Proving Awareness
Generate audit-ready evidence of employee training
Proving Awareness
Security awareness training only counts if you can prove it happened. This evidence demonstrates program effectiveness to auditors.
Audit Requirements
Auditors expect to see:
- Policy acknowledgement records: Dated proof employees received and acknowledged policies
- Training completion records: Evidence employees completed required training
- Quiz results: Scores proving employees understand the material
- Retention over time: Historical records showing ongoing awareness programs
[Screenshot: Training Evidence] Placeholder: Audit report showing acknowledgements and completions
Generating Reports
Create audit-ready evidence:
- Select reporting period: Annual, quarterly, or custom date range
- Choose policies and quizzes: Include relevant training for the audit scope
- Export format: PDF for sharing, CSV for analysis
- Include details: Individual records with names, dates, and scores
Evidence Components
Comprehensive awareness evidence includes:
- Policy distribution log: When policies were published and assigned
- Acknowledgement records: Who acknowledged what and when
- Quiz attempt history: All attempts, scores, and pass/fail status
- Completion certificates: Formal recognition of training completion
- Reminder log: Automated notifications sent to ensure participation
[Screenshot: Evidence Export] Placeholder: Report generation interface with filter options
Audit Storytelling
Present awareness evidence effectively:
- Show continuous improvement in completion rates
- Highlight 100% completion for critical policies
- Demonstrate timely re-training after policy updates
- Prove awareness through quiz scores, not just acknowledgements
Common Audit Questions
Be prepared to answer:
- "How do you ensure employees read policies?"
- Timestamped acknowledgements + comprehension quizzes
- "How often do employees receive training?"
- Scheduled campaigns, annual refreshers, new hire onboarding
- "What happens if employees don't complete training?"
- Automated reminders, manager escalations, access restrictions
- "How do you measure awareness effectiveness?"
- Quiz pass rates, completion rates, incident patterns
[Screenshot: Audit Metrics] Placeholder: Dashboard showing key awareness KPIs
Next Steps
- Prepare for certification audits
- Generate compliance reports including awareness evidence