Most regulated organizations can produce a training record for every employee and a sign-off date for every SOP. What they usually can’t produce is the reasoning behind those records — the method that determined which employees needed which training in the first place. That gap is where audit findings live.

A training needs analysis (TNA) closes it. Done well, it connects a specific organizational requirement, a performance gap, a regulatory change, a CAPA outcome, to a specific training intervention, with evidence that the connection was deliberate rather than assumed. Done poorly, it’s a training wish list dressed up with a document number, and most TNAs are, if we’re honest about it.

This guide walks through a defensible six-step TNA process for regulated environments, the four mistakes that most often turn a TNA into an audit liability, and where a TNA fits inside a broader training and competency program.

What a Training Needs Analysis Actually Is

A training needs analysis is a documented, defensible process that connects organizational requirements to specific training interventions. It exists to answer one question an auditor will eventually ask directly: how did you determine what training your people actually need?

Most organizations answer that question badly, because most organizations don’t run a TNA at all. They run a training wish list. A department manager asks for root-cause-analysis training for their team, it goes straight into the LMS, and nobody checks whether that was ever the actual gap. No data was reviewed. No objective was set. That’s order-taking, and it doesn’t hold up under audit scrutiny, because “the department head asked for it” isn’t a method.

The regulatory pressure to run a real TNA process is genuine, even though most standards never use the term. ISO 9001:2015 Clause 7.2 requires organizations to determine the competence necessary for personnel whose work affects quality (mandatory language, since ISO 9001 is a certifiable standard). ICH Q10 expects a structured approach to performance and process monitoring (guidance language; ICH Q10 isn’t certifiable the way ISO 9001 and ISO 13485 are). Neither standard says “training needs analysis.” Both want the evidence that only one produces.

Step 1: Define the Trigger

A defensible TNA fires in response to a specific event. Valid triggers include a performance gap surfacing in metrics or direct observation, new equipment or a new process going live, a regulatory update, a CAPA outcome, or a deviation trend pointing to a genuine competency issue.

FDA Form 483 observations and warning letters cite training deficiencies constantly, and the usual assumption is that the training itself was bad. Often it isn’t. The training was fine; it was aimed at the wrong problem, because nobody scoped the gap before designing the intervention.

Annual review still has a place in a mature training program. It just isn’t a trigger by itself. It becomes one the moment it surfaces an actual finding worth acting on.

Step 2: Observe Before You Assess

Confirm the problem is actually a training problem before committing resources to training. A recurring deviation in environmental monitoring could reflect a genuine competency gap, a procedure design failure, an equipment limitation, or a hiring mismatch, and training only fixes one of those.

Apply it to the wrong one and nothing changes except the paperwork. There’s now a record showing people got trained, and the deviation is still happening, which is a worse position than doing nothing, because it shows the organization saw the signal and reached for the wrong tool. The TNA functions as a gate here — observation, through root cause analysis, deviation trending, or direct process review, confirms the direction before anyone commits resources.

Step 3: Select the Analysis Type

This is the step most TNAs skip entirely, or run so narrowly it barely counts. Most regulated companies default straight to the individual level, working through performance reviews and competency checklists one person at a time. That’s necessary. It’s also, on its own, a fraction of the picture.

An organizational-level TNA asks whether the entire quality unit understands what a regulation actually requires, not whether individual operators hold a certification. Do staff genuinely understand what the QMSR requires under 21 CFR Part 820, or do they know it exists and stop there? A task-level TNA asks whether every person doing a specific job produces the same result, regardless of who they are. An individual-level TNA asks whether one person needs remedial training after one event.

ISO 13485 Clause 6.2 requires organizations to determine the competence necessary for personnel whose work affects product quality, and to evaluate whether training was effective. It’s framed around role-based competence — the standard itself doesn’t spell out a three-tier structure; the three levels here are a methodology for satisfying that requirement thoroughly. Still, a TNA that only ever looks at individual performance is missing two layers, and so are the auditors who trace a finding upward from one person’s error to a system-level cause.

Step 4: Collect Data That Holds Up

Assessments, direct observations, structured interviews, performance metrics, nonconformance logs, CAPA trend data. All of it counts, as long as it’s documented, because this is what becomes the audit trail. 21 CFR Part 11 applies to training records kept electronically, so a genuinely well-run analysis that lives in spreadsheets and email threads still isn’t defensible. The rigor of the thinking doesn’t make up for the format the evidence is stored in.

Step 5: Link Competency to Goals

Every gap has to map to a specific, measurable objective. “Improve cleanroom behavior” is a wish. You can’t assess it, and you can’t tie it back to whatever gap produced it. “Reduce aseptic technique deviations by 40% within two quarters” is a training objective, because it’s specific, time-bound, and traces directly back to the data that generated it.

This is where the defensibility chain holds or breaks. The gap sets the goal, and from there the goal shapes what the intervention looks like and how you’ll know whether it worked. Skip a measurable objective anywhere in there and you lose the ability to show the training actually closed the gap it was built for, which is exactly what an auditor wants to see when they ask why a specific group got a specific training.

Step 6: Decide Delivery Method and Effectiveness Criteria

Blended learning, e-learning, classroom instruction, structured on-the-job training, all valid, and none of them is the default. The method should follow the need. A TNA that concludes “everyone needs a one-hour computer-based module” regardless of what the gap actually was is a procurement decision wearing a TNA label — a hands-on competency gap wants structured on-the-job training and direct observation, an organizational awareness gap usually wants targeted communication instead. Whatever gets chosen, the way you’ll evaluate it (a follow-up assessment, a deviation-rate check, direct observation again) needs to be decided now, not reverse-engineered later when an auditor asks.

A Worked Example

A manufacturing site’s deviation log starts showing a cluster of documentation errors on batch records, mostly among operators hired in the last six months. That’s the trigger.

The first instinct on the floor is usually “retrain everyone on batch record procedures,” which is exactly the move to resist. Observation shows the errors are consistent in type, missing initials on correction entries mostly, and consistent across new hires specifically. Tenured staff show none of it. That rules out equipment and procedure design and points at a competency gap in documentation practice, specifically among people who haven’t been doing this long. It’s individual- and task-level, not organizational: the org already knows how to do this correctly, a subset of people just hasn’t learned it yet.

The data is the deviation log itself plus a look at what these operators’ onboarding training actually covered. “Improve documentation practices” would be a wish. The actual objective is precise and measurable: reduce correction-related documentation deviations among new hires by 50% within one quarter. And because this is a hands-on skill, the delivery method is on-the-job training with direct observation, with a deviation review at the one-quarter mark to check whether it actually worked.

That’s the whole chain, and it’s what an auditor is looking for when they ask why a specific group got a specific training.

Training Needs Analysis: How to Build a Defensible 6-Step Process

Four Mistakes That Generate Audit Findings

The calendar-driven TNA. Run every year because the SOP says so, whether or not anything changed. It generates training nobody needed, and worse, it teaches auditors what to expect: once they spot one TNA that only exists to satisfy a date, they start digging into everything else in the program.

The copy-paste TNA. The same needs assessment, year after year, new date in the footer. This one is almost always caught, because auditors check version history and metadata as a matter of routine, and a document that’s identical to last year’s down to the typos reads as exactly what it is.

The manager-only input TNA. Training needs decided exclusively by department heads, with nothing from the operators actually doing the work, no cross-reference to performance data, no tie to deviation trends. What you get is a needs assessment built on what leadership assumes the gaps are, which is not the same thing as what’s actually happening on the floor, and that specific gap between assumption and reality is the kind of thing an inspection is built to surface.

The disconnected TNA. TNA documentation sits in a shared drive. Training completion lives in the LMS. CAPA outcomes stay inside the QMS, and none of the three ever talk to each other. When an auditor asks someone to walk a single decision from “here’s the gap we found” to “here’s proof it closed,” the honest answer is often that the work was genuinely done, just not in a way that can be reconstructed. That’s arguably worse than a gap in the work itself, because it looks the same to an inspector either way.

Where a TNA Fits in a Broader Training Program

None of this works as a standalone document. The TNA identifies and documents that training was required. The LMS documents that it was delivered, to whom, and when. The QMS closes the loop with effectiveness checks and, where relevant, CAPA integration, confirming the training actually produced what the TNA’s objective said it should.

Take any one of those three away and the other two get harder to defend. A TNA with no LMS record can’t prove delivery happened. A delivery record with no TNA behind it can’t explain why that group got that training. Effectiveness data that isn’t linked to either one can’t prove the training was actually what moved the number. Most training programs that fail an audit didn’t fail because any one piece was missing. They fail because the three pieces were each done reasonably well and never designed to connect.

Frequently Asked Questions

How often should a training needs analysis be conducted?

Whenever a trigger occurs. Most regulated organizations also run a periodic organizational-level review, usually annual, to catch what doesn’t surface through any single incident.

What’s the difference between a training needs analysis and a skills gap analysis?

People use the terms interchangeably, and they’re related but not identical. A skills gap analysis usually stays at the individual level, comparing what someone can do against what their role needs. A TNA can operate at the organizational, task, or individual level, and it specifically ties each gap it finds to a measurable objective and a chain of evidence an auditor can actually follow from start to finish. A skills gap analysis is a reasonable input into a TNA, one piece of a larger process.

Who should be involved in a training needs analysis?

More than a department head’s opinion. Direct performance data, deviation and CAPA trends, and, where it’s relevant, the people actually doing the work on the floor. TNA data that comes only from managers is one of the most common patterns behind audit findings, for the simple reason that it reflects what leadership believes is happening rather than what is.

Does ISO 9001 or ISO 13485 require a formal training needs analysis?

Not by that name. Neither standard uses the phrase. ISO 9001:2015 Clause 7.2 requires determining the competence necessary for personnel whose work affects quality, and ISO 13485 Clause 6.2 requires that competence be determined and training effectiveness be evaluated, both as mandatory requirements. A structured TNA is simply the practical way most regulated organizations produce that evidence.

What makes a training needs analysis “defensible” in an audit?

Being able to trace one training decision, start to finish: the trigger, the data that confirmed the gap, the objective it became, the delivery method and why, and the evidence it worked. Any missing link and the program is vulnerable at exactly that point, no matter how much training actually happened.

Building the Closed Loop

A TNA is only as strong as its weakest connection: to the LMS that has to show delivery, and to the QMS that has to close the loop with effectiveness evidence. Most regulated organizations run those as three separate systems, which is exactly where the disconnected-TNA problem comes from in the first place.

eLeaP was built around closing that gap: a QMS platform with enterprise LMS integrated at the architecture level, where CAPA-triggered training assignment and document control gating connect directly to the competency records and audit evidence a defensible TNA depends on. See it in action.