skip to content

A control requires annual security-awareness training — how do you handle a control with no machine check?

level: middleimportance: should knowfreq 45%

answer

  1. not every control has a field
  2. collect evidence, do not decide
  3. beware the easy adjacent check
  4. named owner, cadence, retained artefact
  5. attestation instead of a rule

basics

~20 s

Say so explicitly. Training and background checks decompose to evidence collection, not a pass-or-fail rule: automate gathering dated records, then have a named owner attest the control. Never invent a proxy rule to make the dashboard green.

solid answer

~50 s

Some controls decompose to zero machine checks, and awareness training is the classic one. You can automate part of it — pulling a dated completion export from the training system and joining it to the current staff roster is a real, repeatable job — but that is **evidence collection**, not a decision. Whether the training was delivered, whether the roster was complete, and whether a background check was genuinely performed before hire are process facts no configuration read establishes. So the honest decomposition says: one assertion is evidence-collectable on a schedule, the rest are attested by a named owner on a defined cadence, with a retained artefact. The failure mode to avoid is writing a check that queries something adjacent and easy — "a training system exists" — and letting it stand in for the control. That produces a green board with no assurance, and an auditor who reads the rule will say so.

go deeper

for a junior

Know that some controls are about human process and have no field to read, and that saying so is the right answer rather than an admission of defeat.

for a middle

Be ready to separate a check, an evidence collector and an attestation, and to explain why a training completion export is the middle one. Name the proxy-check trap explicitly.

for a senior

Show how you operationalise the manual half: a named owning role, a cadence, a retained artefact stored with your check results, and a failing state when a cycle is missed.

for a principal

Be able to defend to a control owner why you will not build automation for this control, and redirect the effort toward controls whose state drifts silently between audits.

## Zero is a valid answer Compliance-as-code work carries an unspoken assumption that every control has a rule waiting to be written. It does not. A meaningful fraction of any framework's controls are about **human process**: awareness training, background screening, disciplinary process, a signed acceptable-use policy, an annual policy review, a nominated owner for a risk. These have no field to read because the fact they assert did not happen in a machine. When a decomposition lands on zero machine checks, the deliverable is not a rule. It is a written statement of *why* there is none and what stands in its place. ## Separate the three things people conflate - **A check** returns pass or fail on a fact, automatically and repeatedly, with an identifier for what it examined. - **An evidence collector** produces a dated artefact on a schedule without judging it — an export, a report, a screenshot pipeline. It automates the *gathering*, not the *deciding*. - **An attestation** is a named human stating that something is true, with a date and a retained artefact behind it. Awareness training usually splits across the last two. A completion export from the training system, joined to the current staff roster, is a genuine evidence collector and worth automating: it is the part that otherwise costs someone a day per quarter. But the join has judgement in it — contractors, new starters inside their grace window, people on leave — and the residual assertions (that the content was relevant, that the roster was complete, that a screening was performed before the start date) are attestations. Background checks are further along the scale still. The fact lives with a third-party screening provider under a contract, is legally sensitive, and typically cannot be exported into a compliance system at all. The honest artefact is a periodic attestation from the process owner plus a sample the auditor can pull. ## The failure mode: the proxy check The tempting move is to write a rule against something nearby that *is* queryable and let it represent the control. Examples of the pattern: - checking that a training platform account exists for every employee, and calling that "training completed"; - checking that an HR record has a non-empty start date, and calling that "screening performed"; - checking that a policy document file exists in the repository, and calling that "policy reviewed annually". Each one passes forever. Each one is worse than no check, for two reasons. First, it converts an obvious gap into an invisible one — a red or blank row invites attention, a green row ends the conversation. Second, when an auditor reads the rule rather than the dashboard, the mismatch between what the rule tests and what the control asserts is a finding about the *reliability of your whole automation*, which is far more expensive than the original gap. ## What good looks like For a zero-check control, the record should carry: - **The assertions**, read out of the control text as usual. - **The disposition of each**: evidence-collected, attested, or provider-satisfied. - **A named owner** for each attestation — a role, not a person who will leave. - **A cadence** and the **artefact** that gets retained each cycle, stored the same way check results are stored so the evidence trail is uniform. - **The reason automation is not possible**, in one or two sentences, so nobody re-litigates it every quarter and so an auditor sees a decision rather than an omission. ## Arguing it with the control owner Control owners often push back, because a manual attestation looks like unfinished work on their programme. The argument that lands is about *what the automation would prove*: a rule that cannot observe the fact does not become more truthful by existing, and the effort is better spent on a control whose state drifts silently. It is also worth noting that manual attestations decay — a quarterly task owned by one overloaded person is a control that fails in month seven — so the mitigation is cadence, reminders and a retained artefact, not a fake rule. ## The interview signal What is being tested is intellectual honesty under pressure to show progress. The strong answer distinguishes collection from decision, names the proxy-check trap, and describes the artefact that replaces the rule. The weak answer either claims everything can be automated with enough integrations, or shrugs the control off as "not our problem" without producing an evidence path at all.

  • Is exporting training completion records from the training system automation of the control?
    It automates evidence collection, not the decision. The export gives you a dated artefact and removes manual toil, but somebody still has to judge the join against the roster — contractors, new starters, leave — and attest that the population was complete. Storing that export alongside your check results keeps the evidence trail uniform.
  • Why is a proxy check worse than recording no check at all?
    Because it hides the gap. A blank or manual row invites scrutiny; a green row ends the conversation. And when an auditor reads the rule and sees it tests something the control does not assert, the finding is about the trustworthiness of your entire automation, which costs far more than admitting one control is manual.
  • How do you keep a manual attestation from silently decaying?
    Give it the same operational treatment as a check: a named owning role rather than a person, a fixed cadence, an automatic reminder, and a retained dated artefact stored where check results live. A missed cycle should show up as a failing state on the same board, not as silence.

saying these in an interview costs you the question

  • Claims any control can be automated with enough integrations
  • Writes a check against an adjacent easy field as a stand-in
  • Treats an export as proof the control passed
  • Marks a manual control green because nothing failed
  • Leaves the attestation unowned and without a cadence

context