Guide

How do you choose a compliance training platform?

Short answer

To choose a compliance training platform, start from the evidence you must produce for regulators and auditors, then assess platforms against weighted criteria: obligation mapping, role based assignment, assessment beyond completion, versioned content and records, reporting, privacy and security, interoperability, accessibility, administration effort, and data portability. Test shortlisted platforms with scripted demonstrations using your own content and a pilot with real users before deciding.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
8 min

Key takeaways

  • Define the evidence you need to produce before looking at platforms. Features matter only if they produce that evidence.
  • Completion tracking alone rarely answers a regulator. Look for assessment, version history, and a link from each record to the obligation it serves.
  • Privacy and security questions, including where data is stored and who can access it, belong in the first round, not the contract stage.
  • Scripted demonstrations with your own content and scenarios expose gaps that standard demonstrations hide.
  • Check data export before you sign. You will need your records and content when you next change platforms.

What should you define before looking at platforms?

Define the obligations the training supports, the roles in scope, and the evidence you must be able to produce, then turn those into requirements. Starting from product demonstrations tends to produce a shortlist of attractive interfaces rather than a platform that answers an auditor's questions.

  • Obligations. Which laws, standards, and internal policies does the training support? The mapping guide explains how to build this list.
  • Evidence. What must you show, and to whom? For example, Australia's AUSTRAC suggests anti money laundering training records capture what was delivered, including the content and content version, how understanding was assessed, and each person's training history (AUSTRAC).
  • Population. Employees, contractors, and third parties; how they are identified; and whether they have corporate accounts.
  • Delivery mix. Online modules, face to face sessions, on the job assessment, and attestations all need to be recorded in one place. AUSTRAC notes its own e-learning modules cannot be relied on solely to meet training obligations, which is a reminder that the platform must record more than online completions.
  • Constraints. Data location, security classification, integration with HR systems, and budget.

Which criteria matter most for compliance training?

The criteria that matter most are the ones that determine whether you can prove the right people were trained on the right version and could apply it. The table lists criteria, why each matters in regulated settings, and the evidence to request from any provider.

Vendor neutral criteria for a compliance training platform
CriterionWhy it mattersQuestions to askEvidence to request
Obligation mappingShows which obligation each item and record servesCan items be linked to obligations or policies, and can reports be filtered by obligation?Report showing completions grouped by obligation
Role based assignmentTraining must suit the work and its risksCan assignment follow role, location, and risk attributes from the HR system, and update automatically on role change?Demonstration of a role change triggering new assignments
Assessment beyond completionCompletion does not show understandingDoes it support scenario questions, observed assessments, and assessor sign off with evidence attached?A workplace observation recorded with the assessor and version
Content version controlRecords must show which version a person completedIs each completion tied to a content version? Can you see who completed a superseded version?Record history for an item across two versions
Records and audit trailEvidence must be complete and unalteredAre changes to records logged with who and when? Can records be exported in full?Audit log extract and full export sample
ReportingBoards and regulators need clear statusCan reports show overdue, at risk, and completed by role, obligation, and business unit?Sample board level and regulator style reports
Privacy and securityRecords contain personal informationWhere is data stored and processed? Who at the provider can access it? What security assessments exist?Data location statement, security assessment results, subprocessor list
InteroperabilityContent and data must move in and outWhich of SCORM, xAPI, and cmi5 are supported? Which HR and identity integrations exist?Test launch of your own packages; integration documentation
AccessibilityAll learners must be able to complete required trainingWhat conformance level to WCAG 2.2 does the learner interface meet, and how was it tested?Accessibility conformance report
Administration effortManual work creates errors and delaysHow are assignments, reminders, and escalations automated?Walkthrough of a quarterly compliance cycle
Portability and exitYou will change platforms againCan all records, content, and version history be exported in usable formats at no extra cost?Contract clause and a sample export

What privacy and security questions should you ask?

Ask where personal information will be stored and processed, who can access it, how it is protected, and how it will be returned or destroyed at the end of the contract. Training records hold names, roles, results, and sometimes sensitive details from incident based training.

Privacy law governs where training records are stored and who can see them, so check the rules in each jurisdiction where you operate. For example, under the Australian Privacy Principles, APP 8 sets out the steps an entity must take before disclosing personal information overseas, and APP 11 requires reasonable steps to protect personal information and, in certain circumstances, to destroy or de-identify it (OAIC). If the platform includes AI features, the OAIC's guidance on commercially available AI products recommends due diligence on whether the product has been tested for the intended use and who can access information entered into it. Government entities will usually have additional protective security requirements.

What are the steps in a platform selection?

Run the selection as a sequence of narrowing steps, each with a documented output, so the final decision can be explained to procurement, audit, and the board.

  1. Write requirements. Turn obligations, evidence needs, population, and constraints into must have and should have requirements. Output: a requirements list with weights.
  2. Decide the platform category. Decide whether you need a learning management system, a learning experience platform, a content management system, or a combination. Output: a category decision. See LMS vs LXP and LMS vs LCMS.
  3. Issue a request for information. Ask providers to respond to the criteria table in writing. Output: comparable written responses.
  4. Run scripted demonstrations. Give each shortlisted provider the same script using your own content, roles, and a policy change scenario. Output: scored demonstration results.
  5. Complete security and privacy review. Assess data location, access, certifications, and incident handling. Output: a risk assessment for each finalizt.
  6. Pilot. Run a real compliance cycle with a representative group, including managers and assessors. Output: pilot findings, including administrator time and learner feedback.
  7. Score and decide. Apply the weighted scoring model and record the rationale. Output: a decision paper.
  8. Negotiate exit terms. Confirm export formats, timing, and cost before signing. Output: contract clauses for data return and destruction.

How do you score and compare platforms fairly?

Use a weighted scoring model agreed before demonstrations begin, so that scores reflect your priorities rather than the most recent presentation. Score each criterion on a fixed scale against the evidence seen, not claimed.

Illustrative weighted scoring template (weights are examples; set your own)
CriterionExample weightScore 0 to 5Weighted score
Assessment beyond completion15%Enter scoreWeight multiplied by score
Content version control and records15%Enter scoreWeight multiplied by score
Privacy and security15%Enter scoreWeight multiplied by score
Role based assignment10%Enter scoreWeight multiplied by score
Obligation mapping and reporting10%Enter scoreWeight multiplied by score
Interoperability10%Enter scoreWeight multiplied by score
Accessibility10%Enter scoreWeight multiplied by score
Administration effort10%Enter scoreWeight multiplied by score
Portability and exit5%Enter scoreWeight multiplied by score
Scripted demonstration checklist

Load one of your existing packages and launch it. Assign training by role and then change a person's role. Publish a new version of an item and show who completed the old one. Record an observed workplace assessment with evidence. Produce an overdue report by business unit. Export all records for one person. Show the audit log for a changed record. Show how an accessibility issue would be reported and fixed.

What are the warning signs during selection?

The main warning signs are answers that describe completion tracking when you asked about competence, and vague answers about data location or export. Both tend to become expensive problems after go live.

  • Completion is the only status a record can hold.
  • Content updates overwrite the previous version with no history.
  • Records cannot be exported in full without a paid service.
  • Data location or subprocessors cannot be stated in writing.
  • The demonstration cannot use your content or your scenario.
  • Accessibility conformance is claimed but no report or test method is available.

See completion tracking vs competency verification for why the first warning sign matters.

How does Knowledge Foundry approach this?

Knowledge Foundry sits upstream of delivery platforms: it defines the knowledge framework, obligations, outcomes, and assessment points that training must cover, and connects to existing systems for delivery and records. That means the selection criteria above can be tested against a defined framework rather than against content alone. The integrations page lists how it connects.

Frequently asked questions

Do we need a specializt compliance platform or will a general LMS do?

A general learning management system can be enough if it records versions, supports assessment beyond completion, and reports by role and obligation. Specializt tools add features such as obligation libraries and attestation workflows. Decide by testing both types against the same scripted demonstration and your evidence requirements.

Should the platform include off the shelf compliance content?

It can save time for general topics, but check that content matches the law in each jurisdiction where you operate and your own policies, and that you can edit or supplement it. Content that cannot be tailored to your procedures often needs a local addition anyway. See the comparison of off the shelf and custom compliance training.

How important is data location for a training platform?

It depends on your obligations and risk appetite. Training records contain personal information, so APP 8 applies to overseas disclosure. Government entities and some regulated industries have stricter requirements. Ask for a written statement of where data is stored and processed, including backups and support access.

How long should a platform pilot run?

Long enough to complete one realiztic compliance cycle: assignment, reminders, completion, assessment, overdue escalation, and reporting. For many organizations that is several weeks. A short pilot that only tests the learner interface misses the administrator and reporting workload where most problems appear.

Sources

  1. AML/CTF training, AUSTRAC
  2. Australian Privacy Principles quick reference, Office of the Australian Information Commissioner
  3. Guidance on privacy and the use of commercially available AI products, Office of the Australian Information Commissioner
  4. Web Content Accessibility Guidelines (WCAG) 2.2, World Wide Web Consortium (W3C)
  5. The cmi5 Project, AICC cmi5 working group
  6. xAPI Specification, Advanced Distributed Learning (ADL) Initiative

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.