ISO 27001 Security Awareness Training: Key Requirements (UK)

Female presenter in a black blazer explains ISO 27001 security training on a whiteboard with bullet points: information security policies, phishing, incident reporting procedures.

Most organisations pursuing ISO 27001 certification focus heavily on technical controls, firewalls, encryption, access management. But the standard is explicit: your people need to understand their role in protecting information. ISO 27001 security awareness training isn’t optional or nice-to-have. It’s a compliance requirement baked into multiple clauses of the standard, and auditors will check for evidence that you’re doing it properly.

Clauses 7.3 (Awareness) and 6.3 (Planning of Changes) place direct obligations on your organisation to ensure staff know the information security policy, understand how their work affects it, and grasp the consequences of non-compliance. Getting this wrong, or treating it as a tick-box exercise, can stall your certification or, worse, leave genuine gaps that attackers exploit. The challenge for many UK businesses is knowing exactly what auditors expect, how to structure training programmes, and which delivery methods actually work.

At TrustedIA, we’ve supported organisations through ISO 27001 implementation and certification for over 30 years, and security awareness training is one of the areas where we see the most confusion. This guide breaks down the specific requirements, explains what your training policy should include, walks through practical delivery options, and helps you build a programme that satisfies auditors and genuinely reduces risk across your organisation.

ISO 27001 requirements for awareness and training

ISO 27001:2022 treats human behaviour as a security control in its own right. The standard recognises that technical safeguards alone cannot protect your organisation if staff click phishing links, mishandle sensitive data, or ignore your security policies. This is why the requirements for awareness and training appear in multiple places across the standard, not as a single throwaway clause, but as a deliberate, layered obligation that runs from senior leadership down to every person operating under your Information Security Management System (ISMS).

Understanding where these requirements sit and what each one demands is the foundation of any compliant programme. Two primary areas govern your obligations: Clause 7.3, which addresses awareness, and Annex A Control 6.3 (formerly A.7.2.2 in the 2013 version), which covers information security awareness, education, and training more broadly. Both are subject to direct audit scrutiny, and treating either as optional will put your certification at risk.

The clauses you need to know

ISO 27001:2022 contains several clauses that directly or indirectly shape how you deliver iso 27001 security awareness training. Clause 7.2 (Competence) requires you to determine what skills and knowledge people need to perform information-security-related work, ensure they hold those competencies, and retain documented evidence. Clause 7.3 (Awareness) builds on this by specifying that all people working under the ISMS must be aware of the information security policy, understand how their contribution affects ISMS performance, and understand the consequences of nonconformance with requirements.

The clauses you need to know

Auditors will specifically ask for documented evidence that staff have completed training and that training content addresses each of the three awareness points under Clause 7.3.

Annex A Control 6.3 goes further. It requires your organisation to ensure that all employees and relevant contractors receive appropriate awareness, education, and training, along with regular updates on organisational policies and procedures as they relate to their specific roles. The word “appropriate” is deliberate here: a receptionist and a system administrator have very different risk profiles, so their training content should clearly reflect those differences.

What the 2022 revision changed

The 2022 update reorganised the Annex A controls, moving from 114 controls across 14 domains to 93 controls across four themes: Organisational, People, Physical, and Technological. Control 6.3 now sits firmly within the People controls theme, which signals that the standard treats workforce security behaviour as a distinct and significant category rather than a procedural footnote.

For UK organisations already certified under the 2013 version, the transition deadline to ISO 27001:2022 has passed, meaning your ISMS must already reflect the updated control structure. If your training programme was built around the older Annex A, you need to review it against the 2022 controls and update your documentation accordingly. The substance of what training must achieve has not changed dramatically, but the framework around it has shifted, and auditors will expect your policy and records to reference the current version of the standard throughout.

Clause 7.3 vs Annex A 6.3 in plain English

Many organisations treat these two requirements as interchangeable, but they serve different purposes and carry distinct audit expectations. Conflating them is one of the most common mistakes we see during ISO 27001 implementation. Understanding the distinction clearly helps you build a programme that satisfies both obligations, rather than inadvertently leaving a gap that a certification auditor will flag during your assessment.

Clause 7.3: What awareness means in practice

Clause 7.3 establishes a baseline knowledge requirement for everyone working under your ISMS, whether they are a full-time employee, a part-time contractor, or a temporary staff member. The clause specifies three things each person must be aware of: the information security policy and what it actually says, how their individual work contributes to the ISMS achieving its objectives, and the consequences of failing to conform with ISMS requirements.

Awareness is not the same as training. You can achieve it through onboarding packs, briefings, short videos, or internal communications; what matters is that you can evidence it happened.

Being aware under Clause 7.3 is less about formal structured learning and more about ensuring that understanding exists across your entire workforce. Your responsibility is to deliver that understanding through whatever channel suits your organisation, and then retain documented proof that it reached the right people.

Annex A 6.3: What training and education mean in practice

Annex A Control 6.3 goes beyond awareness and requires your organisation to deliver structured information security education and training, and to keep that content current as threats, policies, and procedures change over time. Critically, it also extends your obligation to relevant contractors, not just direct employees, which many organisations overlook until an auditor raises it during a surveillance visit.

Effective iso 27001 security awareness training under Control 6.3 must reflect the individual’s specific role. A finance team member needs to understand invoice fraud and social engineering tactics. A developer needs to grasp secure coding principles and the correct handling of sensitive data within their systems. Control 6.3 is where broad awareness gives way to role-specific, skills-based learning that demonstrably reduces real-world risk across different functions in your organisation.

Who must be trained and how often

ISO 27001 does not restrict training obligations to your IT team or security staff. Every person working under your ISMS has a training requirement, and your programme must clearly reflect that scope. Getting this wrong is a frequent cause of nonconformities during certification audits, particularly when organisations forget to include temporary workers or third-party contractors who access systems or handle data covered by your ISMS.

Who must be trained and how often

Defining your training population

Your starting point is to identify everyone whose work touches your ISMS, which, in practice, means almost your entire workforce. Full-time employees, part-time staff, seasonal workers, and agency staff all fall within scope. Beyond your direct employees, relevant contractors must also receive appropriate training under Annex A Control 6.3. If a contractor handles personal data, accesses your network, or processes any information asset covered by your ISMS, they need demonstrable awareness of your security requirements.

Many organisations discover during their first surveillance audit that contractors were excluded from training records entirely, which results in a nonconformity that is straightforward to avoid.

Senior leadership is not exempt either. Executives and board-level decision-makers need to understand the information security policy and how their decisions affect ISMS performance. The training content can differ from what you deliver to general staff, but the obligation to evidence their awareness remains the same.

How often must training happen

ISO 27001 does not specify a fixed training interval, which gives you flexibility but also places the burden of justification on you. Your organisation must determine what “regular updates” means in your specific context, document that rationale in your training policy, and then stick to it consistently.

Most organisations running iso 27001 security awareness training programmes settle on annual training as a baseline, with additional touchpoints triggered by specific events such as a new threat emerging, a policy change, a security incident, or the onboarding of new staff. New starters should complete training before they handle any information assets, not weeks into their role. Role changes that increase a person’s access or responsibility should also trigger a training review, ensuring that your records reflect the risk profile each person actually carries at any given time.

What good security awareness training covers

A common mistake is treating security awareness training as a policy recitation exercise, asking staff to read through your information security policy, sign a form, and call it done. That approach satisfies almost nothing under ISO 27001 and does even less to change behaviour. Good iso 27001 security awareness training shifts understanding and changes how people act when they encounter a real situation, whether that is a suspicious email, an unusual file transfer request, or a colleague asking for access they should not have.

Core topics every programme should address

Your training programme needs to cover the threats and scenarios that are most relevant to your organisation’s risk profile, rather than pulling a generic module off the shelf and hoping it fits. At a minimum, every member of staff should understand how phishing and social engineering attacks work in practice, what your acceptable use policies require, how to classify and handle information correctly, what the process is for reporting a security incident, and the consequences of non-compliance. These topics form the baseline that auditors expect to see evidenced across your whole workforce.

Training that stops at policy awareness without covering real-world attack scenarios leaves your staff unprepared for the threats that actually reach their inbox.

Beyond those core scenarios, your programme should address password hygiene and multi-factor authentication, physical security in shared or public spaces, and the correct handling of removable media and personal devices. Each of these areas maps to specific controls in your ISMS, so linking training content to those controls makes your documentation easier to maintain and your audit evidence cleaner to present.

Role-specific content that reflects real risk

Once you have covered the baseline topics, your programme needs to go deeper for higher-risk roles. Developers need secure coding awareness and an understanding of data handling within their systems. Finance staff need to recognise invoice redirection fraud and voice phishing. IT administrators need to understand their privileged access responsibilities and the risks associated with elevated permissions.

Structuring your programme this way, with a shared foundation and targeted role-specific layers, means you meet the requirements of Annex A Control 6.3 while delivering training that is genuinely proportionate to the risk each person actually carries.

How to build a compliant training programme

Building a compliant iso 27001 security awareness training programme is not a matter of picking a course from a catalogue and distributing login credentials. You need to design it deliberately, anchoring every decision in your organisation’s risk assessment, your ISMS scope, and the specific obligations laid out in Clauses 7.2, 7.3, and Annex A Control 6.3. Without that foundation, your programme will struggle to survive scrutiny from a certification auditor.

Start with your risk assessment and policy.

Your risk assessment already identifies the threats and vulnerabilities most relevant to your organisation. Use it. The content of your training programme should map directly to those risks, so you can demonstrate to an auditor that your awareness activities are proportionate and targeted. Alongside this, you need a written training policy that defines who must be trained, what topics must be covered, how often training occurs, and how completion will be recorded. Without that policy, you have no baseline against which to measure compliance.

Your training policy is the document auditors reach for first. If it does not exist or lacks detail, everything else you present will carry less weight.

Structure delivery around your workforce

Once your policy exists, structure your delivery to match how your organisation actually operates. General awareness content should be sent to all staff, while role-specific modules should target staff with elevated access or higher-risk responsibilities. You do not need to build every module from scratch. Phishing simulation platforms, e-learning providers, and internal workshops all count, provided you retain evidence of completion for each participant. The delivery method matters far less than your ability to prove it happened and that it addressed the right content for the right people.

Keep the programme live, not static

Treat your training programme as a living part of your ISMS, not a one-time project you set up at certification and revisit three years later. When your risk register changes, update the training content. When a policy is revised, push that update to affected staff and record it. When a new person joins or changes roles, trigger their training before they handle any information assets under your ISMS. This continuous cycle is what separates a programme that genuinely supports your security posture from one that merely satisfies a checklist.

How to evidence compliance for auditors

Completing training is only half the requirement. Proving it happened is the other half, and it is the part that catches many organisations off guard during their certification or surveillance audit. ISO 27001 auditors are not looking for perfection; they are looking for documented evidence that your ISO 27001 security awareness training programme is deliberate, managed, and traceable to specific individuals and dates.

How to evidence compliance for auditors

If your training records exist only in someone’s memory or a spreadsheet that gets updated occasionally, they will not hold up under audit scrutiny.

What records auditors actually look for

Auditors will ask to see evidence across several dimensions, not just a list of names who attended a session. You need to demonstrate who was trained, what content they received, when they completed it, and whether the content aligned with your current policy. The following record types consistently satisfy these requirements:

  • Completion records showing each individual’s name, training module or topic, and date of completion
  • Signed acknowledgement forms or digital confirmations confirming that staff have read and understood the information security policy.
  • Attendance logs from workshops or live sessions, including the agenda covered
  • Role-specific training records that show higher-risk staff received content proportionate to their responsibilities
  • Onboarding training evidence for new starters, with completion dates relative to their start dates
  • Contractor training records, demonstrating that relevant third parties were not excluded from your obligations under Annex A Control 6.3

How to organise your evidence

Keeping records scattered across email inboxes, shared drives, and line manager folders creates unnecessary audit risk. Store all training evidence in a single, accessible location clearly linked to your ISMS documentation. A dedicated folder within your document management system, labelled by year and linked to your training policy, provides auditors with a straightforward path to your evidence without you having to scramble during the audit itself.

Review your records at least once a year, preferably before your surveillance audit, to check for gaps or overdue completions. If someone missed their scheduled training, that absence should appear in your records alongside a corrective action, showing that your programme identifies and resolves lapses rather than simply ignoring them. That level of rigour is what auditors interpret as a genuinely managed compliance programme rather than a static document exercise.

How to measure effectiveness and improve

Completing your iso 27001 security awareness training programme and recording that completion is not the end of your obligation. ISO 27001 requires you to evaluate the effectiveness of your ISMS controls, and training is a control. If you cannot show that your programme is working, an auditor will reasonably question whether it is fit for purpose. Measuring effectiveness does not need to be complicated, but it does need to be deliberate and documented.

Measuring training completion tells you that people attended. Measuring what they actually retained and changed tells you whether your programme is worth running.

Metrics that tell you something useful

Attendance rates and completion percentages are the easiest numbers to gather, but they are also the least informative on their own. You need metrics that connect training activity to actual behaviour change. Phishing simulation results are among the most practical tools available: run a simulated phishing campaign before and after training, then compare click-through and reporting rates across your organisation. A meaningful drop in clicks, combined with an increase in reported suspicious emails, is strong evidence that training is shifting behaviour rather than merely consuming time.

You can also track security incident trends over time, specifically the proportion of incidents attributable to human error. If training is working, that number should decline across successive reporting periods. Combine this with post-training quiz scores or short knowledge assessments to capture whether staff retained specific content, and you have a set of metrics that gives you something genuinely actionable rather than a headcount.

Acting on what you find

Measurement only carries value if you act on the results. When phishing simulation data shows a particular team failing at a higher rate, that is a signal to deliver targeted refresher content to that group, not to wait for the next annual cycle. When a quiz reveals that staff are unclear about incident reporting procedures, update that module and push it out before your next surveillance audit, which could otherwise create an opportunity for that gap to surface.

Feed your findings back into your risk assessment and training policy regularly. Document what changed, why you changed it, and what outcome you expected. This cycle of measure, act, and record is what transforms your training programme from a static compliance artefact into a control that genuinely strengthens your security posture year on year.

iso 27001 security awareness training infographic

Next steps to stay audit-ready

Your iso 27001 security awareness training programme needs consistent attention, not just a burst of activity before each audit cycle. Start by reviewing your training policy against the 2022 version of the standard to confirm that it covers all staff, contractors, and role-specific requirements under Clause 7.3 and Annex A Control 6.3. If gaps exist, address them now rather than discovering them during your next surveillance visit.

From there, build the measurement cycle into your calendar. Schedule phishing simulations, completion reviews, and policy updates at fixed intervals so that nothing slips between audit periods. Document every change you make and the reason behind it, because auditors value a programme that visibly improves over one that simply repeats itself. If you want experienced support pulling this together, talk to the TrustedIA team about how we help UK organisations build training programmes that hold up under audit scrutiny and genuinely reduce risk.