Direct answer: An auditor accepts security awareness training when you can show three things: that it happened, that it reached everyone in scope, and that it recurred on the cadence the framework expects. The content of the slides matters far less than the records behind them. What gets signed off is a dated completion record for each person, a defined onboarding trigger and an annual refresh, and, for most programmes, proof that you test the training with phishing simulations and act on the results.
The evidence, not the slides
Teams put most of their effort into choosing good training content, then lose the control at the evidence stage. An auditor is not grading your curriculum. They are testing an assertion: that personnel who can touch systems or data understand their responsibilities for protecting them. To test that assertion they ask for records, and the records either exist or they do not.
The unit of evidence is one completion record per person, carrying a name, the module or version completed, and the date it was completed. That record has to tie back to a roster, because the question underneath every awareness control is coverage. If you have thirty-eight people who can access production or customer data and you can show thirty-eight dated completions, the control operates. If you can show twenty-nine, it does not, and the nine gaps become an exception regardless of how good the training was.
Scope is where coverage quietly breaks. Contractors with system access are in scope. Contractors without it are not. A developer on a three-month contract who has a GitHub seat and a cloud role needs the training and the record, and this is the population most often missed, because they never appear in the HR onboarding flow that drives everyone else.
Onboarding and annual: the cadence auditors expect
Two triggers satisfy almost every framework. The first is onboarding: new personnel complete awareness training close to their start date, before or shortly after they get access, with the date recorded. The second is an annual refresh for everyone, so that no one goes more than twelve months without it. A programme that trained everyone once in 2024 and never again is not a programme an auditor accepts, because the operating assertion is continuous, not historical.
The practical failure here is drift. The onboarding step is set up once, works for a year, then a hiring spike arrives and three new starters slip through because the person who assigned the module left. The annual refresh is scheduled for March, March gets busy, and it quietly happens in June, which is fine for a Type I snapshot and a problem for a Type II that samples the whole period. Put both triggers on the compliance calendar with an owner, and treat a missed completion as an incident to close rather than a box that will sort itself out.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Phishing simulations: what counts
For most programmes a slide deck alone is thin evidence that awareness actually changed behaviour. A phishing simulation is how you demonstrate it. What an auditor wants to see is a campaign record: the date, the population it reached, the click rate and the report rate, and what you did about the people who failed. The number that matters is not a flattering click rate. It is the follow-up. A simulation that identifies ten repeat clickers and triggers remedial training for them, with that remediation recorded, is a working control. A simulation with a great result and no evidence of what happens to failures is a marketing exercise.
Which frameworks require it, and the evidence each wants
Awareness training is one of the few controls that appears in every framework a Canadian company is likely to face. The wording differs, the evidence barely does.
SOC 2. The common criteria expect the organization to communicate security responsibilities to personnel and hold them accountable for those responsibilities, which the control environment and communication criteria cover. An auditor reads that as onboarding plus annual training with completion records, and in a Type II they sample across the observation window, so the records have to be dated inside the period.
ISO 27001:2022. Annex A control 6.3 is information security awareness, education and training, and clauses 7.2 and 7.3 require competence and awareness across the management system. The certification body looks for a defined programme, evidence that it ran, and awareness that is relevant to people roles rather than one generic module for everyone.
HIPAA. The Security Rule at 45 CFR 164.308(a)(5) requires a security awareness and training programme for all workforce members, with implementation specifications covering security reminders, protection from malicious software, log-in monitoring and password management. It is an addressable specification, which means documented and reasonable, not optional.
PCI DSS. Requirement 12.6 requires a formal security awareness programme, delivered on hire and at least once every twelve months, with personnel acknowledging the applicable security policies and procedures. The acknowledgement record is itself a piece of evidence, separate from the training completion.
Quebec Law 25 and PIPEDA. Neither names a training module, but both require governance. Law 25 requires governance policies and practices for protecting personal information, and PIPEDA Principle 4.1.4 lists staff training and communication as part of implementing the accountability principle. In practice an organization showing it trains staff on handling personal information is evidencing a governance obligation that would otherwise be a paper policy nobody read.
The records that fail an audit
The exceptions we see most often are not about weak content. They are about records that do not hold up when sampled. The common ones: completions that cover employees but not contractors with access; a roster that does not match the identity provider, so coverage cannot be proven; a one-time training event with no annual refresh; dates that fall outside the observation window for a Type II; phishing results with no remediation trail for the people who failed; and acknowledgement of policies conflated with training, where PCI DSS and most mature programmes want both.
If you want to know which of these apply to the frameworks you are actually pursuing, our security training requirement finder maps the cadence and the evidence to each one, so you can see what a given auditor will ask for before you build the programme around a guess.
Does the training have to be an off-the-shelf platform?
No. Auditors do not require a named training vendor. They require evidence of coverage and cadence. A platform makes the records easier to produce and harder to lose, which is why most teams end up using one, but a disciplined programme run on your own tracking can pass the same tests.
How often do phishing simulations need to run?
There is no universal rule, but quarterly is a defensible cadence for most programmes and is enough to show the control operates continuously across a Type II period. What matters more than frequency is that failures trigger recorded follow-up.
Do board members and executives need the training?
If they have access to systems or data in scope, yes, and they are a common gap because they sit outside the normal onboarding flow. Executives are also a high-value phishing target, so leaving them out undermines the control on its own terms.
Want the records to survive fieldwork? We run awareness training and phishing simulations and keep the completion evidence mapped to your framework, so the control is a sample your auditor clears rather than an exception.
See how it worksOr book a call