Blog · Coverage and territory · Compliance
How a compliance team measures mandatory training coverage from the learning system export and the HR roster: each person's required modules from their role, completions and expiry dates, the share complete per business unit and per module, the people overdue with the days, the new joiners past their onboarding window, and the identity that every required assignment is complete, overdue or not yet due.
A compliance team reports training completion at 91 percent. The regulator asks about the trading floor's market abuse module and the answer is a different report, assembled by hand. The learning system export joined to the roster and the role matrix answers every such question from one table. This guide sets out the requirement, the three states, the unit and module views, and the two lists.
Per person, per required module:
Required, from role and the matrix State: complete and in date, overdue (never completed past due date, or expired), not yet due (within onboarding or grace) Days overdue, where overdue
Per business unit, per module:
Completion = complete ÷ required, excluding not yet due Overdue count and median days Expiring in the next 90 days
Person identifiers only.
required assignments = complete + overdue + not yet due
Every assignment in one state. A completion for a module the person's role does not require is listed as voluntary and excluded from the denominator.
| Unit | People | Required assignments | Complete | Overdue | Not yet due | Completion | Median days overdue |
|---|---|---|---|---|---|---|---|
| Trading | 140 | 980 | 870 | 84 | 26 | 91% | 34 |
| Operations | 310 | 1,550 | 1,480 | 41 | 29 | 97% | 12 |
| Sales | 95 | 570 | 430 | 122 | 18 | 78% | 61 |
Sales has a fifth of its required training overdue by two months on average. Trading is at the company average with eighty-four overdue assignments, and the regulator's question about the market abuse module has an answer in the module view.
| Module | Required | Complete | Overdue | Expiring in 90 days |
|---|---|---|---|---|
| Market abuse | 140 | 131 | 9 | 38 |
| Conduct | 140 | 138 | 2 | 12 |
| Information security | 140 | 121 | 19 | 41 |
Nine traders overdue on market abuse, named on the list, and thirty-eight expiries in the next quarter that can be scheduled now.
People within their onboarding window with modules not yet complete, per unit, with days to the window's end. Not overdue yet; the list that stops them becoming so.
Requirement not from role. Everyone assigned everything; completion meaningless.
Expiry ignored. Completed once, compliant forever.
Matrix changed silently. Compliance falls in March because a module was added.
Company figure only. Ninety-one percent, and a unit at seventy-eight.
Mapped once, the roster, the role matrix and the learning export produce the states, the unit and module views, the overdue list and the expiries every month. Covirage builds this from the exports as they are. The compliance page describes the setup, and the testing cadence guide covers the same three-state pattern applied to controls.
A role-to-module matrix the compliance team owns: which modules each role must complete and how often. It is the definition, and it is versioned, because a module added to a role in March makes everyone in that role overdue in March, and the report should say the requirement changed rather than that compliance fell.
The roster's dated role history applies the requirement from the change date, with a stated grace period. A person who moved into a role needing a new module last month is not overdue until the grace period ends, and the report shows them as not yet due.
A completion with a refresh cycle expires at completion date plus cycle. Expired is overdue. The report shows expiries in the next ninety days per unit, so the refresh is scheduled rather than discovered.