Course Creation
How to Turn a Policy Document Into Compliance Training
September 28, 2026

Every compliance training project starts the same way: someone hands you the policy and asks for a course by the end of the month. The policy is twenty pages, written by or for lawyers, and technically complete. Turning it into training is not a formatting exercise.
Why can I not just publish the policy as a course?
Because a policy and a course are written for different purposes. A policy exists to define obligations precisely enough to be enforced, which means it is comprehensive, hedged and organised by legal structure. Training exists to change what someone does on a Tuesday, which means it must be specific, memorable and organised by situation.
Publishing the policy as a course produces something people click through without reading, which is worse than no training at all — you now have completion records suggesting people understood something they did not.
What should I keep and what should I cut?
The useful test for every section: would a reasonable person behave differently having read this?
- Keep the specific obligations that apply to the audience you are training.
- Keep the thresholds and timeframes people are expected to act on — reporting windows, approval limits, escalation triggers.
- Keep the consequences, stated plainly and without melodrama.
- Cut the definitions section, and define terms where they are first used instead.
- Cut the governance scaffolding — review cycles, document control, the approving committee.
- Cut obligations that belong to a different role, and train that role separately.
How do I make it concrete?
Convert rules into situations. A policy says what must not happen; training should show someone recognising the moment it is about to.
The most effective structure is usually a short statement of the rule followed by a scenario where the rule is not obvious — the borderline gift, the colleague who asks you to approve something small, the client request that is almost within scope. People do not fail compliance because they never read the rule. They fail because they did not recognise the situation as the one the rule was about.
What about the legal risk of paraphrasing?
This is the real constraint and it deserves care. Simplifying a policy for training can change its meaning, and if someone acts on your simplification, that is a problem you created.
Three practices that keep it safe:
- Quote exactly where precision is legally load-bearing — thresholds, definitions with legal force, mandatory wording.
- Link to the policy as the authoritative source, and say plainly in the course that it is the authority.
- Have it reviewed by whoever owns the policy, before it goes out and after any edit.
A course that says "this is a summary; the policy governs" and points at the real document is both more honest and safer than one that reads as authoritative.
How do I handle the evidence requirement?
Most compliance training exists partly to demonstrate that training happened. That means completion records, a date, and usually the version of the material. Exporting to SCORM and running the course through your LMS handles this — the LMS records who completed what and when.
Keep a copy of the exported package for each version you deploy. If you are ever asked what people were actually told in March, you will want the March file, not the current course.
The practical route
Copy the policy into a fresh Word document, cut it to the sections that change behaviour, restructure by situation rather than by clause, add scenarios at the points where judgement is required, then import it. Send the draft course to the policy owner before you send it to anyone else.
How often should compliance training be refreshed?
Whenever the policy changes, and on a fixed cycle otherwise — annually for most obligations, more often where the regulator or your insurer specifies it. The fixed cycle matters even when nothing has changed, because the evidence question is usually when a person last completed it, not whether the content moved.
Two things make the refresh manageable. Keep the exported package for every version you deploy, so you can answer what people were told and when. And version the course title or description with a date, because a completion record against a bare policy name is far less useful in three years than one against a version you can still produce.
The part most teams get wrong
Training the whole policy to the whole organisation. Most policies contain obligations for several distinct roles, and pushing all of it to everyone guarantees that most of what each person reads does not apply to them. Two short role-specific courses will be read. One long universal one will not.