Skip to content

Training records

Recording security awareness training, and the monthly check that emails people before their record lapses.

Audience: ISMS Admin.

Where: the Certaria app. Certaria records and chases training. It never delivers it.

What this covers: ISO 27001 control A.6.3 asks that people receive security awareness training appropriate to their role, and that it stays current. Certaria records what you enter and chases expiry. It does not deliver the training.

Once a month it checks whether anyone’s security awareness training is approaching its expiry date. The person concerned is emailed directly so they can book a refresher before their record lapses.

If nothing is near expiry, the run finishes without sending anything. A quiet month is a working month.

Each training record needs the person, what the training was, when they completed it, and when it expires. The expiry date is what drives the reminder, so a record without one is never chased.

Certaria does not judge what counts as adequate training or how often it should recur. Both are yours to set, and both should follow from your risk assessment rather than from a default.

An auditor asking about A.6.3 wants three things:

  • That training happened, with dates and named people.
  • That it was appropriate to the role. A developer and a bookkeeper do not need the same training, and a register showing everyone completed the identical course invites the question.
  • That it stays current. The expiry dates and the fact that people are chased before they lapse.

The third is the one organisations most often fail, and it is the one Certaria automates.

ISO 27001 does not set a retention period, and it will not set one for you. Clause 7.2 asks you to retain “appropriate” evidence of competence. Clause 7.5.3 requires retention and disposal to be controlled, not to be any particular length. Control A.5.33 asks for a defined schedule rather than a defined duration.

So an auditor will not ask whether your period is three years. They will ask what your period is and why. The justification is the thing being audited. The number is not.

Two forces pull in opposite directions, and that tension is the whole decision:

  • Keep records long enough to be evidence. An ISO 27001 certification cycle runs three years, covering initial certification, two surveillance audits and recertification. That is the window an auditor can look back across, so it is the practical floor.
  • Do not keep them longer than you need. Training records are personal data. UK GDPR requires that personal data is kept no longer than necessary, so retaining records indefinitely is a compliance problem in its own right, not simply untidiness.

Common choices are three years, which covers one certification cycle, or six years from the end of employment, which matches the limitation period for contract claims and is what many organisations already apply to employment records generally. Either is defensible. Neither is defensible without a written reason.

The import gives each imported person their opening compliance tasks from the templates you chose, which is where induction training usually sits. Someone who joins later and is added by hand will not get those tasks automatically, so assign them.

SymptomCauseFix
Nobody is being remindedNo records carry an expiry dateThe expiry date drives the check. Records without one are never chased
A person did not receive their emailNo email address on their linked identitySee Import your people
Training shows as expired for a leaverRecords are kept deliberately as evidenceMark the person inactive rather than deleting the record, and remove it when your retention period ends
I never received my reminderThe reminder is an email, and email fails quietlyCheck the person has an email address on their linked identity, then check junk. Nothing in Certaria reports a reminder that failed to arrive
Everyone has identical trainingA single course applied to all rolesReasonable to start with, but expect the question at audit