Most organisations prove policy compliance the same way: they send the document, collect a digital signature or acknowledgment, log the timestamp, and file the record. When an auditor asks whether employees understood the anti-money-laundering policy or the data protection procedure, the compliance officer points to the attestation report. Everyone signed. The box is ticked.

However, attestation proves one thing only: that the employee received the policy and clicked confirm. It does not prove they read it. It certainly does not prove they understood it well enough to apply it correctly under pressure. Furthermore, as regulatory expectations deepen across financial services, healthcare, and HSEQ environments in France and the UK, the gap between attestation and comprehension is becoming a material compliance risk.

What most organisations currently use as proof

Today, the standard toolkit for proving policy understanding combines three mechanisms. First, digital attestation requires employees to confirm they have read and understood the policy before proceeding. Second, end-of-module quiz scores provide a numerical measure of recall, typically across four to ten questions. Third, audit trail exports generate timestamped records showing who received which policy version and when they acknowledged it.

Each of these mechanisms serves a genuine purpose. Attestation creates a legal record. Quiz scores filter for the most significant knowledge gaps. Audit trails give regulators the documentation they expect to see. Consequently, most compliance programmes treat these three mechanisms as sufficient proof of understanding.

The problem is that they measure the easiest parts of comprehension. Attestation measures receipt. A quiz measures recall of the specific facts the question writer chose to test. Neither measures whether the employee understood the policy deeply enough to apply it correctly in an ambiguous real-world situation, which is exactly the scenario a regulator cares about most.

Why attestation is not the same as comprehension

Consider how attestation works in practice. An employee receives an email with a link to a policy document and a button to confirm they have read and understood it. Many employees click confirm before finishing the document. Some click confirm without opening it at all. The attestation system records a successful acknowledgment either way because it has no visibility into what happened between the email arriving and the button being clicked.

Quiz scores have a similar limitation. A four-question quiz on a 30-page data protection policy tests a small and predetermined slice of the content. An employee who scored 100% on the quiz may still be unclear on the sections the quiz did not cover. Moreover, quiz questions are known in advance to repeat across training cycles, which means employees learn to pass the quiz rather than learn the policy.

Taken together, attestation and quiz scores prove that a compliance programme ran. They do not prove it worked.

What genuine proof of policy understanding looks like

Proving employees understood a policy requires visibility into what happened inside the document itself, not just what happened around it. Specifically, genuine comprehension evidence covers four dimensions.

The first is engagement depth. Which sections did each employee spend time with, and which did they move through quickly? A policy section that every employee skips in under ten seconds is either too long, too dense, or poorly positioned in the document. That signal is invisible in an attestation report.

The second is question behaviour. When employees have access to an AI assistant grounded in the policy content, the questions they ask reveal exactly where comprehension broke down. An employee who asked the AI assistant three questions about the escalation procedure in an anti-bribery policy understood that section was important and was trying to get it right. That signal is significantly more meaningful than a ticked checkbox.

The third is re-read patterns. An employee who returned to the same section twice is processing it carefully. An employee who returned to it four times across two sessions is either confused or highly engaged. Both patterns tell the compliance team something actionable about that section.

The fourth is section-level completion versus document-level completion. An employee who engaged deeply with 80% of a policy and skipped 20% entirely is a different risk profile from one who skimmed 100% of it in two minutes. Standard completion tracking cannot make that distinction.

How Libertify generates comprehension evidence for compliance teams

Libertify transforms any policy document, SOP, or training material into a guided comprehension experience without replacing the document itself or requiring a new authoring workflow. Employees engage with an AI assistant grounded strictly in the document content, with no information outside the policy boundaries, and no hallucinations.

As employees work through the material, Libertify generates comprehension signals across all four dimensions described above. Furthermore, it converts those signals into a specific next action for the compliance or L&D team: which employees need a follow-up session before the audit window, which policy sections need to be rewritten for clarity, and which comprehension gaps represent the highest regulatory risk.

The result is audit-ready evidence of understanding rather than audit-ready evidence of distribution. Compliance teams using Libertify can demonstrate not just that every employee received the policy but what each employee engaged with, what they asked, and where the comprehension gaps sit. Explore how it works across compliance and training workflows at libertify.com/use-cases/, and see real outcomes in the Libertify success stories.

Frequently asked questions

How do you prove employees understood a policy?
Proving policy understanding requires evidence beyond attestation and quiz scores. Specifically, it requires visibility into how employees engaged with the policy content: which sections they spent time with, which they skipped, what questions they asked, and where comprehension broke down. Comprehension analytics tools generate this evidence automatically as employees work through the material.

Is employee attestation enough for compliance audits?
Attestation proves distribution, not understanding. In many regulatory environments, particularly financial services and HSEQ in France and the UK, auditors increasingly expect evidence of comprehension alongside attestation records. Attestation alone is no longer sufficient proof of a functioning compliance programme in the most scrutinised industries.

What is the difference between policy acknowledgment and policy comprehension?
Policy acknowledgment is a legal record confirming the employee received and confirmed receipt of a policy. Policy comprehension is evidence that the employee understood the content well enough to apply it correctly. Acknowledgment is necessary but not sufficient. Comprehension is what protects the organisation when a policy is tested in a real situation.

How can compliance teams identify which employees need additional training?
Comprehension analytics reveal which employees skipped key sections, asked questions about the same content repeatedly, or scored poorly on specific topics. Those signals identify the employees who need follow-up before an audit window rather than after an incident.

What evidence should compliance teams present at audit?
Standard audit evidence includes distribution records, attestation timestamps, and quiz completion rates. Stronger audit evidence adds comprehension signals: section-level engagement data, employee questions captured during training, and specific follow-up actions taken to address identified gaps. Together, these demonstrate that the compliance programme was designed to produce understanding, not just completion.

Make your policies understood, not just acknowledged

Upload your next compliance policy to Libertify and generate your first comprehension signals in about three minutes. Make documents understood. Start with Libertify →