Decide what needs evidence
Not every record needs an uploaded file. Decide which training, checks or development records genuinely need evidence.
This keeps the process proportionate and easier for staff to follow. Write down the accepted evidence types for each requirement, especially where a certificate, observed assessment or signed declaration would prove different things.
Request and review proof
Evidence requests should show who needs to upload what and by when.
Where review is needed, managers should be able to see whether proof is missing, uploaded, rejected or approved. A rejection should explain what needs correcting instead of sending the same file around by email.
Keep review status separate from the underlying training status. An uploaded certificate is not automatically valid evidence until the required checks are complete.
Use one decision for each evidence item
Record whether evidence is not required, missing, supplied, approved or rejected. If it is rejected, keep the reason and the replacement action beside the item.
Do not use a file name as the decision. A document called certificate.pdf does not show whether it belongs to the right person, covers the right requirement, is in date or has been reviewed.
Keep evidence audit-ready
Set retention and access rules for the evidence you collect. Remove duplicates and files kept ‘just in case’; keep enough context to understand the record without collecting unrelated personal information.
SkillProof links evidence to staff and training records, then reports on missing or available proof for review.
Example
Evidence decision table
Keep supply and review status separate so an uploaded file is not mistaken for accepted evidence.
Status
Not required
Meaning
The requirement does not need separate uploaded proof.
Next action
Keep the reason in the requirement definition.
Status
Missing
Meaning
Required proof has not been supplied.
Next action
Request the accepted evidence type.
Status
Supplied
Meaning
A file or record is present but not yet accepted.
Next action
Route it to the named reviewer.
Status
Approved
Meaning
The reviewer accepted it for the organisation's process.
Next action
Retain it under the agreed policy.
Status
Rejected
Meaning
The proof is unclear, incorrect or out of date.
Next action
Record the reason and request a correction.
Official guidance used for this guide
Checked
The ICO does not prescribe one retention period for training evidence. Organisations should be able to justify what they keep, set appropriate retention periods and review or delete personal data they no longer need.
Questions this guide answers
What counts as evidence of staff training?
Evidence may include a certificate, completion confirmation, attendance record, assessment result, declaration, observed-practice record or manager sign-off. The right form depends on what the organisation needs to prove.
Does uploading evidence mean it is approved?
No. Upload confirms that a file or record was supplied. Where review is required, keep uploaded, approved, rejected and missing states separate so managers can see what still needs checking.
How long should training evidence be retained?
There is no universal retention period for every training record. Set a justified period using legal, regulatory, contractual and operational needs, review it regularly and delete personal data that is no longer needed.

