What happens to your compliance when training expires and new people join
Closing the last gap in a standard feels a lot like crossing a finish line. The dashboard turns green, the evidence is filed, the report comes out clean. Four weeks later, with nobody touching the configuration, that same dashboard shows uncovered people again, because the training expiry date of several of them passed along the way.
There is a simple explanation for that slide backwards. Coverage of a standard is a snapshot with a date on it, and that turns compliance into a moving target. What counts as covered today stops counting at some point, and while that happens the organisation keeps hiring people who never saw that content.
When we introduced the Compliance Center we showed what real-time compliance looks like, and when we explained how a compliance plan is set up we went through what you decide before it starts. One question is still open. What does that plan do in the months that follow, when the ground moves on its own?
What is training expiry?
Training expiry is the period during which a completed course still counts as valid evidence of compliance. Once that period ends, the person counts as a gap again, even if they passed the content at the time and even if the certificate is still filed away somewhere.
This is not something platforms invented. Control 6.3 of ISO/IEC 27001, which covers information security awareness, education and training, requires personnel to receive appropriate regular updates for their role. The word doing all the work there is regular. Training from two years ago does not meet that requirement, however thorough it was at the time.
It is the mechanism that makes your programme’s compliance fall apart in March without anyone switching anything off. Coverage expires person by person, on different dates.
Why compliance is never finished
Because three things move at the same time, and none of them waits until you have a free afternoon.
The first one is the calendar. Every covered person carries their own expiry date, depending on when they completed the training. Across 500 employees that means 500 clocks that run in parallel, one per completion date. Whoever joined in January expires in January and whoever joined in August expires in August, so there is never a month when the dashboard sits still.
The second one is the headcount itself. Every new hire falls within the scope of the standard from their first day, and every internal move can add an obligation they did not have before.
The third one is the content. Repeating the same material every twelve months keeps the percentage up, but it stops teaching.
How does this work with a spreadsheet?
By hand, all three are handled the same way. Someone opens the spreadsheet every so often, sorts by completion date, cross-checks the list against the latest directory export and puts together the batch of assignments that is due. That is enough to reach the audit, and the cost does not show up in the spreadsheet.
It shows up in the interval. The spreadsheet describes the state of the day it was updated, not today’s, and the gap between those two dates is exactly how long the organisation goes without knowing who is missing training. Someone who starts in September had no chance to complete the training you assigned in April and counts as a gap from day one, but only becomes visible once somebody updates the audience by hand. It is the same trap that makes your compliance percentage lie even at 100%.
Content works out much the same. Reassigning last year’s module is the quick way out when the review is manual, so the second cycle repeats the material from the first. People recognise the screens, click through to the end and pass without reading. You satisfy the record and lose the effect that justified the record.
What does the Compliance Center agent do differently?
The agent in SMARTFENSE’s Compliance Center reviews compliance status every day and assigns training without waiting for anyone to open a spreadsheet. It works on those same three forces, one by one:
- Expiry. Every person has their own expiry date and the agent checks it daily. When coverage lapses, that person returns to gap status and enters the plan’s queue that same day, not at the next quarterly review.
- New hires. The audience is read from the live directory, not from an exported list. When you define scope with smart groups instead of individual names, a new hire enters the plan without anyone editing it, and a leaver drops out of the calculation.
- Rotation. The agent keeps a record of what each person received and in which format. Someone who covered passwords through an interactive module last year sees it this year as a comic, a video or a short reinforcement piece, against the same clause of the standard. The clause stays just as covered and the person pays attention again, because format changes what people retain.
Working through that daily queue, the agent goes after the organisation’s worst gap first, which in practice tends to be whoever has been uncovered the longest. The range of available formats is what lets it sustain the rotation year after year, and rotation becomes a decision the plan makes, not a task you take on every December.
What is left for you to supervise?
The dashboard stops being something you update and becomes something you consult. You supervise; it executes.
What stays with you is the expiry criteria that apply to each standard, the one-off exception when an area cannot take training in a given week, and reading the report when it is time to present it. The agent takes on the repetitive work of spotting who expired, who joined and who is due which content this week.
What changes day to day is where you are looking. You no longer check whether the plan is up to date. You check whether the plan is doing the right thing.
The Compliance Center is running with the first teams that adopted it and we are refining it with them before opening it up more widely. If you run a programme where expiry dates and new hires force you to rebuild the plan every month, write to us to join the early adopter group and we will look at it with your case on the table.
Leave a Reply