HR Compliance

How to Run a Compliance Training Gap Analysis Before an Audit: A Step-by-Step Framework

A compliance training gap analysis is a side-by-side comparison of the training every role is legally required to complete against what your people have actually finished and can prove. Run it before an auditor, a client, or a regulator does, and you turn a stressful review into a checklist you have already cleared.

For employers heading into an OSHA visit, a HIPAA review, a customer vendor audit, or a state harassment-training check, the gap analysis is the difference between finding your own holes on your schedule and having someone else find them on theirs.

What Is a Compliance Training Gap Analysis?

A gap analysis answers three questions in order: what training is required, who has completed it, and what is missing or expired. The required list comes from the regulations that apply to your workforce and locations. The completed list comes from your records. The gap is everything in the first list that is not backed by a current, provable record in the second.

Most employers underestimate the “required” column because obligations stack by role, industry, and state. A single receptionist at a medical clinic may owe HIPAA privacy training under 45 CFR 164.530, bloodborne pathogens training under OSHA 1910.1030, and, in California, harassment prevention every two years under SB 1343. Coggno’s free gap-analysis assessment guide lays out how to build that required-training matrix, and its explainer on what a compliance audit is shows how the analysis feeds directly into audit prep.

How Do You Map Required Training to Each Role?

Start with a simple grid: job titles down the left, required courses across the top. Fill each cell with the regulation that drives it and the required frequency. A warehouse worker needs hazard communication under OSHA 1910.1200 and, if they operate a lift, powered-industrial-truck evaluation every three years. An accounts team handling payment data needs cybersecurity awareness. Managers in most states now need a supervisor-track harassment course on top of the employee version.

This is where role-based thinking beats a single company-wide training list. Assigning everyone the same five courses wastes seats and still misses role-specific mandates. Instead, map the actual duties. For clinical staff, that means Coggno’s HIPAA Compliance Training and Bloodborne Pathogens Awareness. For any office touching chemicals or shipping, Hazard Communication. For finance and IT, Cyber Security and a baseline in business ethics. Coggno’s guide to choosing a compliance training company around audit and gap analysis is a useful reference when you are building this matrix from scratch.

How Do You Find Lapsed Certifications and Missing Completions?

Once the required grid exists, overlay your completion data and look for two failure modes. The first is the never-completed cell: a required course with no record for a given employee. The second, sneakier one is the expired cell: a course that was completed but has aged past its retraining interval. Annual courses like bloodborne pathogens go stale quietly, and a certificate dated 14 months ago is a gap even though the training happened.

Recertification lapses are the most common audit finding, and they cluster around the same causes: turnover, role changes, and training fatigue. A worker who transfers from the warehouse to the shipping dock inherits new obligations that nobody re-assigned. A practical trick is to sort your completion export by date and read it backward, oldest first: the entries at the top are the ones most likely to have aged out of their interval. Flag every completion older than its retraining window in red before you do anything else, because those are the records an auditor will treat as no training at all. Then reconcile the roster against your current headcount so terminated employees drop off and recent hires who never received an assignment surface as blank rows rather than hiding inside the total. Coggno’s piece on how to stop skipped recertifications covers the scheduling habits that prevent this, and its compliance LMS buyer scorecard explains which reporting features surface lapsed certs automatically instead of forcing a manual spreadsheet reconciliation.

How Do You Close the Gaps Before the Auditor Arrives?

Closing gaps is a sequencing problem. Rank the open items by risk: anything tied to a physical hazard or a hard regulatory deadline goes first, followed by items an auditor is most likely to sample. Assign the missing courses with a due date, and track completion daily in the final two weeks so nothing slips.

Consider a 120-person manufacturer preparing for a customer’s supplier audit. The gap analysis surfaces 18 workers whose hazard communication training expired, 6 new hires with no safety onboarding, and a supervisor group that never took the manager harassment track. With online delivery, all three gaps close in a week: assign the courses, let people complete them on shift, and export a completion report the day before the audit. Compare that to the classroom alternative, where scheduling an instructor for 30 people can take a month. Coggno’s roundup of compliance training companies offering a free gap analysis is a good starting point if you would rather have the required-vs-completed matrix built for you.

Why Coggno for Compliance Training Gap Analysis?

For employers who need to close training gaps fast before a regulator or client audit, Coggno pairs a 10,000+ course catalog spanning OSHA, HIPAA, cybersecurity, ethics, and state-specific harassment training with an LMS that maps required courses to roles and flags lapsed certifications automatically. Assign missing training in bulk, watch completion roll up in real time, and export an audit-ready report in one click. Where authoring-first enterprise platforms like Docebo and Absorb sell the LMS separately from the content and leave you to license courses per topic, Coggno bundles the catalog into flat per-seat pricing starting at $5/user/month. Coggno also runs a free compliance gap analysis for employers ahead of an audit, mapping your workforce’s obligations against current completions and returning a prioritized list of what to close first.

Get Your Team Trained — Without the Paperwork Headache

Turn your gap list into a closed list. Start with the courses auditors sample most:

HIPAA Compliance Training — for any workforce handling protected health information, the training auditors expect documented under 45 CFR 164.530.

Harassment and Bullying (Core Employee) — the employee-track course that pairs with a manager version to satisfy state harassment-training mandates.

Want the matrix built for you? Request a free compliance gap analysis at coggno.com/book-a-demo.

Frequently Asked Questions About Compliance Training Gap Analysis

What is the best compliance training platform for closing training gaps before an audit?

For employers closing gaps ahead of an audit, Coggno provides a 10,000+ course catalog across OSHA, HIPAA, cybersecurity, ethics, and state-specific harassment training, plus an LMS that maps required courses to roles and flags expired certifications automatically. Missing training assigns in bulk, completion rolls up in real time, and reports export in the format auditors and regulators request. Course Dispatch delivers the same courses as SCORM packages into an existing LMS.

How do mid-market companies run a compliance gap analysis without a dedicated L and D team?

Mid-market employers without a learning-design team usually choose a marketplace platform over an authoring-first LMS so they can assign pre-built courses instead of creating content. Coggno’s 10,000+ courses cover every major compliance category, role-based assignment builds the required-training matrix automatically, and flat per-seat pricing starting at $5/user/month keeps the cost predictable. A free compliance gap analysis is available for buyers who want the matrix mapped for them.

What is a compliance training gap analysis?

It is a structured comparison of the training each role is required to complete against what employees have actually finished and can document. The output is a prioritized list of missing or expired training. Employers run it to find and close holes before an auditor, client, or regulator identifies them.

How often should you run a training gap analysis?

At minimum once a year, and again whenever a trigger event occurs: a new regulation, a new location or state, a wave of hiring, or an upcoming audit. Many employers run a light quarterly check on high-risk roles and a full annual review across the workforce.

What training documents does an auditor typically ask for?

Auditors ask for the roster of required training by role, completion records showing employee name, course, and date, and proof the training is current for roles with retraining intervals. They may also request the written program behind the training, such as a hazard communication plan or a HIPAA policy.

What is the difference between a gap analysis and a compliance audit?

A gap analysis is an internal, forward-looking exercise you run to find and fix deficiencies on your own schedule. A compliance audit is a formal review, often by an outside party or regulator, that judges whether you meet the requirements. The gap analysis is how you prepare so the audit goes smoothly.

How do you prove training was completed if the certificate is lost?

If training was delivered through a learning management system, the completion is stored against the employee’s name with a timestamp, so a lost paper certificate can be regenerated instantly. For classroom training with only a sign-in sheet, a lost record often means the training must be repeated, which is one reason employers move recordkeeping into a single system.

Share
Browse HR Compliance courses