Key takeaways
Proving a procedure change reached your operators takes five records. You need the approved version with its dates, a record of who it went to, and a named, timestamped acknowledgement. Where a mistake carries a safety or public health risk, you also need a training record and a supervisor's practical sign-off. Then you need an exception list naming who hasn't done it yet. Email can't reliably hold any of these. Keep all five together, and work the exception list every week.
Update, share and audit every procedure
An inspector asks a simple question: how do you know your operators are working to the current procedure?
You can probably answer the first half. The procedure exists, it's approved, and somebody can produce the PDF.
The second half is harder. "We emailed it out" tells the inspector what you sent. But, you’ve not answered the question. They want to know if your operators received and understood it.
For a water or wastewater utility, writing the procedure is rarely the issue. After all, you know how to write a chlorine dosing SOP. What’s difficult is proving afterwards which version is live, who received it, who read it and who understands it.
This is the evidence that usually ends up spread across inboxes, paper sign-off sheets, and shared drives.
In this article, we cover the five records you need and why email can't hold them. We trace one PFAS change from approval to exception list. Then we look at when simple acknowledgement isn't enough, how long to keep everything, and the weekly report that names who's outstanding.
Download our water utilities SOP template
What counts as evidence?
You need all five of the records below. If any one is missing, expect an auditor to ask about it.
| Record | What it shows |
|---|---|
| The approved version, with dates | Which text was in force on a given day, and who approved it |
| The distribution record | Who the change was published to, and when |
| The acknowledgement | A named person confirmed they read it, with a timestamp |
| The training record | Where competence matters, the learning completed and any practical sign-off |
| The exception list | Who hasn't acknowledged or completed, by name, today |
The first three records follow the procedure itself, from approval to the person reading it.
Start with the approved version. Your system should record when each version came into force and when it was replaced. If an incident is investigated 18 months from now, you'll need to show what the procedure said that day.
Next is the distribution record, which shows who the procedure went to. Send it by role and site rather than from a mailing list someone keeps by hand. That way, a new starter picks it up without anyone having to remember to add them.
Then comes the acknowledgement: a name and a timestamp showing that each person read it. Keep it in the system rather than someone's inbox, so it's still on file after that person leaves.
The training record and the exception list are about your people, so they each get their own section below.
Why email doesn't get you there
Email is the obvious way to share a procedure change, and it's easy to see why. Everyone has it, and a sent message feels like a record. But it falls short in three ways.
- Read receipts are optional. The recipient can turn them off, so a missing receipt tells you nothing. And a returned receipt only shows the message was opened. It doesn't show that anyone actually read the procedure.
- Forwarded copies lose track of their version. When a supervisor forwards the attachment to a shift, that PDF gets saved and shared on its own. Six months later, someone could be working from it in good faith, with nothing on the file to say it's been replaced.
- The record leaves with the person. Acknowledgements collected in a supervisor's inbox stay in that inbox. When that supervisor retires, your evidence goes with them, and you won't know until you need it.
So keep using email to tell people a change is coming. Just make sure you keep the evidence somewhere else.
A PFAS position change, from approval to exception list
If you run a drinking water system, you're working to the PFAS limits in the EPA's National Primary Drinking Water Regulation. The limit for PFOA and PFOS is 4.0 parts per trillion. Initial monitoring is due by 2027. Where results exceed the limits, solutions must be in place by 2029.
When you publish the sampling and reporting procedure that reflects this, the right software and processes should leave you with five records. Here's how they would look:
- The approved version. Your compliance manager approves version 1.0 and sets the date it comes into force. The system logs who approved it and when.
- The distribution record. The procedure goes to licensed operators, laboratory technicians, and the collections team at each site. It's sent by role, so anyone who joins those teams later receives it too.
- The acknowledgements. Each person confirms they've read the procedure. Their name and the time they confirmed are saved with it, rather than in a supervisor's inbox.
- The training record. A chain-of-custody mistake on a PFAS sample has public health consequences. So operators complete a short course with a knowledge check, and a supervisor signs off their practical handling.
- The exception list. Let's say that four of your operators haven't acknowledged. Three are on nights and one is on leave. With an exception list you know their names and can chase them well before any audit.
The rule may also change. In May 2026, EPA proposed two amendments. One would let systems request two more years to meet the PFOA and PFOS limits. The other would remove the limits for PFHxS, PFNA, HFPO-DA, and PFBS. Both are still proposals under public comment, so your procedure should describe them that way.
If either is finalized, you would then revise the procedure to version 1.1 and everyone acknowledges it again. Version 1.0 stays on file with the dates it was in force.
Suppose an incident in 2028 depends on what your operators were told in 2026. You can show which version they had, who read it, and how quickly you chased the four who hadn't.
Know which changes need a test as well as a tick
An acknowledgement shows someone received the procedure. For some changes, you also need to know they understand it and can follow it.
Use this test on every change: if doing it wrong has a safety, regulatory, or public health consequence, acknowledgement alone is not enough. The change needs learning with a knowledge check. If the task is hands-on, it also needs a supervisor's practical sign-off.
That sorts your changes into two piles:
- Read and accept. An updated contact list, a revised reporting template, a new way to submit supply requests. People need to know, and nobody needs to demonstrate anything.
- Learning and sign-off. A change to chlorine dosing, confined space entry, chain of custody, or emergency response. Here you need to show the person can do the task.
A course completion and a supervisor's sign-off prove different things, so record them separately. The course completion shows someone understood the procedure well enough to pass a knowledge check. The sign-off shows they can carry out the task correctly on site. For high-risk changes you need both, because passing a quiz doesn't prove someone can handle a sample properly.
Remember, neither one is an operator license. Your state issues and renews those, so keep license records separate too.
Now, back to sorting your changes. Be careful which pile each one goes into, because mistakes cost you in both directions.
Give every change a course, and operators will start clicking through without reading. But if a high-risk change only gets a tick, your evidence is weakest for the task where you need it most.
Running policy acknowledgement and training in the same system also makes it easier to change your mind. If you decide a change needs a course after all, you can add one without setting it up somewhere else.
What to keep, and for how long
A records schedule sets how long you keep each of these.
For a Florida public utility, that's the state's General Records Schedule GS14 for Public Utilities. It took effect in June 2023, and it applies to state, county, city, and special district records custodians. You use it alongside GS1-SL for common administrative records. Where a record series appears in both, the longer retention period applies.
We won't tell you which series your acknowledgement records fall under. Your records officer already knows, and they're the right person to ask.
Before you move any content into a new system, settle three things with your records officer and counsel:
- Ownership. Who is the custodian of each record type once it lives in a platform instead of a mailbox?
- Retention. Which schedule and series applies, and what triggers disposition?
- Export. How do the records come out for a public records request or a change of system? You want them in bulk, readable, and with their metadata intact.
The third is the one people forget. If you can't get your records out of a system, you're stuck with it.
Name the people who haven't done it
A completion percentage looks reassuring, but it doesn't tell you who to chase.
At 96% acknowledgement of a chlorine handling change, some people handling chlorine still haven't read it.
The report you want names them. For example, say four operators, all on nights at the north plant, haven't acknowledged a revision published 11 days ago. Because you can identify them, that's one call to one supervisor and you can ensure that you reach 100% quickly.
Run the exception list every week, rather than the week before an audit. When an audit comes round, there should be no exceptions. A record of you chasing and closing those names each week is useful evidence too.
How Claromentis Enablement Hub keeps the evidence together
Claromentis Enablement Hub keeps the procedure, its approval history, and your staff follow-up records in one place. Three parts of it cover the five records:
- Enablement Hub’s AI Policy Manager handles the document. You get version history, custom review stages and deadlines, notifications when a revision publishes, and mandatory read-and-accept that records the name and timestamp. Plus, an optional AI assistant answers user questions in plain language from the approved text. All AI features within Enablement Hub can be turned off if you prefer.
- The learning management system handles the training aspect. Courses, quizzes, certificates, expiry dates, and training records sit next to the acknowledgements instead of in a separate spreadsheet. Supervisors stay in charge of hands-on assessment.
- Dashboards and intranet governance analytics show outstanding acknowledgements, overdue actions, and audit logs. Named content owners and review dates stop procedures going out of date unnoticed.
For a compliance manager, that's one place to show an inspector the version, who received it, who read it, and who still hasn't.
Your utility owns the regulatory interpretation and the approval. Enablement Hub keeps the records that show a change reached your people and what they completed. We don't decide what a rule requires, and you should be wary of any vendor who suggests otherwise.
Some evidence also belongs elsewhere. Laboratory results and regulatory submissions stay in the systems built for them. And when you're scoping, ask us to show you the export for your own record types. It's the same test we'd tell you to apply to anyone.
We're ISO 27001:2022 certified, and you can host in our secure cloud or on your own infrastructure. Your IT team will ask about security and hosting. Your records officer will want to know where the records are held.
Case study - South Coast Water District
South Coast Water District supplies potable water, recycled water, and wastewater collection across South Orange County, California. It has around 100 staff split between offices and the field.
Its SOPs and communications had spread across shared drives, email, and standalone tools, all on a server due for decommissioning.
The district moved onto one hub. It now runs a knowledge base for SOPs and onboarding, and digital forms for employee requests and approvals. A mobile app lets field crews reach the current version from a phone. Having one place to find procedures is the first step toward keeping all five records.
Check which of the five records you can produce today
You probably have two or three of these already:
- The dated, approved version
- The distribution record
- Named acknowledgements
- Training records and sign-off, where required
- The exception list as it stands this morning
Start with whichever one you can't produce. That's where an auditor is most likely to find a problem.
We've built a water utility SOP template with the approval, version, distribution, and acknowledgement fields laid out. Use it to see the model on paper before you decide anything about software.
Download the water utility SOP template
Or you can book a discussion call with one of our experts. We'll show you how your SOPs and policies could be reviewed, shared, supported with learning, and tracked in Claromentis Enablement Hub.
Empower the people behind safe, reliable water
Give your teams a single hub for policy management, SOP management, communications and training.
Water Utility Procedure Management FAQs
Is an email read receipt enough evidence?
Rarely. A read receipt shows an email client opened a message. It doesn't show the recipient saw the current version or understood it. Recipients can also decline read receipts, so a missing one tells you nothing. If a receipt is your only evidence, expect a follow-up question you can't answer.
How long do we keep acknowledgement records?
Your records schedule decides. For a Florida public utility, that's the state's General Records Schedule GS14, used alongside GS1-SL for common administrative records. Where a series appears in both, the longer retention applies. Ask your records officer which series your acknowledgements fall under, rather than picking a period that sounds reasonable.
What happens to the record when someone leaves?
It has to outlast their account, and in an email-based system it usually doesn't. Acknowledgements collected in a supervisor's mailbox go when the mailbox goes. That's one of the clearest reasons email fails as a system of record. Your evidence shouldn't depend on one person staying in their job.
What is procedure management software, and how is it different from document storage?
Document storage holds files. Procedure management software holds the version that's in force and controls who it reaches. It records who acknowledged it, links it to training where competence matters, and shows who hasn't complied. A shared drive does the first of those and none of the rest.
Do all procedure changes need a training course?
No. A course for every change is a fast way to make operators ignore the ones that matter. Apply one test: if doing it wrong has a safety, regulatory, or public health consequence, the change needs learning with a knowledge check. Hands-on tasks also need a supervisor's sign-off. Everything else can be read-and-accept.