Glossary

What is compliance training?

Short answer

Compliance training is structured workplace learning that equips people to meet the laws, regulations, license conditions, standards and internal policies that apply to their role. Under ISO 37301, the international compliance management standard, it is one control within a wider compliance management system, and it should be traceable to identified compliance obligations and assessed compliance risks rather than chosen as a list of generic topics.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
5 min

Key takeaways

  • Compliance training exists to help an organization meet its compliance obligations: the requirements it must meet and those it chooses to meet.
  • ISO 37301 treats training (clause 7.2.3) and awareness (clause 7.3) as separate support requirements within a compliance management system.
  • Good compliance training is traceable: obligation, role, learning outcome, assessment and record line up.
  • Laws often require training outcomes without prescribing a course: for example, Australia's WHS duty to provide necessary training, and the GDPR task of the data protection officer to monitor awareness raising and training of staff.
  • Completion records show attendance. Regulators and auditors increasingly look for evidence that people can apply the requirement.

What does compliance training mean?

Compliance training is learning designed so that people know, understand and can apply the requirements that govern their work. Its purpose is narrower than general professional development: it exists because an obligation exists, and it should change behavior in the situations where that obligation applies.

The term is anchored by ISO 37301:2021, the certifiable international standard for compliance management systems published in April 2021. ISO 37301 defines compliance obligations as requirements an organization "mandatorily has to comply with as well as those that an organization voluntarily chooses to comply with". Compliance training therefore covers legislation and regulator rules, and also codes, contracts and internal policies the organization has adopted. The obligations themselves are usually listed in a compliance obligations register.

The ISO technical committee's published FAQ lists "personnel trainings and communications" among the measures the standard requires, alongside identifying obligations, assessing compliance risk, monitoring and corrective action. Training is one control, not the whole system.

How does compliance training work in practice?

Effective compliance training runs as a cycle that starts from obligations, not from content. The steps below reflect the sequence implied by ISO 37301 and by regulator guidance.

  1. Identify obligations. List the legal, regulatory and voluntary requirements that apply, and keep the list current when rules change.
  2. Assess risk and exposure by role. Decide which roles face which obligations and how serious a breach would be.
  3. Define learning outcomes. Write what a person must be able to do, not only what they must read. See learning outcomes.
  4. Design and deliver. Choose formats that fit the risk: short e-learning for awareness, supervised practice for high risk tasks.
  5. Assess and record. Check understanding or competence and keep records that link each person to the obligation and version of the material.
  6. Review. Refresh on a defined cycle and whenever an obligation, process or risk changes.

Laws usually set the outcome rather than the course. For example, section 19(3)(f) of Australia's Work Health and Safety Act 2011 requires a person conducting a business or undertaking to ensure, so far as is reasonably practicable, "the provision of any information, training, instruction or supervision that is necessary to protect all persons" from work risks, as Comcare's regulatory guide sets out. In the European Union, Article 39(1)(b) of the General Data Protection Regulation (GDPR) makes it a task of the data protection officer to monitor compliance, "including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations".

How is compliance training different from related terms?

Compliance training overlaps with several terms that are often used interchangeably but mean different things.

Compliance training and neighboring terms
TermWhat it meansRelationship to compliance training
Mandatory trainingTraining the organization requires people to complete, whether or not a law demands itMost compliance training is mandatory, but some mandatory training (for example, a new system rollout) is not about compliance
AwarenessKnowing that a policy or obligation exists and why it matters (ISO 37301 clause 7.3)A lower bar than training; often delivered by communication rather than instruction
Policy attestationA signed or recorded statement that a person has read and will follow a policyEvidence of acknowledgement, not of understanding or competence
Competency assessmentJudging whether a person can perform to a standardThe strongest evidence that compliance training worked

The practical difference between completion and competence is explored in completion tracking vs competency verification.

What does traceable compliance training look like?

The table below is an illustrative example for a whistleblower obligation in an Australian public company. The Australian Securities and Investments Commission (ASIC) RG 270 says an entity should conduct upfront and ongoing training on its whistleblower policy for every employee, with specializt training for staff who receive disclosures (RG 270.131 and RG 270.134).

Illustrative mapping from obligation to evidence
ElementAll employeesEligible recipients
ObligationKnow how to make a protected disclosureHandle disclosures confidentially and prevent detriment
Learning outcomeIdentify who can receive a disclosure and how to contact themApply the confidentiality and detriment rules to a disclosure scenario
AssessmentShort scenario quizScenario based assessment reviewed by the compliance function
RecordCompletion, score, policy versionAssessment result, assessor, date, policy version
Review triggerPolicy change or annual cyclePolicy change, incident, or law change

How does Knowledge Foundry approach this?

Knowledge Foundry records each obligation, the concepts a person needs, and the assessment points that prove understanding before any training content is written. Each learning outcome then carries a link back to its source obligation, so the mapping in the example above is held as data rather than rebuilt for each audit.

Frequently asked questions

Is compliance training required by law?

Often, but rarely as a named course. Laws such as Australia's WHS Act require training or competence as an outcome, and the GDPR makes staff training part of what the data protection officer monitors. Regulator guides then explain expectations. Some roles also need specific licenses or accredited training. Organizations decide the format, and must be able to show the outcome was achieved.

Does ISO 37301 require compliance training?

Yes, for organizations that adopt the standard. It includes requirements for competence, training and awareness within the support clauses. ISO 37301 is voluntary, but it can become a contractual or procurement requirement, and certification by an independent body is available because it is a requirements standard.

How often should compliance training be refreshed?

There is no single rule. Refresh cycles should follow the obligation, the risk and any regulator expectation, and training should also be updated whenever the underlying requirement changes. A fixed annual cycle alone can leave content out of date between reviews. See the guide on setting mandatory training refresh cycles.

Is a completion certificate enough evidence?

Completion proves that someone finished a module. It does not show that they understood or can apply the requirement. For higher risk obligations, regulators and auditors look for assessment results, supervisor sign off or verification of competency linked to the version of the material used.

Sources

  1. ISO 37301:2021 Compliance management systems: Requirements with guidance for use, International Organization for Standardization
  2. ISO 37301 FAQs, May 2022, ISO/TC 309 Governance of organizations
  3. Regulatory guide: Primary duty of care, Comcare
  4. Regulation (EU) 2016/679 (General Data Protection Regulation), Article 39, European Parliament and Council of the European Union (EUR-Lex)
  5. RG 270 Whistleblower policies, Australian Securities and Investments Commission

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.