77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
AI-powered compliance software for training: What counts, what doesn't
Platform & Strategy

AI-powered compliance software for training: What counts, what doesn't

15 July 202613 min readBy Dr. Henrik Bauer
CIVAC

What are the requirements for AI-supported compliance training? How do you differentiate marketing from robust technology? And what evidence does the platform have to provide in order for the training to pass the audit? A methodical guide for DPOs, COs and management.

Training obligations are among the best documented compliance requirements in German law: Section 4 Paragraph 1 GwG requires regular training on money laundering prevention, Section 12 ArbSchG requires training on occupational safety, Section 15 AGG requires anti-discrimination training, and the GDPR derives the obligation to raise awareness among employees from Article 39 Paragraph 1 Letter b GDPR. AI-powered training software promises to fulfil these duties more efficiently through adaptive learning paths, automated knowledge measurement, and integrated evidence storage. But not every platform that prints AI delivers what the supervisory authority wants to see in the audit.

This article explains which functions AI can really contribute to compliance training, which requirements from the EU AI Act must be adhered to for high-risk applications and how proof of training can be stored in a structured manner in a compliance platform and officer-as-a-service. You will receive an evaluation grid with ten criteria, a checklist for checking suitability as a processor in accordance with Art. 28 GDPR and a recommendation on how the training process can be interlinked with the risk register and the compliance officer's appointment document. Others run compliance like a filing cabinet. We run it like software. At the end, you will also receive a recommendation in which order training types should be rolled out and how employee communication can be designed to be legally secure and promote acceptance.

Key Takeaways

  • AI in compliance training is only valuable if it learns adaptively, recognises gaps and documents evidence in an audit-proof manner, not if it just rephrases texts.
  • High-risk applications according to Annex III of the EU AI Act trigger extended documentation and supervision obligations, for example in the case of automated assessment of learning performance with personnel-related consequences.
  • Training courses are only audit-proof when the appointment certificate, list of participants, content version, test results and repeat date are stored in a seamlessly linked manner.

What training requirements compliance software must cover

Compliance training is not a uniform obligation, but rather a bundle of sectoral requirements with different frequencies, addressees and proof requirements. Section 4 (1) of the GwG requires obligated parties to regularly instruct their employees on methods of money laundering and on the obligations under this law. Section 12 ArbSchG requires instructions on occupational safety and health protection before starting work and regularly thereafter, at least once a year. Section 15 AGG obliges the employer to point out the inadmissibility of discrimination in an appropriate manner and to train employees accordingly.

There are also industry-specific obligations: Section 4 Paragraph 5 No. 3 ProdSG for those placing products on the market, Section 8 Paragraph 1 LkSG for supply chain risks, Section 3 Paragraph 1 IT-SiG 2.0 for KRITIS operators, ISO/IEC 27001:2022 Control A.6.3 for information security awareness and education. Compliance training software must cover this range or at least be able to dock neatly into specialised modules.

This diversity results in a first, often underestimated requirement: The software must automatically manage various mandatory frequencies, such as annual data protection training, semi-annual IT security awareness modules, event-related instructions after incidents, onboarding training for new employees within four weeks of joining. Anyone who maintains these frequencies manually in tables as a compliance officer loses the overview after six months at the latest in a company with 500 employees and 12 training types. The platform must support the deadline mechanics itself, with configurable escalations and reports to management. There are also special cases such as temporary employees, working students, temporary workers and external service providers with site access, whose training obligations must be fulfilled partly by the hirer and partly by the lender and must be clearly documented. Another aspect is the role-specific mandatory matrix: Board members, managing directors and supervisory boards are subject to extended training obligations, for example in accordance with Section 4 GwG Paragraph 3 or Section 25a Paragraph 1 KWG. These duties cannot be integrated into general onboarding, but require their own, separately documented training path with documented participation.

What AI really contributes to compliance training

Marketing claims about AI in compliance training are often vague. There are only four functional classes that provide measurable added value. First: adaptive learning paths. The software uses response patterns to identify which subject areas the employee has mastered and which not, and dynamically adjusts the order and depth of the modules. This shortens the average training duration by typically 20 to 35 percent compared to linear learning paths, without diluting the knowledge level measurement.

Second: automated knowledge level measurement with question generation from the training content. An LLM-supported component generates multiple-choice and free-text questions for each module that do not come from a static question bank. This reduces the risks of question bingo and increases the validity of the exam. Third: escalation and risk scoring. The software recognises employees whose repeated failed attempts or delayed repeat appointments result in a risk profile and prioritises them in the reporting view for the compliance officer.

Fourth: translation and localization. In international corporate structures, the same content must be available in multiple languages, often with cultural adjustments. AI translation with subsequent expert review speeds up this process significantly. What AI should not do: legal assessment. Training on AGG obligations must be curated by a qualified lawyer or certified trainer, not hallucinated by a language model. The value of AI lies in adaptation, measurement, localization, not in content authority. If you make this distinction clearly, you will avoid the most common mistakes when using AI-supported training platforms and at the same time avoid the discussion about hallucination-related compliance risks. A fifth, often mentioned function is the automated text summarization of long legal texts. The following applies here: Summaries do not replace training, but are learning aids. The mandatory content itself must remain curated. Anyone who declares AI summaries as training runs the risk that the supervisory authority will criticize the lack of professional responsibility in the audit.

EU AI Act: When training software becomes a high-risk system

The EU AI Act (Regulation 2024/1689) has been fully applicable since August 2026 and differentiates AI systems according to risk classes. Compliance training software typically falls into the class of limited risk, but as soon as it generates evaluations with personnel-related consequences, such as recommendations for transfer, warning or bonus reduction, it moves into the high-risk class according to Annex III No. 4 lit. b AI Act (evaluation of employees).

Significant obligations apply to high-risk AI systems: risk management system according to Art. Recording obligations according to Art. 12 (logging), transparency according to Art. 13, human supervision according to Art. 14, accuracy and cybersecurity according to Art. 15. In addition, there is the obligation for fundamental rights impact assessment (FRIA) according to Art. 27 AI Act for public bodies and for private actors who perform public tasks.

Transparency obligations according to Art. 50 AI Act also apply below the high-risk threshold: employees must know that they are working with an AI system interact, that their answers are evaluated and what consequences this has. The data protection impact assessment according to Art. 35 GDPR must be carried out in parallel because the processing of learning data is particularly sensitive. Whoever is involved in the selection as a data protection officer therefore not only checks the functional description, but also the provider's conformity assessment in accordance with Article 43 of the AI ​​Act and the CE marking in accordance with Article 48. If the conformity assessment is missing, use as a high-risk application is formally inadmissible. The EU database for high-risk AI systems according to Article 71 of the AI ​​Act is also a test indicator: a system registered there has demonstrably followed the conformity path, while a system that is not registered has not. Anyone who purchases here without a documented assessment of the AI ​​Act risk profile is placing a compliance responsibility on their own company that is difficult to get rid of.

Selection grid: Ten criteria for compliance training platforms

Selecting an AI-powered training platform is a combined IT, data protection, compliance and HR decision. A reliable selection grid includes ten criteria. First: regulatory coverage. Which types of training are available out of the box (AMLA, GDPR, IT security, AGG, occupational safety, LkSG)? Second: frequency management. Can repetition intervals be configured per training type and per employee role? Third: evidence storage. Which fields are documented in the audit trail and can certificates be generated automatically?

Fourth: AI transparency. Does the provider provide a model map, a data origin description, and a conformity assessment according to the AI ​​Act? Fifth: data protection. EU data residency, order processing contract according to Art. 28 GDPR with all sub-processors, ban on model retraining with customer data without consent. Sixth: integration. Interfaces to HR systems (SAP SuccessFactors, Personio, Workday), single sign-on (SAML/OIDC), API for risk registers and processing directory.

Seventh: ISMS maturity of the provider. ISO/IEC 27001:2022, SOC 2 report, penetration testing. Eighth: language diversity and localization. Ninth: Reporting for management with configurable KPIs and escalation thresholds. Tenth: contract exit and data export. Can the entire training history be exported in a machine-readable format without vendor lock-in? Anyone who systematically applies these ten criteria avoids both greenwashing and over-motivated procurement decisions that later fail due to the reality of supervisory practice. The evaluation per criterion should be supported by concrete evidence, not by provider self-statements, otherwise the selection decision itself is not audit-proof. An eleventh, voluntary criterion is provider maturity in the event of a crisis: incident response plan, early warning times for security incidents, documented escalation paths to the customer, willingness to report a joint data breach in accordance with Art. 33 GDPR. In an emergency, this criterion determines the speed of reaction of the entire compliance organisation and should not be underestimated when making the selection. In addition to the criteria, a proof of concept over 4 to 8 weeks with real learning content, defined KPIs and a documented assessment by the DPO and compliance officer is recommended.

Evidence filing: What is actually presented in the audit

A training course is only relevant to compliance if it can be documented in an audit-proof manner. The following minimum fields in the proof arise from Section 4 GwG, Section 12 ArbSchG, Section 15 AGG, ISO/IEC 27001:2022 Control A.6.3 and the accountability requirement in accordance with Art. Repeat date, trainer or system identification used, language and format if applicable.

These fields must be kept in a single source from which filtering, exporting and archiving can be carried out in an audit-proof manner. PDF folders or Excel lists do not meet the requirements because they offer no versioning, no access control and no protection against manipulation. A modern training platform with a revision-proof audit trail digitally signs evidence and links it to the appointment certificate of the responsible compliance officer.

Retention periods: According to Section 257 of the German Commercial Code (HGB) and Section 147 of the AO, training evidence must be retained as business documents for at least 6 years, and up to 10 years in the tax and balance sheet context. For safety-related training courses, it is recommended that they be retained until the end of employment plus 5 years, because labour law disputes often only arise years later. The auditor calls, the evidence is ready. That is exactly the function of the evidence storage: to turn an obligation into a tool that can be used in the event of need without any advance notice. Anyone who operates the evidence storage in the CIVAC platform also has a link to the appointment certificate, reporting line and risk register, so that the training does not act as an isolated measure, but as part of a coherent compliance system. For training courses with a certification-relevant character (e.g. ISO 27001 Lead Auditor or AMLA Money Laundering Officer), the identity of the trainer, their qualifications and the issued certificates with serial numbers must also be stored.

Order processing and data protection for AI training platforms

AI-supported training platforms process employees' personal data on behalf of the employer. This means that the obligations under Art. 28 GDPR apply: written order processing contract, documented instructions, ensuring confidentiality, obligations to support data subjects' rights and DPIA, complete list of sub-processors with the controller's right to object.

The clause on the use of customer data for model retraining deserves particular attention. Many AI providers reserve the right in standard terms and conditions to use anonymized input data to improve their models. In compliance training, this data is typically personal (learning speed, error patterns, career data), so anonymization within the meaning of Recital 26 GDPR is rarely successful. Recommendation: Contractual prohibition of model retraining with customer data, documented in the AVV.

Third country transfer is a second risk area. Many US-based AI platforms route requests to US data centres. Since the abolition of the Privacy Shield and with the EU-US Data Privacy Framework, third country transfers are generally possible again, but are subject to strict conditions: self-certification of the provider in the DPF program, standard contractual clauses as backup, Transfer Impact Assessment (TIA). Anyone who chooses EU data residency avoids this complexity and reduces both the legal and operational layers of effort. The CIVAC platform with EU data residency and ISO/IEC 27001:2022 compliant operation meets these requirements by design. In addition, attention should be paid to the sub-processor chain: Even with EU hosting, a single US LLM provider can compromise the entire data protection architecture in the background if it is not also operated in accordance with EU regulations. Anyone who takes data protection seriously should have the provider provide them with the complete order processing and sub-processor chain in list form and check whether transfer impact assessments are currently available. In addition, it is recommended to have a contractual audit rights clause that grants the person responsible the right to carry out an on-site or remote audit of the provider at least once a year.

Training strategy: fulfil duty or achieve impact

Compliance training is carried out in many organisations purely as a fulfilment of obligations: quotas, click quotas, completion quotas. The supervisory authorities are increasingly no longer just evaluating the rate, but rather the impact. Section 130 OWiG sanctions the violation of supervisory obligations if appropriate supervisory measures would have prevented or significantly made violations more difficult. A training course that has only been clicked on is not considered a suitable supervisory measure.

Effect-oriented training courses differ in five points: Firstly, they rely on scenarios from a real work context (phishing simulations, whistleblower case studies, AGG conflict situations). Second, they measure not just knowledge, but behaviour (e.g. click rate on phishing emails before and after training). Thirdly, they are target group-specific (board of directors, managers, employees with special responsibilities, general workforce). Fourth, they document concrete lessons learned from incidents. Fifth, they visibly involve management because Tone from the Top measurably contributes to effectiveness.

AI-supported platforms can support this impact orientation, for example through automated phishing simulations, through language-sensitive conflict scenarios, through reporting based on risk class instead of completion rate. Requirement: The platform not only provides learning content, but also behavioral measurements and evaluations that are incorporated into the risk register and the report to management. A pure quota platform is not an effective supervisory measure, even with an AI layer. The bridge to effectiveness is built through an integrated workspace that brings together learning, measurement and reporting in one data model. From supervisory practice: Anyone who has to calculate a fine in an emergency will benefit significantly from documented impact measurement, because Article 83 Para. 2 GDPR expressly names the measures taken to reduce the damage as a mitigating factor. Even in the case of OWiG fines against company management, a reliable, documented effectiveness measurement acts as a relief and can noticeably reduce the amount of fines.

Integration: From the learning system to the compliance control system

An AI-powered training platform only realizes its value through integration. Four interfaces are critical. First: HR system. Master data (entry, departure, role change, location) must flow automatically, otherwise there will be training gaps for new hires and phantom duties for departures. Second: risk register. Training deficiencies of individual employees or areas must appear as a risk entry in the central register, with the probability of occurrence and amount of damage.

Third: processing directory. The training platform itself is processing within the meaning of Art. 30 GDPR and must be completely deposited there, including the order processing contract and, if applicable, the DPIA. Fourth: Appointment certificates and reporting lines. Each representative (compliance, data protection, information security, money laundering, hygiene) has their own training obligations towards employees and their own obligations to provide evidence to management. The platform must reflect this distribution of roles.

The CIVAC platform integrates these four interfaces in a data model so that the training, appointment certificate, processing directory and risk register are consistent with one another. This is the difference between an isolated learning system and a compliance control system. Anyone planning the integration should also pay attention to an identity provider concept that combines single sign-on with the Active Directory or Entra ID, as well as an API-first architecture that allows later expansions without vendor lock-in. A typical integration error is the duplication of master data: If the training platform maintains employee master data in parallel with the HR system, inconsistencies inevitably arise that appear in every regulatory audit as a data quality deficiency and undermine trust in the entire compliance system. Recommended architecture: The HR system remains leading, the training platform consumes master data read-only and only writes back training results. This means that data sovereignty remains clear, audit trails can be clearly assigned and data protection rights (information, correction, deletion) can be fulfilled centrally without the person responsible having to synchronize between multiple systems.

CIVAC: Compliance-Plattform und Officer-as-a-Service

The decision between an internal training platform and external support is not an either/or question. CIVAC offers both as an integrated offering: compliance platform and officer-as-a-service. In the platform model, your internal representatives receive access to 490 audit templates, 93 controls according to ISO/IEC 27001:2022, an audit-proof workspace with EU data residency and training modules for 25 representative roles. In the Officer-as-a-Service model, we provide external representatives who carry out training duties for your employees, with an appointment certificate, reporting line to management and an SLA of 2 working days.

Licence the workspace for your internal representatives, or have our representatives appointed. The choice depends on your industry, the maturity of your existing compliance function and the desired speed. For SMEs with 50 to 500 employees, the officer-as-a-service route is often more cost-effective and faster. For corporations with an established compliance function, the platform licence provides the missing tool with which internal representatives can work in an audit-proof manner.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We will respond within two working days with a needs analysis for your training obligations, an assessment of your current platform landscape and a specific recommendation as to the order in which modules should be rolled out. If you are already using training software, we will check it against the ten selection criteria from this article and provide a list of gaps with concrete correction steps. The appointment certificate, signed, filed, verifiable. In this way, the fulfilment of obligations creates a controllable compliance instrument that is used in every supervisory audit. In the first conversation, we clarify the industry, number of employees, existing duty matrix and desired escalation speed so that the recommendation remains connected to your ongoing structures.

FAQ

What legal training requirements does a compliance platform have to cover?

The most common are Section 4 GwG (prevention of money laundering), Section 12 ArbSchG (occupational safety), Section 15 AGG (anti-discrimination), Art. 39 GDPR (data protection awareness), Section 8 LkSG (supply chain risks), ISO/IEC 27001:2022 Control A.6.3 (Information Security Awareness) as well as sector-specific obligations in KRITIS, financial services and healthcare. The software must be able to map this bandwidth or dock it in a modular manner in order to function in an audit-proof manner.

When is AI-supported training software considered a high-risk system according to the EU AI Act?

As soon as the software generates automated evaluations that have personnel-related consequences (promotion, warning, bonus reduction), Annex III No. 4 lit. b AI Act applies. Obligations regarding risk management (Art. 9), data governance (Art. 10), logging (Art. 12), transparency (Art. 13), human supervision (Art. 14) and conformity assessment (Art. 43) with CE marking according to Art. 48 then apply.

How long must training records be kept?

Training certificates are considered business documents in accordance with Section 257 of the German Commercial Code (HGB) and Section 147 of the AO with retention periods of 6 to 10 years. For safety-related training courses, it is recommended that they be retained until the end of employment plus 5 years, because labour law disputes often only arise years later. When it comes to money laundering training, BaFin requires complete proof of the entire period covered by the obligation.

Which clause on model retraining belongs in the order processing contract?

An express prohibition on the use of customer data to improve or train the provider's AI models without documented consent. Standard terms and conditions of many AI providers contain reverse clauses that are not permitted for compliance data. The AVV according to Art. 28 GDPR must contain this prohibition in writing and bind sub-processors with identical obligations, otherwise a gap will arise in the data protection chain.

What distinguishes effective training from purely compulsory training according to Section 130 OWiG?

Effective training measures behaviour instead of just quotas, uses scenarios from the real work context, is target group-specific, visibly involves management and documents lessons learned from incidents. Section 130 OWiG sanctions violations of supervisory duties if appropriate supervisory measures would have prevented violations. Pure click rates do not meet this standard and, in case of doubt, do not protect management from fines.

How does CIVAC integrate training into the overall compliance system?

The CIVAC platform links training certificates with the appointment certificate, reporting line, processing directory according to Art. 30 GDPR and risk register in a data model with EU data residency. Training deficiencies become visible as a risk entry, repeat appointments are automatically escalated, and configurable reports are generated for management. As Officer-as-a-Service, our external representatives take on the training duties for your employees with a response time of 2 working days, including an appointment certificate and an audit-proof reporting line to management.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles