Compliance Training Courses: Build vs. Buy (How to Decide in 2026)
Here's a number that should end the way most companies think about compliance training.
The typical organization loses about 3 million dollars a year to fraud. Not the scandal-of-the-decade companies. The typical one. And when EY surveyed executives, 42 percent said they could justify unethical behavior to hit a financial target. Nearly half.
The two numbers that frame everything

Now hold that against what compliance training looks like at most companies. An annual click-through course. A quiz everyone passes. A certificate in a folder. A 100 percent completion report that goes up the chain and makes everyone feel safe.
Harvard Business School's Eugene Soltes and Hui Chen, the former compliance counsel expert at the US Department of Justice, studied why this happens. Their conclusion was blunt: most compliance programs fail because companies treat them as box-checking exercises and never measure whether anything actually changed. The training happened. The behavior didn't move. The 3 million dollars walked out the door anyway.
So when someone asks me "should we build our compliance training or buy it," my honest answer is that they're asking the wrong question first. Because the build vs buy debate, the way it's usually argued, is stuck. Every article gives you the same tired pros and cons and ends with "it depends." Nobody tells you what it depends on.
I'm going to fix that. And it starts with an idea I haven't seen anywhere else in this debate.
Compliance training is secretly two different products
Here's the thing everyone misses. When we say "compliance training," we're actually talking about two completely different things wearing the same name. Once you see the split, the build vs buy decision almost makes itself.

Layer 1 is the Certificate Layer. This is OSHA. HAZMAT. HIPAA. Food handler cards. Forklift certification. DOT requirements. Training where the deliverable is the credential itself, issued against a standard written by a regulator, not by you.
Think about what actually matters here:
- Accuracy against the regulation
- Recognition by the issuing authority
- Proof that stands up in an audit
And what doesn't matter? Your company's culture, your hallways, your specific pressures. An OSHA fall-protection course is an OSHA fall-protection course whether you run a bakery or a construction firm. The regulator defined the content. Your job is to deliver it faithfully and document it.
Layer 2 is the Culture Layer. This is harassment prevention that reflects how people actually interact at your company. Ethics decisions under your revenue pressure. Data security in your actual tools. The gray-area judgment calls that happen in your meetings, your Slack, your sales calls.
Here what matters is the opposite:
- Context is everything
- The deliverable isn't a certificate, it's how people behave when nobody's watching
- Generic content is precisely what fails
An employee watching actors in a stock-footage office resolving a conflict that would never happen at your company learns exactly one thing: how to find the skip button.
This is the Soltes and Chen insight wearing different clothes. Box-checking compliance is what you get when you apply Certificate Layer thinking to Culture Layer problems. You bought a generic course, everyone completed it, the box got checked, and the behavior never moved. The failure wasn't that you bought training. It's that you bought training for a layer that can't be bought.
How to buy the Certificate Layer well
For regulatory certifications, buying isn't settling. It's correct. Building your own OSHA course is like printing your own passport. Even if you get every detail right, you've spent enormous effort producing something a recognized provider would have handed you for a few hundred dollars, with the regulatory authority already baked in.
The buy market for this is mature. Providers like Compliance Training Online, a division of 360training that serves over 31,000 organizations, exist precisely for this layer. They carry the full regulatory catalog: OSHA, EPA, DOT, HIPAA, MSHA, EEOC and more, with completion certificates, wallet cards where relevant, and content that gets updated when the regulations change. That last part matters more than people realize. Regulations move constantly, and one of the quiet killers for small and mid-sized businesses is keeping pace with changing employment and safety law using a skeleton crew. When you buy from a serious provider, tracking those changes becomes their job, not yours.
That's it. Buying Layer 1 is a procurement problem, and a well-solved one. Don't overthink it, and definitely don't build it.
How to build the Culture Layer with Nano LMS
Now the layer where buying fails and building used to be too expensive to consider.
The reason companies default to generic Culture Layer content was never that they believed in it. It's that building custom content the traditional way meant weeks of instructional design work per course, and nobody has that. So they bought the generic harassment course, checked the box, and quietly accepted that nobody would remember it by Friday.
That math has changed. Here's what the build actually looks like now:

You build Culture Layer training as scenarios, not lectures. Instead of a module that states your ethics policy, you drop the learner into the moment the policy exists for. The supplier sends a 600 dollar gift the week before you sign the contract. What do you do? The learner chooses, sees the consequence play out, and feels why the policy exists. That's the difference between knowing the rule and owning the decision.
With Nano LMS the build works like a conversation. You describe the situation to the AI the way you'd explain it to a colleague: "Build a scenario where a manager hears a report of harassment secondhand and has to decide what to do, and make the wrong options genuinely tempting." The AI drafts the branches, the consequences, and the feedback. You refine it by chatting. A scenario that used to take a design team two weeks takes an afternoon, and it's set in your world, with your pressures, not stock-footage world.
Then the part Soltes and Chen would insist on: measurement. Because these are decision-based scenarios, you're not tracking who pressed play. You're tracking which choices people make:
One of those numbers is a report. The other is a warning you can act on before it becomes a real case. Certification tracking, expiry, and audit-ready completion records ride along automatically.
That's the Culture Layer built right: your context, real decisions, measured behavior, at a build cost that finally makes custom viable.
The sorting test: how to pick, topic by topic
Take your compliance list and run every item through four questions:
- Who defined the content? A regulator, or your own values and risks?
- What's the deliverable? A recognized credential, or a changed behavior?
- Would this training be identical at your competitor?
- If it goes wrong, what does failure look like? A missing certificate, or a lawsuit born from someone's judgment?

Run a real list through this and it sorts cleanly almost every time:
| Compliance topic | Layer | Decision |
|---|---|---|
| Forklift certification | Certificate | Buy |
| Anti-bribery decisions in your sales process | Culture | Build |
| HIPAA basics for new hires | Certificate | Buy |
| What “patient privacy” means in your clinic’s workflows | Culture | Build |
| Fire safety / OSHA | Certificate | Buy |
| The scenario where a star performer crosses a line | Culture | Build |
Nobody else can build that last one, and no catalog will ever sell it.
Hybrid isn't a compromise. It's the architecture.
Here's where the Two-Layer view pays off completely. Every build vs buy article treats hybrid as the diplomatic middle option. It isn't. Hybrid is simply what a correctly sorted compliance program looks like, because every real company has both layers.

Companies that get this wrong usually get it wrong symmetrically:
- They build what they should buy: reinventing OSHA content at consultant rates, wasted money
- They buy what they should build: checking the harassment box with a generic course while the actual culture problem grows, wasted risk
The two failure modes have the same root: nobody sorted the layers.
What it costs, honestly
Ballpark numbers so you can budget, with the caveat that seat counts and scope move these around.
| BuyCertificate layer | Build traditionallyCulture layer | Build with AI NewCulture layer | |
|---|---|---|---|
| Typical cost | $25–$300 per seat per course | $5,000–$15,000+ per custom course | Platform from free; ~$1 per learner/mo |
| Time to launch | Same day | 4–12 weeks per course | Hours to days |
| Fit to your context | None, by design | High | High |
| Updates | Provider handles regulation changes | You pay again | Edit by chatting |
| What you measure | Completion and certificates | Depends on the build | Decisions and behavior signals |
Read that table with the layers in mind and the strategy is obvious. Buying Layer 1 is cheap and correct. Building Layer 2 traditionally was the thing nobody could afford, which is why everyone bought generic and got box-checking. AI-built scenarios remove that excuse. For most mid-sized companies, the full hybrid program now costs less than what they were already spending on seat licenses for training nobody remembered.
The cost of getting it wrong
One more set of numbers, because the alternative to doing this well isn't zero cost. It's the most expensive option on the table.
- Regulatory penalties: scale into the millions for serious violations, before legal fees
- A single harassment lawsuit: typically six figures to defend, even when you win
- The fraud leak: ~$3M a year for a typical organization when compliance is theater
- The quiet costs: customer trust you don't get back, and good employees who leave cultures where the training says one thing and the hallway says another
Against that backdrop, the entire build vs buy debate is small money. The real risk was never overspending on training. It's spending anything at all on training that doesn't change what people do, and holding a folder of certificates while the behavior that actually sinks companies goes completely unmeasured. That's the box Soltes and Chen warned about, and in 2026 there's no longer a cost excuse for staying in it.
The decision, in one breath
- Sort every compliance requirement into its layer
- Buy the Certificate Layer from a recognized provider and let them chase regulation changes
- Build the Culture Layer as scenarios in your own context, because that's where behavior lives and generic content dies
- Track both in one place
- Measure decisions, not completions
Build vs buy was never really the question. Sorting was. Now you know how to sort.
If you want to see what building the Culture Layer actually looks like, Nano LMS creates branching compliance scenarios from a plain-language description in minutes, with certification tracking and audit-ready records built in. Free to start, no credit card.
R.S Raghavan
Raghav is the Founder and CEO of Animaker, an AI-powered creative technology company trusted by 35+ million users globally. He has built a multi-product ecosystem including Nano LMS, Vmaker AI, Steve AI, Picmaker, and Show, empowering creators and businesses with AI-driven content creation.