ISO/IEC 27001 Annex A 6.3: Why Awareness Training Now Has to Prove It Reduces Human Risk

Table of contents
Subscribe to newsletter
KEY TAKEAWAYS
- A.6.3 covers more than your employees. Personnel and relevant interested parties, including contractors and outsourced help desks, must receive awareness, education, and training suited to their role, plus regular updates when policies change.
- The 2022 wording now applies to every certified organization. The transition period for 2013 certificates ended on October 31, 2025, so auditors assess programs against ISO/IEC 27001:2022 and its ISO/IEC 27002 guidance.
- Awareness, training, and education are separate layers. Treat them as distinct programs with their own content, audience, and measure of success.
- Attackers have moved to the phone. With the human element in 62% of breaches and help desk impersonation behind 13% of attacks, training must cover voice, SMS, and chat as well as email.
- Auditors want proof of effectiveness, not just delivery. A strong evidence trail maps training to roles, includes everyone in scope, tracks policy updates, and shows whether behavior actually changed.
- Human Risk Intelligence turns training into measurable risk reduction. It connects training, phishing, identity, and dark web exposure data, so you can target training by individual risk and show high risk users and toxic combinations falling over time.
ISO/IEC 27001 Annex A 6.3 requires organizations to give employees, and relevant interested parties such as contractors, security awareness, education, and training suited to their respective roles, plus regular updates when policies change. In 2026, that clause faces its toughest test yet. The human element appears in 62% of breaches, third parties in 48%, and attackers are phoning IT help desks to bypass multifactor authentication. This article explains what auditors expect under A.6.3, why completion rates fall short as evidence, and how Human Risk Intelligence connects training, phishing, identity, and dark web exposure data to prove that human risk is actually falling.
What is ISO/IEC 27001 Annex A 6.3?
ISO/IEC 27001 Annex A 6.3 is the people control that requires an organization to give its personnel, and relevant interested parties, information security awareness, education, and training appropriate to their job function, together with regular updates whenever the information security policy, topic specific policies, or procedures change. It sits in the people controls theme of ISO/IEC 27001:2022 and replaces control A.7.2.2 from the 2013 edition.
The difference between the two editions matters more now than it did a year ago. The transition period for certificates issued against the 2013 edition ended on October 31, 2025, which means every certified organization is now assessed against the 2022 wording and its companion guidance in ISO/IEC 27002:2022. That guidance describes a structured program aligned with the organization's security policy and topic specific policies, delivered periodically, extended to new starters and to people moving into new roles, and assessed for effectiveness once delivered.
Awareness, Education, and Training are Three Different Layers
The control names three activities, and auditors increasingly expect organizations to treat them as distinct. Awareness is broad and aims to change attention and reflexes across the whole workforce. Training builds specific skills that particular roles need to perform securely. Education builds deeper, specialist understanding for the people who design, operate, and defend your systems.

How Annex A 6.3 Relates to Clauses 7.2 and 7.3
Annex A 6.3 does not operate alone. Two mandatory clauses in the main body of the standard shape what it must deliver, and auditors often trace a single finding across all three.

Why Does the Awareness Training Clause Matter More in 2026?
The clause matters more because people remain the most dependable way into an organization, and attackers have changed the channels they use to reach them. Verizon's 2026 Data Breach Investigations Report, drawn from more than 22,000 confirmed breaches across 145 countries, found the human element in 62% of breaches. IBM's 2026 Cost of a Data Breach Report found that phishing, including voice and SMS phishing, was the most common initial attack vector for the fourth consecutive year, present in 17% of breaches at an average cost of $5.29 million.

Two further details from these reports change what a training program needs to cover. IBM found that attackers used social engineering such as impersonating help desk staff in 13% of attacks, at an average cost of $5.23 million. And for the first time, IBM reported that one in four malicious breaches was AI enabled, with deepfake impersonation the largest category and an average cost of about $6 million.
Attackers Have Moved from the Inbox to the Phone
The most instructive incidents of 2026 did not start with a malicious attachment. In January, Google's Mandiant researchers described a campaign linked to the ShinyHunters extortion group in which callers posed as internal IT staff, told employees their MFA settings needed an update, and directed them to branded lookalike login pages. Victims entered their single sign on credentials and live MFA codes, the attackers registered a new MFA device, and data was then taken from connected cloud applications for extortion. Organizations publicly linked to the wave included Betterment, SoundCloud, and Crunchbase.
In March 2026, identity protection company Aura disclosed that a targeted voice phishing call against one employee gave an attacker access to roughly 900,000 records from a marketing database. The same month, Hasbro detected unauthorized access to its network through a compromised employee account; the company later estimated the incident's revenue impact at about $25 million.
Regulators have noticed. On February 6, 2026, the New York State Department of Financial Services issued an advisory on an ongoing campaign in which attackers impersonate IT help desk staff, often with spoofed caller ID, to steal credentials. Its recommended mitigations were identity verification procedures that do not rely on caller ID, and targeted awareness training on exactly this technique.

Your workforce includes people you do not employ
Annex A 6.3 deliberately extends beyond employees to relevant interested parties, and 2025 showed why. Marks & Spencer confirmed that attackers entered its systems through social engineering at a third party supplier. Online sales were halted for 46 days and the retailer put the hit to operating profit at around £300 million.
The pattern is widening. Verizon's 2026 DBIR found a third party involved in 48% of breaches, a 60% increase on the prior year. For managed service providers and outsourced service desks, this cuts both ways. They are interested parties in every client's ISMS, and their own technicians hold exactly the reset privileges that attackers call to exploit. An A.6.3 program that stops at the payroll boundary leaves the most frequently abused door unguarded.
Shadow AI is the newest gap in training content
Verizon found that 45% of employees now regularly use AI tools at work, up from 15% a year earlier, and that 67% of users accessing AI services on corporate devices did so through personal, noncorporate accounts. IBM's figures point the same way: unapproved employee AI use was involved in 43% of AI related incidents, up from 20%, and 68% of breached organizations had no governance in place to manage AI or detect shadow AI.
Most organizations have responded by writing an acceptable use policy for AI. Under Annex A 6.3, writing it is only half the job. The control requires regular updates on topic specific policies as relevant to each role, so an AI policy that people have never been trained on is an A.6.3 gap as well as a data leakage risk.
What Do Auditors Look For under Annex A 6.3?
Auditors look for evidence that the program is planned, relevant to each role, actually delivered to everyone in scope, kept current as policies change, and assessed for whether it worked. The standard does not prescribe a format, but a mature evidence trail usually includes the following.
- A training and awareness plan that maps content to roles and risk, rather than listing a single course for all staff.
- Delivery records for everyone in scope, including contractors, temporary workers, and outsourced teams with access to systems or data.
- Joiner and role change triggers showing new starters and people moving into sensitive roles are trained before or soon after they gain access.
- Policy update communications proving that changes to the security policy and topic specific policies reached the people they affect.
- Effectiveness measures that go beyond attendance, such as simulation trends, reporting rates, and changes in individual risk.
- Management review inputs showing leadership sees the results and acts on them.
How Does Human Risk Intelligence Strengthen Annex A 6.3 Compliance?
Human Risk Intelligence strengthens A.6.3 by connecting the signals that already describe each person's risk, scoring that risk at the individual level, directing training to where it will reduce the most exposure, and measuring whether it did. The result is an evidence trail that answers the effectiveness question directly.
Most organizations already hold the data. Training records sit in one platform, phishing simulation results in another, identity and MFA status in a third, dark web credential exposure somewhere else, and policy acknowledgments in their own repository. Individually, each tells a partial story. Brought together, they show which people combine influence, access, weak hygiene, and exposed credentials, which is precisely the overlap attackers look for when they choose who to call.

From Job Function to Risk Profile
The control asks for training appropriate to job function. Human Risk Intelligence lets organizations go one step further and tailor training to each person's actual risk profile. Two people in the same role can present very different exposure. A finance analyst with strong MFA, no exposed credentials, and a clean simulation history needs a different intervention from a finance director whose password appeared in a breach database last quarter and who has failed two voice simulations.
Evidence that Speaks to Auditors, Insurers, and the Board
When training decisions are driven by risk data, the same data becomes the proof. Instead of presenting an auditor with a completion report, a security leader can show the number of high risk users falling quarter by quarter, reporting rates rising across email and phone, and toxic combinations being closed. That evidence also answers the questions cyber insurers and boards increasingly ask about how human risk is being managed.
How to Build an Annex A 6.3 Program that Holds up in 2026
Build the program as a cycle: define who is in scope, baseline their risk, deliver layered content, measure outcomes, and feed the results into management review. The six steps below follow that order.

What Annex A 6.3 really asks of security leaders in 2026
ISO 27001 Annex A 6.3 asks a simple question: do the people who handle your information know how to protect it? In 2026 that question has sharpened. The organizations best placed for their next audit, and their next vishing call, are those that treat A.6.3 as a risk reduction program rather than a training obligation. They tailor content to role and to individual risk, cover contractors and service providers, test the channels attackers really use, and prove effectiveness with outcome data. Human Risk Intelligence is what connects those pieces, turning awareness training from something you can show you did into something you can show worked.
Frequently Asked Questions
- Is security awareness training mandatory under ISO/IEC 27001?
Yes, in practice. Clause 7.3 requires people doing work under the organization's control to be aware of the security policy, their contribution to the ISMS, and the implications of not conforming. Annex A 6.3 is technically selected through risk assessment and the Statement of Applicability, but it is almost never excluded because Clause 7.3 cannot be met without some form of awareness program.
- How often does ISO/IEC 27001 require awareness training?
ISO/IEC 27001 does not set a fixed frequency. The control requires training appropriate to job function plus regular updates when policies and procedures change, and ISO/IEC 27002 guidance calls for a periodic program. Auditors increasingly expect ongoing activity, onboarding and role change triggers, and a frequency that reflects the organization's risk rather than a single annual course.
- Do contractors and suppliers need training under Annex A 6.3?
The control covers personnel of the organization and relevant interested parties. Contractors, temporary staff, and outsourced service desk teams with access to your systems or data are usually in scope, either trained directly or covered by contractual training obligations that you verify.
- Do phishing simulations count as evidence for Annex A 6.3?
Phishing simulations are strong supporting evidence because they test behavior rather than knowledge. They are most persuasive when they cover the channels attackers actually use, including voice and SMS, and when results feed targeted follow up training and trend reporting.
- What is the difference between Clause 7.3 and Annex A 6.3?
Clause 7.3 sets the outcome: people must be aware of the policy and their responsibilities. Annex A 6.3 describes the control that achieves it: a structured program of awareness, education, and training tailored to job function, with regular updates when policies change.
BOOK A DEMO
See Human Risk Intelligence in action
A 30-minute walkthrough of how to cut human risk across your users, tailored to MSPs and IT teams.
Subscribe to newsletter
Discover how professional services firms reduce human risk with usecure
See how IT teams in professional services use usecure to protect sensitive client data, maintain compliance, and safeguard reputation — without disrupting billable work.
Related posts
Explore more insights, updates, and resources from usecure.



