Skip to main content

Linking a published Policy to a Policy Test

Written by Brady Price

Understanding the 2 types of Policy tests

In Secureframe, admins can expect to encounter many associated tests for framework policies.

Some are related to the obligation of having an approved policy, other tests are related to personnel acknowledgement of those policies. The type of policy will depend on the framework you have in your Secureframe platform.

  1. Policy Review & Approval by Owner - The first type of policy test simply requires the Secureframe Admins to review, assign an owner and publish each of the applicable Policies. This ensures that your organization has all the relevant policies for the applicable frameworks loaded into Secureframe.

    • Using our Policies - Secureframe already provides each of the required policies for the frameworks your organization has purchased. If you plan to utilize our Policies, those will already be located in the Policies page.

    • Using your own Policies - If you have your own policies, then you will first upload the policy text or completed PDF's and then review, assign an owner and finally publish.

  2. Policy Acknowledgement by Personnel - the second type of policy test is acknowledgement of the policies for the relevant frameworks. This test ensures that for each in-scope personnel has reviewed each of the applicable polices and accepted them as part of your onboarding effort.


Video Tutorial


Linking Tests When Publishing a New Policy

Interactive Walkthrough:Launch the interactive walkthrough to practice editing a policy and linking it to a policy test. Click the highlighted areas on each screen to move to the next step. This is not a play/pause video.

To link tests to your policy when you’re ready to publish your policy, follow the steps below.

  1. From the Policies page, select the policy you want to publish and click Publish.

  2. You’ll be prompted to add tests to the policy.

    • Click Not Right Now if you want to add them later.

    • Click Add to Existing Tests if you’re ready to associate tests now.

  3. A pop-up window will appear with a list of available policy tests.

  4. Select one or more tests you want to associate. A single policy can be linked to multiple tests.

  5. Click Add.

  6. The test will appear under the Testing tab in the policy, and the test will automatically refresh to reflect the new association.

Note: for policy acknowledgement tests, once all personnel assigned to the policy have reviewed and accepted the published policy, the test status will change to Passing.


Linking Tests to a Policy Before Publishing

If you want to link tests to a policy before it's ready to publish, you can do that directly from the test's Evidence tab.

  1. Navigate to the Tests page and open the test you want to update

  2. Click the Evidence tab

  3. Select the policy or policies you want to associate with the test

  4. Click Add

You can link multiple policies to a single test. All linked policies will appear on the Evidence tab once added.

A few things to keep in mind:

  • If a linked policy is still in draft, Secureframe will display a warning banner on the test. Draft policies are labeled (draft) with muted styling in the policy picker so they are easy to spot.

  • A draft policy will not satisfy the test and personnel will not be able to acknowledge it until it is published.

  • Once you publish the policy, the paired acknowledgement test will re-run automatically. You do not need to manually refresh it.


Linking Tests to an Existing Published Policy

  1. From the Policies page, click the policy you want to update.

  2. Navigate to the Testing tab.

  3. Click Add Test.

  4. Select one or more tests you want to associate. A single policy can be linked to multiple tests.

  5. Click Add.

  6. The test will refresh automatically to show the connection between the policy and the test.


Removing a Test from a Policy

  1. Open the policy from the Policies page.

  2. In the Testing tab, locate the associated test you want to remove.

  3. Click the three-dot menu next to the test.

  4. Select Remove Test.


Frequently Asked Questions (FAQ)

I created a custom policy (for example, AI Governance). How do I get an Acknowledgement of that policy that tracks each user?

  • Publish the policy with Require employee acceptance checked, assign the right Policy Groups, and save/publish so users can accept it in Employee Onboarding.

  • Publishing does not create an Acknowledgement of [policy name] test automatically.

  • To drive an acknowledgement test on the Tests page, link the published custom policy to an existing acknowledgement test (or related policy test) from the policy Testing tab, or when prompted at publish.

  • Use a Custom Upload Test or Pass with Upload when acknowledgements happen outside Secureframe, or when you only need existence/approval evidence. Learn more: Policy User Acknowledgement.

Why is my Acknowledgement test (e.g., "Acknowledgement of...") failing or showing unexpected results?

  • There are two common causes:

    • This usually happens when more than one policy is linked as evidence on the related policy test. When multiple policies are linked, the Acknowledgement test requires personnel to accept all of them.

      • To fix it: open the policy test, go to the Evidence tab, and review the Policies listed there. Remove any that don't belong, leaving only the correct policy, then refresh the Acknowledgement test. This should clear the failing users.

    • No policy is linked to the test. If you see "Personnel can't accept this policy yet. No published policy is linked to this test," open the linked policy test and link a published policy so personnel can review and accept it.

How do I create and or edit my policies?

  • You can review our complete guide on how to edit policies here.

What's the difference between Secureframe policies and custom policies?

  • Secureframe policies are pre-built for your frameworks and usually already link to the matching Policy and Acknowledgement tests.

  • Custom policies with onboarding acknowledgement: publish with Require employee acceptance checked so users can accept in onboarding. Then link the published policy to an existing acknowledgement test (or related policy test) if you need that test to pass. Publishing does not create Acknowledgement of [policy name] automatically.

  • Custom policies for existence/approval evidence only: link your published custom policy to an existing framework Policy test on the Evidence tab, or create a Custom Upload Test and attach the policy. You cannot create a new platform Policy test type from Add Test.

I see both "Policy Test" and "Acknowledgment Policy Test" in the Tests page. What’s the difference?

  • Policy Test: Verifies that a specific policy exists and is accessible. You can link a custom policy to this test by adding its URL as evidence.

  • Acknowledgment Policy Test: Verifies that users have acknowledged a policy. If you're not using Secureframe's acknowledgment workflow, you can disable these tests.

Can I disable the default policy-related tests?

  • Yes. You can disable both the Policy Test and Acknowledgment Policy Test if you're not using Secureframe’s policy templates. Then, create your own tests tied to each of your custom policies.

I created my own policy. Why can't I create a "Policy" test?

  • Secureframe does not offer a creatable test type labeled Policy from Add Test. Built-in Policy tests come from the frameworks and Secureframe policy templates you have enabled.

  • For onboarding acknowledgement on a custom policy: publish with Require employee acceptance checked, then link that published policy to an existing acknowledgement test (or related policy test). Publishing does not create a new Acknowledgement of [policy name] test.

  • For existence/approval evidence without Secureframe acknowledgement: create a Custom Upload Test (TestsAdd TestCustom Upload Test), then attach the published policy on the Evidence tab. Or open an existing framework Policy test and link your published custom policy there.

What's the best way to link a custom policy to a test?

  • For onboarding acknowledgement, publish with Require employee acceptance and assign Policy Groups.

  • For Tests-page acknowledgement, link the published policy to an existing Acknowledgement of... test (or related Policy test) from the policy Testing tab or the publish prompt. Do not expect a new Acknowledgement of [custom policy name] test to appear automatically.

  • If you only need existence/approval evidence (or acknowledgements happen outside Secureframe), use Custom Upload TestEvidence → add the published policy URL or PDF, or link the policy to an existing framework Policy test. You cannot create a new platform Policy test type from Add Test.

How can customers upload evidence that policy acknowledgement was completed to Secureframe?

  • If acknowledgements are completed outside Secureframe (for example in your HRIS or another policy tool), use Pass with Upload on the related acknowledgement or Custom Upload test. This path is for external evidence, not for Secureframe's built-in acknowledgement workflow.

  • If you want Secureframe to track each user's acceptance, publish the policy with Require employee acceptance so users can accept in onboarding, and link the policy to an acknowledgement test if you need that test to pass. Do not use Pass with Upload for that path.

  • Pass with Upload lets you upload a single summary report (CSV or PDF) of who acknowledged. The test shows as Passed with upload. Individual acknowledgements will not map to personnel records, and pending acknowledgement tasks may still appear under Personnel.

Why is there a warning banner on my policy test saying my policy is in draft?

  • If a policy linked to a test hasn't been published yet, Secureframe will display a warning banner letting you know the policy is still in draft. Draft policies won't satisfy the test and personnel won't be able to acknowledge them until they're published. To resolve this, navigate to the Policies page, open the draft policy, and publish it. Once published, the paired acknowledgement test will re-run automatically.

Did this answer your question?