Security policy compliance is two different questions wearing one phrase, and only one of them is answerable this afternoon. The first is whether your policies say the right things, which takes judgement and time. The second is whether the people bound by them have agreed to the version currently in force, which is record keeping and has a yes or no answer. Organisations spend their effort on the first and get asked for the second.
Where the question comes from
A customer's security questionnaire, an insurer's proposal form, an incident review, or somebody senior asking out loud after reading about somebody else's breach. All four arrive without warning and all four want the same artefact: evidence that the rule existed and that the people it binds knew it. Drafting quality is not what any of them ask about first.
Why a distribution list is not a record
An email with a read receipt shows that a message was delivered and opened. It does not show which version was attached, and it does not show agreement. The question you get is what this person agreed to and when, and a mailbox cannot answer it without somebody reconstructing an argument from timestamps. A record of person, version and date answers it in one line.
The version number is what makes it defensible
Acknowledgement has to be against a version rather than against a policy, because the useful question is always about a moment in time: did this person, in March, know the rule as it then stood. That is only answerable if March's text still exists and the signature points at it. Policies edited in place, with no version history, cannot produce that answer however carefully the emails were filed.
Where policy sits in the frameworks people ask about
If the question came from a questionnaire, it probably references a published structure. The NIST Cybersecurity Framework 2.0 organises its Core as a hierarchy of six Functions with GOVERN at the centre of the wheel and the other five arranged around it, which is a fair picture of where a written policy sits: not one activity among several, but the thing the rest are supposed to be executing. Mapping to it helps you answer questions; adopting it wholesale to answer one questionnaire does not.
Questions people ask about security policy compliance
Is a signature on a handbook enough?
For the version signed, yes. The problem is that a handbook changes and the signature does not, so a year later it evidences a document nobody is working to.
Do contractors have to acknowledge?
Anyone the policy binds. If the scope says employees and contractors then yes, and if it does not, look again at the scope.
What about people who joined before the policy existed?
Issue the current version to everybody and collect afresh. A backdated record is worse than an honest gap.