As part of your compliance program, you’ll need to set up your Policies page in Vanta. Policies document how your company meets its security and compliance requirements—the procedures, expectations, and responsibilities that support your controls. Auditors review your policies to understand not just which controls you have in place, but how your team follows them in practice.
Once approved and assigned for acceptance, each policy supports your compliance evidence through two associated tests on the Tests page: one checks that the policy has been approved, and the other checks that relevant employees have accepted it.
📖 Learn more: Explore the Vanta Academy—take our self-paced course or join an instructor-led workshop on policy writing. If you can’t attend live, you’ll receive a recording after.
Creating policies
When you go to the Policies page, you’ll see a default list of policies associated with your enabled frameworks. These come from Vanta's policy library and are added to your policy list based on your framework setup.
For each one, you can use a Vanta template to complete the policy or import your existing policy. If one of your existing policies clearly matches a Vanta-provided policy, open that policy and import your document—this keeps Vanta’s default policy structure, mappings, and tests in place. If you’d rather use your own policies in place of the Vanta defaults, you can import them as custom policies.
Using a Vanta template
Vanta gives you ready-made templates for your required policies, built on framework requirements and security best practices.
To browse available templates, go to the Policies page, click Add policy, select Add from policy library.
For eligible frameworks, you can use the policy builder to walk through customizing the template to your business. For other frameworks, you can still use the policy editor in Vanta to fill out the template—just without the guided policy builder experience.
To add a policy to your list that isn't available as a template in the policy library, you can add it as a custom policy.
Importing an existing policy
Instead of drafting in a Vanta template, you can upload a policy document to the matching policy listed in Vanta:
Go to the Policies page, open the policy, and click Import an existing policy.
Then choose to upload a file from your computer (PDF, DOCX) or sync one from a supported integration (Confluence, Google Drive, Sharepoint).
Importing custom policies
Vanta AI helps speed up the bulk import process by reviewing the uploaded files, pulling out key details, and creating custom policies from those files. After the policies are in Vanta, AI-suggested control mapping can help identify which controls each policy may support, so you can review and confirm the mappings instead of starting from scratch.
From the Policies page, click Add policy, select Import policies, and upload your files.
From the Vanta Agent, ask for help importing your policies in bulk.
📖 Learn more: Importing Custom Policies
Approving policies
Approving your policies in Vanta is an important step to confirm your organization's compliance posture. If you import a policy into Vanta, you can also set historical approvers and approval dates to track the policy's timeline. If Vanta AI is enabled for your account, Vanta can automatically extract this information for you making the process faster.
How to approve policies
Submit the policy for approval: After drafting or importing a policy, select Submit to begin approval.
Select the approver: Approvers can be anyone at your company (including yourself) with Admin or Editor status in Vanta. We recommend selecting the individual who enforces the policy and can answer questions during an audit.
Await approval: Once you submit the policy for approval, the approver is notified via email. They will review the draft and confirm approval in Vanta.
Check status: Once approved, your new policy version will move from Pending Approval to Approved on the Policies page. When a policy is approved, Vanta marks the related policy test as "OK" and the approved policy document becomes visible in both your Monitors and Documents views.
Multiple approvals
Depending on your plan, you can designate multiple approvers for each policy.
Assign up to five steps of approval, with each step allowing up to three approvers.
This lets you involve key team members in the process, ensuring thorough review and sign-off before finalizing a policy.
Employee acceptance
Once you have you finished drafting and approving policies, it's time to set up your personnel and assign them tasks, including reviewing and accepting policies. Then you can monitor the status of employee acceptance for each policy on the Policies page.
Once employees accept a policy, Vanta automatically updates the related policy acceptance test to OK. This ensures that both your document evidence (the approved policy file) and your test evidence (employee acceptance) are complete for audit readiness.
Some controls won't reach OK status until both tests pass—for example, the SOC 2 control "Continuity and Disaster Recovery plans established" depends on an approved Business Continuity and Disaster Recovery Plan that employees have accepted.
Notification and reminder management
Admins play a key role in ensuring employees complete the policy acceptance process. The following actions can be implemented:
Enable Notifications: Turn on employee notifications in the Vanta settings. Notifications will automatically remind employees about pending security tasks, including policy acceptance, based on the reminder cadence set (e.g., weekly reminders). To manually remind a specific user, navigate to their profile on the People page and click on Remind.
Manual Access to Policies: As an alternative to automatic notifications, employees can be directed to the onboarding page to complete their tasks manually.
Customizing policy assignments to groups
Vanta allows admins to assign policies to specific groups:
Configure onboarding group settings to determine which employees need to accept each policy.
Customize group-specific settings or default all policies to be accepted by all group members. This flexibility helps organizations efficiently manage diverse teams.
Troubleshooting common issues
Here are solutions to common challenges faced during policy acceptance workflows:
Inconsistent Task Status: If tasks like "Accept security policies" revert to incomplete, it might be due to the system not recognizing the acceptance state correctly. Ensure employees revisit the onboarding page to complete and save tasks.
Checklist Configuration Issues: If employees cannot see or accept certain policies, it could be due to checklist settings. Approve the policy and navigate to the checklist section to enable policies for the desired employee group.
Differentiating Agreements: Policy acceptance in Vanta does not replace the need for signed employee agreements, as these documents address different compliance controls.What's Next?
Technical Notification Issues: If your organization received notifications regarding policy reacceptance due to technical issues (e.g., affecting policies from specific timelines such as July to August 2024), these serve as proactive communication. As long as the majority of users have accepted the policies, no further action is required. Policies created and accepted during the specified timeframe remain valid and compliant.
Each year, you'll need to review and re-approve your policies. You'll be notified via email when it's time.
If there are material changes to your policy, we recommend you ask employees to re-accept them.
When you create your new policy version, you'll be asked to confirm whether the new policy version should be sent to employees for review and acceptance.
On the Policies page, you'll see the status of your policies change from OK to Renew soon (when renewal is coming up in the next six weeks).
If you don't renew in time, your policy status will change to Expired.
For better alignment, you can update all policies at once and request users to reaccept them, ensuring that all policies will be due for renewal concurrently on the same date the following year. This approach facilitates an annual scheduled re-acceptance process.
If policies are updated and need to be reaccepted, follow these steps:
During policy updates, select the option Yes, ask employees to reaccept this policy.
Vanta will automatically prompt employees to reaccept the updated policy based on your notification cadence.
If this option was not selected, reapprove the policy with the option enabled to ensure compliance. The effective date of a policy in Vanta marks when it officially goes into effect for your organization. However, users can accept the policy at any point within the designated onboarding SLA to remain compliant. If there are uncertainties about specific compliance periods, it is recommended to consult directly with your auditor for tailored guidance.
