What auditors ask for as proof of training
“We trained everyone” is not evidence. Whether you’re preparing for an ISO 27001 surveillance audit, a SOC 2 review, a PCI DSS assessment, or an NDPC inquiry, auditors tend to ask for the same small set of specific artifacts. Here’s what to have ready.
1. A per-employee completion record
Not a sign-in sheet from a single meeting. Auditors want to see, by name or employee ID, which modules each person completed and when. If someone joined mid-year, the record should show they completed the required training within a defined onboarding window, not “eventually.”
2. The actual training content, not just a title
Be ready to show what a module actually covers, not just its name on a list. A title like “Security Awareness Training” tells an auditor nothing about whether phishing, password hygiene, or data handling was actually taught. Specific, documented learning objectives per module matter here.
3. Evidence the training is current
Auditors are increasingly skeptical of training that hasn’t been touched in years, especially around fast-moving topics like AI tool use or deepfake fraud. Being able to show when a module was last updated, and why, is a good signal that your program is actively maintained.
4. Simulation results, where applicable
If your framework or your own risk assessment calls for phishing simulations, auditors may ask for the data: how many simulations ran, what the click or report rate was, and whether it’s trending in the right direction. A single simulation two years ago reads very differently than a running, rotating program.
5. A named owner and a defined cadence
Who owns the training program, and how often is it reviewed or refreshed? “Whenever someone remembers” is a finding waiting to happen. A documented cadence, even a simple one, shows the program is managed rather than accidental.
6. How you handle people who don’t complete it
Auditors sometimes ask what happens when someone misses a deadline. Having even a simple escalation step (a reminder, then a manager notification) shows the completion requirement has teeth.
Compliance mapping helps, but don’t overstate it
It’s reasonable to show an auditor how your training maps to ISO 27001 Annex A.6.3, SOC 2 CC1.4/CC2.2, PCI DSS Requirement 12.6, or HIPAA’s security awareness standard. Just be precise about what’s confirmed versus what still needs your own compliance team’s sign-off, especially for frameworks with recent amendments. Overstating a mapping is its own audit finding.
Our Courses pages show the exact compliance mapping per module, including where we flag a clause as needing independent verification, so you’re not caught citing something you can’t back up.