What is compliance training?
Compliance training is structured workplace learning that equips people to meet the laws, regulations, license conditions, standards and internal policies that apply to their role. Under ISO 37301, the international compliance management standard, it is one control within a wider compliance management system, and it should be traceable to identified compliance obligations and assessed compliance risks rather than chosen as a list of generic topics.
By the Knowledge Foundry editorial team. How we write and check these pages
- Published
- Updated
- Reading time
- 5 min
Key takeaways
- Compliance training exists to help an organization meet its compliance obligations: the requirements it must meet and those it chooses to meet.
- ISO 37301 treats training (clause 7.2.3) and awareness (clause 7.3) as separate support requirements within a compliance management system.
- Good compliance training is traceable: obligation, role, learning outcome, assessment and record line up.
- Laws often require training outcomes without prescribing a course: for example, Australia's WHS duty to provide necessary training, and the GDPR task of the data protection officer to monitor awareness raising and training of staff.
- Completion records show attendance. Regulators and auditors increasingly look for evidence that people can apply the requirement.
What does compliance training mean?
Compliance training is learning designed so that people know, understand and can apply the requirements that govern their work. Its purpose is narrower than general professional development: it exists because an obligation exists, and it should change behavior in the situations where that obligation applies.
The term is anchored by ISO 37301:2021, the certifiable international standard for compliance management systems published in April 2021. ISO 37301 defines compliance obligations as requirements an organization "mandatorily has to comply with as well as those that an organization voluntarily chooses to comply with". Compliance training therefore covers legislation and regulator rules, and also codes, contracts and internal policies the organization has adopted. The obligations themselves are usually listed in a compliance obligations register.
The ISO technical committee's published FAQ lists "personnel trainings and communications" among the measures the standard requires, alongside identifying obligations, assessing compliance risk, monitoring and corrective action. Training is one control, not the whole system.
How does compliance training work in practice?
Effective compliance training runs as a cycle that starts from obligations, not from content. The steps below reflect the sequence implied by ISO 37301 and by regulator guidance.
- Identify obligations. List the legal, regulatory and voluntary requirements that apply, and keep the list current when rules change.
- Assess risk and exposure by role. Decide which roles face which obligations and how serious a breach would be.
- Define learning outcomes. Write what a person must be able to do, not only what they must read. See learning outcomes.
- Design and deliver. Choose formats that fit the risk: short e-learning for awareness, supervised practice for high risk tasks.
- Assess and record. Check understanding or competence and keep records that link each person to the obligation and version of the material.
- Review. Refresh on a defined cycle and whenever an obligation, process or risk changes.
Laws usually set the outcome rather than the course. For example, section 19(3)(f) of Australia's Work Health and Safety Act 2011 requires a person conducting a business or undertaking to ensure, so far as is reasonably practicable, "the provision of any information, training, instruction or supervision that is necessary to protect all persons" from work risks, as Comcare's regulatory guide sets out. In the European Union, Article 39(1)(b) of the General Data Protection Regulation (GDPR) makes it a task of the data protection officer to monitor compliance, "including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations".
How is compliance training different from related terms?
Compliance training overlaps with several terms that are often used interchangeably but mean different things.
| Term | What it means | Relationship to compliance training |
|---|---|---|
| Mandatory training | Training the organization requires people to complete, whether or not a law demands it | Most compliance training is mandatory, but some mandatory training (for example, a new system rollout) is not about compliance |
| Awareness | Knowing that a policy or obligation exists and why it matters (ISO 37301 clause 7.3) | A lower bar than training; often delivered by communication rather than instruction |
| Policy attestation | A signed or recorded statement that a person has read and will follow a policy | Evidence of acknowledgement, not of understanding or competence |
| Competency assessment | Judging whether a person can perform to a standard | The strongest evidence that compliance training worked |
The practical difference between completion and competence is explored in completion tracking vs competency verification.
What does traceable compliance training look like?
The table below is an illustrative example for a whistleblower obligation in an Australian public company. The Australian Securities and Investments Commission (ASIC) RG 270 says an entity should conduct upfront and ongoing training on its whistleblower policy for every employee, with specializt training for staff who receive disclosures (RG 270.131 and RG 270.134).
| Element | All employees | Eligible recipients |
|---|---|---|
| Obligation | Know how to make a protected disclosure | Handle disclosures confidentially and prevent detriment |
| Learning outcome | Identify who can receive a disclosure and how to contact them | Apply the confidentiality and detriment rules to a disclosure scenario |
| Assessment | Short scenario quiz | Scenario based assessment reviewed by the compliance function |
| Record | Completion, score, policy version | Assessment result, assessor, date, policy version |
| Review trigger | Policy change or annual cycle | Policy change, incident, or law change |
How does Knowledge Foundry approach this?
Knowledge Foundry records each obligation, the concepts a person needs, and the assessment points that prove understanding before any training content is written. Each learning outcome then carries a link back to its source obligation, so the mapping in the example above is held as data rather than rebuilt for each audit.
Frequently asked questions
Is compliance training required by law?
Often, but rarely as a named course. Laws such as Australia's WHS Act require training or competence as an outcome, and the GDPR makes staff training part of what the data protection officer monitors. Regulator guides then explain expectations. Some roles also need specific licenses or accredited training. Organizations decide the format, and must be able to show the outcome was achieved.
Does ISO 37301 require compliance training?
Yes, for organizations that adopt the standard. It includes requirements for competence, training and awareness within the support clauses. ISO 37301 is voluntary, but it can become a contractual or procurement requirement, and certification by an independent body is available because it is a requirements standard.
How often should compliance training be refreshed?
There is no single rule. Refresh cycles should follow the obligation, the risk and any regulator expectation, and training should also be updated whenever the underlying requirement changes. A fixed annual cycle alone can leave content out of date between reviews. See the guide on setting mandatory training refresh cycles.
Is a completion certificate enough evidence?
Completion proves that someone finished a module. It does not show that they understood or can apply the requirement. For higher risk obligations, regulators and auditors look for assessment results, supervisor sign off or verification of competency linked to the version of the material used.
Sources
- ISO 37301:2021 Compliance management systems: Requirements with guidance for use, International Organization for Standardization
- ISO 37301 FAQs, May 2022, ISO/TC 309 Governance of organizations
- Regulatory guide: Primary duty of care, Comcare
- Regulation (EU) 2016/679 (General Data Protection Regulation), Article 39, European Parliament and Council of the European Union (EUR-Lex)
- RG 270 Whistleblower policies, Australian Securities and Investments Commission
This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.