A metric that measures attendance, not capability
Completion rates show whether a training activity happened. They do not, on their own, demonstrate whether someone can perform a particular task under realistic conditions. Keep completion reporting, but add practical evidence where the role warrants it. NIST NICE Framework: work-role and task vocabulary
Define the decision the metric should support
A board or committee may use readiness evidence to discuss resilience, investment and unresolved role gaps. This is a proposed governance practice, not a claim that every regulator mandates a particular workforce score or reporting cadence.
What a readiness metric looks like, as distinct from a completion metric
A role-readiness baseline: what specific judgement or action does each role need to be capable of in a security-relevant scenario, defined before measuring anything, rather than reporting generic training completion against no defined standard.
Scenario-based assessment evidence: whether people have been tested against a practical, realistic scenario relevant to their role, not only assessed via a multiple-choice knowledge check at the end of a training module.
A trend line, not a single snapshot: whether readiness is improving, flat or declining over successive assessment cycles, which is a more useful governance signal than a single point-in-time percentage.
Gaps named specifically, by role or team, rather than reported as an aggregate organisational average that can obscure a serious gap in one critical function behind a healthy number everywhere else.
Making this a genuine governance item, not a training-department report
The practical shift is treating workforce readiness evidence the same way technical control evidence is treated: reviewed by the board or a board committee on a defined cadence, with named ownership for closing identified gaps, rather than surfacing only as an HR or L&D update disconnected from the broader risk conversation.
Where this connects to a broader programme
Depending on scope, this typically starts with a role and readiness baseline — mapping current skills against the judgement each role actually needs to exercise — which is the same starting point whether the immediate driver is a board reporting gap, a placement or graduation outcome, or a genuine capability-building priority.
Define the measure before running the exercise
The NICE Framework supplies a vocabulary for work roles, tasks, knowledge and skills. It does not prescribe the scoring model below. This is an illustrative assessment design to adapt and validate for the organisation. NIST NICE Framework: work-role and task vocabulary
- Choose one role and task: for example, a helpdesk operator handling an account-recovery request with conflicting identity evidence. Define the safe action, required escalation and evidence trail before participants see the scenario.
- Use a fixed rubric: 0 means not demonstrated; 1 means completed with assistance; 2 means completed independently to the agreed standard. Mark safety-critical actions separately so a high total cannot conceal an unauthorised reset.
- Publish the denominator. Independent readiness rate equals participants meeting all required criteria without assistance divided by participants assessed. Also report how many eligible staff were not assessed; do not present a small volunteer sample as the entire workforce.
- For illustration only, if 18 of 24 assessed staff meet the criteria, the observed rate is 75%. If 40 staff were eligible, assessment coverage is 60%. Report both figures and the scenario scope; neither proves readiness across all incidents.
- Calibrate assessors on sample responses, record assistance and use an equivalent scenario for retest. If the scenario difficulty, role mix or scoring changes, explain the break in comparability rather than presenting a clean trend line.
Report the decision alongside the score: which task needs practice, who owns the intervention and when it will be reassessed. Share individual results only with people who need them; board reporting can normally use appropriately grouped information. Readiness evidence should support improvement, not encourage staff to hide uncertainty or avoid escalation.

