Trust and recognition centre

The proof behind what we do

Choosing a training vendor is a reputational decision. Everything your due diligence team needs to check before working with us is here, and the full pack is one email away.

One place for your reviewer to work from, and a named contact when they need more.

Compliance, Done Right. GDPR aligned. Faculty to doctorate level. Regulated content updated within 30 days of a change in the law.
1 dayto send the pack

What is in the due diligence pack

  • Privacy notice and lawful bases
  • Data processing agreement
  • Sub-processor list and security summary
  • Certificates and recognitions in scope
  • Accessibility statement and insurance
One named compliance contact for follow-ups
What we are

A specialist compliance training institute for UK and EU employers

We develop the courses and the evidence behind them, quality-assure the result, and keep it current as the law changes. We list every recognition and partnership with its scope, and we never claim standing we do not hold.

Recognised, working with and aligned to

FSB member Malta Chamber of SMEs CIPD CPD Certification Service AGRC GDPR [ISO 37301 aligned]
Who this is for

Two teams, one page

For your L&D and HR team

  • Learning built to change performance, not just to be completed
  • Written to your jurisdiction and kept current to the law
  • Certificates issued so your records stand up to scrutiny

For your compliance and procurement team

  • Personal data held securely, used only as our privacy notice sets out
  • A data processing agreement and a full due diligence pack on request
  • A named contact, and a published complaints and appeals route
Honest by design

What we are, and what we are not

What we do

Develop, quality-assure, and keep it current

We build compliance courses and the evidence behind them, quality-assure the result, and update them as the criteria and the law change, so your workforce always trains on the law as it currently stands.

What we are not

Not the regulator, and no overclaiming

We are a training institute, not a regulator or an awarding body. Where a qualification is awarded by a partner body, we say so. We claim only the standing we actually hold, in scope.

How we keep content correct

The same repeatable route on every course

This is what sits behind the 30-day update commitment.

1

Horizon-scan

We watch the regulators and the frameworks for changes in the law.

2

Review

Affected content is reviewed on a set cadence, not ad hoc.

3

Sign-off

A subject-matter expert checks and signs off the change.

4

Update

The course is updated within 30 days of a confirmed change.

5

Show dates

Each module shows when it was last reviewed and when it is next due.

Why Auren is a safe choice

Six reasons your reviewer can rely on

Experienced

We have done the work

Delivering compliance training since 2010, with practitioners and faculty to doctorate level behind every course.

Recognised

Recognised standing, in scope

Recognised partnerships and memberships listed exactly as held, with certificates in the pack. We claim only what we hold.

Current

We keep pace with the law

A regulator and framework horizon-scan, and content updated within 30 days of a confirmed change.

Data safe

Your data is handled properly

Privacy notice, a lawful basis with a clear opt-out, a retention schedule, MFA across the core stack, and a DPA on request.

Secure

Protected by default

Multi-factor authentication, least-privilege access, joiner and leaver controls, and supplier due diligence.

Answerable

There is always a named contact

A due diligence pack ready to send, a named compliance contact, and a published complaints and appeals route.

Security and data questions

Answers your team will ask

What recognition and partnerships do you hold?

We work with recognised bodies including the FSB, the Malta Chamber of SMEs, CIPD, the CPD Certification Service and AGRC, and our faculty are educated to doctorate level. We list each with its scope, exactly as held, and we never claim standing we do not have. The certificates in scope are in the due diligence pack.

Do you have a privacy notice and a lawful basis for processing?

Yes. Our privacy notice sets out how we hold and use personal data. Our business outreach relies on legitimate interests, with an assessment on file and a clear opt-out in every message.

Do you offer a data processing agreement?

Yes, on request. A template is ready and reviewed, and it forms part of the due diligence pack.

Do you use multi-factor authentication?

Yes, across the core stack: the learning platform, the CRM and outreach tools, email, hosting and admin consoles.

Who are your sub-processors?

The current sub-processor list is available on request, and it is included in the due diligence pack.

Do you hold a security certification?

We do not currently hold a formal certification such as Cyber Essentials. We describe the controls we do run: multi-factor authentication across the core stack, least-privilege access, a retention schedule, and a data processing agreement on request. We will state any certification here only once it is held.

How do you keep training content current?

We run a regulator and framework horizon-scan, and affected content is reviewed on cadence, signed off by a subject-matter expert, and updated within 30 days of a confirmed change in the law.

How do you handle a data breach?

We contain, assess and log it, and notify the supervisory authority within 72 hours where the risk to people's rights requires it.

Request our due diligence pack

One email, and we send it within one working day

Everything your reviewer needs, in one place. Send us your own security questionnaire and we will complete that too.

Company details. Auren Institute, specialist compliance management training for employers across the UK and the EU.
UK: 5, Glen Moy, East Kilbride, Glasgow, G74 2BE, +44 7505 706062
Malta: 92, No. 1, St Edward Street, Qormi, QRM 2136, +356 9999 1039
Registration number P1421. VAT number MT20967027.
Last reviewed 3 September 2026.
In scopeonly what we hold

What the pack contains

  • Privacy notice and data processing agreement
  • Sub-processor list and security controls summary
  • Legitimate interests assessment summary
  • Retention schedule
  • Certificates and recognitions in scope
  • Accessibility statement and proof of insurance
  • Policies: quality, integrity, safeguarding, AML, anti-bribery, counter fraud