Skip to main content

Using External Security Training Instead of ComplyJet's Built-in Courses

Already run phishing simulations or security training through another tool? You don't have to make employees redo it in ComplyJet.

Written by Upendra Varma

ComplyJet's built-in Security Awareness Training is the default path, but it's not the only acceptable one. If your team already completes security or phishing-awareness training through another tool — CanIPhish and similar platforms are common — auditors generally accept that as equivalent evidence; you don't need employees to redo training they've already completed elsewhere just because it wasn't run through ComplyJet.

How to handle it

There isn't a self-serve "upload external training evidence" button on the training completion tracker today — this is a support-assisted path rather than something you configure yourself. Reach out via Contact Support with:

  • What tool the training was completed through

  • Records showing which employees completed it and when (an export or screenshot from the other platform is normally sufficient)

Support can get that credited against the relevant training requirement so it shows correctly in your compliance status, rather than employees appearing as non-compliant for a course they've genuinely already completed.

Ongoing training still needs to happen somewhere

Whichever tool you use, most frameworks expect security awareness training to repeat on a regular cadence (typically annually) — switching to an external tool doesn't remove that requirement, it just changes where the evidence comes from. If you're running training outside ComplyJet, it's worth keeping a simple internal record of completion dates so the next renewal cycle is easy to evidence again.

Did this answer your question?