Feature Compliance Strategy
Training KRIs: Completion Rates Are Not Enough — What to Track Instead
A 97% training completion rate sounds impressive until your BSA examiner asks what roles made up the 3% who didn't complete it. Here are the five training KRIs that actually predict compliance risk.
Table of Contents
TL;DR
- Training completion rates measure activity, not risk — and examiners know the difference
- The five training KRIs that matter: overdue rate for high-risk roles, assessment failure patterns, pre-effective-date completion for regulatory changes, training-to-incident correlation, and remediation training completion speed
- BSA/AML training is where examiners drill hardest — tracking completion by role and function is a baseline expectation, not a best practice
- If your training KRI is a single completion percentage, you are reporting what examiners will dismiss as a vanity metric
The bank had a 97% training completion rate. Monthly monitoring reports on schedule. Policies reviewed annually. The BSA examiner asked one question: “Of the 3% who didn’t complete the AML module, what were their job functions?”
The answer was that six were transaction monitors. Four were customer-facing relationship managers handling high-net-worth clients. Two were operations staff who processed wire transfers.
The 97% completion rate became a matter requiring attention in under twenty minutes.
Completion rates are a KPI — they tell you whether an activity occurred. They are not KRIs. A KRI tells you where risk is building before an examiner finds it. These are different things, and if your training dashboard only shows the first one, you are flying blind in the area BSA, CFPB, and OCC examiners scrutinize most.
Why Completion Rates Fail as Risk Indicators
A completion rate answers one question: did people take the training? It doesn’t answer:
- Were the right people trained before they performed the covered function?
- Did they understand the material — did anyone fail the assessment?
- Is the content current enough to address today’s regulatory expectations?
- After a finding, did targeted employees actually complete remediation training quickly?
Examiners are trained to ask the next question. A 97% completion rate prompts “who is the 3% and what do they do?” A 100% rate prompts “what was the assessment pass rate?” The metric on your dashboard is the opening bid. What comes next determines whether you pass the exam.
The CFPB Supervision and Examination Manual frames training as one of four Compliance Management System pillars. Examiners assess whether training is role-appropriate, frequency-appropriate, updated for regulatory changes, and connected to findings remediation. If your training KRI can’t answer any of those questions, it’s not measuring compliance risk — it’s counting clicks.
The OCC’s Comptroller’s Handbook on Compliance Management Systems applies the same framework: a CMS exam reviews whether training is tailored to employee responsibilities, occurs with appropriate frequency, and is updated when regulations change or findings surface.
The Five Training KRIs That Actually Matter
1. Overdue Rate for High-Risk Roles
Track training completion separately for your highest-risk employee populations. Aggregating every role into a single percentage guarantees that the most important gaps are invisible.
Minimum role tiers to track separately:
- BSA/AML analysts and transaction monitors
- Customer-facing staff with consumer-disclosure or suitability obligations
- Operations staff handling wire transfers, ACH processing, or payment execution
- Management and supervisors with escalation responsibilities
- New hires who haven’t completed pre-go-live required training
| KRI | Measurement | Data Source | Owner | Threshold |
|---|---|---|---|---|
| Overdue rate — BSA/AML roles | % of AML analysts and monitors overdue on required AML training | LMS / HR | BSA Officer / Compliance | 0% is target; any overdue role is red |
| Overdue rate — customer-facing staff | % of customer-facing staff overdue on consumer compliance training | LMS / HR | Compliance | 0% target; flag >2% |
| Pre-go-live training completion | % of new hires who completed required training before starting covered functions | LMS / HRIS | Compliance / HR | 100% required; any exception is a finding |
Why timing matters for new hires: The FFIEC BSA/AML examination procedures and FinCEN’s five pillars of BSA/AML compliance both specify that training reach “appropriate personnel” — which examiners interpret as before they perform the relevant function, not within 90 days of starting. A relationship manager opening accounts before completing AML training is a control gap regardless of your overall completion rate. That gap follows the next transaction monitor who files a late SAR.
2. Assessment Failure Patterns
You’re probably tracking whether employees passed assessments. You’re probably not tracking which modules had the highest failure rates, which roles failed repeatedly, or whether assessment design explains the failures. That’s where the signal lives.
| KRI | Measurement | Data Source | Owner | Threshold |
|---|---|---|---|---|
| Assessment failure rate by module | % of employees failing each training module | LMS | Compliance / Training | Flag any module >10% failure rate |
| Repeat failure rate | % of employees requiring >2 attempts to pass | LMS | Compliance | Flag >5% in any high-risk role population |
| High-risk role assessment failures | Failure rate in BSA, AML, OFAC, consumer compliance modules for high-risk roles | LMS | BSA Officer | Any high-risk role failure triggers follow-up; 0% is target |
What assessment failures tell you: A 15% failure rate on the AML Red Flags module means either the content is poorly designed or the population doesn’t understand the material. Both are control risks with different remedies. A repeat failure rate above 5% in customer-facing staff means some of your highest-exposure employees are cycling through training without absorbing it.
Examiners reviewing BSA training records ask about failure rates, not just completion. The K&L Gates analysis of 2024 BSA/AML enforcement actions identified training program deficiencies as a recurring contributing factor in consent orders — consistently traced back to inadequate targeting of high-risk populations, not low overall completion rates.
3. Pre-Effective-Date Completion for Regulatory Changes
When a new regulation takes effect, the training question isn’t “did we train everyone by Q4?” — it’s “were relevant staff trained before the rule was effective?”
This is one of the most common gaps in compliance training programs. A regulatory change arrives. Training is updated. Completion is tracked on a quarterly cadence. But the module went live six weeks after the effective date — meaning staff were operating under the new rule without training during the gap.
| KRI | Measurement | Data Source | Owner | Threshold |
|---|---|---|---|---|
| Regulatory change training — % complete before effective date | % of affected staff who completed training before the rule took effect | LMS / compliance change log | Compliance | 100% target; any affected-staff completion after effective date is a gap |
| Training content currency | Average age of compliance training modules vs. the regulation they cover | LMS / compliance calendar | Compliance | Flag any module >18 months old in a fast-evolving regulatory area |
| Regulatory change-to-training deployment lag | Days between a rule’s effective date and training module availability | LMS / compliance calendar | Compliance | Flag >30-day lag; any module deployed after effective date is a gap |
How to fix the tracking problem: Most LMS systems track training against internal completion deadlines, not regulatory effective dates. Fix this by connecting your training calendar directly to your compliance change management process. Every regulation affecting training should generate a training deadline set before the effective date — with an owner who can escalate if the module won’t be ready in time.
4. Training-to-Incident Correlation
This is the KRI most compliance programs don’t measure — and the one that reveals the most about whether training is working at all. When a compliance incident or finding occurs, was the responsible employee current on the relevant training at the time?
You’re not looking to blame employees. You’re trying to determine whether your training program is reaching the right people at the right time, and whether training deficiencies are a root cause of compliance failures.
| KRI | Measurement | Data Source | Owner | Threshold |
|---|---|---|---|---|
| Training currency at incident | % of compliance incidents where responsible employee was current on relevant training | Incident log + LMS | Compliance | Track trend; interpret direction (see below) |
| High-risk role incidents with training gap | Number of incidents where responsible employee was overdue on directly relevant training | Incident log + LMS | Compliance / BSA | Any instance triggers both incident review and training program review |
How to read the signal: If 70% of your AML-related incidents involved employees who were current on their AML training, the training isn’t preventing the behavior. That’s a control design or escalation failure — not a training coverage failure. If 70% involved employees who were overdue, you have a delivery and targeting problem. Both diagnoses are useful. Neither is visible from a completion rate dashboard.
The FFIEC BSA/AML examination manual expects examiners to evaluate whether a training program is effective — not just whether it exists. Training-to-incident correlation is how you demonstrate effectiveness with data rather than declarations.
5. Remediation Training Completion Speed
When an exam finding, MRA, or audit result requires targeted remediation training, the training must happen quickly and with documentation. This is where many programs lose ground they’ve otherwise built.
The remediation plan says “provide targeted training to affected staff.” Training is eventually completed — three months later, after the next monitoring cycle has already run the same procedures. When the follow-up examiner asks about the remediation, the answer is “it was done, but late.” That’s a continuing deficiency, not a closed finding.
| KRI | Measurement | Data Source | Owner | Threshold |
|---|---|---|---|---|
| Remediation training — days to completion | Days between finding issuance and remediation training completion for affected staff | Issues tracker + LMS | Compliance | Flag if >30 days; any High-severity finding >14 days unresolved is red |
| Remediation training completion rate | % of staff identified in finding who completed required remediation training | LMS / issues tracker | Compliance | 100% required; any gap extends the finding |
| Remediation training documentation | Whether evidence of completion is attached in the issues tracker | Issues tracker audit | Compliance | Flag if evidence not attached within 5 business days of completion |
What examiners check on return: The FFIEC’s BSA/AML exam procedures note that examiners can carry forward prior conclusions where the bank’s risk profile hasn’t materially changed — but training remediations cited in a prior exam are typically re-checked. If the training was completed but not documented, or documented but completed months after the finding, the examiner characterizes it as a continuing deficiency.
The Reporting Structure: What Goes Where
Not every training KRI belongs in every report.
Board or risk committee (quarterly): Training overdue rate for high-risk roles, regulatory change training completion status, and remediation training completion rate. These are program-level health indicators — the board needs to know whether the CMS training pillar is functioning, not the module-by-module breakdown.
Management reporting (monthly): Full overdue breakdown by role tier, assessment failure rates by module, incident-to-training correlation trend, and remediation training aging for open findings.
Operational/functional reporting (weekly or continuous): New hire pre-go-live training completion, high-priority remediation training tracking, and individual overdue flags for BSA/AML and OFAC roles where a gap is an immediate control failure.
So What?
A 97% training completion rate is evidence that 97% of employees clicked through a module. It’s not evidence that your compliance training program is working.
What the completion rate doesn’t tell you: which roles are in the 3%, whether those roles are your highest-risk functions, whether anyone who completed the module can pass an assessment on the material, whether the content addresses current regulatory expectations, and whether your last three compliance incidents involved employees who were current on relevant training.
The broader compliance KRI framework gives you the program-wide view across training, monitoring, complaints, and policy management. The KRI design guide helps you build thresholds and owner assignments that make these metrics actionable. This article gives you the five training KRIs that predict compliance risk before findings show up.
Build them. Assign owners. Make sure your BSA officer can answer the examiner’s second question before it’s asked.
The Compliance Essentials bundle includes policy templates, compliance calendar, and compliance program documentation that connect to your KRI tracking — so training metrics don’t sit in isolation from the broader compliance management system your examiners are actually evaluating.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What's wrong with using training completion rate as a KRI?
What training KRIs do CFPB examiners actually look at?
What is a training-to-incident correlation KRI?
How specific should role-based training tracking be?
What is the regulatory expectation for training timing — before hire or within a fixed window after?
What happens when remediation training after a finding is completed late?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Compliance Essentials
Multi-domain compliance coverage: data privacy, incident response, BCP/DR, and SOC 2 — 43% off.
◆ Keep reading
Related posts.
Compliance Strategy
GRC Framework for a Small Risk Team: One Control Library, Five Workflows, No Enterprise Platform
A GRC program that runs on one control library, five traceable workflows, and a set of spreadsheets beats a half-implemented enterprise platform every time. Here's how to build it.
Jul 24, 2026
Compliance Strategy
Compliance Monitoring Plan in Excel: Convert the Risk Assessment Into a Defensible Test Universe
Build a compliance monitoring plan template in Excel that traces risks and obligations to scope, evidence, exceptions, and remediation.
Jul 23, 2026
Compliance Strategy
Your Reg E Program Wasn't Built for FedNow: The Error Resolution Timeline Trap in Instant Payments
Reg E's 10-business-day provisional credit requirement applies to FedNow and RTP consumer transactions—but instant payment irrevocability means the fraud money is gone before you finish the investigation. Here's what your error resolution procedures actually need to say for instant payments, and where most programs have a documented gap.
Jul 22, 2026