Back to blog

How to Document Your Security Training So It Holds Up If the FTC Asks

Daniel Chang, Founder of Kompflow

Your firm ran a security training session last quarter. Everyone attended. The topics were relevant. The team learned something useful. But if an FTC investigator asked you to produce evidence of that training, could you?

Could you show who attended? What topics were covered? When it happened? Whether the attendees acknowledged understanding the material? Could you produce a sign-in sheet, a copy of the training materials, and a dated record that ties it all together?

For most small firms, the answer is no. The training happened, but the documentation didn't. And under the regulatory framework that governs your firm, that distinction matters more than you might expect.

Why Documentation Matters More Than the Training Itself

That sounds counterintuitive, so let me explain. Obviously, the actual learning matters. You want your team to recognize phishing emails, handle client data properly, and understand their role in your security program. But from a compliance perspective, the training only counts if you can prove it happened.

The FTC Safeguards Rule requires you to provide security awareness training to all personnel and to provide specialized training for employees responsible for implementing your security program. The rule also requires you to maintain records of your security program activities. When those two requirements intersect, the message is clear: training that isn't documented is a compliance gap.

IRS Publication 4557 reinforces this with even more specific language. Training must be "logged with dates and attendance records." Staff training logs must be "signed and dated." The IRS uses a blunt standard: if it isn't written and timestamped, it doesn't exist.

In practice, this means a firm that conducts excellent training but keeps no records is in a weaker compliance position than a firm that conducts adequate training and documents everything. That's the regulatory reality, and it shapes how you should approach your training program.

What the FTC Wants to See

When the FTC investigates a firm, either following a complaint, a breach, or a random compliance review, they issue formal document requests. Those requests specifically include training materials and training records alongside your information security plan, risk assessments, and audit results.

The FTC evaluates whether your security practices are "reasonable" based on the sensitivity of the data you hold, the size and complexity of your firm, and the costs of available security tools. Employee training is one of the key indicators they look at. If you can produce comprehensive training records, it demonstrates that security awareness is part of your firm's culture, not just a checkbox. If you can't produce records, the investigator draws a reasonable conclusion: the training either didn't happen or wasn't taken seriously enough to document.

In nearly every FTC enforcement action, regulators focus on documentation, oversight, and continuity. Training documentation sits at the intersection of all three. It proves oversight (someone planned and delivered the training), documentation (the records exist), and continuity (the training happens regularly, not just once).

Exactly What to Record

Every training event, whether it's a formal session, an online module, a phishing drill debrief, or a one-on-one orientation for a new hire, should generate a record that captures the following:

Date and time. When did the training occur? Be specific. "Q2 2026" is not a date. "June 15, 2026, 2:00 PM to 3:00 PM" is a date.

Attendees. Who was present? List full names, job titles, and departments. For a 10-person firm, this is a simple list. For a larger firm, use an attendance sheet.

Topics covered. What specific subjects were addressed? "Security training" is too vague. "Phishing recognition, password hygiene, reporting suspicious emails, and data handling procedures for client tax documents" is specific enough to demonstrate substance.

Training materials. Save a copy of whatever was presented or distributed. If you used slides, save the file. If you showed a video, note the title and source. If you walked through examples of phishing emails, save screenshots. These materials corroborate the topic list.

Delivery method. Was this in-person, virtual, self-paced, or a combination? This matters because different delivery methods have different verification capabilities.

Trainer or facilitator. Who delivered the training? This could be the firm's qualified individual, an outside consultant, an IT provider, or an online platform. Document the name and affiliation.

Assessment results. If the training included a quiz, test, or simulation (like a phishing drill), record the results. This is the strongest form of evidence because it demonstrates not just attendance but comprehension.

Signed acknowledgment. Each attendee should sign a form confirming they participated in the training and understood the material. This is the single most important piece of documentation because it creates individual accountability.

Building a Simple Acknowledgment Form

Your acknowledgment form doesn't need to be complicated. It needs to capture four things: who attended, what was covered, that the attendee understood the material, and their signature and date.

Here's what to include:

The employee's full name, title, and department. The training date, topic, and duration. A statement that the employee participated in the training and understands the applicable policies and procedures. A statement that the employee understands their role in protecting client data and the firm's information systems. The employee's signature and the date they signed. Optionally, a line for the trainer's signature as a witness.

Keep the language simple. One page is enough. The goal is to create a clear record that ties a specific person to a specific training event on a specific date.

How to Store Training Records

Training records should be stored in the same location as your other compliance documentation: alongside your WISP, your risk assessment, your vendor assessment records, and your incident response plan.

Create a folder structure that makes retrieval easy. One approach: organize by year, with a subfolder for each training event. Inside each subfolder, include the attendance list, the training materials, the signed acknowledgment forms, and any assessment results.

If you use a cloud-based document management system, that works fine. If you prefer a local folder on your server, that works too. The key is that the records are organized, accessible, and backed up. When someone asks for evidence of your training program, you should be able to produce it within minutes, not hours.

The IRS recommends storing training records under clearly labeled folders within your WISP directory. This makes sense because it keeps your entire compliance documentation in one place, which simplifies both ongoing management and any future audit response.

What Topics Your Training Must Cover

The FTC Safeguards Rule doesn't prescribe a specific curriculum. It requires security awareness training that addresses your firm's specific risks. For a CPA firm, that means your training should cover:

Recognizing phishing emails and social engineering attempts. This is the highest-priority topic because phishing is the most common attack vector for small professional services firms.

Password management and authentication. How to create strong passwords, why password reuse is dangerous, and how to use multi-factor authentication properly.

Safe data handling. How to transmit client data securely, what not to send via unencrypted email, how to use client portals, and how to handle paper documents.

Reporting procedures. What to do when something suspicious happens. Who to contact. How quickly. The goal is to make reporting easy and expected, not something people hesitate to do.

Physical security. Locking workstations, securing paper files, visitor protocols, and secure document disposal.

Remote work practices. If your team works remotely at any time, training should cover secure home network practices, VPN usage, and protecting client data outside the office.

The specific mix of topics should reflect your most recent risk assessment. If phishing is your highest-rated risk, spend more time on phishing. If remote access has expanded significantly, dedicate more time to remote work security.

How Often to Train and Document

The FTC requires training with "regular refreshers." The practical standard for small firms is annual formal training at minimum, supplemented by quarterly touchpoints like phishing drills or brief refresher sessions.

The recommended best practice is 15 to 20 minutes of interactive training per month combined with monthly phishing simulations. For a small firm, this might be more realistic as quarterly sessions: a formal annual training in January, a phishing drill in April, a topical refresher in July, and a year-end review in October.

Whatever cadence you choose, document every session. The regulators care less about the exact frequency than about consistency and evidence. A firm that trains quarterly and documents every session is in a stronger position than a firm that claims to train monthly but has no records.

New employees present a special case. The FTC expects employees to be trained before they access client data. For seasonal hires during tax season, this means orientation should include a security training component on Day 1. Document it the same way you document every other session.

Common Mistakes to Avoid

Relying on informal training without records. 95.8% of U.S. workers report receiving informal training, but only 69.8% received formal, documented training. For compliance purposes, the informal conversation doesn't count. If you told a new hire about phishing during lunch, that's great, but unless you recorded it with a date, topic, and signature, it's not evidence.

Training once and never again. A single training event in 2023 doesn't satisfy the ongoing training requirement. The FTC looks for evidence of continuity. If your records show one session three years ago and nothing since, that's a gap.

Documenting attendance but not topics. A sign-in sheet that just has names and a date, with no description of what was covered, doesn't demonstrate much. The topic list is what proves the training was substantive and relevant to your firm's security risks.

Failing to train seasonal and temporary staff. If you bring on seasonal preparers during tax season and don't include them in security training, that's a compliance gap and a practical risk, since new employees are often the most vulnerable to phishing and social engineering.

What You Can Do This Week

  1. Create an acknowledgment form template. Use the elements listed above. One page. Save it as a reusable template.

  2. Set up your training documentation folder. Create a folder in your WISP directory called "Training Records" with a subfolder for the current year.

  3. Backfill what you can. If you've conducted training in the past but didn't document it well, create a summary record now: date, topics, attendees (as best you can recall). It's not as strong as contemporaneous documentation, but it's better than nothing.

  4. Schedule your next training session. Put it on the calendar. Assign someone to prepare the attendance sheet and acknowledgment forms. Make documentation part of the planning, not an afterthought.

  5. Plan your annual training calendar. Map out four quarterly touchpoints for the rest of the year: one formal session, one phishing drill, and two brief refreshers. Document each one using the same process.

The Bottom Line

Training your team is important. Documenting it is essential. The FTC doesn't ask whether you trained your people. They ask you to prove it. The firms that can produce organized, comprehensive training records demonstrate something beyond compliance: they demonstrate a culture that takes security seriously enough to measure, record, and improve.

The documentation process doesn't need to be burdensome. An acknowledgment form, an attendance list, a copy of the materials, and a dated folder. That's the whole system. It takes 15 minutes per session to set up and fills a compliance requirement that could otherwise become a six-figure problem.

If you want training documentation built into a system that tracks sessions, collects acknowledgments, and generates compliance-ready reports automatically, Kompflow handles all of it. But even a folder and a template are enough to start. The important thing is that when someone asks, "Can you prove your team was trained?" your answer is yes.

Training without documentation is a story. Training with documentation is evidence. Build the evidence.

Ready when you are

Pick where to start.

Buy the WISP yourself if you need the document.
Talk to us if you want the platform.

30-day money-back on Kompflow WISPCancel anytimeNo setup fees on any tier

We use cookies to measure site performance. No data is sold to third parties. You can opt out at any time. Privacy Policy