- Documentation
- Run your ISMS
Training records
Setting training requirements, recording completions, and the monthly email that tells each person what is expiring and what is missing.
Audience: ISMS Admin.
Where: the Certaria app. Certaria records and chases training. It never delivers it.
What this covers: ISO 27001 control A.6.3 asks that people receive security awareness training appropriate to their role, and that it stays current. Clause 7.2 asks you to evaluate whether the training worked. Certaria records what is required, records what you enter, and chases the gap. It does not deliver the training.
Requirements first, records second
Section titled “Requirements first, records second”Training in Certaria has two halves:
- A training requirement says what training your organisation requires, who it applies to (all staff, or particular roles), and how often it recurs. Certaria ships with one already in place: annual security awareness training for all staff, every 12 months. Add your own for anything role-specific.
- A training record says a named person completed something on a date, with an expiry date if it recurs.
A record should be linked to the requirement it satisfies. That link is what lets Certaria answer “who still owes this training?” A record without a requirement behind it, such as an external certificate, is still kept and still chased on expiry, but it does not count towards any requirement and does not appear on your ISMS site.
The requirement also carries an evaluation method. Clause 7.2 asks you to evaluate the effectiveness of the training programme, not to ask each employee to self-assess, so the method lives on the requirement rather than on individual records.
What Certaria does
Section titled “What Certaria does”Once an hour, your people’s completed training is published to the ISMS SharePoint site as read-only confirmations. Each person can open only their own; ISMS administrators see everything. The list of requirements is visible to everyone, and each requirement shows its audience, Everyone or the roles it applies to, so staff can see what is expected of them.
Once a month, each person is emailed a training summary if there is anything to say: records due to expire in the next 60 days, and required training they have not yet completed. If neither applies, no email is sent. A quiet month is a working month.
What you record
Section titled “What you record”Each training record needs the person, what the training was, when they completed it, when it expires, and the requirement it satisfies. The expiry date is what drives the reminder, so a record without one is never chased.
Certaria does not judge what counts as adequate training or how often it should recur. Both are yours to set, and both should follow from your risk assessment rather than from a default.
Making it evidence rather than a list
Section titled “Making it evidence rather than a list”An auditor asking about A.6.3 wants three things:
- That training happened, with dates and named people.
- That it was appropriate to the role. A developer and a bookkeeper do not need the same training, and a register showing everyone completed the identical course invites the question. Role-targeted requirements are how you evidence the difference.
- That it stays current. The expiry dates, the monthly chase, and the requirements nobody has yet met.
The third is the one organisations most often fail, and it is the one Certaria automates.
How long to keep records
Section titled “How long to keep records”ISO 27001 does not set a retention period, and it will not set one for you. Clause 7.2 asks you to retain “appropriate” evidence of competence. Clause 7.5.3 requires retention and disposal to be controlled, not to be any particular length. Control A.5.33 asks for a defined schedule rather than a defined duration.
So an auditor will not ask whether your period is three years. They will ask what your period is and why. The justification is the thing being audited. The number is not.
Two forces pull in opposite directions, and that tension is the whole decision:
- Keep records long enough to be evidence. An ISO 27001 certification cycle runs three years, covering initial certification, two surveillance audits and recertification. That is the window an auditor can look back across, so it is the practical floor.
- Do not keep them longer than you need. Training records are personal data. UK GDPR requires that personal data is kept no longer than necessary, so retaining records indefinitely is a compliance problem in its own right, not simply untidiness.
Common choices are three years, which covers one certification cycle, or six years from the end of employment, which matches the limitation period for contract claims and is what many organisations already apply to employment records generally. Either is defensible. Neither is defensible without a written reason.
New starters
Section titled “New starters”The import gives each imported person their opening compliance tasks from the templates you chose, which is where induction training usually sits. Someone who joins later and is added by hand will not get those tasks automatically, so assign them. Requirements need no such step: a requirement for all staff applies to a new starter the moment their person record exists, and their first monthly summary will say so.
Common failure modes
Section titled “Common failure modes”| Symptom | Cause | Fix |
|---|---|---|
| A completed course still shows as outstanding | The record is not linked to the requirement | Open the record and set its requirement. An unlinked record satisfies nothing |
| A confirmation is missing from the site | The record has no requirement behind it | Same fix. The site list requires the link, so unlinked records stay in the register only |
| Nobody is being reminded about expiry | No records carry an expiry date | The expiry date drives the check. Records without one are never chased |
| A person did not receive their email | No email address on their linked identity | See Import your people |
| Training shows as expired for a leaver | Records are kept deliberately as evidence | Mark the person inactive rather than deleting the record, and remove it when your retention period ends |
| I never received my reminder | The reminder is an email, and email fails quietly | Check the person has an email address on their linked identity, then check junk. Nothing in Certaria reports a reminder that failed to arrive |
| Everyone has identical training | A single course applied to all roles | Reasonable to start with, but expect the question at audit |
- Import your people, where induction tasks are assigned
- Tasks and deadlines
- The registers you maintain