Video Training, EnterpriseTube, Compliance, Legal, Security and Compliance, Legal and Privacy

Compliance Training Tracking: What You Have to Prove

The question a regulator asks is narrower than the one most training programs are built to answer.

They do not ask whether the company takes anti-bribery seriously, or whether the training was well received, or how many people attended. They ask whether the eleven people on the trading desk completed the revised policy module in the third quarter, and they ask it about named individuals on a specific date. "We circulated it to the team" is not a response to that question. Neither is a completion rate.

This is what makes compliance training tracking a different problem from training, and it is why it tends to sit with Legal rather than with learning and development. The material is the smaller half. The artifact that has to exist afterward, and survive someone motivated to find a hole in it, is the real deliverable. Most of the wider question of what an organization does with recorded material is about making content useful; this one is about making a record defensible.

Why this lands on Legal

Learning and development owns training as a discipline and usually owns the platform. Legal owns the mandate and carries the consequence, and those are different jobs that pull in different directions.

An L&D team is measured on engagement, completion rates and whether people found the course useful. Those are reasonable goals and none of them is the thing a regulator will test. Legal is measured on whether the company can demonstrate, after the fact and under pressure, that a specific obligation was discharged. When the two teams share a system that was chosen for the first purpose, the second purpose is usually discovered to be unsupported at exactly the wrong moment.

The practical consequence is that the requirements have to be written by whoever will have to defend the record. Anti-bribery and corruption, insider trading and market abuse, competition law, sanctions, conflicts of interest and data protection all carry obligations where the company rather than the individual is on the hook, and where the absence of evidence is treated as absence of compliance.

What "completed" has to mean

The weakest compliance records fail on a single ambiguity: the system recorded that a person opened the material, and the organization has been treating that as completion.

An examiner does not have to prove that nobody watched. They only have to establish that your evidence cannot distinguish watching from opening, at which point the record stops being useful to you. Access logs are vulnerable in exactly that way, and a well-prepared regulator will ask the question directly.

You do not have to guess at the questions. The Justice Department publishes them. The Criminal Division's Evaluation of Corporate Compliance Programs, updated September 2024, tells prosecutors to ask "What analysis has the company undertaken to determine who should be trained and on what subjects?", "How has the company measured the effectiveness of the training?", and "Has the company evaluated the employees' engagement with the training session and whether they have learned the covered subject matter?" The stated purpose is to decide whether a program is "being disseminated to, and understood by, employees in practice."

Read those three together and they describe a record, not a curriculum. Who was in scope and why. Evidence of engagement rather than access. Evidence of comprehension rather than attendance.

Three things close the gap, and they are worth specifying rather than assuming.

Assignment rather than publication

Training assigned to named people with a start date, an end date and an enforced completion window produces a roster of who was in scope. A module published to a library and announced by email produces no such thing, which means the population you were meant to train has to be reconstructed later from memory and org charts.

Progression that cannot be skipped

Mandatory interactions stop playback advancing until a check is completed, with reattempts and replay-on-failure configurable. That converts "the file was open for fifty minutes" into "this person answered questions at three points inside the material", which is a substantively different claim.

Per-participant results

Quiz reporting has to resolve to the individual rather than to the cohort. An aggregate pass rate tells you about the module; a per-person record tells you about the person the examiner asked about.

Together those produce the shape a regulator recognizes: assigned, completed, dated, and not skipped.

One question in that DOJ list catches most programs out, and it is worth building for before it is asked: "How has the company addressed employees who fail all or a portion of the testing?" A system that records only passes has no answer. Keep the failed attempt, the remediation and the eventual pass, because the remediation is better evidence of a functioning program than a clean first-time record would be.

The record has to outlive the people

Compliance evidence gets requested years later, and by then the people involved have moved on. This is where otherwise-solid programs come apart.

The person who ran the training has left. The spreadsheet they maintained lives in a departed employee's drive. The platform was replaced in a migration that moved the content but not the completion history. None of these are exotic failures; they are the normal life cycle of a corporate system, and they are why the record needs to be a property of the system rather than of a person.

Two requirements follow. Reporting has to be about people rather than content, meaning you can ask what a named individual watched, how far they got, which assessments they completed and which certificates they hold, without reconstructing it from several places. And retention has to be deliberate, with a schedule that keeps the evidence for as long as the obligation runs and disposes of it on a rule rather than by hand. Holding records past their schedule is its own exposure in several jurisdictions, so "keep everything forever" is not the safe answer people assume it is.

Ask any prospective platform how a completion record survives an export, a migration and a person's departure. Ask it of your current one too, because the answer is what you will be relying on.

How VIDIZMO EnterpriseTube fits

EnterpriseTube supplies the chain that turns delivered material into a defensible record.

Training is assigned to named people rather than published and hoped for, with start and end dates and an enforceable completion window, which establishes who was in scope. Mandatory interactions stop playback continuing until the learner completes them, with reattempts and replay-on-failure configurable, so completion is a stronger claim than access. Progress tracking distinguishes partial completion from none and from full. Quizzes report per participant. Certificates issue on completion from templates defined per portal.

The reporting layer is the part that matters most for this use and it is worth naming precisely: user analytics report on people rather than on content, covering what an individual watched, how far they got, the assessments they completed and the certificates they earned. That is the shape of an audit response rather than a dashboard. Retention disposition then handles the other end, disposing of records on a schedule rather than by hand, with content restorable while it remains within the recoverable window.

Where the platform's job stops needs stating plainly, because this is the area where vendor language gets loosest. It evidences that a named person completed defined material on a date. It does not certify the company against any regulatory standard, it does not tell you what your obligations are, and no accreditation attaches to a completion certificate. Whether the training you delivered satisfies the rule is a legal judgment that stays with you. Anyone implying otherwise is selling something a platform cannot be.

What to build before the next obligation arrives

The work that makes compliance training tracking defensible happens long before anyone asks to see it.

Decide who owns the record, and make it whoever will have to defend it. Define your completion standard in writing, meaning what a person must actually do before the system says done, so that the standard does not quietly change when a new administrator arrives. Assign rather than publish, from the first module, because a roster cannot be retrofitted. Set the retention schedule against the obligation rather than against convenience. And run one fire drill: pick a person and a module at random and try to produce the record. Whatever takes longer than a few minutes is the thing that will fail you under real pressure.

Organizations that do this find the second obligation costs a fraction of the first, since the pattern generalizes even though the subject matter does not. The same machinery serves a different audience with a different adversary in how firms evidence CLE credit, and service providers face a third version of it in showing reviewers were trained to a stated protocol.

Talk to a specialist about what a defensible completion record looks like for the obligations your department carries, or read what a legal video platform does for a firm for the wider question of recorded material and who can see it.

FAQ

Frequently Asked Questions

Is a completion rate enough for a regulator?

No. A completion rate is a management metric. An examiner asks about named individuals on specific dates, so the record has to resolve to a person and a module rather than to a percentage across a population.

How do we prove someone did not just leave the video playing?

Mandatory interactions that stop progression until a check is answered, combined with progress tracking. Together they convert an access log into evidence that the person engaged at defined points, which is a materially stronger claim.

Should compliance training sit with Legal or L&D?

L&D usually runs the delivery and should. The record, the completion standard and the retention schedule should belong to whoever will defend them, which is normally Legal, because the consequence of a weak record lands there rather than on the training team.

Does a completion certificate mean we are compliant?

It means a named person completed defined material on a date. Whether that discharges your obligation is a legal judgment about your circumstances and the rule in question. No platform certifies a company against a regulatory standard, and any that implies it should be asked which body accredits it.

How long should we keep the records?

As long as the obligation runs, which varies by regime and jurisdiction, and then dispose of them on a schedule. Indefinite retention is not the cautious option it appears to be, since holding records past their schedule creates exposure of its own in several jurisdictions. Talk to a specialist about what a defensible completion record looks like for the obligations your department carries, or read [what a legal video platform does for a firm](/blog/video-for-law-firms) for the wider question of recorded material and who can see it.

TopicsVideo TrainingEnterpriseTubeComplianceLegalSecurity and ComplianceLegal and Privacy

You may also like

Document Review Training: Proving One Standard

The challenge, when it comes, is almost never that a reviewer was unqualified.

CLE Video: Delivering the Session, Proving the Credit

Recording the session is the easy half, and the hard half does not announce itself until roughly a year in.

Litigation Video Review: Intake, Access and Purge

A matter produces nothing for months, then several hundred hours arrive inside two weeks because a production deadline ...

See all posts

See it on your own content

Tell us what you are trying to solve and we will show you how it works on your infrastructure.