Checkpoint · Feature

Review and approval

In a larger organisation the person who writes a policy should not be the only one who checks it, and the person who accepts a risk should be the one accountable for it. Checkpoint records both, in your tenant.

The demo is the real console with sample data. No sign-up.

Review before approval

  • In Settings → Approvals, choose which drafts need a second person’s review: none, the information security policy, every policy, or every generated document.
  • The reviewer is asked through My tasks and, in your tenant, by email. They record "Reviewed" or "Changes requested" with comments.
  • The person who prepared the draft cannot review it, and the reviewer cannot approve it.
  • Any edit after the review ends it, so what is approved is what was reviewed.
  • The review appears in the document history and on the sign-off table of the printed and Word copies, with the approver.

Risk acceptance by the person accountable

With the second setting on, accepting a residual risk sends a request to the person accepting it. They record the decision signed in as themselves, and the audit log shows who asked and who accepted.

Segregation of duties (ISO 27001 A.5.3) can also be enforced, so nobody approves a document or accepts a risk they raised.

Proportionate

Both settings are off by default. A small organisation with one or two people running Checkpoint keeps a single approval step; a larger one turns on the steps it needs.

Questions

Who can review a document?
Anyone except the person who prepared it. The reviewer then cannot be the approver, so a reviewed document involves at least three people when the setting is on.
What happens if the document is edited after it is reviewed?
The review no longer applies, and the document needs reviewing again before it can be approved.
Is the review recorded?
Yes. It is in Checkpoint’s audit log, the document history and the sign-off table of the approved document.
Microsoft Teams