Training Records System Input
| Field | Value |
|---|---|
| Version | 1.0 |
| Effective Date | April 2026 |
| Review Cycle | Annual |
| Document Owner | Chief Information Security Officer (CISO) |
| Classification | CONFIDENTIAL — Internal Use Only |
| Applicable Standard | SOC 2 Type II — Security, Availability, Confidentiality |
1. Purpose and Scope
This document establishes the training programme framework for QA Touch employees, contractors, and relevant customer-facing personnel involved in data entry, system input processing, and input control oversight. It provides SOC 2 auditors with evidence that personnel are adequately trained on input controls to support Processing Integrity criteria (PI1) and Personnel Controls (CC1.4).
2. Training Programme — Module Reference
| Module ID / Title | Description | Target Audience | Frequency |
|---|---|---|---|
| TRN-01 │ QA Touch Platform Onboarding | Navigation, creating projects/test cases/runs/defects, understanding roles and workspace structure. | All new users (internal and customer teams) | Once at onboarding |
| TRN-02 │ Data Entry Standards and Quality | Field requirements, validation rules, mandatory vs optional fields, import template usage, error resolution. | QA engineers, support staff, data entry personnel | Annually + on material change |
| TRN-03 │ Import and Export Procedures | Preparing import files, running imports, interpreting error reports, exporting data in supported formats. | All users with import/export permission | Annually |
| TRN-04 │ REST API Usage and Input Controls | API authentication (API keys, OAuth), request formatting, validation error handling, rate limit management, idempotency. | Engineering and integration teams | Annually + on API version change |
| TRN-05 │ Security Awareness — Input Controls | Social engineering, phishing, SQL injection awareness, secure handling of test data, password hygiene. | All employees and contractors | Annually (mandatory) |
| TRN-06 │ Secure Coding — Input Validation (Engineering) | Implementing server-side validation, parameterised queries, file upload controls, XSS/CSRF mitigations in code. | All software engineers | At onboarding; annually |
| TRN-07 │ AI Feature Data Handling | What data is transmitted to AI providers, appropriate use of AI generation, handling sensitive prompt content, opt-out procedures. | All users with AI feature access | On AI feature launch; annually |
| TRN-08 │ Integration Configuration and Data Flows | Configuring Jira, Azure DevOps, GitHub, and other integrations; field mapping; understanding synced data flows and failure modes. | Admins configuring integrations | On integration setup; annually |
| TRN-09 │ Privacy and Data Handling | GDPR/CCPA basics, data minimisation, handling Data Subject Requests, reporting suspected breaches. | All employees | Annually (mandatory) |
3. Training Delivery Methods
- Online self-paced modules hosted on QA Touch’s Learning Management System (LMS) [VERIFY platform] with automated completion tracking.
- Virtual instructor-led sessions (vILT) for complex or security-sensitive topics.
- In-app guided tours and contextual help tooltips for platform onboarding.
- Annual refresher modules delivered through the LMS; completion tracked automatically.
- Knowledge checks / spot quizzes embedded in online modules; minimum passing score of 80% required; one re-attempt permitted before escalation.
4. Training Record Fields
The following fields must be captured and retained for every training completion event:
| Field | Example Value | Notes |
|---|---|---|
| Employee Full Name | Jane Smith | Legal name per HR records |
| Employee ID | EMP-00234 | Unique HR system identifier |
| Job Title / Department | Senior QA Engineer / Platform Team | |
| Module ID and Title | TRN-02 │ Data Entry Standards and Quality | As listed in Section 2 |
| Module Version | v1.3 | Version of training content completed |
| Completion Date | 2025-03-15 | ISO 8601 format |
| Delivery Method | Online — LMS | Online / Virtual ILT / In-Person |
| Assessment Score | 88% | N/A if no assessment associated with module |
| Pass / Fail | Pass | Threshold: 80% |
| Acknowledgement / Attestation | Electronically signed via LMS | Confirms employee read and understood associated policies |
| Next Due Date | 2026-03-15 | Annual recurrence date |
| Remedial Action (if failed) | Re-attempt scheduled; manager notified | Applicable if first attempt failed |
ASSUMPTION: Training records are retained for a minimum of 3 years in the LMS or HR system and are available for SOC 2 auditor inspection upon request.
5. Non-Compliance and Escalation Procedure
| Trigger | Action | Responsible Party |
|---|---|---|
| Training past due by 1–7 days | Automated LMS reminder email to employee. | LMS (automated) |
| Training past due by 8–14 days | Escalation email to line manager; employee flagged in compliance dashboard. | LMS (automated) + HR |
| Training past due by 15+ days | HR formal notification; CISO review of access suspension need. | HR + CISO |
| Assessment failed twice | Mandatory one-to-one coaching session scheduled; third attempt permitted after coaching. | Line manager + HR |
| Willful non-compliance | HR disciplinary process initiated per Disciplinary Policy. | HR + CISO |
6. Training Reporting
- Training completion rates reported to senior management and the CISO on a quarterly basis.
- Annual training completion evidence package prepared for SOC 2 audit, including completion rates by department and module.