We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

SigmAcademy · Training evidence

Compliance Training Records & Evidence

Every framework asks a version of the same question: can you prove your people were trained, and that it worked? The organisations that suffer are not the ones who skipped training — they are the ones who trained everyone and kept no defensible record.

What frameworks actually require

PCI DSS 12.6 (awareness incl. phishing, with acknowledgement), ISO 27001 A.6.3 and clause 7.2 (role-appropriate, evaluated, recorded), SOC 2 CC1.4/CC2.2 — all sample records, not intentions.

Records by construction

Completion, assessment scores and acknowledgements are captured as training runs — the evidence exists because the programme ran, not because someone assembled a spreadsheet in audit week.

Per-role defensibility

Because paths are role-based, the record shows the right people got the right content — the nuance that separates a pass from a finding on "appropriate to role".

One programme, many audits

The same records serve the PCI assessment, the ISO surveillance audit and the SOC 2 window — training evidence is the easiest build-once-comply-many-times win there is.

FAQ

Do we need acknowledgement signatures?

PCI 12.6.2 expects personnel to acknowledge the policy at least annually; captured acknowledgements are part of the record set.

How far back should records go?

At least the current audit period plus one prior cycle is the practical norm; retention is configurable to your policy.

Can HR systems consume the records?

Records are exportable for HRMS and GRC consumption — where they live is your call; that they exist is the point.

Certification readiness

See SigmAcademy on your environment

Scoped to your stack in one conversation — with the CyberSigma practice behind the platform.