Short Answer: Yes, Absolutely
Auditors will interview staff at all levels. They're checking whether your security awareness programme actually works — not whether it exists on paper.
What Auditors Typically Ask Staff
•"What is the information security policy?"
•"What would you do if you suspected a security incident?"
•"How do you handle sensitive data?"
•"What are the rules about passwords/access?"
•"Have you received security awareness training?"
What Good Looks Like
Training Programme
•Regular security awareness training (at least annual)
•Role-specific training for IT, developers, managers
•New starter induction includes security
•Records of attendance/completion
Awareness Activities
•Phishing simulations
•Security bulletins or newsletters
•Visible security culture (posters, Slack channels, etc.)
•Incident reporting is easy and encouraged
What Fails
•Annual training that nobody remembers
•Generic e-learning with no relevance to your business
•No way to verify understanding
•Training records that don't match employee lists
Pro Tip
Don't just train — test understanding. Even a simple quiz after training creates evidence of awareness and helps retention.