Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Training KRIs: Completion Rates Are Not Enough — What to Track Instead

A 97% training completion rate sounds impressive until your BSA examiner asks what roles made up the 3% who didn't complete it. Here are the five training KRIs that actually predict compliance risk.

By Rebecca Leung · May 28, 2026 ·
Table of Contents

TL;DR

  • Training completion rates measure activity, not risk — and examiners know the difference
  • The five training KRIs that matter: overdue rate for high-risk roles, assessment failure patterns, pre-effective-date completion for regulatory changes, training-to-incident correlation, and remediation training completion speed
  • BSA/AML training is where examiners drill hardest — tracking completion by role and function is a baseline expectation, not a best practice
  • If your training KRI is a single completion percentage, you are reporting what examiners will dismiss as a vanity metric

The bank had a 97% training completion rate. Monthly monitoring reports on schedule. Policies reviewed annually. The BSA examiner asked one question: “Of the 3% who didn’t complete the AML module, what were their job functions?”

The answer was that six were transaction monitors. Four were customer-facing relationship managers handling high-net-worth clients. Two were operations staff who processed wire transfers.

The 97% completion rate became a matter requiring attention in under twenty minutes.

Completion rates are a KPI — they tell you whether an activity occurred. They are not KRIs. A KRI tells you where risk is building before an examiner finds it. These are different things, and if your training dashboard only shows the first one, you are flying blind in the area BSA, CFPB, and OCC examiners scrutinize most.

Why Completion Rates Fail as Risk Indicators

A completion rate answers one question: did people take the training? It doesn’t answer:

  • Were the right people trained before they performed the covered function?
  • Did they understand the material — did anyone fail the assessment?
  • Is the content current enough to address today’s regulatory expectations?
  • After a finding, did targeted employees actually complete remediation training quickly?

Examiners are trained to ask the next question. A 97% completion rate prompts “who is the 3% and what do they do?” A 100% rate prompts “what was the assessment pass rate?” The metric on your dashboard is the opening bid. What comes next determines whether you pass the exam.

The CFPB Supervision and Examination Manual frames training as one of four Compliance Management System pillars. Examiners assess whether training is role-appropriate, frequency-appropriate, updated for regulatory changes, and connected to findings remediation. If your training KRI can’t answer any of those questions, it’s not measuring compliance risk — it’s counting clicks.

The OCC’s Comptroller’s Handbook on Compliance Management Systems applies the same framework: a CMS exam reviews whether training is tailored to employee responsibilities, occurs with appropriate frequency, and is updated when regulations change or findings surface.

The Five Training KRIs That Actually Matter

1. Overdue Rate for High-Risk Roles

Track training completion separately for your highest-risk employee populations. Aggregating every role into a single percentage guarantees that the most important gaps are invisible.

Minimum role tiers to track separately:

  • BSA/AML analysts and transaction monitors
  • Customer-facing staff with consumer-disclosure or suitability obligations
  • Operations staff handling wire transfers, ACH processing, or payment execution
  • Management and supervisors with escalation responsibilities
  • New hires who haven’t completed pre-go-live required training
KRIMeasurementData SourceOwnerThreshold
Overdue rate — BSA/AML roles% of AML analysts and monitors overdue on required AML trainingLMS / HRBSA Officer / Compliance0% is target; any overdue role is red
Overdue rate — customer-facing staff% of customer-facing staff overdue on consumer compliance trainingLMS / HRCompliance0% target; flag >2%
Pre-go-live training completion% of new hires who completed required training before starting covered functionsLMS / HRISCompliance / HR100% required; any exception is a finding

Why timing matters for new hires: The FFIEC BSA/AML examination procedures and FinCEN’s five pillars of BSA/AML compliance both specify that training reach “appropriate personnel” — which examiners interpret as before they perform the relevant function, not within 90 days of starting. A relationship manager opening accounts before completing AML training is a control gap regardless of your overall completion rate. That gap follows the next transaction monitor who files a late SAR.

2. Assessment Failure Patterns

You’re probably tracking whether employees passed assessments. You’re probably not tracking which modules had the highest failure rates, which roles failed repeatedly, or whether assessment design explains the failures. That’s where the signal lives.

KRIMeasurementData SourceOwnerThreshold
Assessment failure rate by module% of employees failing each training moduleLMSCompliance / TrainingFlag any module >10% failure rate
Repeat failure rate% of employees requiring >2 attempts to passLMSComplianceFlag >5% in any high-risk role population
High-risk role assessment failuresFailure rate in BSA, AML, OFAC, consumer compliance modules for high-risk rolesLMSBSA OfficerAny high-risk role failure triggers follow-up; 0% is target

What assessment failures tell you: A 15% failure rate on the AML Red Flags module means either the content is poorly designed or the population doesn’t understand the material. Both are control risks with different remedies. A repeat failure rate above 5% in customer-facing staff means some of your highest-exposure employees are cycling through training without absorbing it.

Examiners reviewing BSA training records ask about failure rates, not just completion. The K&L Gates analysis of 2024 BSA/AML enforcement actions identified training program deficiencies as a recurring contributing factor in consent orders — consistently traced back to inadequate targeting of high-risk populations, not low overall completion rates.

3. Pre-Effective-Date Completion for Regulatory Changes

When a new regulation takes effect, the training question isn’t “did we train everyone by Q4?” — it’s “were relevant staff trained before the rule was effective?”

This is one of the most common gaps in compliance training programs. A regulatory change arrives. Training is updated. Completion is tracked on a quarterly cadence. But the module went live six weeks after the effective date — meaning staff were operating under the new rule without training during the gap.

KRIMeasurementData SourceOwnerThreshold
Regulatory change training — % complete before effective date% of affected staff who completed training before the rule took effectLMS / compliance change logCompliance100% target; any affected-staff completion after effective date is a gap
Training content currencyAverage age of compliance training modules vs. the regulation they coverLMS / compliance calendarComplianceFlag any module >18 months old in a fast-evolving regulatory area
Regulatory change-to-training deployment lagDays between a rule’s effective date and training module availabilityLMS / compliance calendarComplianceFlag >30-day lag; any module deployed after effective date is a gap

How to fix the tracking problem: Most LMS systems track training against internal completion deadlines, not regulatory effective dates. Fix this by connecting your training calendar directly to your compliance change management process. Every regulation affecting training should generate a training deadline set before the effective date — with an owner who can escalate if the module won’t be ready in time.

4. Training-to-Incident Correlation

This is the KRI most compliance programs don’t measure — and the one that reveals the most about whether training is working at all. When a compliance incident or finding occurs, was the responsible employee current on the relevant training at the time?

You’re not looking to blame employees. You’re trying to determine whether your training program is reaching the right people at the right time, and whether training deficiencies are a root cause of compliance failures.

KRIMeasurementData SourceOwnerThreshold
Training currency at incident% of compliance incidents where responsible employee was current on relevant trainingIncident log + LMSComplianceTrack trend; interpret direction (see below)
High-risk role incidents with training gapNumber of incidents where responsible employee was overdue on directly relevant trainingIncident log + LMSCompliance / BSAAny instance triggers both incident review and training program review

How to read the signal: If 70% of your AML-related incidents involved employees who were current on their AML training, the training isn’t preventing the behavior. That’s a control design or escalation failure — not a training coverage failure. If 70% involved employees who were overdue, you have a delivery and targeting problem. Both diagnoses are useful. Neither is visible from a completion rate dashboard.

The FFIEC BSA/AML examination manual expects examiners to evaluate whether a training program is effective — not just whether it exists. Training-to-incident correlation is how you demonstrate effectiveness with data rather than declarations.

5. Remediation Training Completion Speed

When an exam finding, MRA, or audit result requires targeted remediation training, the training must happen quickly and with documentation. This is where many programs lose ground they’ve otherwise built.

The remediation plan says “provide targeted training to affected staff.” Training is eventually completed — three months later, after the next monitoring cycle has already run the same procedures. When the follow-up examiner asks about the remediation, the answer is “it was done, but late.” That’s a continuing deficiency, not a closed finding.

KRIMeasurementData SourceOwnerThreshold
Remediation training — days to completionDays between finding issuance and remediation training completion for affected staffIssues tracker + LMSComplianceFlag if >30 days; any High-severity finding >14 days unresolved is red
Remediation training completion rate% of staff identified in finding who completed required remediation trainingLMS / issues trackerCompliance100% required; any gap extends the finding
Remediation training documentationWhether evidence of completion is attached in the issues trackerIssues tracker auditComplianceFlag if evidence not attached within 5 business days of completion

What examiners check on return: The FFIEC’s BSA/AML exam procedures note that examiners can carry forward prior conclusions where the bank’s risk profile hasn’t materially changed — but training remediations cited in a prior exam are typically re-checked. If the training was completed but not documented, or documented but completed months after the finding, the examiner characterizes it as a continuing deficiency.

The Reporting Structure: What Goes Where

Not every training KRI belongs in every report.

Board or risk committee (quarterly): Training overdue rate for high-risk roles, regulatory change training completion status, and remediation training completion rate. These are program-level health indicators — the board needs to know whether the CMS training pillar is functioning, not the module-by-module breakdown.

Management reporting (monthly): Full overdue breakdown by role tier, assessment failure rates by module, incident-to-training correlation trend, and remediation training aging for open findings.

Operational/functional reporting (weekly or continuous): New hire pre-go-live training completion, high-priority remediation training tracking, and individual overdue flags for BSA/AML and OFAC roles where a gap is an immediate control failure.

So What?

A 97% training completion rate is evidence that 97% of employees clicked through a module. It’s not evidence that your compliance training program is working.

What the completion rate doesn’t tell you: which roles are in the 3%, whether those roles are your highest-risk functions, whether anyone who completed the module can pass an assessment on the material, whether the content addresses current regulatory expectations, and whether your last three compliance incidents involved employees who were current on relevant training.

The broader compliance KRI framework gives you the program-wide view across training, monitoring, complaints, and policy management. The KRI design guide helps you build thresholds and owner assignments that make these metrics actionable. This article gives you the five training KRIs that predict compliance risk before findings show up.

Build them. Assign owners. Make sure your BSA officer can answer the examiner’s second question before it’s asked.

The Compliance Essentials bundle includes policy templates, compliance calendar, and compliance program documentation that connect to your KRI tracking — so training metrics don’t sit in isolation from the broader compliance management system your examiners are actually evaluating.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What's wrong with using training completion rate as a KRI?
Completion rate is a lagging activity metric, not a risk indicator. It tells you whether training occurred, not whether the right people were trained before they needed it, whether they understood the material, or whether the content was current enough to address current risks. A 98% completion rate can coexist with 40% of your highest-risk employees being overdue — and your exam finding will cite the 40%, not celebrate the 98%.
What training KRIs do CFPB examiners actually look at?
The CFPB's compliance management system examination treats training as one of four CMS pillars. Examiners assess whether training is role-appropriate, updated for regulatory changes, and whether high-risk populations receive targeted training before they engage in high-risk activities. They also trace training records to specific incidents — if an employee caused a violation, examiners check whether they were current on the relevant training at the time.
What is a training-to-incident correlation KRI?
Training-to-incident correlation asks: when a compliance incident occurs, was the responsible employee current on relevant training at the time? If the answer is frequently 'no,' you have a training delivery or targeting problem. If the answer is frequently 'yes,' you have a control gap that training alone won't fix. Either way, it's a more useful risk signal than whether 97% of staff checked a training completion box.
How specific should role-based training tracking be?
At minimum, track separately: BSA/AML analysts and transaction monitors, customer-facing staff with consumer-disclosure or suitability obligations, operations staff with wire or payment execution responsibilities, and management with escalation responsibilities. Aggregating all roles into one completion percentage masks the risk concentration in your highest-exposure populations.
What is the regulatory expectation for training timing — before hire or within a fixed window after?
FinCEN's AML/CFT modernization rule and the FFIEC BSA/AML examination procedures both require that training reach 'appropriate personnel.' Examiners interpret this as before the relevant staff performs the covered function, not within 90 days of hire. For customer-facing BSA roles, pre-go-live training completion is increasingly expected. For regulatory changes, training should be completed before the effective date — not after.
What happens when remediation training after a finding is completed late?
Examiners returning for follow-up exams check specifically whether targeted training required under a prior exam finding or MRA was completed and documented. If the training was required but completed months later, or completed but not documented, the examiner will likely characterize it as a continuing deficiency — even if the underlying behavior improved. Remediation plan credibility depends on timely execution.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Compliance Essentials

Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.