-scope person in their own Secureframe account.

  • Admins can assign policies, track who has not accepted, send reminders, and review completion status from Personnel or the related policy acknowledgment test.

  • Admins can upload training certificates or other proof where the product allows admin upload (for example third-party training evidence in the Data Room or on a training test). That is not the same as accepting a policy for someone else.

  • If someone is unavailable, use your auditor-approved exception process. Do not have an admin click accept while logged in as that person unless your auditor has explicitly approved that approach.

<

Did this answer your question?