FillTrust

How to answer

Do employees complete security awareness training?

An easy yes for most teams, and one of the few questions where the follow-up is a date rather than a document.

A model answerConfirmed in your documents

Yes. All employees complete security awareness training within their first [30] days and annually thereafter. Completion is tracked, and the current completion rate is reported to management.

Square brackets are yours to fill in. FillTrust grades an answer like this confirmed in your documents when your documents support it.

Answered from
Your information security policy, your onboarding checklist, and the HR section of your SOC 2 report.
Evidence to attach
A completion report from your training provider is sometimes requested. Names can be redacted; the reviewer wants the percentage and the date.
Where it is asked
CAIQ v4.0 · HRS-11SIG LiteISO 27001 Annex A · A.6.3

This is one of the least interesting questions on any questionnaire and one of the most reliably answered badly, because it is easy to say yes to and easy to have let lapse.

What a reviewer is testing is not whether your team knows what phishing is. It is whether you have a cycle: something that happens on joining and something that happens every year, with a record. The record is the part small teams skip. Watching a course together in a Friday meeting is real training and leaves nothing behind, so when the follow-up arrives asking for a completion rate there is nothing to send.

Onboarding is the half that is usually true. Most companies do brief new starters, often informally. If that briefing is on a checklist somewhere, it is documentable, and saying "covered in the onboarding checklist, tracked in our HR system" is a complete answer.

The annual cycle is the half that lapses. If your last cycle was eighteen months ago, the honest answer is that training is delivered at onboarding and refreshed periodically, with the refresh cadence being tightened. That is a weaker answer than an unqualified yes and it is also the one that will not embarrass you when somebody asks for the report.

Who counts. Contractors, part-time staff and anyone with production access all count. If your training covers employees only, say so and say what contractors get instead: an NDA and a scoped access grant are worth stating.

Two things make this question stop costing you time. Put the cadence in the policy, in one sentence, so a document supports the answer. Then approve the answer once in your library: this exact question appears on CAIQ, on SIG, on ISO 27001 questionnaires and on most bespoke ones, phrased four different ways, and it is the same answer every time.

How this one goes wrong

Specific to this question, not general advice.

  • Answering yes on the strength of a video everyone watched once in 2024. Annual is the expectation, and the follow-up question is the date of the most recent cycle.
  • Forgetting contractors and part-time staff. If they have access to production, a reviewer counts them as employees for this question.
  • Claiming phishing simulation because your email provider has the feature. Answer for what you run, not for what is available on your plan.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.