By Compyl Research · Last reviewed September 2026
Compliance training is a control, and like every other control it is judged on evidence rather than intent. Auditors do not ask whether your training was good; they ask who was trained, on what, when, whether they understood it, and what happened to the people who did not complete it. That distinction — between training delivered and training evidenced — is where most programs fall down, and it determines which topics belong in yours.
Key takeaways
- Seven topics cover the mandatory core for most organizations: security awareness and phishing, data privacy, acceptable use, incident reporting, harassment and conduct, anti-bribery and antitrust, and role-specific regulatory training.
- Several frameworks require training explicitly. HIPAA, PCI DSS, ISO 27001 and SOC 2 all name it. Training is not a nice-to-have you can defer until after certification.
- Annual is the floor, not the design. Most requirements say “at least once every 12 months and upon hire” — plus on material change. A program that only fires annually misses new joiners and new threats.
- Completion is not effectiveness. The Department of Justice’s guidance on evaluating corporate compliance programs asks whether training is tailored to role and risk, whether comprehension is tested, and whether the company measures whether it changed anything.
- The evidence is the deliverable. Attendance records, content versions, assessment results, exception handling and remediation for non-completers are what an assessor samples.
What is compliance training?
Compliance training is structured instruction that makes employees aware of the laws, regulations, frameworks and internal policies that govern their work, and equips them to act accordingly. It splits into two kinds that are often confused and should be managed differently.
Mandatory regulatory training is required by a law, regulation or framework: security awareness under PCI DSS, workforce training under the HIPAA Privacy and Security Rules, safety training under OSHA, harassment prevention in the states that mandate it. Here the content, the audience and often the frequency are prescribed. The compliance question is coverage and evidence.
Risk-driven training is what your organization decides it needs based on its own risk register: a fintech that keeps failing wire-fraud simulations, an engineering team with production database access, a sales team operating in markets with bribery exposure. Nothing requires it by name; the risk assessment does. This is where the return on training actually comes from.
A good program runs both. A program that runs only the first satisfies auditors and changes very little.
Which frameworks and laws actually require training?
| Requirement | Who it applies to | What it requires |
|---|---|---|
| HIPAA Security Rule — 45 CFR 164.308(a)(5) | Covered entities and business associates | A security awareness and training program for all workforce members, including periodic security updates, malicious software protection, log-in monitoring and password management. |
| HIPAA Privacy Rule — 45 CFR 164.530(b) | Covered entities | Training of all workforce members on privacy policies and procedures, as necessary and appropriate for their functions, including for new members and after material policy changes. |
| PCI DSS v4.x — Requirement 12.6 | Anyone storing, processing or transmitting cardholder data | A formal security awareness program, documented and reviewed at least every 12 months; training on hire and at least annually; content covering threats such as phishing and social engineering, and acceptable use of end-user technologies. |
| ISO/IEC 27001 — Clause 7.2 and 7.3, Annex A awareness controls | Certified organizations | Competence for people doing work affecting information security performance, and awareness of the policy, their contribution, and the implications of non-conformance. Evidence of competence must be retained. |
| SOC 2 — Trust Services Criteria (COSO-aligned control environment) | Service organizations under examination | Demonstrated commitment to competence, including onboarding and periodic training, with evidence sampled across the examination period. |
| OSHA standards | Employers, by hazard | Hazard-specific training with documented delivery and, for many standards, demonstrated comprehension. |
| State harassment-prevention statutes | Employers, by state and headcount | Prescribed content, audience, frequency and record retention. Requirements vary materially between states. |
| Federal Sentencing Guidelines §8B2.1; DOJ compliance program guidance | Organizations facing enforcement | An effective compliance and ethics program including training as a factor in charging and sentencing decisions. |
Two observations. The frameworks converge on “at hire and at least annually” as the minimum cadence. And every one of them expects a record — which is why the operational problem is usually record-keeping rather than content.
Which compliance training topics should you cover?
These seven cover the mandatory core for most organizations. Depth and audience should follow your risk assessment, not a template.
1. Security awareness and phishing
The highest-frequency, highest-consequence topic, and the one most frameworks name directly. Cover credential handling, phishing and social engineering, device and remote-work practices, and what to do when something looks wrong. Simulations are the only way to get behavioral data rather than completion data.
2. Data privacy and data handling
What personal data the organization holds, the lawful basis for it, classification and handling rules, retention and deletion, and how to recognize and route a data subject request. This is where privacy law becomes a daily behavior rather than a policy document.
3. Acceptable use of technology
Company systems, personal devices, shadow IT, file sharing, and — increasingly the live issue — what may and may not be entered into generative AI tools. PCI DSS names acceptable use of end-user technologies specifically, and DOJ’s 2024 compliance guidance pushed organizations to address emerging technology risk directly.
4. Incident and issue reporting
How to report a suspected breach, a policy violation or an ethical concern; what timeframes apply; and — the part that determines whether anyone actually does it — the anti-retaliation protections that apply to the person reporting. A program where nobody reports anything is not a low-risk program.
5. Workplace conduct, harassment and discrimination
Mandatory in several states with prescribed content and frequency, and a governance expectation almost everywhere else. Supervisors generally require a longer and different course than individual contributors.
6. Anti-bribery, corruption and antitrust
Relevant wherever the organization sells, procures, works with public officials or interacts with competitors. Covered in more detail below.
7. Role-specific regulatory training
The training that only some people need: HIPAA for staff touching PHI, PCI for anyone in the cardholder data environment, secure development for engineers, financial controls for finance, sector rules for regulated functions. This is the category most commonly under-scoped, because it requires knowing which employees fall into which population.
How often is compliance training required?
Four triggers matter, and a program built on only the first is incomplete:
- On hire, before or shortly after access is granted. Most frameworks expect this, and it is the most commonly missed population.
- At least annually, which is the stated floor in PCI DSS and the practical expectation everywhere else.
- On material change — a new policy, a new system, a new regulation, a new market. The HIPAA Privacy Rule names this explicitly.
- On role change, when someone moves into a population with different requirements. An engineer moving into a support role with customer data access needs the training that role carries.
High-frequency risks deserve a higher cadence than the compliance floor. Phishing simulation programs typically run monthly or quarterly, because annual awareness training has almost no measurable effect on click rates.
What makes training effective rather than merely completed?
The Department of Justice’s guidance for prosecutors evaluating corporate compliance programs is the most useful published standard here, because it is written by people trying to find out whether a program was real. Its questions about training are worth applying to your own:
- Is it tailored? Do high-risk roles receive training designed for their risk, or does everyone get the same course? Is it delivered in a language and format employees actually engage with?
- Is comprehension tested? Not attendance — understanding. Can employees demonstrate they know what to do?
- Is effectiveness measured? Does the organization track whether training changed behavior — reporting rates, simulation results, incident causes — and revise the content when it does not?
- Does it reflect what actually went wrong? Prior incidents and near misses in your own organization and your industry are the strongest curriculum input available.
- Does it cover new risk? The 2024 update to the guidance pushed specifically on emerging technology, including AI, and on whether employees understand and trust internal reporting channels.
The practical version: if your only training metric is a completion percentage, you can prove the course was delivered and nothing else.
How do you design a compliance training program?
- Map obligations to populations. For each requirement, define exactly who is in scope. “All employees” is rarely correct and usually hides a gap — contractors, temporary staff and third parties with system access frequently sit outside the HR system that drives enrolment.
- Add the risk-driven layer. Take the top risks from your risk register and ask which of them a person could prevent. Those become courses.
- Set the cadence per topic. Annual for the regulatory core, more often for behavioral risks such as phishing.
- Design for comprehension, not completion. Short, role-relevant, scenario-based, with assessment. Long generic courses produce high completion and low retention.
- Automate enrolment and reminders. Trigger from the HR system on hire, role change and termination so the population is always right.
- Define what happens on non-completion before you need it — escalation to manager, then access restriction. An enforcement path you have never used is not a control.
- Capture evidence as you go. Content version, delivery date, completion record, assessment result, exception approvals. Reconstructing this at audit time is the single largest avoidable cost in the program.
- Review annually against incidents. If the same root cause appears twice, the training did not work regardless of what the completion rate says.
What is antitrust compliance training, and who needs it?
Antitrust compliance training teaches employees to recognize and avoid conduct that restrains competition — most importantly agreements with competitors on price, output, markets or customers, and bid rigging, all of which can be criminal.
Three federal statutes form the core:
- The Sherman Act (1890) prohibits contracts, combinations and conspiracies in restraint of trade and monopolization. Criminal enforcement — including individual prison sentences — comes from here.
- The Clayton Act (1914) addresses mergers and acquisitions that may substantially lessen competition, exclusive dealing, tying and interlocking directorates.
- The Federal Trade Commission Act (1914) prohibits unfair methods of competition and unfair or deceptive acts, and created the FTC.
Who needs it: anyone with pricing authority, sales and business development staff, procurement, executives and board members, and — often overlooked — anyone who attends trade association meetings or industry conferences, which is where the highest-risk conversations tend to happen. Also anyone involved in bidding for public contracts, given how bid rigging is prosecuted.
Note the distinction between regulation and antitrust: a regulator sets rules a whole sector must follow, whereas antitrust law polices competitive conduct across all sectors and is enforced through litigation and prosecution rather than through supervision. The Department of Justice’s Antitrust Division takes the existence and quality of a compliance program into account when making charging decisions, which makes training here a directly consequential control rather than a formality.
What evidence will an auditor ask for?
- The training policy or plan, with an owner, an approver and a review date.
- The curriculum and content versions, so it is clear what a given employee was actually taught on a given date.
- The in-scope population per course, and how it is derived.
- Completion records with dates, usually sampled against a headcount list including joiners and leavers during the period.
- Assessment results where comprehension is tested.
- Exception and escalation records for people who did not complete, and what was done about it.
- Evidence of periodic review, particularly the annual update PCI DSS requires of the awareness program.
For a SOC 2 Type II examination, all of this has to hold across the examination period rather than at a point in time — which is a record-keeping problem before it is a training problem.
Why do compliance training programs fail?
- The population is wrong. Contractors, part-time staff and third parties with access sit outside the enrolment source and are never trained.
- Annual only. Someone hired in February waits ten months for their first training while holding production access.
- One course for everyone. Generic content produces completion without comprehension, and DOJ’s guidance treats tailoring as a marker of a real program.
- No consequence for non-completion. Once employees learn the deadline is soft, completion rates become a measure of persistence by the compliance team.
- Evidence assembled at audit time. Content versions and enrolment logic are hard to reconstruct months later.
- No feedback loop from incidents. The most valuable curriculum input in the organization is what already went wrong in it.
- Completion rate as the only metric. It measures delivery, not risk reduction.
How Compyl helps with compliance training
Compyl treats training as what it is — a control with an owner, a population, a cadence and evidence. Training requirements map to the frameworks that impose them, so one course satisfies several requirements rather than being tracked separately per audit; populations and completion status stay current instead of being reconstructed; and the evidence an assessor samples is collected continuously across the period rather than assembled in the weeks before fieldwork.
Book a demo to see how Compyl handles training alongside the rest of your compliance program.
Compliance training FAQs
What is compliance training?
Structured instruction that makes employees aware of the laws, regulations, frameworks and internal policies governing their work and equips them to act accordingly. It covers both mandatory regulatory training required by a specific rule and risk-driven training an organization adds based on its own risk assessment.
What topics should compliance training cover?
For most organizations: security awareness and phishing, data privacy and data handling, acceptable use of technology, incident and issue reporting, workplace conduct and harassment, anti-bribery and antitrust, and role-specific regulatory training. Depth and audience should follow the risk assessment rather than a template.
How often is compliance training required?
The common floor is on hire and at least once every 12 months, plus on material change to policy, systems or regulation, and on role change. PCI DSS states the annual cadence explicitly and also requires the awareness program itself to be reviewed and updated at least every 12 months. Behavioral risks such as phishing warrant a higher frequency than the compliance floor.
Is compliance training legally required?
For many organizations, yes — by specific rules rather than by a general obligation. The HIPAA Security and Privacy Rules, PCI DSS Requirement 12.6, OSHA standards and several state harassment-prevention statutes all mandate training for defined populations. ISO 27001 and SOC 2 require demonstrated competence and awareness as part of certification and examination.
Who needs antitrust compliance training?
Anyone with pricing authority, sales and business development staff, procurement, executives and board members, anyone attending trade association meetings or industry events, and anyone involved in competitive bidding. The core statutes are the Sherman Act, the Clayton Act and the Federal Trade Commission Act.
How do you measure whether compliance training works?
Beyond completion rates: assessment scores and repeat failures, phishing simulation click and report rates over time, internal reporting volumes through the whistleblower or issue channel, and whether incident root causes recur after training addressed them. Completion measures delivery; these measure effect.
Does training have to be in person?
No. Frameworks specify content, audience and frequency rather than delivery method, and PCI DSS explicitly contemplates multiple delivery mechanisms. What matters is that delivery is recorded, comprehension is tested where required, and the content is tailored to the role.
What records do we need to keep, and for how long?
Completion records with dates, the content version delivered, assessment results, the in-scope population, and exception handling. Retention follows the framework and the applicable records rules — HIPAA documentation must be retained six years from creation or last effective date, and a SOC 2 Type II examination needs continuous evidence across the whole examination period.
What is the difference between compliance training and security awareness training?
Security awareness training is one component of a compliance training program — the part covering threats such as phishing, social engineering and credential handling. Compliance training is the broader set that also includes privacy, conduct, anti-bribery, antitrust and role-specific regulatory topics.
