Back to Columns
ISMS & Certification13 min read

Designing Security Awareness Training: Operating at 100% Completion

September 14, 2026

Designing Security Awareness Training: Operating at 100% Completion
Share this article

The most common training arrangement in an ISMS is "send one e-learning module to everyone once a year and count the completions." It is not wrong, but it meets about half the requirement, because the standard asks for competence and awareness separately, and the two differ in audience and in how they are demonstrated.

The arrangement also leaks. People who joined mid-year. People returning from extended leave. Contractor personnel working on site. A single annual send misses all three — and that is exactly where auditors and customer audits find the gaps.

Then there is the completion rate. People ask whether 95% is acceptable. It is not: 100% is required. This article explains why, and turns training design into practice. For where the requirement sits, see Clause 7: Support; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

Why This Trips People Up

Trying to satisfy competence and awareness with one initiative

CompetenceAwareness
What is requiredPeople doing work that affects ISMS performance have the ability that work needsPeople working under the organisation's control understand the policy, their contribution, and the implications of not conforming
AudienceSpecific role holders (ISMS manager, internal auditors, system administrators, developers)Everyone working under the organisation's control
How it is securedTraining, experience, qualifications, or reassigning peopleCommunication, training, day-to-day reinforcement
Evidence to keepEvidence of competence (completion, qualification, background)Records that awareness was delivered
How it is judgedDefine the competence each role needs, then judge sufficiencyEveryone is in scope; judge coverage

One e-learning module to everyone covers awareness reasonably well but cannot demonstrate competence. The competence an internal auditor needs, the secure-coding knowledge a developer needs, and the access-management understanding a system administrator needs each have to be defined and secured separately.

Defining "workers" too narrowly

Awareness extends to people working under the organisation's control — not just permanent employees, but directors, fixed-term staff, part-timers, agency staff, and contractor personnel working under your direction. Limiting it to permanent employees invites a question about the validity of the scope. See Defining ISMS Scope.

Training that is just the policy read aloud

An e-learning module amounting to "I have read the policy" partly satisfies awareness but changes no behaviour. Awareness asks for understanding of how one's own work contributes and what follows from not conforming. Generalities do not reach either.

Completion rates are counted but non-completers are not handled

"We reached 95%" means, read the other way, you know exactly who the other 5% are and have done nothing about them. That is the easiest thing in the world for an auditor to pull on. 95% is read not as evidence of control but as evidence that an incomplete state was left alone.

Why it has to be 100%

Three reasons.

  1. The requirement says everyone. Awareness applies to people working under the organisation's control. A subset does not satisfy it
  2. Your records identify the non-completers. Once you are tracking completion, the people who did not complete are named. Named and untreated is a nonconformity to correct
  3. Attacks target the weakest individual. Phishing and insider misuse happen to a person, not to a statistical average. "Almost everyone knows" is not a defence

There are legitimately unreachable periods — extended sick leave, parental leave. Handle these as "out of scope this cycle, delivered on return," not as non-completion. Excluded properly from the denominator, with a procedure for delivery on return, nothing has been left alone.

What You Have to Decide

1. Who is in scope, and where the roster comes from

Define the audience and decide which system supplies the roster — HR, time and attendance, or identity management. A hand-maintained spreadsheet goes stale with every joiner and leaver. Tying the training roster to the same source as account provisioning leaks the least.

2. Types of training and their audiences

TypeAudienceFrequencyMain contentRecords kept
InductionNew joiners (including mid-career) and internal moversWithin N days of joining/movingPolicy, basic rules, reporting route, confidentiality undertakingDate, attendee, comprehension check, signed undertaking
Annual all-handsAll workersAnnuallyPolicy essentials, last year's incidents, changes, worked casesDate, attendee, comprehension results
Role-basedAdministrators, developers, supplier managers, HRAnnually or as neededAccess management, secure coding, supplier assessmentCompletion record plus competence judgement
Internal auditorInternal auditorsOn appointment plus maintenanceAudit method, gathering evidence, reportingCertificate, audit history
ExercisesAll workers or specific teamsAt least annuallyPhishing simulation, incident response drillExecution record, results, improvements
Ad hocThose affectedOn eventsPost-incident prevention, communicating procedure revisionsExecution record, audience covered

Derive role-based training from the SoA and role definitions. Mapping "operating this control requires this knowledge" keeps competence definitions from being arbitrary.

3. What goes in a completion record

  • Date delivered or completed
  • Name and department of the attendee
  • Course name and version (bump the version whenever content changes)
  • Delivery method (classroom, e-learning, video, on the job)
  • Whether there was a comprehension check, and the result
  • Treatment of non-completers (chase dates, scheduled date, reason for exclusion)

A comprehension check is more useful for "who got what wrong" than for the score. A question the whole organisation fails points straight at next year's content — and is a meaningful Clause 9 measurement. See Setting Security Objectives and KPIs.

4. Mid-year joiners, returners and contractor personnel

  • Mid-career joiners: mandate induction within N days and tie it to account provisioning. "No production access until induction is complete" is a control with real teeth
  • Returners from leave: re-deliver on return, including procedure changes made while they were away, plus any annual module they were excluded from
  • Contractor personnel: either deliver your own training, or obtain evidence that the supplier delivered equivalent training. Decide which in the contract. See Supplier Security Management

How to Do It

Step 1: Build an annual training plan

At the start of the year, fix timing, audience and owner for each type above. Without a plan, you discover in March that something never happened. The plan also feeds the management review.

Step 2: Make the roster obtainable automatically

Export the audience from HR or identity management. If a manual roster is unavoidable, name the owner and the monthly refresh step. Roster freshness determines whether the completion rate means anything.

Step 3: Build content from your own cases

Generic security material changes little. Include your own near misses, points customers raised, and last year's internal audit observations, and the audience's sense of ownership changes. In the first year, when you have few cases, use published incidents from your sector.

Step 4: Deliver, then chase weekly

After sending, refresh the non-completer list weekly and send it to line managers. Completion arrives faster through the manager than through the individual. Add reminders a week before the deadline and on the day.

Step 5: Escalate after the deadline

The ISMS manager escalates remaining non-completers to the individual and their manager. The critical part is keeping the escalation record. Even if a handful are outstanding at year end, chase and escalation records show this is a managed incompletion. With no records, it reads as neglect.

Step 6: Evaluate and feed next year

Compile completion rates, comprehension results and exercise outcomes — click rates and report rates for phishing simulations, for instance — and report to the management review. See Phishing Simulation Exercises and Running a Management Review.

Step 7: Have internal audit verify coverage

Put "reconcile the roster against completion records" on the audit checklist. Reconciling the two is how you find gaps in the roster itself — the on-site contractor nobody added. See Running an Internal Audit.

Where It Goes Wrong

One annual send, and mid-year joiners fall through

The single most frequent failure: sent in April, a July joiner goes untrained until the following April. A standalone induction mechanism fixes it.

Records that do not name individuals

"Distributed to all staff" exists, but per-person completion does not, so coverage cannot be shown. Confirm at selection time whether your e-learning platform's logs can serve as evidence directly.

No comprehension check — opening equals completion

Treating a played video as completion secures no awareness in practice. Three to five questions suffice. Make at least one a genuine judgement question; a quiz everyone aces measures nothing.

No role-based training at all

Trying to meet the competence requirement with all-hands training. Internal auditor competence in particular is always checked; an audit performed by someone who does not know the method casts doubt on the internal audit itself.

Contractor personnel excluded

On site every day but absent from the employee roster, and therefore from training. Regardless of contract form, anyone touching your information assets should be in scope.

The same content every year

Three years of identical slides and nobody reads them. The policy essentials may not change, but last year's cases, procedure revisions and sector developments should. Versioning the content makes the refresh visible in the record.

Comprehension results never used

Tallying the score and stopping there. A widely failed question suggests either the procedure is written unclearly or the rule does not match how work is done. Building a route from training results back into procedure revision is where the ISMS starts to move.

No record of chasing non-completers

As above: falling short of 100% matters less than having no record of what you did about it. Keep the chase and escalation dates.

Healthcare Examples

A healthcare SaaS provider

Beyond all-hands training, you need role-based training for anyone who might touch production patient data: support, SRE, some engineers, analysts. Cover the access request procedure, what may be viewed, the fact that access is logged, and the prohibition on extraction. Making completion a precondition for granting production access turns it into a real control.

Hospital customers' security questionnaires almost always ask about training frequency and coverage. 100% completion plus the role-based training list answers them directly. See When ISMS Becomes a Contract Condition.

A PHR operator

Because data is held under the individual's consent, training centres on never exceeding the consented scope. Teach scope judgement through concrete cases so marketing and analytics staff do not assume "we hold it, so we may use it." See ISMS for PHR Operators.

A SaMD developer

ISO 13485 carries its own training requirements, so design not to maintain two sets of records. Add a "requirement satisfied (ISMS / QMS)" column to one record format and use it for both audits. See SaMD, ISMS and ISO 13485.

A development or maintenance supplier to hospitals

The hospital has its own staff training obligations, and the subjects overlap. Your own training should cover the remote maintenance procedure, what to do on seeing patient data, and the obligation to notify the hospital. For the hospital-side design see Designing Staff Security Training, and for the guidelines overall, The Three-Ministry Guidelines.

Conclusion

  1. The standard requires competence and awareness separately; one all-hands e-learning module cannot satisfy competence
  2. Awareness covers everyone working under the organisation's control — directors, fixed-term staff, agency staff and on-site contractor personnel included
  3. 100% completion is required. 95% reads as "non-completers identified and not handled." Exclude long-term absentees properly from the denominator and procedure their delivery on return
  4. The gaps appear in three places: mid-year joiners, returners and contractor personnel. Run induction as its own mechanism, tied to account provisioning
  5. Completion records need name, date, content version, comprehension result and treatment of non-completers
  6. When you fall short, chase and escalation records are what separate a managed incompletion from neglect

Pottech supports ISMS build and operation with a focus on healthcare. Training is an area where getting the scope definition and record design wrong at the outset cannot be repaired in later years. See ISMS Certification Support or contact us.

References and Sources

Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.