I have been asked to re-assess our organisations 80% target for compliance training completions.  Wanted to see what targets other org's have set?

1.3k viewscircle icon4 Comments
Sort by:
CIO in Retail10 months ago

The compliance training goal depends on the regulation you are tied to, so depending on that, you may need to reach 100% or some other slightly lower percentage. In our case, most of the time we are required to meet 100% of the objective.

VP Cybersecurity in Banking10 months ago

I'm currently with a financial institution and we have a 100% compliance target and we also remove access if your course material has not been passed.  Training material is more detailed in the first 2 years of employment and then refresher material is given in subsequent years to make it less burdensome but also effective.

VP of IT in Retail10 months ago

The target has always been 100% in my current and past organizations.  My last company had a hard date of May 31st, and after that your account would be disabled.  You would then need to go to HR and complete your training to regain access.  That's a sign of a company that truly sees compliance as must do.

Director of Information Security in Energy and Utilities10 months ago

I think the target needs to correspond to your organization's risk profile.   Why 80%?  Why not 70% or 90%?  If your organization is in a highly regulated environment, then 80% sounds low to me.  You might even have different target % for different sections/divisions within your company.  My target is 100% for high-risk users and 80% for medium and below.

Content you might like

0% flagged for high risk13%

1-25% flagged for high risk57%

26-50% flagged for high risk22%

51-74% flagged for high risk5%

75%+ flagged for high risk

View Results

Lack of visibility16%

No data oversight39%

Unknown code and security controls34%

Risk of data exposure7%

Other2%

View Results