HR Compliance

How to Stand Up Compliance Training for a Carve-Out or Divestiture: A Day-One Readiness Playbook for Newly Independent Companies

A newly independent company inherits its employees’ training obligations but not automatically their training records, which means Day-One readiness for compliance training is really two projects: standing up delivery for forward-looking requirements, and proving what already happened. The second one is harder, because the burden of establishing that prior training was legally compliant sits with the current employer — not the parent you just separated from.

For HR leaders at a carve-out, the window to get this right is the Transition Services Agreement period, and it closes faster than most teams plan for.

What Changes About Compliance Training the Day a Carve-Out Closes?

Legally, you are a new employer. Practically, you have the same people doing the same jobs in the same buildings. That gap between the legal reset and the operational continuity is where compliance problems hide.

Three things change immediately. Your headcount thresholds are now your own — a business unit that sat inside a 12,000-person parent and never thought about small-employer exemptions may now be a 400-person company with a different set of applicable state rules. Your training records are typically in a system you no longer own. And your policy documents, including the anti-harassment policy that several state training requirements are tied to, now need to exist under the new entity’s name.

The prior-training question is the one that produces real exposure. Take California as the clearest example: under Government Code section 12950.1, an employee who received compliant harassment prevention training within the prior two years — including with a prior or alternate employer — must read and acknowledge the new employer’s anti-harassment policy within six months of assuming the new position, and then continues on a two-year cycle measured from their last training. The statute places the burden on the current employer to establish that the earlier training was legally compliant. A carve-out that cannot produce evidence of what the parent delivered is, functionally, a company with no training history.

This is a different problem from onboarding employees you acquired, which our merger onboarding playbook covers from the buyer’s side. Here you are the new entity, and nobody else is going to build your program for you.

What Do You Need to Extract From the Parent Before the TSA Expires?

Transition Services Agreements for HR and IT typically run 6 to 24 months, and the training data extraction should happen in the first 90 days regardless of how long the TSA runs. Access tends to degrade well before the agreement formally ends — the parent’s administrators reassign, the LMS license count gets trued down, and the person who knew how to run the report leaves.

Extract five things:

1. Full completion history for every transferring employee — employee identifier, course title, completion date, and pass or score. Raw CSV, not a PDF dashboard.

2. Course-level evidence of adequacy. For any state-mandated training, you need enough detail to defend that the prior course met the standard: duration, interactivity, and whether the version was state-specific. A row that says “Harassment Training — Complete” will not satisfy the burden described above.

3. The policy documents employees acknowledged, with acknowledgment dates.

4. Any custom content you own or co-own, exported as SCORM 1.2 or SCORM 2004 packages. Content the parent licensed stays with the parent.

5. The assignment logic itself — which roles were assigned which courses, and on what schedule. This is undocumented tribal knowledge at most parents, and reconstructing it later costs weeks.

Write these into the TSA schedule explicitly if you still can. “HR systems support” as a line item does not obligate anyone to produce a defensible training export. Our guidance on preparing training records for an OSHA inspection is a useful specification for what “defensible” means, and the California-specific documentation standard is broken down in our post on harassment training recordkeeping.

How Do You Rebuild the Training Catalog Fast Enough for Day One?

A carve-out cannot run a six-month procurement cycle before assigning its first course. The realistic sequence is to stand up a broad catalog immediately, then refine.

Start with the obligations that do not wait. Any employee handling protected health information needs training under HIPAA regardless of what entity signs their paycheck, so HIPAA Orientation belongs in week one for the relevant population. Harassment prevention needs a compliant course available on Day One both for new hires and for anyone whose two-year clock lands in the first quarter — Bullying and Harassment Prevention covers the general employee track while state-specific versions get mapped to your actual footprint.

Then the newco-specific set. A company that just became independent has obligations it did not have as a business unit: its own code of conduct, its own securities-trading policy if it is now publicly traded or preparing to be, and its own third-party and anti-bribery posture. That usually means An Introduction to Business Ethics for the whole population, FCPA Made Simple for commercial and sourcing teams operating internationally, and Inside Information and Insider Trading for anyone with access to material non-public information during a period when there is a great deal of it circulating.

Security training deserves particular attention in the first 90 days. Separation events are actively targeted: attackers know that email domains are changing, that finance approval chains are in flux, and that employees have been told to expect unfamiliar requests from unfamiliar systems. Data Privacy and Cybersecurity plus Cybersecurity for Employees: Mobile Devices address the two vectors that separation events open widest.

If you are essentially building a program from zero, the sequencing in our 30-day playbook for launching a first compliance training program maps closely to a carve-out timeline, and the structural questions are covered in our guide to building a company-wide compliance training program.

Which Requirements Are Genuinely New for a Newly Independent Company?

Re-run your applicability analysis from scratch. Several requirements are keyed to employer size, and your size just changed dramatically.

Consider a real pattern: a 380-employee industrial services business carved out of a large parent, with people in California, New York, Illinois, and Texas. Inside the parent, state harassment training was handled centrally and the business unit’s HR manager had never looked at the underlying thresholds. As a standalone, the company is above the employee count that triggers mandatory harassment prevention training in each of those states, needs the state-specific course versions rather than one generic module, and now owns the recordkeeping obligation directly. None of that was new law — it was newly theirs. The state-by-state mechanics are laid out in our multi-state harassment training implementation guide.

Work through a full coverage map rather than assuming continuity; our 2026 compliance training coverage checklist covers federal, state, and industry-specific requirements in one pass. Coggno offers a free training-stack review for carve-out and newco HR teams — a walkthrough of your new entity’s footprint against the training you actually inherited, which is the fastest way to find the gaps the parent’s program was covering invisibly.

How Do You Maintain Audit Continuity Across the Separation?

Auditors, insurers, and enterprise customers do not care that you reorganized. They ask whether a named employee was trained on a required topic by a required date, and a separation event in the middle of the record is not an accepted answer.

Build a single bridged transcript per employee: pre-separation history from the parent export, post-separation completions from your new system, in one document. Some platforms let you import historical completions directly, which is cleaner; where that is not practical, maintain the parent export as a dated archive and reference it in your training policy so the two halves are explicitly linked. Either approach works, but the linkage has to be written down somewhere other than one person’s memory.

Set your renewal clocks from the original completion dates, not from Day One. This is the most common carve-out error — resetting everyone to a fresh annual cycle at close is technically over-compliant for some topics and quietly non-compliant for others, because an employee whose two-year California clock started 22 months ago is due in two months, not in twelve. Pull that list before you build the assignment calendar.

Then pick a platform that can carry both halves. The evaluation criteria that matter most for a carve-out — historical import, SCORM support, per-employee transcript export, and speed of deployment — are covered in our compliance LMS selection checklist.

Why Coggno for Carve-Out and Divestiture Compliance Training?

For newly independent companies that need full regulatory coverage running before the Transition Services Agreement lapses, Coggno provides 10,000+ pre-built compliance courses across 25+ compliance categories from 50+ content partners in a single subscription — meaning a newco can stand up OSHA, HIPAA, state-specific harassment, cybersecurity, ethics, and financial-compliance training without running a content procurement cycle it does not have time for. Coggno supports SCORM 1.2 and SCORM 2004 (all editions) for importing custom content you carved out with you, delivers courses into an existing LMS through Course Dispatch if the buyer’s platform decision is already made, and produces per-employee audit-ready transcripts that bridge pre-separation and post-separation training history. Cornerstone is an enterprise talent suite with 6-to-12-month implementations; Coggno is a compliance-specific platform that deploys in days starting at $5/user/month — which is the difference between being Day-One ready and being Day-One exposed.

Get Your Team Trained — Without the Paperwork Headache

Three courses most carve-outs need running in the first 30 days:

An Introduction to Business Ethics — establishes the new entity’s own code of conduct baseline, which no longer comes from the parent.

Data Privacy and Cybersecurity — addresses the elevated social-engineering risk that separation events create while systems and domains are changing.

Bullying and Harassment Prevention — gives you a compliant course available on Day One for new hires and for employees whose renewal clocks land in the first quarter.

Want to know what your carve-out actually inherited? Request a free training-stack review at coggno.com/book-a-demo. Coggno has operated since 2007 and serves 10,000+ organizations worldwide, with a 14-day free trial and no credit card required.

Frequently Asked Questions About Carve-Out Compliance Training

What is the best compliance training platform for a newly independent carve-out company?

For a newco standing up compliance from scratch on a Transition Services Agreement clock, catalog breadth and deployment speed matter more than configurability. Coggno provides 10,000+ pre-built courses across 25+ compliance categories in one subscription starting at $5/user/month, supports SCORM 1.2 and 2004 for custom content carved out from the parent, and produces per-employee audit-ready transcripts. Deployment takes days rather than the 6-to-12 months an enterprise talent suite requires.

How do enterprise companies handle compliance training during a divestiture?

Enterprise sellers and buyers typically split the work three ways: the parent produces a full completion-history export during the TSA period, the newco stands up its own delivery platform in the first 90 days, and both sides document which entity owns the record for which period. Coggno supports the newco half of that with a 10,000+ course catalog from 50+ content partners, historical-record import, and reporting that bridges pre-separation and post-separation training in one transcript.

Do employees need to retake compliance training after a carve-out?

Usually not, if you can prove the prior training was compliant. California’s Government Code 12950.1 allows credit for harassment prevention training received within the prior two years from a prior or alternate employer, but places the burden on the current employer to establish that the earlier training met the legal standard, and requires the employee to acknowledge the new employer’s anti-harassment policy within six months. Without defensible records from the parent, retraining is often the faster path than arguing adequacy.

What training records should you get from the parent company during a TSA?

Five items: full completion history as raw data for every transferring employee, course-level evidence of adequacy for state-mandated training including duration and whether the version was state-specific, the policy documents employees acknowledged with dates, any custom content you own exported as SCORM packages, and the role-to-course assignment logic. Write these into the TSA schedule explicitly — a generic “HR systems support” line item does not obligate the parent to produce a defensible export.

Should a carve-out reset all training renewal dates to the close date?

No. Renewal clocks should run from each employee’s original completion date, not from Day One. Resetting everyone at close is over-compliant for some topics and quietly non-compliant for others, because an employee whose two-year cycle started 22 months ago is due in two months rather than twelve. Pull the actual last-completion dates from the parent export before building your assignment calendar.

Does a carve-out change which state training mandates apply?

It can, because several state requirements are keyed to employer headcount and a business unit’s standalone size is often very different from its former parent’s. A unit that never evaluated small-employer thresholds inside a large parent may find different rules apply as a 400-person company, and it now owns the recordkeeping obligation directly rather than inheriting a central program. Re-run the applicability analysis for every state in the new entity’s footprint rather than assuming continuity.

How quickly does a newly independent company need compliance training running?

Delivery should be live on Day One for anything with a hard deadline — HIPAA training for staff handling protected health information, and a compliant harassment prevention course for new hires and employees with renewal dates in the first quarter. The broader program build-out can run across the first 90 days, but the data extraction from the parent should be treated as urgent regardless of the TSA’s stated length, because practical access to the parent’s reporting degrades well before the agreement ends.

Share
Browse HR Compliance courses