Report 13 · Risk and compliance
Compliance People Finish
The most funded and least loved training category, rebuilt so people finish, comprehension is measured, and the evidence file would survive an audit tomorrow.
The short version
Most compliance spend buys documentation, not protection.Compliance training eats 13% of the average training budget, tied with management for the largest single category, and the people taking it deliver a brutal verdict. Fewer than one in four rate their last compliance training excellent, and only one in ten strongly agree it changed how they work.
Gallup's sharpest finding cuts deeper. Poorly trained employees are indistinguishable from untrained ones, which means most compliance spend buys documentation rather than protection. The redesign is not about making the module fun. It is risk tiering, spacing, scenario-based comprehension, and an evidence file that would survive an audit tomorrow.
Evidence: 1 Training Magazine (2025) / 2 Gallup (2025)
Compliance's share, the largest category alongside management training.
1 Training Magazine, 2025Employees who would call their last compliance training excellent.
2 Gallup, 2025Strongly agree the training changed how they work.
2 Gallup, 2025Organizations that check whether anyone understood, the audit gap.
3 LRN, Deloitte and Compliance Week, 2025What's inside
Most compliance spend documents effort. The job is to reduce risk, and that needs a different design.
Why the annual slog fails twice
Bored humans and thin evidence.The standard design is one annual, hour-long, click-through module per topic, and it fails on both of its jobs. It fails the behavior job because it is built against memory. A single massed session loses up to 90% of its content within a week, and the delivery format makes it worse. Digital-only compliance training scores lowest of every format, rated excellent by 17% of employees against 30% for in-person and 28% for blended.
It fails the evidence job because completion is the only thing it records. Half of companies use completion rate as their primary measure of effectiveness, while only 44% measure comprehension and 37% track misconduct trends after training. An auditor, or a plaintiff's lawyer, who asks whether people understood gets handed a spreadsheet of clicks.
Evidence: 2 Gallup (2025) / 3 LRN, Deloitte and Compliance Week (2025) / 4 Ebbinghaus forgetting-curve tradition and spacing-effect literature (2025)
The annual module is a receipt for money spent, not evidence of risk reduced. Bad training is indistinguishable from no training, and it costs the same.
Evidence: 2 Gallup (2025)
The annual module records that people showed up. It does not show that anything changed.
Risk-tier before you design
Depth where the exposure lives.The single biggest efficiency unlock is to stop giving 400 people the training that 40 people need. Map each compliance topic against actual role exposure, then place every role in one of three tiers.
| Tier | Who | Format | Example |
|---|---|---|---|
| Awareness | Everyone the topic touches only incidentally. | Spaced micro-doses of three to five minutes, refreshed quarterly, retrieval based. | Phishing basics for non-finance staff, or GDPR awareness outside data-handling roles. |
| Working | Roles that handle the risk every week. | Monthly micro-scenarios plus one 45-minute applied workshop a year built on real cases. | Recruiters on non-discrimination, or support teams on data-subject requests. |
| Expert | The 5% to 10% who own the risk. | Deep course, certification and manager-led case reviews. They co-author the scenarios everyone else sees. | The DPO and security team, finance on anti-money-laundering, and the managers whose tone only 33% of organizations train for. |
The tier model is our editorial framework; assign it against your own topic and role map.
Evidence: 3 LRN, Deloitte and Compliance Week (2025)
Tiering typically shrinks total seat-hours by 40% to 60% while increasing depth where exposure is real. It is the rare redesign that reads as both cost control and risk control, because regulators consistently reward programs that are proportionate to the role.
Fewer total seat-hours, more depth where the risk actually lives.
The redesign in five moves
From slog to system.Once the tiers are set, five moves turn the annual slog into a system that works with memory instead of against it.
Space it
Take the same hour and cut it into monthly five-minute scenario reps. Spacing lifts long-term retention by roughly 200%, and it turns compliance-week dread into a habit that never spikes anyone's calendar.
Lead with the scenario
Every rep is a judgment call rather than a definition. A realistic situation with a decision to make is what changes day-of behavior, which is why policy recital leaves only one in ten people saying the training changed how they work.
Localize the cases
Generic vendor scenarios read as fiction. Rewrite the same skeletons with your tools, your client types and your gray areas, with expert-tier owners supplying the raw cases. Relevance is the engagement program.
Check comprehension at 30 days
Two to four weeks later, run a short re-check of three scenario decisions per topic and trend the accuracy by tier. That trend is the comprehension evidence the 56% of organizations relying on completion cannot produce.
Involve managers
Add one scripted two-minute team conversation per quarter about the scenario most people got wrong. Manager follow-up is the top item on Gallup's fix list, so give managers the script rather than hoping.
Evidence: 2 Gallup (2025) / 3 LRN, Deloitte and Compliance Week (2025) / 4 Ebbinghaus forgetting-curve tradition and spacing-effect literature (2025)
Same hour, spaced and scenario-based, measured at 30 days.
Measure comprehension, not clicks
The number an auditor asks for.Completion answers a question no auditor is asking. It records attendance, not understanding, yet half of organizations still use it as their primary measure of whether a program worked.
The measurement gap is where most programs are exposed. Only 44% check comprehension at all, and only 37% look at whether misconduct trends moved after training. The two numbers that would actually defend a program are the ones most rarely collected.
Evidence: 3 LRN, Deloitte and Compliance Week (2025)
Source: LRN 2025 Program Maturity study; Deloitte and Compliance Week
Evidence: 3 LRN, Deloitte and Compliance Week (2025)
A spaced re-check two to four weeks after each topic, scored as decision accuracy and trended by tier and quarter, is the artifact that separates a defensible program from a spreadsheet of clicks.
Completion is necessary and nowhere near sufficient. Comprehension at 30 days is the number that defends you.
When documentation becomes a legal duty
The regulator now expects a paper trail.Role-proportionate, documented training is no longer only good practice. Since February 2025, Article 4 of the EU AI Act has required every provider and deployer of an AI system in the EU, of any size and at any risk tier, to ensure a sufficient level of AI literacy among the staff and contractors who operate those systems.
There is no fixed curriculum and no mandated certificate. What the law asks for is training that is tailored to the role and backed by records, and the Commission's own guidance is explicit that a single onboarding video is not sufficient. National authorities begin enforcing from August 2026, which makes the evidence file a regulatory instrument, not only an internal one.
Evidence: 5 European Union (2024)
The literacy duty in one line
Provide AI literacy that is proportionate to each role and keep the records to prove it. The design pattern the regulation rewards, tiered depth plus documentation, is exactly the one this guide describes. This is a summary, not legal advice.
Evidence: 5 European Union (2024)
A program that is tiered by role and documented as it runs is already shaped the way the regulator expects.
Self-audit, would your program survive scrutiny
Eight questions in about three minutes.Check every statement that is true of your program today.
| Score | Band | What it means |
|---|---|---|
| 0–2 | Click theater | You are buying receipts, not protection. Start with the risk-tier map. |
| 3–4 | Compliant-ish | The paperwork exists but the behavior does not. Space the doses and lead with scenarios. |
| 5–6 | Defensible | Comprehension is measured. Close the incident loop and script the managers. |
| 7–8 | Risk system | Training, evidence and incidents run as one loop. Audit season is quiet now. |
A low score is not a verdict, it is a starting order. Begin with whichever move sits earliest in the list.
The evidence file and the one-page version
What an auditor should find in one folder, and the takeaways to keep.Design the paper trail as deliberately as the training. One folder per topic-year, six artifacts, is also close to the documentation posture the EU AI Act's guidance asks for on AI literacy.
Evidence: 5 European Union (2024)
The six-artifact evidence file, per topic-year.
Evidence: 3 LRN, Deloitte and Compliance Week (2025)
Takeaways, the one-page version
Evidence: 2 Gallup (2025) / 3 LRN, Deloitte and Compliance Week (2025) / 4 Ebbinghaus forgetting-curve tradition and spacing-effect literature (2025)
This week, draft the three-tier map and pick one topic to redesign. This quarter, ship the first 30-day comprehension re-check and assemble that topic's evidence file end to end.
Sources and method
Every external numeric claim in this report points to one of these 2024 to 2026 sources. Forecasts and self-reported surveys are labelled so they are not mistaken for causal proof.
2025 Training Industry Report
Compliance at 13% of training budgets, tied with management and supervisory training as the largest single category.
trainingmag.com4 Hard Truths About Ethics and Compliance Training
23% rate their compliance training excellent; digital-only 17% versus in-person 30% and blended 28%; 1 in 10 strongly agree it changed how they work; poorly trained employees are indistinguishable from untrained ones; manager follow-up is the leading fix.
gallup.comProgram Maturity study and compliance effectiveness survey
44% measure comprehension; 37% track misconduct trends after training; 33% offer manager-specific training; 50% use completion rate as the primary effectiveness measure.
lrn.comSpacing-effect research synthesis, more than 800 experiments
Up to 90% of a single massed session is lost within a week; spaced practice raises long-term retention by roughly 200%. Directional synthesis across the experimental literature.
pubmed.ncbi.nlm.nih.govRegulation (EU) 2024/1689, Article 4, and Commission Q&A
AI literacy duty in force since February 2025 for all providers and deployers, any size and any risk tier, covering staff and contractors; role-tailored and documented, with enforcement by national authorities from August 2026. Summary, not legal advice.
eur-lex.europa.eu