SigmAcademy · Training evidence
Compliance Training Records & Evidence
Every framework asks a version of the same question: can you prove your people were trained, and that it worked? The organisations that suffer are not the ones who skipped training — they are the ones who trained everyone and kept no defensible record.
What frameworks actually require
PCI DSS 12.6 (awareness incl. phishing, with acknowledgement), ISO 27001 A.6.3 and clause 7.2 (role-appropriate, evaluated, recorded), SOC 2 CC1.4/CC2.2 — all sample records, not intentions.
Records by construction
Completion, assessment scores and acknowledgements are captured as training runs — the evidence exists because the programme ran, not because someone assembled a spreadsheet in audit week.
Per-role defensibility
Because paths are role-based, the record shows the right people got the right content — the nuance that separates a pass from a finding on "appropriate to role".
One programme, many audits
The same records serve the PCI assessment, the ISO surveillance audit and the SOC 2 window — training evidence is the easiest build-once-comply-many-times win there is.
FAQ
Do we need acknowledgement signatures?
PCI 12.6.2 expects personnel to acknowledge the policy at least annually; captured acknowledgements are part of the record set.
How far back should records go?
At least the current audit period plus one prior cycle is the practical norm; retention is configurable to your policy.
Can HR systems consume the records?
Records are exportable for HRMS and GRC consumption — where they live is your call; that they exist is the point.
See SigmAcademy on your environment
Scoped to your stack in one conversation — with the CyberSigma practice behind the platform.
