Security awareness training, built as evidence.
Security awareness training software is a learning management system that assigns, tracks, and certifies staff training. grComply's training module goes further: every course, quiz, and phishing-simulation result rolls into the same computed completion percentage as your framework controls — so training isn't a side activity your auditor has to take on faith. A real curriculum hierarchy, a required compliance mapping before publish, a learning board, and automated phishing simulation — available inside grComply, or on its own with training-only seats.
What is security awareness training software? It's an LMS purpose-built for compliance and security topics — phishing recognition, data-handling, incident response — that assigns courses to staff, tracks completion, and issues certificates. grComply's training module is the same idea with one structural difference: every course carries a mandatory purpose and a compliance-framework mapping before it can ever publish, checked server-side, not as an optional field someone forgets to fill in.
Training that answers to your compliance programme
Every course answers "why" and "which compliance"
A stated purpose and at least one compliance-framework mapping (or an explicit, justified general-awareness opt-out) are hard-gated at publish — carried onto every certificate and evidence item the course produces, so an auditor never has to ask what a training exists to satisfy.
A real curriculum, not a flat file
Category ▸ Course ▸ Module ▸ Content Block, arbitrary depth — the same tree pattern grComply already uses for framework controls. A course can be one five-minute video or a multi-module curriculum with a cumulative final exam.
Nine content types, all data
Text, captioned video, read-and-acknowledge documents, interactive simulations, puzzles/games, polls, in-lecture quizzes, module assignments, and imported SCORM/xAPI packages — extensible the same way custom fields are, without a deployment.
Completion is evidence
A finished TrainingAssignment is generated the same way as an uploaded document or a scan finding, and rolls into the same computed completion percentage as every other control — one readiness number, not two systems to reconcile.
Automated phishing simulation
Schedule once from a versioned lure template — send, open, click, and report are tracked per recipient with no manual step after. A click auto-enrols the recipient into remedial training, bounded by an explicit non-punitive usage policy.
Seat-based, decoupled from your platform licence
A training-only seat pool is allocated per tenant, separate from the core GRC user entitlement — so a whole workforce can take awareness training without buying GRC seats for people who only need My Learning.
Every stage of the training lifecycle, built in
Course authoring and the publish gate
A Content Creator (Mutex-side, or a tenant's own delegated author) builds curricula in a dedicated studio: title, purpose, category, curriculum modules, and a compliance-mapping panel. Publish stays locked until a reviewer distinct from the author is assigned, a compliance mapping (or justified opt-out) exists, and video/interactive blocks pass an accessibility check — captions attached, keyboard and screen-reader operability verified. An AI assistant can draft lecture text or quiz questions from source material already in the platform, always labelled AI-generated and requiring human approval before publish.
Built for: Platform Admin, delegated Content CreatorTenant catalog and custom courses
A Tenant Admin activates only the published courses relevant to their organisation from the global catalog — mirroring how framework assignment already works elsewhere in grComply. A tenant can also author its own internal-only course (an onboarding runbook, a company-specific incident drill) with the same tools and the same publish gate, kept private to that tenant unless a Platform Admin later promotes it to the global library.
Built for: Tenant AdminGroups, campaigns, and recurring refreshers
Build a target group — by individual, department rule, or role — then launch a campaign against it with a due date, recurrence, and grace period. Set a course's validity period once and grComply auto-generates a new campaign per learner before certificate expiry, so annual-awareness requirements under ISO 27001, SOC 2, PCI DSS, SAMA CSF, or NIST never need manual re-assignment.
Built for: Tenant AdminThe learning board and My Learning
A Kanban-style board — Not Started, In Progress, Completed, Overdue, Exempt — filterable by course, group, department, or due date, with drill-in and one-click reminders. Learners get the mirror view, My Learning, plus a performance and interactivity dashboard: scores per quiz/module/exam, time spent, and progress trend. Optional gamification — points, streaks, and badges — rewards genuine engagement, not just pass/fail.
Built for: Tenant Admin, every learnerAutomated phishing simulation
Versioned lure templates (subject, sender, body, landing page — optionally AI-drafted and human-approved) drive a scheduled, recurring campaign that runs end-to-end with no manual step once configured. Per-recipient outcome — sent, opened, clicked, reported — feeds the same reporting dashboard as standard training completion, and a "clicked" outcome auto-creates a remedial assignment. Usage is bounded by an explicit non-punitive, privacy-scoped policy stated on the campaign screen, not buried in a document.
Built for: Tenant AdminCertificates and legacy import
A PDF certificate renders on final-exam pass, tenant-branded, and expires per the course's validity period. Historical completion records from a client's previous LMS or a spreadsheet import as clearly flagged legacy evidence, so adopting grComply's training module doesn't reset an already-compliant workforce's awareness posture to zero.
Built for: Tenant Admin, Platform AdminTwo access levels, one seat pool
Awareness training usually needs to reach a whole workforce — not just the handful of people who use the rest of a GRC platform. grComply licenses the training module separately for exactly that reason.
Restricted by design
Sees only My Learning and their own certificates and performance — no evidence, risk, or control data, enforced server-side. Consumes one training seat.
Standard User, Compliance Officer, etc.
Draws from the tenant's core platform user entitlement instead — completely unaffected by the training-seat pool, and vice versa.
Sized for the whole workforce
A Platform Admin allocates each tenant a training-seat pool, visible live to the Tenant Admin. Invites past the pool are rejected server-side, and a seat releases automatically the moment its user is deactivated.
Four roles, one training programme
9 screens, captured from the live workspace
From course authoring through to a learner's own certificates — the same workspace shown at every stage of the training lifecycle.









Standalone awareness tools vs. a compliance-mapped module
| Approach | Typical tools | What you get |
|---|---|---|
| Standalone awareness training | KnowBe4, Proofpoint Security Awareness, Hoxhunt, Curricula | Course library and phishing simulation as a separate contract — completion evidence exported and manually re-attached to your GRC or audit tooling. |
| grComply training module | Built into grComply, or licensed on its own with training-only seats | Courses mapped to the exact control they satisfy; completion rolls into the same compliance percentage automatically — no export, no manual re-attachment. |
grComply's wedge: teams that don't want a training completion spreadsheet sitting next to their GRC evidence — the training module reports into the same control tree, the same completion cache, and the same audit export as everything else.
Security awareness training in grComply
What is security awareness training software?
Security awareness training software is a learning management system (LMS) that assigns, delivers, and tracks staff training on security and compliance topics — phishing recognition, data-handling, incident response — and produces a completion record auditors and regulators can check. grComply's version also maps every course to the specific control it satisfies.
Does training completion count as compliance evidence?
Yes. A finished assignment is generated the same way as an uploaded evidence document or a scan finding, and rolls into the same computed completion percentage as every other control — so training posture shows up alongside everything else, not in a separate spreadsheet.
What content types can a course include?
Text, captioned video, read-and-acknowledge documents, interactive simulations, puzzles/games, polls, in-lecture quizzes, module assignments, a cumulative final exam, and imported SCORM/xAPI packages — all normalized into the same progress and scoring model.
How does the phishing simulation work?
A Tenant Admin schedules a recurring campaign from a versioned lure template — send, open, click, and report are tracked per recipient with no manual step after setup. A click auto-enrols that person into remedial training, governed by an explicit non-punitive usage policy.
Can we import our existing SCORM or xAPI courses?
Yes. Existing packages import as a content block alongside natively authored ones, and historical completion records from a previous LMS or spreadsheet import as clearly flagged legacy evidence — adopting grComply doesn't reset an already-compliant workforce to zero.
What is a training-only seat?
A restricted account that sees only My Learning and its own certificates and performance — no evidence, risk, or control data — drawing from a separate training-seat pool a Platform Admin allocates per tenant, independent of your core platform user entitlement.
How often does refresher training need to run?
Whatever cadence your framework requires — set a course's validity period once and grComply auto-generates a new campaign per learner before certificate expiry, matching annual-awareness requirements under ISO 27001, SOC 2, PCI DSS, SAMA CSF, or NIST.
Can a tenant build its own internal-only course?
Yes. A Tenant Admin or delegated Content Creator can author a custom course with the same authoring tools and the same publish gate as the global catalog. See full pricing on the grComply pricing page.
See training completion become compliance evidence
Powered by Mutex Systems. Back to grComply overview → · grComply pricing → · grComply vs GRC platforms →
Talk to us about training seats
Tell us the size of your workforce and which frameworks your training needs to map to, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to roll out training your auditor will trust?
We respond within one working day — or reach us instantly on WhatsApp.