Compliance & audit
Evidence an assessor accepts
Auditors do not want a screenshot of a training portal. They want a register: who was assigned what, when they completed it, what happened when they failed, and proof the record has not been edited since. That is an export, not a project.
- 6
- frameworks mapped
- 1 click
- evidence export
- 13 mo
- default retention
The gap
Completion percentages do not survive a question
"94% completed" answers nothing an assessor asked. They want the assignment record for the 6%, the date, the content version, and what the programme did about the people who failed a test in between. SafeLoop keeps all four by default.
- Per-person assignment, completion date and content version
- Failure-to-enrolment chain, timestamped
- Append-only log that cannot be quietly edited
- Spotting a spear-phish4 min · Complete
- MFA fatigue & push bombing3 min · Complete
- Invoice fraud and BEC5 min · 62% done
- QR codes in the wild3 min · Assigned
The export
One pack per framework
Choose the framework and SafeLoop assembles the register, the certificates and the audit-log extract with the control references already attached, so the assessor is not asked to infer the mapping themselves.
- Framework-specific control references
- CSV and PDF, or over the API
- Scoped to a date range and business unit
- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
- Report rate9
- Real-threat response7
- Training completion6
- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
Mapping
Framework to evidence
| Framework | Control | What we export |
|---|---|---|
| NIST CSF 2.0 | PR.AT | Assignment and completion register, content versions |
| HIPAA | §164.308(a)(5) | Awareness programme record plus reminder cadence per person |
| PCI DSS v4.0 | 12.6.3 | Hire-date baseline, annual completion, phishing result trend |
| GDPR | Art. 39(1)(b) | Training register with retention notes |
| ISO 27001:2022 | Annex A 6.3 | Scope, per-control mapping and an effectiveness metric |
| SOC 2 | CC2.2 | Assignment, acknowledgement and audit-log extract |
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
2 questions
Will this satisfy our auditor on its own?
For the awareness and training controls listed above, the export is the artefact assessors normally ask for: assignment, completion, content version and a tamper-evident log. Your auditor decides on sufficiency, and we have not yet had a customer told the register was inadequate.
How long is evidence retained?
Event data for 13 months by default, or whatever your tenant policy sets. Completion certificates are retained for as long as you need them as evidence, and survive a deletion request for the underlying event data.
Keep reading
Related
Bring your framework to the demo
Tell us which control you report against and we will show the export that answers it.