Course development

How to design a compliance training course that passes an audit

Last reviewed 7 September 2026.

Short answer

A compliance training course passes an audit when three things line up: the learning outcomes state what a learner must be able to do, the assessment actually tests those outcomes, and the records prove each learner met them. Auditors do not mark your slides. They follow the thread from outcome to assessment to evidence, and they fail the course where that thread breaks. Build the thread first and the content second.

Start with the outcome, not the content

Write the learning outcomes before you write a single slide. An outcome is a plain statement of what the learner will be able to do after the course, expressed with a verb an assessor can test, such as identify, apply, or report. Vague outcomes like understand or be aware of cannot be assessed, and an outcome that cannot be assessed cannot be evidenced, which is exactly what an auditor looks for.

For a compliance course this matters more than for most subjects, because the point is behaviour under a rule, not recall of the rule. An anti money laundering course whose outcome is knows the regulations is weak; one whose outcome is can identify and escalate a suspicious transaction is auditable, because you can set a task that tests it.

Map every outcome to the source it comes from

Tie each outcome to the specific obligation it exists to serve, and keep that map. Compliance content dates fast, so an auditor will ask where an outcome came from and when you last checked it. A course that cannot show its source is a course nobody can trust to be current, and any outcome that maps to no real obligation is padding you can cut.

Design the assessment at the same time as the outcome

Decide how each outcome will be assessed while you are still writing it, not after the content is built. If the outcome is can identify a suspicious transaction, the assessment is a scenario where the learner has to spot one, not a multiple choice question about the definition. Assessment that only tests recall will not survive scrutiny on a course that claims to change behaviour.

Write the marking criteria in the same breath, so an auditor can see that two assessors would reach the same decision on the same evidence.

Build the records before you deliver, not after

Decide what evidence each learner will generate and where it will live before the first cohort runs. The record is the part auditors actually inspect: who enrolled, what they were assessed on, what they scored, who signed it off, and when. A brilliant course with no retrievable records fails, and a modest course with clean records passes.

Version and date everything

Put a version number and a review date on the course and on every assessment. When a regulator changes a rule, you need to show which learners took the old version and which took the new one, and you cannot do that without versioning. An undated compliance course is a liability the day the law moves, so build in a review trigger that checks the content on a set cadence and after any material change, and record each review.

Decide the recognition route before you sell it

Choose how the course will be recognised before you market it, because the claim you make has to be true. A course can be a regulated qualification, a credit rated qualification, CPD certified, or simply internal, and each carries a different promise. Selling a course as accredited when it only carries CPD certification is the fastest way to fail an audit and lose a client. If you want the course to carry a framework level, that decision shapes the design, so make it early. Our accreditation services page sets out the routes, and the course development service covers the build.

Common failure points, and how to avoid them

Most compliance courses that fail an audit fail for the same few reasons, and all of them are avoidable at the design stage.

Common questions

What makes a compliance course auditable?

A compliance course is auditable when each learning outcome can be tested, the assessment tests it, and there is a retrievable record proving each learner met it. Auditors follow the thread from outcome to assessment to evidence, so if any link is missing the course is not auditable, however good the content is.

Do compliance courses need to be accredited?

Not always. A compliance course can be a regulated qualification, a credit rated qualification, CPD certified, or internal only, and the right choice depends on what your buyers need. What matters is that you claim only the recognition the course actually holds, because an inflated claim fails audit and damages trust.

How often should a compliance course be reviewed?

Review a compliance course on a set cadence and immediately after any material change in the underlying rule. Compliance content dates quickly, so build a review trigger and a review date into the course and record each review, so you can always show the content was current when a learner took it.

What records does an auditor want to see?

An auditor wants enrolment and identity, the assessment attempt and result tied to the outcomes, the assessor decision with a name and date, and the version of the course the learner took. Decide where each record lives before the first cohort runs, because reconstructing records after the fact is where most providers come unstuck.

Can you help us design the course and get it accredited?

Yes. Apollo Accreditation builds the course and maps it to the right recognition route for training providers in the UK and Malta. Book a scoping call and we will map the outcomes, the assessment, the records and the route to your own case.

Planning a programme, an accreditation route or a quality system?

Book a 30 minute scoping call. We will map the route, the standards that apply and a realistic timeline. No preparation needed.

Book a 30 minute scoping call

Prefer to write first? Contact us.

Sources

Cookies and trackers on this site We use cookies and trackers to run this site, to see which pages people read (HubSpot analytics) and to identify the businesses that visit us for our own marketing (Apollo). These load when you use the site, under our legitimate interest. You can opt out in your browser or by contacting us. Read the cookie policy.