What Role-Based CJIS Training Actually Requires
Most agencies approach CJIS training as a completion problem. Someone needs to finish a course before they can access the system. A record is generated. The requirement is checked.
That reading does not survive AT-3.
The control does not ask whether training happened. It asks whether the right training happened for the right person, at the right interval, covering the right content. Those are four separate questions, and most training programs answer only the first.
The four tiers the policy actually defines
AT-3(d) establishes four categories of personnel, each with progressively broader training obligations:
General users receive awareness training covering rules of behavior, computer security awareness, and the operational implications of handling criminal justice information. That is the baseline. It applies to everyone with access, and it applies annually after initial completion.
IT users carry everything the general tier requires, plus additional topics mapped to specific controls: AC-17 remote access, AU-6 audit log review, CM configuration management, IA identification and authentication, IR incident response, SA-9 external system services, and SI system integrity. An IT administrator and a patrol officer have materially different training requirements under v6.1. A training program that delivers the same course to both is not satisfying either.
Privileged users add a third layer on top of the IT tier: access control, alternate storage site (CP-6), system backup (CP-9), system and communications protection, flaw remediation, and the most recent changes to the CJIS Security Policy. "Most recent changes" is not a static topic. It requires that training content be updated as the policy is updated.
Organizational personnel with security responsibilities carry all three prior tiers plus a fourth: their own role-specific obligations under Section 3.2.9, the Authorized Recipient Security Officer role under any applicable Compact, and findings from prior state and FBI CJIS audits. That last item is specific. If your CSA's audit findings from the last cycle are not part of the training your security personnel receive, the training does not satisfy what the policy asks for at this tier.
AT-3(5) — a separate obligation that most programs miss
AT-3 carries a fifth enhancement with zero-cycle status: training in the employment and operation of PII processing and transparency controls, required for all personnel whose access gives them the ability to view, modify, or make use of unencrypted CJI.
That is not awareness training. It is specific to privacy controls and how CJI is handled in practice. It applies at initial access and annually. The zero-cycle designation means the obligation exists now even though full-compliance enforcement begins in 2027. A program that does not address AT-3(5) for personnel with unencrypted CJI access is leaving a gap.
What AT-4 adds to this picture
AT-4 is the records control. It requires documenting training activity and retaining individual training records for a minimum of three years. The three-year period accounts for the triennial audit cycle — an auditor reviewing an agency's posture will look back across the current cycle, not just at the most recent training event.
AT-4 carries both Existing and Priority 4 markings. Section 1.4 makes existing requirements sanctionable regardless of priority tier. The records obligation has applied since before v6.1 took effect on June 25, 2026. A missing or incomplete training record for the three-year window is an existing-requirement finding.
The gap between completion and compliance
CJIS Online records training delivery. It shows that an individual completed a course on a given date. That record is necessary. It is not sufficient.
What AT-3 requires is that the training matched the person's role, covered the content the policy specifies for that role, and remained current with any changes to the policy since completion. What AT-4 requires is that the record of that training exists and is retained. What CA-7 then requires is that the training metric — specifically AT-4(a) — is being actively monitored as part of a continuous monitoring strategy.
The completion record answers the first question. The CA-7 monitoring obligation asks whether the agency knows, at any given moment, that its training program is current and correctly matched to its current roster and roles.
Those are different questions. Most programs answer the first and assume the second follows.
Sources: CJIS Security Policy v6.1, 06/25/2026 — AT-3 Role-Based Training; AT-3(5) Processing Personally Identifiable Information; AT-4 Training Records; CA-7 Continuous Monitoring; §1.4 Terminology Used in This Document. Requirement Companion Document v6.1.