Reading time: 11 minutes
A guide to building a multi-standard training record without duplicating work

A training non-conformity rarely means training is missing. It usually means the evidence that it exists is spread across several partial records, none of which fully answers what the auditor is asking.
Third audit of the year. The same person opens the same shared folder again, looks up the same courses for the same workers and reorders them into a different format, because the quality auditor doesn't ask the way the safety technician does, and neither of them asks the way the health inspector does.
None of that means people aren't trained. It means the evidence that they are lives scattered across systems that don't talk to each other. And in an audit, scattered evidence behaves exactly like evidence that doesn't exist.
We're going to lay out what each standard actually requires on training, where they overlap (far more than it seems), where they genuinely diverge, and how to build a single training record that works for all of them: one multi-standard record that answers any audit without duplicating work.
We call this Evidence Fragmentation: an organization delivers one training session, and that single fact generates several partial records, one per standard that requires it, with none of them holding the complete picture. The manual handling course exists in the safety file, gets mentioned in the quality plan, and appears nowhere when the client audits the plant.
This isn't sloppiness. It's the predictable result of three reasonable decisions taken at different moments.
Quality certification is usually the oldest. Occupational safety came later, with its own consultant and its own folder structure. Food safety or information security arrived later still, under yet another owner. Each one built its own record system without touching the previous one, because touching it would have put a working certification at risk.
Quality sits with the management systems lead. Safety sits with the prevention service or the in-house technician. Food safety sits with the HACCP lead. Training sits with HR. Four people recording the same fact against different criteria, who rarely compare files except when an audit forces them to.
This is the underlying design flaw. Almost every system stores "who took course X". But no standard asks that. Standards ask about the person, the risk or the activity, and rebuilding that answer from a course list means manual cross-referencing every single time.
Placed side by side, the requirements look far more alike than their separate folders suggest. All of them ask for the same thing underneath: that the company knows what each person needs to know, can demonstrate it taught them, and keeps documented proof of it.
| Standard | What it requires on training | What you need to be able to demonstrate | Where the record usually fails |
|---|---|---|---|
| ISO 9001:2015 (clauses 7.2 and 7.5) | Determine the competence needed, ensure it, act when it's missing and evaluate the effectiveness of the action | Documented information serving as evidence of competence⁴ | There's an attendance record, but no proof the action worked |
| ISO 45001:2018 (clauses 7.2 and 7.3) | Competence to identify hazards, plus awareness of policy, job risks and the right to remove oneself from danger⁵ | Documented information on competence and awareness actions | Awareness leaves no documentary trace: it's assumed |
| ISO 14001:2015 (clauses 7.2 and 7.3) | Competence of anyone doing work with environmental impact, and awareness of applicable legal requirements | Documented information equivalent to the quality record | Only environmental staff are covered, not operations |
| ISO/IEC 27001:2022 (clause 7.2 and control A.6.3) | Awareness and periodic training on information security policies and procedures | Record of the actions and of their updates |
The important reading of this table isn't in the differences. It's in the right-hand column. The failures repeat. And they repeat because they're the same failure seen from seven angles: the record stores that the training happened, not that it produced the effect the standard asks for.
Clause 7.2 of ISO 9001 contains a phrase that decides a lot of audits. It doesn't only ask you to take action to acquire the necessary competence: it asks you to evaluate the effectiveness of the actions taken.⁴ ISO 45001 and ISO 14001 repeat the same requirement with the same structure.
An attendance certificate evaluates nothing. It proves someone was there. A signature sheet doesn't either, and a 100% completion rate in the LMS only proves the button was clicked.
A concrete example of what does work. A plant changes its lockout procedure and trains the 40 operators on shift. Three weeks later, the line supervisor observes two real executions per operator against a four-point checklist and logs the result. That record, with a date, an observer and an outcome, is evidence of effectiveness. It doesn't need more ceremony: it needs to exist and to be attached to the same file as the course.
When it's missing, the auditor doesn't conclude that the training was bad. They conclude the organization can't demonstrate it worked, which for conformity purposes amounts to the same thing. We break this down block by block in our ISO 45001 digital audit checklist.
A single training record can answer all seven standards in the table above if it carries these fields. None is optional, and the last two are the ones that are almost never there.
| Field | What it must contain | Which standard demands it most |
|---|---|---|
| 1. Person and role on the date | Worker identification and the role held that day, not the current one | Occupational safety law, ISO 9001 |
| 2. Content and version | What exactly was taught, with the material's version number | ISO 9001, 852/2004 |
| 3. Date and duration | When and for how long, inside or outside working hours | Occupational safety law |
| 4. Who delivered it and their qualification | Internal or external trainer, and why they're qualified | 852/2004, occupational safety law |
| 5. Proof of receipt | That this specific person received this specific content | All of them |
| 6. Evidence of effectiveness | Proof the person can apply it, not just that they saw it | ISO 9001, 45001, 14001 |
| 7. Expiry or triggering event | Deadline or change that invalidates the previous training |
Evidence of effectiveness is proof that the person can apply what they learned, and it doesn't have to be an exam. It can be an on-the-job observation signed by the supervisor, a resolved case study, a performance check or a drill log. What makes it valid is that it comes after the training, that it's dated, and that it assesses the expected behaviour rather than recall of the content.
It's worth being honest about the cost: this is the most expensive field to maintain, which is exactly why it's missing. It's also the only one that separates a training archive from evidence of competence, and the first thing an experienced auditor looks for.
The expiry of a training session is rarely a date. In occupational safety, the law talks about changes in duties, technologies or work equipment.¹ In food safety, about a change in the handler's activity. In the AI Act, about a change in the system being used.
That means the record needs a link to the fact that invalidates it. If the procedure changes in March and the training file doesn't change state, by September nobody will know who was trained on the old version. Deciding who has to be retrained when a procedure changes is a separate conversation, but the operational answer always starts in this field: without it, the question has no data to answer with.
Here's the real difference between the standards, and it isn't the one people usually assume. They don't ask for different things. They ask from different units.
A record organized by course answers none of the four without manual work. A record organized around the combination of person × content version × date answers all four by reading the same table down different columns. That's the whole difference between preparing an audit in three weeks and answering one in an afternoon.
Structuring the information this way (something learning systems like Vidext generate by default when every piece of content is versioned) doesn't require switching tools to get started. It requires changing the axis of the archive.
Nobody is going to reconstruct ten years of records. Nor do they need to.
Pick a date, usually the start of the financial year. From there, every new record enters with all seven fields. Everything before stays as it is and gets flagged as historical. No auditor demands retroactivity; they demand control from the point the system claims to have it.
Without a version number on the training material, the rest of the record doesn't hold, because there's no way to know what each person learned. Numbering the versions you already have is the least glamorous task in the process and the one that prevents the most trouble later.
A two-column table, content and standards affected, built once and maintained as new material is added. It's what lets a single recorded session serve quality, safety and health inspections at the same time without duplicating it.
One owner for the training file, with the other functions contributing content. Evidence Fragmentation regenerates on its own as long as there are four owners, however well intentioned they are.
Companies that sail through audits don't have more training than everyone else. They have the same information organized in a way that accepts several different questions.
Changing the axis of the archive, from course to person and version, doesn't cost a certification or a six-month project. It costs a decision about how you store what you're already doing. You can see it set up in a demo if you want a visual reference, but the decision comes before any tool.
In the end, an audit doesn't measure what an organization taught. It measures what the organization can demonstrate. And that gets decided long before the auditor knocks on the door.
Yes, as long as it includes the evidence of effectiveness required by ISO 9001 clause 7.2 and the link to the change in duties or equipment required by article 19 of Spanish Law 31/1995.¹ A record that only proves attendance falls short for both.
Not as an officially approved document. Royal Decree 109/2010 expressly repealed Royal Decree 202/2000, which regulated the prior authorization of training bodies.³ The obligation to train didn't disappear: it moved to the food business, which must document it before official control in whatever format it chooses.²
Anything that comes after the training, is dated, and assesses application rather than recall. An on-the-job observation with a checklist, a resolved case study, a performance check or a drill log all work. An attendance certificate doesn't.
Yes. Article 4 of Regulation (EU) 2024/1689 also applies to organizations that merely use AI systems, and requires literacy proportionate to the role and context of use.⁶ The seven questions worth being able to answer are in our AI Act checklist for training leads.
In practice, none. You set a cut-off date, flag everything before it as historical, and apply the full format from there. What an auditor values is that the system has been under control since the organization says it has.
A single function, usually HR or the management systems lead, with quality, safety and operations contributing content and criteria. Shared ownership is the most common reason records stop reconciling with each other.
With the record in order, preparation stops being a documentary reconstruction. If the date is already on top of you, the order of priorities is in our guide on how to prepare teams for an internal audit.
¹ Ley 31/1995, de 8 de noviembre, de prevención de Riesgos Laborales, article 19 - BOE ² Manipuladores de alimentos: situación actual, reproducing Chapter XII of Annex II of Regulation (EC) 852/2004 - Consejería de Salud, Junta de Andalucía ³ Real Decreto 109/2010, de 5 de febrero, sole repealing provision - BOE ⁴ ISO 9001:2015, Quality management systems - International Organization for Standardization ⁵ ISO 45001:2018, Occupational health and safety management systems - International Organization for Standardization ⁶ Regulation (EU) 2024/1689, European Artificial Intelligence Act, article 4 - EUR-Lex
| The initial induction is recorded, later refreshes are not |
| Spanish Law 31/1995, art. 19 (occupational risk prevention) | Theoretical and practical training, sufficient and appropriate, on hiring and when duties, technologies or work equipment change¹ | Proof of training delivered within working hours and at no cost to the worker | The change that triggered it isn't recorded, only the initial session |
| Regulation (EC) 852/2004, Annex II, Ch. XII | Supervision and instruction or training of food handlers appropriate to their work activity, plus specific training for HACCP owners² | Documentary accreditation before official control, in any format² | A generic certificate is kept that doesn't match the actual job |
| Regulation (EU) 2024/1689, art. 4 (AI Act) | AI literacy proportionate to the role, the context of use and the specific system being used⁶ | The regulation prescribes no record format: it requires measures. In practice you demonstrate it through the link between person, system used and training received | There's no inventory of who uses which tool |
| Law 31/1995 art. 19, AI Act |
Programme to promote permanent employment of qualified young people within the framework of the National Youth Guarantee System. A grant under the above programme has been received from LABORA (Valencian Employment and Training Service) for the permanent hiring in 2024 of qualified young person(s) registered in the National Youth Guarantee System, an action eligible for co-financing by the European Social Fund Plus (ESF+) 2021-2027 or any other European Union fund. Expediente ECOGJU/2024/550/46.


