Which frameworks require security awareness training, the evidence auditors actually ask for, and the gaps that fail an audit.
Security awareness training is not only good practice — most frameworks an organisation is measured against expect it. Because human error is involved in the majority of breaches, auditors want evidence that you are actively educating people, not just intending to.
One thing to be clear about first: training supports your compliance evidence, it does not deliver compliance. No tool or course makes an organisation compliant. What a good programme gives you is the documentation an assessor asks for.
What the frameworks expect
- SOC 2 and ISO 27001. Both treat awareness as part of the control environment and expect proof that staff are trained on security risks — SOC 2 under its common criteria, ISO 27001 as an Annex A control on awareness, education and training.
- HIPAA. The Security Rule requires a security awareness and training programme for all workforce members (45 CFR 164.308(a)(5)). See security awareness training for healthcare.
- GDPR. Does not prescribe a course, but expects appropriate organisational measures and staff awareness as part of protecting personal data — which in practice means records showing people were trained.
- PCI DSS. Requirement 12.6 mandates a formal security awareness programme for anyone handling cardholder data. See PCI DSS v4.0 training requirements.
- FFIEC and FINRA. Financial services carry additional expectations around managing human risk — see phishing simulation for financial services.
What auditors actually ask for
Assessors rarely want to see your training content. They want evidence it happened, consistently, to the right people.
Completion records. Per person, timestamped, covering everyone in scope — including contractors and joiners mid-year, which is where most gaps appear.
A current written policy. Dated, reviewed, and naming an owner. See the policy template.
Evidence the programme runs. Simulation results and training history over time, not a single burst before the audit.
Follow-up on failures. What happened after someone clicked or missed their training. An assessor asking "and then what?" is testing whether the programme has consequences or just records.
Where audits go wrong
The joiners gap. Everyone employed in January is trained; the six people who joined in August are not. Tie training to onboarding rather than an annual date.
Contractors excluded. Often out of scope in the policy but very much inside your systems.
No evidence of remediation. Records showing who failed, and nothing showing what was done about it.
The audit-season spike. All training completed in one fortnight each year. It satisfies the letter of a requirement and tells an experienced assessor exactly how seriously the programme is taken.
Records you cannot produce. Evidence living in an inbox or a spreadsheet somebody has since left with. If you cannot export per-person completion and simulation history on request, you effectively do not have it.
Beyond the checkbox
The most common mistake is treating training as an annual event to survive an audit. Frameworks are written to encourage ongoing programmes because ongoing is what actually reduces risk — and a continuous security culture produces better evidence as a by-product than any pre-audit scramble.
Related Learning
More Learning Resources
View all learning resourcesBusiness Email Compromise (BEC) Explained
Learn what Business Email Compromise (BEC) is, how these sophisticated financial scams work, and the strategies organizations can use to defend against them.
What Is Phishing?
What phishing is, the forms it takes, why it works on careful people, and the two habits that stop most of it.
Cybersecurity Awareness Glossary
Plain-English definitions of the phishing, social engineering, email authentication and awareness-programme terms security teams actually use.
Ready to stop phishing attacks?
Run realistic phishing simulations and high-impact security awareness training with PhishSkill's automated platform.