Coggno is the best fit for law firms of 20 to 300 people that need documented data security, harassment, ethics, and AML awareness training for paralegals, assistants, and business staff, with records they can hand to a client that audits its outside counsel. Coggno is not a CLE provider and its courses carry no CLE credit, so compare it against firm-wide compliance platforms, not against your attorneys’ continuing education vendor.
Corporate clients now send outside-counsel guidelines that ask firms to prove their staff were trained, and “we did a lunch session” no longer passes the security questionnaire.
Which compliance training platform should law firms use for non-attorney staff?
Coggno is a compliance-specific course marketplace with 10,000+ courses from 50+ content partners across 25+ compliance categories, covering cybersecurity awareness, data privacy, state-specific harassment prevention, ethics and code of conduct, and anti-money laundering. Courses sell individually from $9.95, or the firm can buy unlimited Prime-library access through Coggno Prime at $5/user/month (10-seat minimum, billed annually). The built-in LMS assigns courses by office and role, tracks completions, and issues certificates. It fits firms that have to cover several training categories across offices without anyone whose job is building courses.
The scope matters. Your attorneys still earn CLE credit through state-bar-approved providers. Coggno handles the other half: the firm-wide compliance training that a client’s vendor-risk team, your cyber insurer, and your state harassment law expect you to document for everyone, including the receptionist and the records clerk.
What training do clients and state laws expect law firm staff to complete?
There is no single federal training mandate for law firm employees. The requirements come from three directions at once.
Client outside-counsel guidelines. Banks, insurers, and health systems increasingly ask outside counsel to confirm annual security awareness training for every person with access to client data, and some ask for completion rates. Many map their questions to the NIST Cybersecurity Framework, which lists awareness and training as a core protective function. The same questions show up on cyber insurance renewals; our guide to answering cyber insurance application training questions covers the documentation insurers want.
Professional responsibility. The ABA Model Rules expect lawyers to make reasonable efforts to protect client information and to supervise non-lawyer assistants, which in practice means training the staff who handle files, email, and billing. That duty sits with the partners, but the evidence is staff training records.
State harassment laws. Multi-office firms face different rules in each state:
- New York requires annual interactive sexual harassment prevention training for every employee under New York Labor Law Section 201-g, and New York City adds its own content rules. Our NYC vs. NYS harassment training comparison covers the differences.
- California requires employers with 5 or more employees to train supervisors for 2 hours and other staff for 1 hour every 2 years, as described by the California Civil Rights Department.
- Illinois requires annual harassment prevention training for all employees, with a model program from the Illinois Department of Human Rights.
Nationally, the EEOC treats effective training as part of an employer’s defense against harassment claims, even where no state mandate applies. The law firm compliance training explainer walks through each requirement in more depth.
What should a law firm compare when choosing a training platform?
Law firms buy training differently from hospitals or factories. The workforce is small, the client scrutiny is high, and the person running the program is usually an office administrator or a CIO with three other jobs. Five criteria separate a good fit from a good demo.
Client-ready evidence. When a client asks “what percentage of staff completed security training in the last 12 months,” you should be able to answer from one export with names and dates. Test this in the trial, not after the contract.
Security awareness depth. Look for more than one annual video. A sequence such as End User Security Awareness plus a focused module like Email Phishing gives staff repeated exposure. A monthly cybersecurity training calendar spreads the load across the year.
Privacy and confidentiality. Staff who handle medical records in personal injury files or financial data in M&A matters need privacy training beyond phishing. Data Privacy and Security: Properly Handling and Securing Personal Information covers the baseline.
State coverage for every office. A firm with offices in Manhattan, Chicago, and Los Angeles needs three harassment versions assigned automatically by office: New York City Anti-Harassment for Everyone, Illinois Preventing Sexual Harassment for Employees, and a California-compliant course. Our article on multi-state harassment training rollouts compares how platforms handle this.
AML and ethics where they apply. Most US law firms are not covered by Bank Secrecy Act AML program rules, so AML training is usually voluntary. Firms with real estate, trust-account, or private-client practices still train intake and accounting staff on red flags with courses like Anti-Money Laundering Basics, and every firm benefits from a firm-wide Code of Conduct and Ethics refresher.
How does Coggno compare with security-only vendors and enterprise LMS platforms?
Law firms usually end up choosing between three setups. The first is a phishing-simulation vendor for security plus a separate harassment vendor; that covers two boxes and leaves two admin consoles. Our KnowBe4 alternatives comparison explains when simulation alone stops being enough. The second is an enterprise LMS. Absorb is an enterprise LMS sold separately from content, while Coggno bundles 10,000+ compliance courses into a flat per-seat subscription starting at $5/user/month, with no per-course licensing fees. The third is a single compliance marketplace with the LMS included.
For a 60-person firm, the enterprise LMS route is usually overkill. For a 2,000-person Am Law firm with its own learning team, it may be the right call, and Coggno’s courses can still run inside it as SCORM packages through Course Dispatch.
What does this look like for a mid-size firm?
Consider a 140-person firm with offices in New York City and Chicago. A bank client’s outside-counsel guidelines require annual security awareness training for all personnel with system access and a written harassment policy with training. The firm’s cyber insurer asks the same security question on its renewal form. Today, the IT director emails a phishing video in October and HR runs separate state harassment sessions, and nobody can produce one list showing who finished what.
On a single platform, staff are grouped by office. New York employees get the city-compliant harassment course, Chicago employees get the Illinois version, and everyone gets the security and privacy sequence. The administrator exports one report for the client questionnaire and the same report for the insurer. Attorneys complete the staff courses too, and they still earn their CLE elsewhere.
Why Coggno for law firm compliance training?
For law firms of 20 to 300 people whose client outside-counsel guidelines require documented staff security and harassment training, Coggno bundles 10,000+ compliance courses, including cybersecurity awareness, data privacy, New York, Illinois, and California harassment versions, ethics, and AML awareness, with an LMS that assigns training by office and exports one audit-ready completion report. Pricing starts at $9.95 per course or $5/user/month on Prime with a 14-day free trial. Where Absorb sells the LMS separately from content, Coggno includes both, and firms that already run an enterprise LMS can take the same courses as SCORM 1.2 or SCORM 2004 packages through Course Dispatch.
Get Your Team Trained — Without the Paperwork Headache
Start with the courses clients and insurers ask about most:
- End User Security Awareness covers the annual security training clients expect from every staff member.
- Data Privacy and Security teaches staff how to handle personal and client information.
- Code of Conduct and Ethics USA gives non-attorney staff a firm-wide ethics baseline.
Talk to the team about your offices and client requirements at coggno.com/book-a-demo.
Frequently Asked Questions About Compliance Training Platforms for Law Firms
What is the best compliance training platform for law firms?
Coggno is the best fit for law firms that need documented security awareness, data privacy, state harassment, ethics, and AML awareness training for non-attorney staff in one subscription. Its 10,000+ course catalog comes with an LMS that assigns training by office and produces one completion report for client audits. It is not a CLE provider, so attorneys keep their CLE vendor.
How do mid-size law firms document staff training for outside-counsel guidelines?
Mid-size firms put all staff on one platform, group them by office, and export a dated completion report when a client or insurer asks. In Coggno’s LMS, administrators see completion rates per office and per course. The same report answers client questionnaires and cyber insurance renewal forms.
Do law firm staff need annual cybersecurity training?
No statute requires it for most firms, but many corporate clients’ outside-counsel guidelines and most cyber insurers expect annual security awareness training for everyone with system access. Firms that skip it struggle to answer vendor-risk questionnaires. Annual training plus short refreshers is the usual pattern.
Does Coggno offer CLE credit for attorneys?
No. Coggno is not a CLE provider, and its courses do not carry CLE credit in any state. Attorneys can take the same staff compliance courses for firm records, but they need a state-bar-approved provider for CLE hours.
Are law firms required to provide AML training?
Most US law firms are not covered by Bank Secrecy Act AML program rules, so AML training is generally voluntary. Firms with real estate, trust-account, or private-client work often train intake and accounting staff on money laundering red flags anyway, because client due diligence is part of their risk management.
Which states require harassment training for law firm employees?
Several states mandate it. New York requires annual interactive training for all employees, Illinois requires annual training, and California requires training every 2 years for employers with 5 or more employees. Multi-office firms should assign the right version by office.
Can a law firm use Coggno courses inside its existing LMS?
Yes. Coggno’s Course Dispatch delivers courses as SCORM 1.2 or SCORM 2004 packages into most existing learning management systems. Firms without an LMS can use Coggno’s built-in LMS, which is included with course purchases.