Helia HR

Blog

Who has actually read the policy?

2026-09-13 · Ihor Kosheliev, Founder, Helia HR

Hi everyone. I spent years as the product owner of an internal HR system at an IT services company, sitting next to the HR team while they used it. One request came back every single quarter, and it was never phrased as a feature request. It was a question: "Can you tell me who has actually read the new policy?"

They were not asking for signatures. They were asking for evidence.

The word "signature" sends you shopping for the wrong thing

Say "we need people to sign the handbook" out loud in a planning meeting and within ten minutes somebody has a vendor tab open, a per-envelope price and a procurement conversation. That is a reasonable reflex and it is usually the wrong instrument.

EU law is more precise than the word "signature" is. eIDAS recognises three levels: a simple electronic signature, an advanced one, and a qualified one. They are not grades of quality, they are different tools for different risks. A qualified signature means an identity verified against a document and backed by a certificate from a trust-service provider. That is the right instrument for something a court may have to accept with no further evidence.

An employee confirming they have read the remote-work policy is not that.

What you actually need, and what it proves

For a handbook, a policy, a code of conduct, an equipment agreement or a security briefing, the record that matters has four parts:

That is a simple electronic signature, and Article 25 of eIDAS is explicit that an electronic signature is not denied legal effect merely for being electronic. What it proves is that this account, at this time, from this address, confirmed having read this file. What it does not prove is that the person behind the account is who the account says. That gap is exactly why the advanced and qualified levels exist.

Anyone selling you an acknowledgement flow while implying it is a qualified signature is selling the cheaper instrument at the more expensive price. Ask which of the three it is. A straight answer tells you something about the rest of the product.

Five things that make the record worth having

  1. Ask per document, not per person. "Everyone completed onboarding" is not a record. "Forty-seven of sixty have acknowledged Information Security Policy v3" is. The document is the unit, because the document is the thing that changes.
  2. Version by replacing, never by editing. A policy edited after people confirmed it has acknowledgements pointing at text nobody read. A new version is a new document and a new ask. This is the rule most in-house implementations get wrong, and it is the one that matters most.
  3. Record what they typed, not what you had on file. If the record echoes the name already in your database, it is your assertion, not theirs.
  4. Make declining a first-class answer. A form whose only exit is Sign manufactures consent. "This is the wrong version" and "I need more time" are things you want to hear before the audit rather than during it.
  5. Chase it automatically, then stop. A due date and two reminders close most of the gap. What is left is a short list of names, and a short list of names is a conversation you can actually have.

When a simple acknowledgement is not enough

Do not stretch it. An employment contract, anything touching immigration paperwork, and anything a regulator names specifically all belong with a qualified signature or wet ink, depending on where you operate. The test is not how important the document feels. It is whether you would be comfortable having only a log line if the matter were ever disputed. If the answer is no, buy the heavier instrument for that one document and stop paying for it on the other forty.

I am not a lawyer and none of this is legal advice. The split above is the one every lawyer I have asked draws first, but your jurisdiction and your works council get the final word.

What we built

Helia HR keeps employee documents with an expiry date and lets you ask people to acknowledge one. The record stores the name as typed, the time, the IP address and the browser, and the page says in plain words that this is a simple electronic acknowledgement and not a qualified signature. A product that lets an HR manager believe otherwise has done them real harm. HR sees "47 of 60" and the thirteen names, reminders go out before the due date, and it is part of the base plan rather than a separate line item.

A signature is a ceremony. A record is what you actually need on the day somebody asks.

Related reading: onboarding checklist for an IT company and GDPR and HR data in a small company.

Who has actually read the policy? · Helia HR