How do I manage policy reviews and sign-offs for SOC 2 compliance?

Last updated: September 25, 2025

Context

When preparing for SOC 2 compliance, organizations need to establish and maintain policies that require review and sign-off from appropriate team members. Understanding the proper process for policy review and sign-off is crucial for successful SOC 2 implementation.

Sign-Off Process

Here's how to manage the policy review and sign-off process:

  1. Review and Publish Policies

    • Navigate to https://app.mycroft.io/policies

    • Review each policy and assign appropriate owners

    • Ensure privacy policies align with both internal and public-facing documentation

    • Click the "Publish Policy" button for each policy you want to distribute

  2. Distribute for Sign-off

    • Go to https://app.mycroft.io/people

    • Click "Send Reminders" to initiate the review process

    • Team members will receive an email to review policies and complete training

  3. Who Needs to Sign

    • All employees involved in daily operations must complete the review

    • Set clear deadlines for review and sign-off (typically within one week)

Even if you were involved in creating or publishing the policies, you still need to complete the formal review and sign-off process to meet compliance requirements.

Important considerations:

  • While immediate sign-offs are ideal, it's acceptable to accommodate vacation schedules and extend reasonable deadlines

  • Aim to complete all sign-offs within a reasonable timeframe (ideally within one month) to maintain good compliance timing

Best Practice: Plan around team member availability and vacations when setting review deadlines to ensure comprehensive coverage while maintaining compliance timelines.

Additional FAQ

My policies are not ready yet - waiting for feedback/sign-off from my boss, lawyer, etc.... Will this put me out of SOC 2 Compliance?

Answer:

  • If your goal is a Type 1, drafted/complete policies waiting for consultation or sign-off will be fine.

  • If your goal is Type 2, you will not be ready for an audit without employee sign off on necessary (published) policies. In this case, it would be best to publish the current versions of the policies as is, and follow up as soon as it is updated.