Skip to main content

Updates and recertification

The reason to subscribe to a program rather than buy a document is that the law keeps moving. This page explains what happens when it does.

What a version number tells you

Programs use three-part versions, and the level is chosen by what it costs you, not by how much the publisher edited.

ChangeMeansPeople retrained
Major (1.0.0 to 2.0.0)An obligation changed such that people must be retrained, or a document must be re-approvedYes
Minor (1.0.0 to 1.1.0)Additive. New content, a new scenario, a new language, a new roleNo
Patch (1.0.0 to 1.0.1)Editorial. A typo, formatting, or a citation refresh that does not change meaningNo

A publisher who rewrites half the wording without changing what anyone must do is issuing a patch. A publisher who changes one sentence in a way that alters what a person should do in a real situation is issuing a major release. Judge a release by its stated impact, not its size.

What a release tells you

Every release records why it happened, not just what changed:

  • The instrument and article that moved.
  • The direction: tightened, loosened, clarified, deferred or repealed.
  • A plain summary of the change.
  • The source, and the date the publisher verified it.
  • Whether recertification is required, and which roles are affected.

A loosening is recorded as carefully as a tightening. If an obligation softened, you want to know your exposure dropped. And content already written to the stricter standard is reframed as exceeding the requirement rather than deleted, so nobody is told their evidence became worthless.

You can read the full history on a program's catalog page.

Applying a release

A new version arrives the same way the first one did, as a signed file you load. What it creates depends on what changed:

  • Revised documents arrive as new versions of the existing documents, in review. Your currently effective version stays effective until you approve and release the new one.
  • Revised training arrives as new training versions, pending review.
  • New roles or rules appear in the mapping step so you can decide where they apply.

Anything the publisher did not actually change is left alone. The preview marks each item as new, changed or unchanged, and unchanged items keep the version you already approved. This matters more than it sounds: re-approving forty identical documents to get at the two that moved is how a quality function learns to approve without reading.

Installing the new version supersedes the previous one, so there is always exactly one live version of a program and a single answer to "which version are we running". The superseded record is kept, not deleted.

Your existing evidence is untouched. A program update never edits or deletes a record of what somebody did.

When people have to be retrained

Recertification triggers when a release states that someone holding valid evidence would now act differently in a real situation. Not when a citation was refreshed, and not when a paragraph was rephrased.

When it does trigger, and once you approve and activate the new version:

  1. People who already completed the affected training are re-enrolled.
  2. Their previous evidence is marked superseded. It is not deleted and not altered, so the audit trail still shows what they completed and when.
  3. They appear in the normal assignment and reminder flow.

You control the timing, because nothing happens until you activate the new version.

Evidence expiry, separately

Independently of releases, competence evidence has a validity period, and a program declares triggers that make a re-assessment necessary even when nothing about the program changed. Typically:

  • The AI system or process changed materially.
  • Its purpose changed.
  • A new risk was identified.
  • The person's role changed.
  • A serious incident occurred.
  • The capability has not been exercised for a long period.
  • A control indicated a gap.

These are judgement calls for your quality function, not automatic events. The program tells you what should prompt a re-assessment; you decide when one has happened.

Keeping your own changes

If you edited an installed document to fit your organisation, a publisher revision does not silently overwrite it. It arrives as a new version alongside yours, and you decide what to carry forward when you approve it. Compare the versions before approving, exactly as you would for internally authored content.