Field Guide

Which Regulations Actually Require Compliance Training? A Cross-Regime Map

The short version

A compliance training obligation is a requirement that an organization deliver defined instruction to defined personnel, and the obligations across regulated regimes differ in the legal weight that stands behind them. A survey across more than 40 regulated domains found a dedicated training obligation in nearly every one. Those obligations fall into four classes: binding federal or EU regulation using "shall" or "must"; examiner or supervisory guidance using "should"; a private contractual standard rather than a government rule; and regimes with no discrete training clause at all, where the training that exists is best-practice gap-fill. The class an obligation falls into determines what a defensible program has to evidence and what a regulator can cite as the basis for a finding.

A compliance training obligation is the requirement, imposed by a statute, a regulation, a supervisory framework, or a private standard, that an organization deliver defined instruction to defined personnel and retain evidence that the instruction was delivered. The word "required" covers several distinct legal postures, and a program built as though every regime's training obligation carried identical weight will over-invest against some obligations and under-document against others.

This guide maps compliance training obligations across thirteen regimes documented in enough depth to cite: BSA/AML, money transmission, OFAC sanctions, broker-dealer conduct, HIPAA, the EU's DORA and AI Act, GDPR, PCI-DSS, anti-corruption, OSHA, the Corporate Transparency Act's beneficial ownership rule, Australia's AML/CTF regime, and the CFPB's Section 1033 open banking rule. Each entry records the obligation, the citation, and the class of legal weight behind it.

Classes of legal weight behind a training obligation

Every training requirement in the table below falls into one of four classes:

Conflating the four classes produces error in two directions: a binding requirement treated as optional on the assumption that it was guidance, and a best-practice choice described internally as a legal requirement that no citation supports.

The cross-regime map

The table records thirteen regimes, the training obligation each imposes, the citation, and the class of legal weight behind it.

RegimeTraining obligationCitationClass
BSA/AMLAppropriate personnel receive training that is current, role-tailored, and recurring, with completion tracked.31 CFR 1020.210(b)(4); FFIEC BSA/AML Examination ManualBinding regulation
Money transmissionLicensee must maintain an agent training program.CSBS Money Transmission Modernization Act §301; 31 CFR 1022.210Binding regulation
OFAC sanctionsTraining program adequate to the institution's own OFAC risk assessment, delivered at least annually.OFAC Framework for Compliance Commitments (2019), Component ESupervisory guidance
Broker-dealersAssociated persons and their supervisors are trained on Reg BI's care and conflict obligations.Reg BI, 17 CFR 240.15l-1(a)(2)(iv); FINRA Rule 3110(a)(6)-(7)Binding regulation
HIPAASecurity awareness training and workforce training on privacy policies and procedures.45 CFR 164.308(a)(5); 45 CFR 164.530(b)Binding regulation
EU DORACompulsory ICT risk management training modules for all staff, including senior management, on a defined cadence.Regulation (EU) 2022/2554, Article 13Binding regulation
EU AI ActAI literacy for staff dealing with AI systems, plus training for human overseers of high-risk systems.Article 4 (AI literacy); Article 26 (oversight training)Binding regulation
GDPRData protection officer's duty includes monitoring and supporting staff awareness and training.Article 39(1)(b)Binding regulation
PCI-DSSFormal security awareness program for all personnel, plus secure-coding training for developers.Requirement 12.6; Requirement 6.2.2Contractual standard
Anti-corruptionRisk-based anti-corruption training as evidence of an adequate compliance program.FCPA Resource Guide, Hallmark 5; UK Bribery Act Guidance, Principle 5Supervisory / prosecutorial guidance
OSHATraining on lockout/tagout, personal protective equipment, and hazard communication.29 CFR 1910.147(c)(7); 1910.132(f); 1910.1200(h)Binding regulation
Corporate Transparency Act (BOI)Training for personnel with access to beneficial ownership information on safeguarding obligations.31 CFR 1010.955(d)(1)Binding regulation
Australia AML/CTFRisk-awareness training program covering employees' AML/CTF obligations.AML/CTF Rules, Chapter 8.2; AML/CTF Act s.26F(4)Binding regulation
CFPB Section 1033 (open banking)No discrete training clause in the rule itself. Any training is a program's own risk-reduction choice.12 CFR Part 1033No statutory mandate

The class column governs how each row is used. Ten of the thirteen regimes above carry a binding clause. Two rest on guidance that examiners enforce in practice but that a regulator cannot cite as a standalone statutory violation. One rests on a card-brand contract. Section 1033 carries no training clause of any kind.

Regimes with no statutory training mandate

Section 1033 is one instance of a broader condition in which a rule contains no training clause. A compliance function that trains staff on such a rule is exercising its own judgment about risk reduction; describing that training as legally required misstates its basis. The accurate framing is that the training fills a gap the rule left open, built on the program's assessment of the underlying risk the rule is directed at.

The distinction has documentary consequences. An examiner or auditor who identifies a program citing a nonexistent legal requirement has grounds to test whether other parts of the program's documentation are aspirational rather than accurate. A program that records "no statutory mandate; training delivered as a chosen control" states its basis accurately. Precision about what is required and what is chosen is itself an indicator of program maturity.

The common spine

Separated from their citations, the thirteen obligations above reduce to the same four elements. Every training requirement in this map, binding or guidance or contract, asks a program to evidence four things:

Every regime in the table above is a variation on these four, differing mainly in how prescriptive the citation gets about content and cadence, and in how much legal weight backs the requirement. A program built around this spine, then adapted per regime with the correct citation attached to each piece, scales across regulatory obligations without reinventing the training model each time a new regime enters scope.

Application to a multi-regime program

Organizations past a certain size operate under more than one regime. A fintech with a money transmission license, a bank partnership, and a consumer product touches BSA/AML, sanctions, and in some structures Reg BI or state consumer protection rules within the same org chart. A healthcare payments company touches HIPAA and PCI-DSS at once. Building a separate training program per regime produces duplicated content, inconsistent recordkeeping, and no single place to answer the question an examiner or auditor puts: who was trained on what, and which rule required it.

The better structure is one training function with a per-regime obligation table behind it, each row carrying its own citation and its own class. That table is what lets the program answer the binding-versus-guidance-versus-contract question honestly when it matters, and it is what keeps a program from either under-investing in a binding requirement it mistook for guidance, or overselling a best-practice choice as a legal mandate it never was.

Common questions

Is compliance training legally required in every regulated industry?
Not in the same way everywhere. A survey across more than 40 regulated domains found a dedicated training obligation in nearly every one, but the legal weight behind that obligation varies. Some sit in binding statute or regulation. Some sit in examiner or supervisory guidance that carries real consequences without being codified as law. Some sit in a private contractual standard rather than government regulation. And a few regimes have no explicit training mandate at all, where the training that exists is best-practice gap-fill rather than a legal requirement.
What is the difference between a binding training mandate and examiner guidance?
A binding mandate sits in a statute or regulation, using language like "shall" or "must," and a regulator can cite the provision directly as the basis for an enforcement action or a finding. Examiner or supervisory guidance describes what an examiner will look for and typically uses language like "should," without a discrete statutory training clause behind it. Guidance still drives findings in practice, because examiners test against it, but the legal basis for a citation is different, and a program can argue proportionality against guidance in a way it cannot against a binding rule.
Does PCI-DSS legally require security awareness training?
PCI-DSS Requirements 12.6 and 6.2.2 require a security awareness program and secure-coding training, but PCI-DSS is a private industry standard maintained by the payment card brands and enforced through merchant and processor contracts, not a government regulation. The obligation is real and it is audited, but it is contractual rather than statutory, which matters for how a program frames its legal basis and where the training requirement can be renegotiated or waived.
What happens when a regulation has no explicit training mandate?
Some regimes, including the CFPB's Section 1033 open banking rule, contain no discrete clause requiring staff training. In those cases the training a mature program runs is best-practice gap-fill: built to reduce the underlying risk the rule is meant to control, not because a specific citation demands it. That training is still worth doing, but a program should describe it honestly as a chosen control rather than dress it up as a statutory requirement that does not exist.
Which regulations have the strictest training mandates?
The EU's DORA regulation is among the most explicit: Article 13 requires compulsory ICT-risk training modules for all staff, including senior management, on a defined cadence. HIPAA, OSHA, the EU AI Act, and Reg BI for broker-dealers are also binding regulations with clear training clauses rather than general expectations. BSA/AML training is binding under 31 CFR 1020.210(b)(4), though the regulation itself is principles-based rather than prescriptive about content and cadence.
How should a company with multiple regulatory regimes structure training?
One training function, supported by a per-regime obligation table that tags each requirement with its citation and its legal class: binding regulation, examiner guidance, contractual standard, or best-practice gap-fill. Every regime's obligation reduces to the same four elements, training the right people, on relevant content, on a recurring cadence, with a record. Standardizing on that spine lets one program serve many regimes without a separate training model for each, while preserving the ability to show an examiner which citation backs which piece of the program.
About this library

This reference library is maintained by Rupture Labs, the company behind Compliance Command Center, compliance software built and reviewed by practitioners. Contact.

Primary sources

The authoritative texts this guide is grounded in. Government and standard-setter sites may block automated access but resolve in a browser.