Skip to content

Compliance & audit

Evidence an assessor accepts

Auditors do not want a screenshot of a training portal. They want a register: who was assigned what, when they completed it, what happened when they failed, and proof the record has not been edited since. That is an export, not a project.

6
frameworks mapped
1 click
evidence export
13 mo
default retention
EVIDENCE PACKAssignment registerWho, when, which content versionPR.AT12.6.3A.6.3CC2.2One export per framework, references already attached.

The gap

Completion percentages do not survive a question

"94% completed" answers nothing an assessor asked. They want the assignment record for the 6%, the date, the content version, and what the programme did about the people who failed a test in between. SafeLoop keeps all four by default.

  • Per-person assignment, completion date and content version
  • Failure-to-enrolment chain, timestamped
  • Append-only log that cannot be quietly edited
  • Spotting a spear-phish4 min · Complete
  • MFA fatigue & push bombing3 min · Complete
  • Invoice fraud and BEC5 min · 62% done
  • QR codes in the wild3 min · Assigned
An enrolment generated by one failed simulation — assigned, tracked and certificated automatically.

The export

One pack per framework

Choose the framework and SafeLoop assembles the register, the certificates and the audit-log extract with the control references already attached, so the assessor is not asked to infer the mapping themselves.

  • Framework-specific control references
  • CSV and PDF, or over the API
  • Scoped to a date range and business unit
A90–100Resilient
B80–89Solid
C70–79Uneven
D60–69Exposed
F≤59Critical
01

Susceptibility

What people fall for

32/40
  • Susceptibility rate10
  • Credential-submit rate8
  • Repeat-clicker rate8
  • Time-to-click6
02

Resilience

What they do about it

22/30
  • Report rate9
  • Real-threat response7
  • Training completion6
03

Exposure

Surface their role carries

17/30
  • Multi-channel exposure7
  • Department risk5
  • Tenure / onboarding risk5
Ten factors, each weighted out of ten. Count the cells — the grade is arithmetic you can check, not a length you have to trust.

Mapping

Framework to evidence

FrameworkControlWhat we export
NIST CSF 2.0PR.ATAssignment and completion register, content versions
HIPAA§164.308(a)(5)Awareness programme record plus reminder cadence per person
PCI DSS v4.012.6.3Hire-date baseline, annual completion, phishing result trend
GDPRArt. 39(1)(b)Training register with retention notes
ISO 27001:2022Annex A 6.3Scope, per-control mapping and an effectiveness metric
SOC 2CC2.2Assignment, acknowledgement and audit-log extract

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

2 questions

Will this satisfy our auditor on its own?

For the awareness and training controls listed above, the export is the artefact assessors normally ask for: assignment, completion, content version and a tamper-evident log. Your auditor decides on sufficiency, and we have not yet had a customer told the register was inadequate.

How long is evidence retained?

Event data for 13 months by default, or whatever your tenant policy sets. Completion certificates are retained for as long as you need them as evidence, and survive a deletion request for the underlying event data.

Bring your framework to the demo

Tell us which control you report against and we will show the export that answers it.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.