Guide

How often should mandatory training be refreshed?

Short answer

Mandatory training should be refreshed at the frequency a law, standard, or regulator sets where one exists, such as annual cyber security awareness training under Australia's Information Security Manual. Where no source sets a frequency, which is common, set the cycle on risk: the consequence of error, how often the task is performed, how quickly the rules change, and what assessment and incident data show. Add event triggers so changes prompt retraining between cycles.

By the Knowledge Foundry editorial team. How we write and check these pages

Published
Updated
Reading time
7 min

Key takeaways

  • Only some frameworks set a refresh frequency. Many require training to be suitable, adequate, or ongoing without naming an interval.
  • Where a frequency is set, record the exact source and wording. Where it is not, record the risk rationale for the cycle you chose.
  • Risk factors for a cycle include consequence of error, how often the skill is used, rate of change, and evidence from assessments and incidents.
  • Event triggers (a changed rule, procedure, system, or an incident) often matter more than the calendar.
  • Different roles can have different cycles for the same topic. Regulator examples, such as those from the Australian Transaction Reports and Analysis Centre (AUSTRAC), show that approach while noting they are examples only.

Is there a legal rule for how often training must be refreshed?

There is no general rule. A refresh frequency applies only where a specific law, standard, code, or regulator sets one for a specific group, and many regimes instead require training that is suitable, adequate, or ongoing without naming an interval. Treat any stated frequency as applying only to the population and topic its source covers.

For example, the PIC/S Guide to GMP, which many medicines regulators adopt, asks for continuing training whose practical effectiveness is "periodically assessed", but it does not set an interval (PE009-16 Part I, clause 2.11). Requirements of this kind tell you that training must continue and must work, and leave the cycle to you.

Where do laws and regulators set a frequency?

Some instruments do name an interval, usually for a defined group and topic. The table lists examples confirmed against the primary source for this guide, as at September 2026. It is a sample, not a complete register; check the instruments that apply to your organization in each country where you operate.

Examples of refresh frequencies set by primary sources
SourceApplies toWhat it setsStatus of the wording
Information Security Manual (Australia), ISM-0252Organizations applying the ISM, including government entitiesCyber security awareness training undertaken annually by all personnelControl
Information Security Manual, ISM-1565Personnel with privileged access to systemsTailored privileged user training undertaken annuallyControl
OSHA Bloodborne Pathogens standard (United States), 29 CFR 1910.1030(g)(2)Employees with occupational exposure to blood or other potentially infectious materialsTraining at initial assignment and at least annually thereafter, within one year of the previous trainingFederal regulation ("shall")

Sources: ASD ISM personnel security guidelines, 29 CFR 1910.1030 on eCFR. See also ISM awareness training and PSPF security awareness training.

Examples are not requirements

AUSTRAC gives example ongoing training frequencies, such as every 6 to 12 months for AML/CTF compliance officers and senior management and every 12 months for customer facing personnel, and states that "these are examples only, and the frequency you deliver training must be appropriate to your business" (AUSTRAC). Treat regulator examples as a reference point for your risk assessment, not as a rule.

How do you set a refresh cycle when no source sets one?

Set the cycle by assessing risk factors for each topic and role, choosing an interval that matches the result, and recording why. The factors below are the ones most often used; weight them to suit your risk framework.

  • Consequence of error. How serious is the harm if someone gets this wrong: to people, customers, the organization, or its license?
  • Frequency of use. Skills used daily are practiced at work. Skills used rarely, such as emergency response or unusual transaction reporting, fade and need more frequent practice.
  • Rate of change. How often do the underlying law, policy, procedure, or system change?
  • Evidence of performance. Assessment results, audit findings, errors, complaints, and incidents show whether current knowledge is holding.
  • Role exposure. People who make the relevant decisions need shorter cycles than those who only need awareness.

What does a risk based refresh cycle look like?

A risk based cycle rates each topic and role on the factors above and maps the result to an interval and a method. The example is illustrative only: topics, ratings, and intervals are invented to show the method and are not recommendations for any regime.

Illustrative risk based refresh matrix
Topic and roleConsequenceFrequency of useRate of changeResulting cycle and method
Escalating suspicious transactions: front line staffHighLowMedium12 months, scenario practice; plus event triggers
Escalating suspicious transactions: compliance analystsHighHighMediumOngoing supervision and quality review; formal refresh every 12 months or on change
Complaints handling basics: all customer facing staffMediumHighLow24 months awareness refresh; targeted refresh when complaint data shows issues
Evacuation procedure: all staff on siteHighVery lowLow12 months with a drill; on any change to the site or procedure
Code of conduct: all staffMediumMediumLow24 months, with annual attestation

Where a topic is also covered by a set frequency, such as annual security awareness under the ISM, the set frequency is a floor. The risk method can shorten it for some roles but not lengthen it.

What are the steps to set and maintain refresh cycles?

Identify set frequencies, assess risk for everything else, add event triggers, then document and review. Each step has an output that becomes part of your training policy or matrix.

  1. List mandatory topics by role. Use your training matrix. Output: topic by role list.
  2. Find set frequencies. For each topic, check the instruments that apply and record the exact wording and source. Output: a register of set frequencies with citations.
  3. Assess risk for the rest. Rate each topic and role on the risk factors. Output: a risk rating per cell.
  4. Choose intervals and methods. Map ratings to intervals and to a method: full course, short refresher, scenario practice, drill, or assessment only. Output: a refresh schedule.
  5. Define event triggers. List the changes that require retraining before the next cycle: new or amended law, policy, procedure, or system; an incident or audit finding; a role change. Output: a trigger list with owners.
  6. Allow assessment first where suitable. For stable topics, let people take the assessment first and complete the refresher only if they do not meet the standard. Output: a test out rule.
  7. Document the rationale. Record the reasons in the training policy. Output: an approved policy section.
  8. Review with data. At least annually, compare assessment and incident data against the cycles and adjust. Output: review minutes and changes.

When should training be refreshed outside the normal cycle?

Refresh outside the cycle whenever the knowledge the training teaches has changed or has been shown not to hold. A calendar cycle alone can leave people working to a superseded rule for most of a year.

Requirements that training be suitable for the risks and controls in place support this: when risks or controls change, earlier training may no longer be adequate. AUSTRAC, for example, says it expects entities to consider updating and providing AML/CTF training "as soon as practicable" in response to changes to AML/CTF laws, new and emerging risks, changes to their AML/CTF program, and review findings that indicate training gaps (AUSTRAC). See how to update training when a regulation changes.

How does Knowledge Foundry approach this?

Knowledge Foundry links each outcome to the sources it depends on, so a change to a source can identify the people and outcomes that need retraining rather than triggering a full cycle for everyone. Set frequencies and risk rationale can be recorded against the obligation they come from. The knowledge governance page describes this.

Frequently asked questions

Is annual compliance training a legal requirement?

Only where a specific instrument says so for a specific group, such as annual cyber security awareness under ISM-0252 in Australia or annual bloodborne pathogens training under 29 CFR 1910.1030 in the United States. Many other regimes require suitable or ongoing training without a set interval. Annual cycles are common practice, but practice is not the same as a legal requirement.

Can staff skip refresher training if they pass an assessment?

Where no source prescribes the training itself, a test out approach is often defensible: people who meet the standard on a well designed assessment have shown the knowledge is current. Where a source requires the training to be undertaken at a frequency, check whether an assessment alone would satisfy that wording.

Should every role have the same refresh cycle for a topic?

Not necessarily. Roles that make the relevant decisions often need shorter cycles and deeper practice than roles that only need awareness. AUSTRAC's examples, for instance, suggest different intervals for compliance officers, customer facing staff, and other personnel, while stressing they are examples only.

How do we evidence the rationale for our refresh cycles?

Record, for each topic and role, any set frequency with its citation, or the risk ratings and the reasoning for the interval chosen. Keep this in the training policy or matrix, approve it through governance, and record each review. Auditors look for a considered, current rationale rather than a particular interval.

Sources

  1. Information Security Manual: Guidelines for personnel security, Australian Signals Directorate
  2. 29 CFR 1910.1030 Bloodborne pathogens, US Occupational Safety and Health Administration (eCFR)
  3. AML/CTF training, AUSTRAC
  4. PIC/S Guide to GMP PE009-16, Part I: Basic requirements for medicinal products, Therapeutic Goods Administration

This page is general information, not legal or compliance advice. Check the primary sources above and obtain advice for your circumstances. See our editorial standards.

Ready to see it?

Bring a subject. Leave with a framework.

A 45-minute working session with our team on a real subject or program you own. You see the system operate on your material, and you keep the framework it produces.

We reply within one business day.