From mandatory hours to intelligent assessment
The first shift is to invert the default: assess first, train second.
Today, many firms translate obligations into hours and courses, giving everyone in scope the same modules and refreshers. This creates an appearance of control, but only proves that training was completed, not that employees can understand, apply or challenge what they have learned.
Luxembourg’s regulatory framework already points in this direction. Under MiFID II, the CSSF requires firms to ensure and demonstrate that relevant staff have the knowledge and competence needed for their roles. CSSF Circular 17/665 implements ESMA’s Guidelines for the assessment of knowledge and competence and reinforces the obligation to evidence competence and maintain records for supervisory review.
This points to a more mature model: an annual knowledge and competence check-up for relevant roles and topics. HR, Compliance and business leaders define what each role must know and do, then translate this into structured assessments, scenario-based checks, or manager-supported reviews. Where evidence is strong and stable, full generic training can be reduced or replaced by short refreshers or updates. Where evidence shows gaps, deterioration or new exposure, targeted training is triggered.
This is not about lowering standards. It is about raising the quality of evidence.
For stable, knowledge-heavy topics, a well-designed assessment can be more demanding than passive attendance. If test-out options are used, the bar should be higher than simply completing a generic e‑learning and aligned with the institution’s risk appetite, regulatory obligations, and internal control expectations. The point is not to let people avoid learning, but to stop assuming everyone needs the same intervention every year.
This distinction is essential. Some topics can be tested; others must be experienced, discussed and practiced. Culture, ethics, conduct, leadership judgement, and client behavior cannot be reduced to quizzes, they require discussion, scenarios, coaching, and ongoing reinforcement.
A smarter model does not treat all compliance learning equally. It differentiates between knowledge that can be evidenced, judgement that must be practiced, and behaviors that must be reinforced over time.
That is where the control value of learning improves. Leaders see not just who completed training, but where competence is strong, where it is deteriorating, and where risk may be concentrated.
From catalogs to precision development
The second shift is to move from catalog logic to precision development.
People in the same role do not start from the same place. They differ in technical depth, client exposure, confidence, career ambition, language capability, digital maturity or regulatory experience. Yet many learning paths still assume a standard learner, sequence, and pace.
That is no longer sufficient.
A stronger model connects four elements: the role, the skills, the evidence available, and the development actions needed. HR defines core capabilities for roles, mobility, promotions, and strategic priorities. Compliance and Risk specify where regulatory evidence is required. Managers add business reality, including team priorities, performance signals, upcoming changes, and operational pressure. Employees bring their own confidence, ambition and development needs.
The result is not a “learning journey” for the sake of it, but a targeted development plan that answers four questions:
- What does this person need to know or do in this role?
- What evidence shows they can do it?
- Where are the gaps or risks?
- What is the most efficient development action to close them?
This approach reshapes HR and technology. HR moves from publishing catalogs to curating development building blocks that can be assembled around real needs. Technology moves from being a content repository to a connector of signals: assessments, performance feedback, career aspirations, role requirements, and emerging skills.
AI can scale this, but only on solid foundations. Without clear skill definitions, reliable data, governance, transparency, and employee literacy, AI will simply generate weak assumptions faster. Used responsibly, however, it can help turn role, skill, and assessment data into more continuous, targeted recommendations.
The Luxembourg market shows why this shift is urgent. A recent ABBL/House of Training survey of 147 financial sector professionals found that eight out of ten respondents already use AI regularly or occasionally, yet 66% have never had dedicated AI training and only 5% report a formal AI strategy.
Most respondents came from Risk, Compliance and Audit, followed by Operations and IT/Data, the very functions where AI use, governance, and control will converge. This is not just a training gap; it is a readiness gap, where usage outpaces structured capability.
Catalog-led learning cannot keep up. Financial institutions need a precise model that distinguishes who needs awareness, hands-on practice, governance training, and technical depth, and who must make decisions on AI risk.
Redesign the operating model, not only the curriculum
The third shift is governance.
A more precise learning model will fail if it is treated as a Learning and Development initiative only. Clear collaboration across HR, Compliance, Risk, managers, and employees is essential.
HR is the architect. It translates regulatory requirements, business priorities, and role expectations into a clear framework: what is mandatory, what is recommended, what can be evidenced through assessment, what requires discussion-based reinforcement, and what counts as sufficient evidence. HR must also keep the model usable: simple to run, defensible to regulators, and credible for employees.
Compliance and Risk are not just reviewers; they are design collaborators. They help determine where evidence is required, where training records matter, how regulatory expectations evolve, and where competence gaps could become control weaknesses. In financial institutions, learning is part of governance, offering a way to prove that people can perform regulated activities responsibly.
Managers are the integrators. They translate business reality into development priorities, validate whether plans fit the role and timing, protect time for learning, and reinforce application on the job. They are also the main bottleneck if overloaded, inconsistent, poorly equipped to review development or not held accountable for people management. This is not just an HR perspective.
In the UK, the Financial Conduct Authority’s (FCA) guidance on training and competence defines competence as the skills, knowledge, and expertise needed to perform a role. It expects firms to review competence and training needs regularly, monitor and assess training effectiveness, test knowledge, follow up weaknesses, reassess competence, and use results to shape supervision levels. This is a useful comparator for Luxembourg, showing that thinking moves towards evidence, effectiveness, and accountable supervision.
Employees also need a more active role. They cannot remain passive recipients of annual assignments. They need to engage seriously with assessments, reflect honestly on their capability and ambition, and take ownership of agreed development actions.
In return, the organization must make the model worth engaging with. If employees see assessment as another compliance mechanism, they will comply superficially. If they see it as an opportunity for more relevant development, better mobility conversations, and less repetitive training, the dynamic changes.
The future model is therefore not simply individualized learning. It is shared accountability: HR designs the system, Compliance and Risk strengthen its defensibility, managers make it operational, and employees own their part of readiness.