A compliance training obligation is a requirement that an organization deliver defined instruction to defined personnel, and the obligations across regulated regimes differ in the legal weight that stands behind them. A survey across more than 40 regulated domains found a dedicated training obligation in nearly every one. Those obligations fall into four classes: binding federal or EU regulation using "shall" or "must"; examiner or supervisory guidance using "should"; a private contractual standard rather than a government rule; and regimes with no discrete training clause at all, where the training that exists is best-practice gap-fill. The class an obligation falls into determines what a defensible program has to evidence and what a regulator can cite as the basis for a finding.
A compliance training obligation is the requirement, imposed by a statute, a regulation, a supervisory framework, or a private standard, that an organization deliver defined instruction to defined personnel and retain evidence that the instruction was delivered. The word "required" covers several distinct legal postures, and a program built as though every regime's training obligation carried identical weight will over-invest against some obligations and under-document against others.
This guide maps compliance training obligations across thirteen regimes documented in enough depth to cite: BSA/AML, money transmission, OFAC sanctions, broker-dealer conduct, HIPAA, the EU's DORA and AI Act, GDPR, PCI-DSS, anti-corruption, OSHA, the Corporate Transparency Act's beneficial ownership rule, Australia's AML/CTF regime, and the CFPB's Section 1033 open banking rule. Each entry records the obligation, the citation, and the class of legal weight behind it.
Classes of legal weight behind a training obligation
Every training requirement in the table below falls into one of four classes:
- Binding regulation. Language in a statute or regulation itself, using "shall" or "must," that a regulator can cite directly as the basis for a finding or an enforcement action. This class carries the greatest legal weight, and the obligation is not open to a proportionality argument that the training was optional.
- Examiner or supervisory guidance. No standalone statutory training clause, but a supervisory framework or examination manual that describes what examiners look for, typically in "should" language. Guidance produces findings in practice because examiners test against it, though the legal basis for a citation is weaker and a program retains room to argue proportionality.
- Industry or contractual standard. A requirement set by a private standard-setter and enforced through contract rather than government regulation. The obligation is real and audited, but its legal basis runs through a merchant agreement, not a statute.
- No statutory mandate. A regime with no discrete training clause anywhere in the rule. Programs that train anyway are filling a gap the regulator left open, on their own judgment about what reduces risk.
Conflating the four classes produces error in two directions: a binding requirement treated as optional on the assumption that it was guidance, and a best-practice choice described internally as a legal requirement that no citation supports.
The cross-regime map
The table records thirteen regimes, the training obligation each imposes, the citation, and the class of legal weight behind it.
| Regime | Training obligation | Citation | Class |
|---|---|---|---|
| BSA/AML | Appropriate personnel receive training that is current, role-tailored, and recurring, with completion tracked. | 31 CFR 1020.210(b)(4); FFIEC BSA/AML Examination Manual | Binding regulation |
| Money transmission | Licensee must maintain an agent training program. | CSBS Money Transmission Modernization Act §301; 31 CFR 1022.210 | Binding regulation |
| OFAC sanctions | Training program adequate to the institution's own OFAC risk assessment, delivered at least annually. | OFAC Framework for Compliance Commitments (2019), Component E | Supervisory guidance |
| Broker-dealers | Associated persons and their supervisors are trained on Reg BI's care and conflict obligations. | Reg BI, 17 CFR 240.15l-1(a)(2)(iv); FINRA Rule 3110(a)(6)-(7) | Binding regulation |
| HIPAA | Security awareness training and workforce training on privacy policies and procedures. | 45 CFR 164.308(a)(5); 45 CFR 164.530(b) | Binding regulation |
| EU DORA | Compulsory ICT risk management training modules for all staff, including senior management, on a defined cadence. | Regulation (EU) 2022/2554, Article 13 | Binding regulation |
| EU AI Act | AI literacy for staff dealing with AI systems, plus training for human overseers of high-risk systems. | Article 4 (AI literacy); Article 26 (oversight training) | Binding regulation |
| GDPR | Data protection officer's duty includes monitoring and supporting staff awareness and training. | Article 39(1)(b) | Binding regulation |
| PCI-DSS | Formal security awareness program for all personnel, plus secure-coding training for developers. | Requirement 12.6; Requirement 6.2.2 | Contractual standard |
| Anti-corruption | Risk-based anti-corruption training as evidence of an adequate compliance program. | FCPA Resource Guide, Hallmark 5; UK Bribery Act Guidance, Principle 5 | Supervisory / prosecutorial guidance |
| OSHA | Training on lockout/tagout, personal protective equipment, and hazard communication. | 29 CFR 1910.147(c)(7); 1910.132(f); 1910.1200(h) | Binding regulation |
| Corporate Transparency Act (BOI) | Training for personnel with access to beneficial ownership information on safeguarding obligations. | 31 CFR 1010.955(d)(1) | Binding regulation |
| Australia AML/CTF | Risk-awareness training program covering employees' AML/CTF obligations. | AML/CTF Rules, Chapter 8.2; AML/CTF Act s.26F(4) | Binding regulation |
| CFPB Section 1033 (open banking) | No discrete training clause in the rule itself. Any training is a program's own risk-reduction choice. | 12 CFR Part 1033 | No statutory mandate |
The class column governs how each row is used. Ten of the thirteen regimes above carry a binding clause. Two rest on guidance that examiners enforce in practice but that a regulator cannot cite as a standalone statutory violation. One rests on a card-brand contract. Section 1033 carries no training clause of any kind.
Regimes with no statutory training mandate
Section 1033 is one instance of a broader condition in which a rule contains no training clause. A compliance function that trains staff on such a rule is exercising its own judgment about risk reduction; describing that training as legally required misstates its basis. The accurate framing is that the training fills a gap the rule left open, built on the program's assessment of the underlying risk the rule is directed at.
The distinction has documentary consequences. An examiner or auditor who identifies a program citing a nonexistent legal requirement has grounds to test whether other parts of the program's documentation are aspirational rather than accurate. A program that records "no statutory mandate; training delivered as a chosen control" states its basis accurately. Precision about what is required and what is chosen is itself an indicator of program maturity.
The common spine
Separated from their citations, the thirteen obligations above reduce to the same four elements. Every training requirement in this map, binding or guidance or contract, asks a program to evidence four things:
- Right people. Training reaches the roles that actually touch the obligation, scoped by what each role does rather than delivered as one generic module to everyone.
- Relevant content. The material covers the institution's own policies and procedures and the regulatory obligations and red flags that role is positioned to encounter, not a generic overview of the topic.
- Recurring. Training runs on a defined cadence, at minimum annually for most regimes, plus on onboarding and whenever a material change hits, a new product, a new rule, a new risk.
- Recorded. Completion is tracked by person, by course, by date, with the content that was actually delivered retained, so the program can prove training happened rather than merely assert it.
Every regime in the table above is a variation on these four, differing mainly in how prescriptive the citation gets about content and cadence, and in how much legal weight backs the requirement. A program built around this spine, then adapted per regime with the correct citation attached to each piece, scales across regulatory obligations without reinventing the training model each time a new regime enters scope.
Application to a multi-regime program
Organizations past a certain size operate under more than one regime. A fintech with a money transmission license, a bank partnership, and a consumer product touches BSA/AML, sanctions, and in some structures Reg BI or state consumer protection rules within the same org chart. A healthcare payments company touches HIPAA and PCI-DSS at once. Building a separate training program per regime produces duplicated content, inconsistent recordkeeping, and no single place to answer the question an examiner or auditor puts: who was trained on what, and which rule required it.
The better structure is one training function with a per-regime obligation table behind it, each row carrying its own citation and its own class. That table is what lets the program answer the binding-versus-guidance-versus-contract question honestly when it matters, and it is what keeps a program from either under-investing in a binding requirement it mistook for guidance, or overselling a best-practice choice as a legal mandate it never was.