Y6.04.3Training record traceabilitydesignresearch

Training records must be traceable for accident investigation

Aliases: training traceability · qualification provenance · competency evidence chain

What it is

Training record traceability links a person's authority to course revision, target equipment configuration, assessment criterion, result, assessor identity, and time. It is an evidence chain for competence, not an attendance row saying "completed."

This entry is only about what shape a training record needs to be usable after the fact — not about how an investigation should be conducted, which is a separate and larger question. The scope here stops at what a record is missing when it cannot answer the question it is asked.

Why it happens

A question no accident review can skip is: was this person trained and assessed on the version of the procedure and equipment actually in front of them at the time? If a record only says "completed course X in year Y, result: pass," that question cannot be answered — "trained" degrades into a binary label that hides whether the content matched the current version, whether the assessment criteria were stale, or whether the assessment itself was a formality.

Making a record actually usable requires bidirectional linkage. One direction goes from a person to the sequence of equipment and procedure versions they were trained on — answering "which version did this person actually learn." The other direction goes from an equipment version involved in an incident back to every currently qualified person whose training record still points to an older version — used to proactively flag risk before an incident, not to reconstruct it afterward file by file. A one-directional link (only "was this person ever trained") supports neither kind of proactive check.

A common source of broken links is not the absence of any record, but a system migration: when a training-management system is replaced, the version-linkage fields on old records are often not carried forward or backfilled. The result looks complete in the new system — course name, date, marked "pass" — but is missing exactly the one field that says which equipment version or procedure revision it corresponds to. That gap stays invisible during routine use and only surfaces when the record is actually needed to rule out "was this operator correctly trained" as a variable.

Studying it

Audit in both directions: trace backward from current authorization to the original assessment evidence, checking each link is intact; and trace forward from a hypothetical incident task to the relevant training records, counting broken or inconsistent links. A usable completeness metric is whether contemporaneous competence evidence and known limitations can be reconstructed from a given task within a set time limit — a better signal than simply counting how many fields are filled in, since field completeness alone conflates record quality with organization size and digital maturity, a confound that needs to be controlled for separately.

Where it stops holding

A complete record does not prove the training itself was effective — it can only show what happened and what standard was applied, not whether that standard was well designed. Nor should the record become a tool for assigning blame after the fact: its purpose is to rule in or out whether training was adequate, and once it is repurposed as grounds for discipline, records get selectively kept or retouched, which undermines the very traceability it exists to provide.

Access to health and identity information embedded in these records should be limited to roles that genuinely need it. Statutory retention and privacy periods vary by jurisdiction and industry, so no single duration applies universally here — it has to follow the regulation actually in force.

Applying it

  • Record at minimum: equipment configuration/version, the course or material revision the training content matched, the target competency, the assessment result broken down by item (not just "pass"), assessor identity, and a timestamp.
  • Use non-shared personal identifiers for recording results, and keep an amendment trail for any correction so it stays possible to see who authorized what, on what evidence.
  • Treat migration of version-linkage fields as its own acceptance-test item during any system migration — never assume a new system inherits configuration mappings automatically.
  • Regularly rehearse a hypothetical equipment-version upgrade: check whether, within a set time limit, the roster can be searched backward from equipment version to every currently qualified person whose record points to the old version, and forward from a given person to the sequence of versions they were trained on — both directions need to work.

Related

  • Same group: Y6.04.1 Qualification must match the equipment version actually operated · Y6.04.2 Recertification intervals should follow skill-decay rates, not fixed years · Y6.04.4 Systems should automatically restrict access when qualifications expire
  • Nearby: Y7.05 Accident investigation and organizational learning · Y5.01 Operating procedures
  • Search terms: training traceability · qualification evidence · audit trail

Cards in the same group

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/handbook/Y6.04.3