Training records that prove competence
Attendance sheets prove training happened, but auditors want proof people can apply what they learned. See what a defensible competence record needs and how to build one before you deliver the training.
An auditor often asks one question that shapes the review of your training system: can you show that the person doing the work is competent to do it? Attending a session and signing a sheet both count for something. They record that the training happened, and that record is a necessary part of training management. The next step is to show that the person can apply what they learned. This article covers what that evidence looks like and how to build compliance training records that hold up under review.
What auditors ask for
A signed attendance sheet is useful. It proves someone received the training and when. It is the starting point of a good record, and you should keep it. On its own, though, it does not show what the person retained or whether they can apply it. That is why an auditor usually looks for more.
When an auditor samples a role and asks for competence evidence, they tend to expect a chain: the requirement for the role, the training delivered against it, an assessment of understanding, and a dated record tying it to a named person.
In practice, that means four things per record. First, the competence requirement, drawn from the job or the process it supports. Second, the training content and delivery date, including who attended. Third, an assessment result, such as a pass mark or a supervised sign-off. Fourth, a review or refresh date, because competence can lapse when procedures change.
Where ad-hoc onboarding tends to fall short
Training records often run into the same recurring issues. The evidence sits across email, a shared drive, and a spreadsheet, which makes it hard to produce a complete picture on demand. Dates can drift out of sequence, so a sign-off appears to predate the procedure it covers. Some records show completion but no assessment, which leaves understanding undocumented. And it may be unclear who last reviewed the training against the current version of the work instruction.
These gaps are common, and they are avoidable. They usually come from treating onboarding as a task to finish rather than a record to keep. A practical fix is to design the record before you deliver the training, rather than assembling it afterwards.
Building defensible records
Start from the role. List the competences each role needs and map each one to a document, a procedure, or a regulation. This map is the backbone an auditor can follow. Then attach the training, the assessment, and the sign-off to that map so every requirement has evidence against it.
Keep the records immutable and time-stamped. A record you can edit after the fact is one an auditor may question. Store the version of the procedure the person was trained on, so that when the procedure changes you can identify who needs re-training and confirm who was competent on which version.
Set refresh intervals and let the system flag them. A record without a review date can go stale without anyone noticing. Our QMS functionality is structured around ISO 9001, which treats competence as a controlled input to process quality rather than a one-off event. You can read more in our ISO 9001 QMS overview and see how tenant data is kept separate in our data isolation model.
Where the data lives
Training records are personnel records, so hosting and isolation matter to your audit and to your data protection obligations. ComplyTrain hosts in AWS eu-central-1 (Frankfurt). Each customer is isolated using the silo model: schema-per-tenant, Cognito-pool-per-tenant, and bucket-per-tenant. Your records sit in your own schema, your own user pool, and your own storage bucket, not pooled with another organisation's data.
A short checklist
Before your next audit, confirm four things for a sample of roles. One, every role has a documented competence requirement. Two, every requirement has training mapped to it, with attendance recorded. Three, every training record has a dated assessment result. Four, every record has a review date and the version of the procedure it was based on. If any of the four is missing, the record shows activity but does not yet demonstrate competence.
To see how these records are built and held in one place, book a walkthrough of ComplyTrain and bring a role you want to test against.
