Quick answer: There is no single list of mandatory compliance training that applies to every U.S. employer in 2026. Requirements depend on the law, jurisdiction, industry, employer size, employee role, workplace hazards, and triggering events. A defensible training matrix should identify the governing source, covered population, timing, content and delivery rules, trainer qualifications, documentation, and any state or local overlay.
Compliance training becomes difficult to manage when organizations begin with course titles instead of legal duties. A course called “workplace safety” may be useful, but it does not show which OSHA standard applies, which employees need training, whether hands-on practice is required, or when retraining must occur. The same problem appears in harassment prevention, privacy, health care, transportation, financial services, and other regulated areas.
This 2026 guide provides a practical framework for mapping mandatory compliance training requirements by industry and state. It highlights common federal and state examples, corrects several widely repeated cadence errors, and explains how to evaluate online training without implying that one course can satisfy every employer's obligations.
Important: This article is general educational information, not legal advice. Laws, regulations, agency guidance, contracts, and enforcement positions can change. Employers should confirm requirements with qualified counsel and the responsible agency for each jurisdiction and workforce.
To see why a generic checklist fails, consider a hypothetical employer with a warehouse in Illinois, remote supervisors in California, and employees who prepare hazardous materials for transportation. The company may need state harassment training, hazard-specific OSHA instruction, and function-specific DOT training, but those duties come from different sources and follow different timing rules. This is a planning example, not a TraineryXchange client case or a conclusion about any particular employer.
What Makes Compliance Training Mandatory?
Training may be required directly by a statute or regulation, indirectly through a duty to implement policies and safeguards, or contractually through a customer, insurer, grant, or industry relationship. These sources should not be treated as interchangeable.
A direct rule may specify the covered employees, subjects, timing, trainer, interactivity, or records. An example is the federal Hazardous Materials Regulations, which require hazmat employees to receive training that addresses general awareness, function-specific duties, safety, security awareness, and, when applicable, an employer's security plan.
Other frameworks require workforce awareness or policy training without prescribing one universal course or annual date. A company may also decide that additional training is an appropriate control even when no rule names that exact program. That training may support risk management, but it should not be represented as a statutory mandate unless the source says so.
The Seven Fields Every Requirements Matrix Should Include
1. Governing source: Record the statute, regulation, official guidance, contract, or internal policy. Link to the current source and note the last review date.
2. Covered employer or entity: Identify thresholds and status tests, such as employer size, covered-entity status, public or private sector, industry, location, and whether a state-plan standard applies.
3. Covered employee or role: Requirements may depend on job duties, exposure, supervisory status, access to information, or work with regulated materials. Avoid assigning a legal label to the entire workforce when the rule is role-specific.
4. Timing and trigger: Capture initial training, recurring cadence, promotion or transfer, policy change, new hazard, observed deficiency, and any deadline tied to the employee's anniversary.
5. Content and delivery: Note required topics, interaction, language, literacy level, practical exercises, equipment-specific instruction, accessibility, and whether online delivery can cover the entire obligation.
6. Trainer or evaluator qualifications: Some requirements call for a knowledgeable trainer, qualified person, competent person, or workplace evaluation. A generic online course may address knowledge while leaving the employer responsible for practical instruction or evaluation.
7. Documentation: Record what must be retained, such as employee name, date, course or topic, trainer, test or evaluation, version, location, and the applicable retention period.
OSHA Training Requirements Are Standard-Specific
OSHA publishes a guide to training requirements in its standards, but the publication is a starting point rather than a substitute for the underlying rule. Employers still have to determine which standards apply to their hazards, equipment, processes, and workforce.
Bloodborne Pathogens
Under OSHA's Bloodborne Pathogens standard, 29 CFR 1910.1030, employers with employees who have occupational exposure must provide training at the time of initial assignment and at least annually thereafter. Annual training must occur within one year of the previous training. Changes in tasks or procedures that affect occupational exposure create an additional training duty, although that instruction may be limited to the new exposures.
The training must be appropriate in content and vocabulary to the educational level, literacy, and language of employees. The standard also specifies subjects and an opportunity for interactive questions and answers with a knowledgeable person.
Powered Industrial Trucks
Forklift operator training under 29 CFR 1910.178 combines formal instruction, practical training, and evaluation of performance in the workplace. The employer must evaluate each operator's performance at least once every three years.
Refresher training follows specified events rather than the calendar alone. Unsafe operation, an accident or near miss, an evaluation showing deficient operation, assignment to a different truck type, or a workplace change that could affect safe operation can trigger it. The separate three-year requirement concerns evaluation of operator performance, not an automatic repeat of the same course.
Lockout/Tagout
The control of hazardous energy standard distinguishes authorized, affected, and other employees. Training should match how each group interacts with the energy-control program.
Annual activity under 29 CFR 1910.147 centers on a periodic inspection of each energy-control procedure. Employee retraining follows a different logic: relevant changes in job assignment, machines, equipment, processes, or energy-control procedures, or evidence of deviations or inadequate knowledge. Conflating the inspection with blanket annual retraining misstates the standard.
For a detailed mapping of manufacturing topics and OSHA standards, use the OSHA manufacturing training guide. It separates awareness topics from task-specific instruction and workplace evaluation.
Harassment Training Requirements Vary by State
Federal law prohibits employment discrimination and harassment based on protected characteristics. In its Promising Practices for Preventing Harassment, the EEOC identifies regular, interactive training as a prevention practice. The guidance does not create one generally applicable federal private-employer training schedule, while several states and local jurisdictions impose specific duties.
These four rules illustrate why “annual training” is not a sufficient matrix entry. California separates supervisor and nonsupervisor duration and generally uses a two-year cycle. New York focuses on annual interactive training. Illinois sets a calendar-year deadline. Connecticut combines initial obligations with a separate long-interval supplemental requirement.
Delaware, Maine, and Washington are among the other states with requirements for specified employers, roles, or industries. Local rules may add another layer. The 2026 state harassment training guide provides a more detailed state-by-state analysis.
Health Care and HIPAA Training
“HIPAA training” is often described too broadly. First determine whether the organization is a covered entity, business associate, or another party with contractual or state-law responsibilities. Then identify which workforce members need training based on their functions and access.
According to the U.S. Department of Health and Human Services' HIPAA guidance, the Privacy Rule requires a covered entity to train workforce members on its privacy policies and procedures as necessary and appropriate for their functions. New workforce members must be trained within a reasonable period, and a material policy or procedure change can create another duty. The Security Rule separately includes a security awareness and training program for workforce members, including management.
Organizations often use recurring awareness activities as part of their security and privacy programs, but the federal rules should not be summarized as one universal annual HIPAA course with the same content for everyone. State privacy, breach, health-record, professional licensing, facility, and payer requirements may add separate duties.
Transportation and Hazardous Materials
Under 49 CFR 172.704, hazmat employees must receive general awareness or familiarization, function-specific, safety, and security awareness training. Employees covered by an employer's security plan must also receive in-depth security training.
Recurrent training is required at least once every three years. A new or newly assigned hazmat employee may perform covered functions before completing training only under the direct supervision of a properly trained and knowledgeable employee and only within the regulatory time limit. Training is also necessary when an employee's function changes in a way that introduces duties for which the employee has not been trained.
The role definition matters. “Works for a transportation company” is not the legal test. The matrix should identify the functions each hazmat employee performs and the training elements connected to those functions.
Financial Services, Ethics, and Internal Controls
Financial organizations may face overlapping requirements from banking, securities, anti-money laundering, privacy, cybersecurity, licensing, and supervisory regimes. The applicable training depends on the institution, products, regulators, employee functions, and location.
Sarbanes-Oxley is frequently placed on generic mandatory-training lists. The law establishes corporate governance, reporting, certification, audit, and internal-control responsibilities, but it should not be summarized as a universal requirement that every employee complete an annual “SOX course.” Organizations may use role-based training to support internal controls and codes of conduct. The legal basis and audience should be documented accurately.
The same discipline applies to ethics, insider trading, anti-bribery, anti-money laundering, and information security. Identify the governing rule and covered role instead of assuming that one corporate course satisfies all obligations.
Industry-Specific Planning Questions
Manufacturing and construction: Which OSHA standards, state-plan rules, equipment, hazardous substances, and site conditions apply? Which topics need practical demonstration, competent-person involvement, or site-specific instruction?
Health care: Which workers have occupational exposure, patient contact, protected health information, controlled-substance duties, professional licensing requirements, or facility-specific obligations?
Transportation and logistics: Which employees meet the definition of hazmat employee, operate powered industrial trucks, perform regulated driving, or handle security-sensitive functions?
Financial services: Which regulator, license, product, transaction, customer type, or information-access role creates the duty? How do policies, supervision, attestations, and monitoring connect with training?
Hospitality and retail: Do state or local harassment rules include industry-specific content? Which employees handle food, alcohol, payments, customer data, equipment, or workplace hazards?
Distributed and multi-state employers: Is coverage determined by the employee's work location, employer location, supervisory relationship, or another rule? How will remote employees, temporary workers, contractors, transfers, and short-term assignments be evaluated?
When Online Compliance Training May Be Sufficient
Online training can support consistent delivery, accessibility, version control, knowledge checks, and completion records. Whether it satisfies a legal duty depends on the specific rule and the actual course experience.
Review the course against required subjects, duration, interactivity, language, reading level, accessibility, examples, trainer availability, and record fields. Confirm that the current version reflects the applicable law. Then identify what must happen outside the course, such as site-specific policy review, equipment demonstration, hands-on practice, live questions, manager discussion, or workplace evaluation.
A completion certificate proves that a defined learner completed a defined activity according to the system record. It does not by itself prove that every legal requirement was satisfied or that the employee can perform a task safely. Keep the certificate with the requirement mapping, course version, supporting activities, and evaluation evidence.
Building the 2026 Compliance Training Matrix
Begin with locations, entities, roles, hazards, and regulated activities. Assign an owner to each legal area and require a citation to the current source. Map initial and recurring timing separately from event-triggered requirements.
Connect the matrix to authoritative employee data. Hire, location, supervisor status, job, promotion, transfer, leave, and termination changes affect assignments. Hazard, equipment, process, and policy changes may create separate triggers that the human resources system does not capture.
For each course, record title, provider, version, learning objectives, delivery format, accessibility status, languages, evidence produced, and last legal review. If the course addresses only part of a requirement, state what completes the process.
Schedule periodic reviews and event-based reviews. A calendar helps with fixed cycles, while workflow triggers address hires, promotions, transfers, new hazards, policy changes, unsafe operation, and observed deficiencies. The companion 2026 compliance training calendar turns those obligations into a quarterly operating rhythm.
Documentation and Governance
Define who interprets requirements, approves content, assigns training, monitors completion, conducts practical evaluation, handles exceptions, and retains records. Legal or compliance owners should review the matrix, but operational managers may own site-specific instruction and evaluation.
Use exception reports before deadlines. Investigate missing assignments, failed notifications, unavailable languages, duplicate employee records, and learners on leave. Document how late or missed training is escalated and remediated.
Preserve course versions and change history. If a law or policy changes, the organization should be able to identify who received the earlier version, who needs supplemental training, and what evidence supports the decision.
Conclusion
Mandatory compliance training requirements in 2026 cannot be reduced to a universal annual checklist. The right program starts with the governing source and maps coverage, role, timing, content, delivery, qualifications, and evidence. Industry and state overlays then determine which employees receive which parts of the program.
Course selection comes after that analysis. Evaluate every option against the documented obligation and combine online learning with practical, interactive, site-specific, or role-specific elements when the source requires them.
Official Legal and Agency Sources
OSHA: Training Requirements in OSHA Standards
OSHA: Bloodborne Pathogens, 29 CFR 1910.1030
OSHA: Powered Industrial Trucks, 29 CFR 1910.178
OSHA: Control of Hazardous Energy, 29 CFR 1910.147
EEOC: Promising Practices for Preventing Harassment
California Civil Rights Department: Sexual Harassment Prevention Training
New York State: Sexual Harassment Prevention Model Policy and Training
Illinois Department of Human Rights: Training FAQs
U.S. Department of Health and Human Services: HIPAA for Professionals




