Training Records System Input


FieldValue
Version1.0
Effective DateApril 2026
Review CycleAnnual
Document OwnerChief Information Security Officer (CISO)
ClassificationCONFIDENTIAL — Internal Use Only
Applicable StandardSOC 2 Type II — Security, Availability, Confidentiality

1. Purpose and Scope

This document establishes the training programme framework for QA Touch employees, contractors, and relevant customer-facing personnel involved in data entry, system input processing, and input control oversight. It provides SOC 2 auditors with evidence that personnel are adequately trained on input controls to support Processing Integrity criteria (PI1) and Personnel Controls (CC1.4).

2. Training Programme — Module Reference

Module ID / TitleDescriptionTarget AudienceFrequency
TRN-01 │ QA Touch Platform OnboardingNavigation, creating projects/test cases/runs/defects, understanding roles and workspace structure.All new users (internal and customer teams)Once at onboarding
TRN-02 │ Data Entry Standards and QualityField requirements, validation rules, mandatory vs optional fields, import template usage, error resolution.QA engineers, support staff, data entry personnelAnnually + on material change
TRN-03 │ Import and Export ProceduresPreparing import files, running imports, interpreting error reports, exporting data in supported formats.All users with import/export permissionAnnually
TRN-04 │ REST API Usage and Input ControlsAPI authentication (API keys, OAuth), request formatting, validation error handling, rate limit management, idempotency.Engineering and integration teamsAnnually + on API version change
TRN-05 │ Security Awareness — Input ControlsSocial engineering, phishing, SQL injection awareness, secure handling of test data, password hygiene.All employees and contractorsAnnually (mandatory)
TRN-06 │ Secure Coding — Input Validation (Engineering)Implementing server-side validation, parameterised queries, file upload controls, XSS/CSRF mitigations in code.All software engineersAt onboarding; annually
TRN-07 │ AI Feature Data HandlingWhat data is transmitted to AI providers, appropriate use of AI generation, handling sensitive prompt content, opt-out procedures.All users with AI feature accessOn AI feature launch; annually
TRN-08 │ Integration Configuration and Data FlowsConfiguring Jira, Azure DevOps, GitHub, and other integrations; field mapping; understanding synced data flows and failure modes.Admins configuring integrationsOn integration setup; annually
TRN-09 │ Privacy and Data HandlingGDPR/CCPA basics, data minimisation, handling Data Subject Requests, reporting suspected breaches.All employeesAnnually (mandatory)

3. Training Delivery Methods

  • Online self-paced modules hosted on QA Touch’s Learning Management System (LMS) [VERIFY platform] with automated completion tracking.
  • Virtual instructor-led sessions (vILT) for complex or security-sensitive topics.
  • In-app guided tours and contextual help tooltips for platform onboarding.
  • Annual refresher modules delivered through the LMS; completion tracked automatically.
  • Knowledge checks / spot quizzes embedded in online modules; minimum passing score of 80% required; one re-attempt permitted before escalation.

4. Training Record Fields

The following fields must be captured and retained for every training completion event:

FieldExample ValueNotes
Employee Full NameJane SmithLegal name per HR records
Employee IDEMP-00234Unique HR system identifier
Job Title / DepartmentSenior QA Engineer / Platform Team
Module ID and TitleTRN-02 │ Data Entry Standards and QualityAs listed in Section 2
Module Versionv1.3Version of training content completed
Completion Date2025-03-15ISO 8601 format
Delivery MethodOnline — LMSOnline / Virtual ILT / In-Person
Assessment Score88%N/A if no assessment associated with module
Pass / FailPassThreshold: 80%
Acknowledgement / AttestationElectronically signed via LMSConfirms employee read and understood associated policies
Next Due Date2026-03-15Annual recurrence date
Remedial Action (if failed)Re-attempt scheduled; manager notifiedApplicable if first attempt failed

ASSUMPTION: Training records are retained for a minimum of 3 years in the LMS or HR system and are available for SOC 2 auditor inspection upon request.

5. Non-Compliance and Escalation Procedure

TriggerActionResponsible Party
Training past due by 1–7 daysAutomated LMS reminder email to employee.LMS (automated)
Training past due by 8–14 daysEscalation email to line manager; employee flagged in compliance dashboard.LMS (automated) + HR
Training past due by 15+ daysHR formal notification; CISO review of access suspension need.HR + CISO
Assessment failed twiceMandatory one-to-one coaching session scheduled; third attempt permitted after coaching.Line manager + HR
Willful non-complianceHR disciplinary process initiated per Disciplinary Policy.HR + CISO

6. Training Reporting

  • Training completion rates reported to senior management and the CISO on a quarterly basis.
  • Annual training completion evidence package prepared for SOC 2 audit, including completion rates by department and module.