The CIPD sets no minimum number of CPD hours. What it asks for instead is a minimum of three CPD records a year, written in your own words, and it audits a random sample of members every year to check. For HR professionals used to counting hours, that is a harder standard, not a softer one — you cannot satisfy it by sitting through a day of training and logging seven hours.
This guide covers what the CIPD actually requires, how the annual audit works, what makes a CPD record pass or fail, and the legal duties sitting on HR right now that your development plan should probably cover.
At a glance: Nexis CPD offers £9 CPD-accredited online courses relevant to HR and people management, with a verifiable e-certificate on passing — and any three courses cost £18.

What the CIPD requires
CPD is a condition of CIPD membership at every level, from Foundation to Chartered Fellow. The requirements are:
- A minimum of three CPD records a year. The CPD year runs from January to December.
- Records written in your own words. The CIPD checks for AI-generated text when auditing and asks members to resubmit records that were not written by them.
- Genuine reflection, not description. The recording tool asks what you did, why, what you learned and what you are doing differently as a result.
- Ownership of your own development. Identifying learning needs, planning, acting on the plan, and recording and reflecting on the outcome.
Note what is absent: no hour count, no approved provider list, no points. The CIPD’s Code of Conduct and Ethics describes an ongoing commitment to development expected of all members regardless of level, and the records are the evidence of it.
The annual audit
The CIPD runs an annual audit by sampling members at random. If you are selected:
- you are notified by email
- you are asked to submit three CPD records
- you are given around two months to submit them
Being selected is not an accusation. It is a sample. But it does mean the records need to exist before the email arrives, which is the practical argument for logging as you go rather than reconstructing a year in a fortnight.
The AI check deserves a line of its own. The CIPD asks for reflection in your own words and will ask for resubmission where records appear not to be. Given that the entire value of a reflective record is that it captures your thinking, a generated one defeats the purpose as well as failing the audit.
Why “no hours” is harder than hours
An hours target is easy to satisfy and easy to fake: attend, sign in, log the time. A reflection standard cannot be met by attendance alone. You have to be able to say what changed.
That has a useful consequence. The activities that produce strong CPD records are often the ones already in your week:
- a grievance or disciplinary case that made you rethink how your policy reads in practice
- a tribunal decision or legislative change you had to work out the implications of
- redesigning a process — onboarding, absence management, pay review — and seeing what the redesign exposed
- coaching a line manager through a difficult conversation and noticing what they actually needed from you
- a course or webinar, where the record captures what you applied afterwards
The test the CIPD applies is the same in each case: what did you learn, and what are you doing differently?
A worked example
The difference between a weak and a strong record is easiest to see side by side.
Weak: “Attended a webinar on the preventative duty for sexual harassment. Useful session covering the legal background and what employers need to do. Will share with the team.”
Strong: “Attended a webinar on the preventative duty because our harassment policy had not been reviewed since before October 2024 and I was not confident it evidenced reasonable steps. I had assumed our annual e-learning was sufficient. The session made clear that a risk assessment is expected and that reactive complaint handling does not discharge the duty. I have since drafted a harassment risk assessment covering our two highest-risk settings — the night shift at the depot and client hospitality — and put a proposal to the SLT for targeted manager briefings rather than a single all-staff module. I also changed how I advise managers to record informal concerns, because the current practice leaves no trail if a pattern develops.”
The second one takes four minutes to write and would pass any audit, because it shows a gap, a correction to a prior assumption, and specific changes in practice.
A yearly rhythm
Three records a year is the minimum, and a quarterly habit clears it comfortably:
- Q1: self-assess against the Profession Map, set two or three development priorities for the year, and write the first record against something you are already dealing with.
- Q2 and Q3: one record each, ideally from live work rather than a course — a case, a process change, a piece of advice that did not land as expected.
- Q4: a fourth record and a short review: what changed in your practice this year, and what that suggests for next year.
Four records rather than three gives you margin, and means an audit request is a matter of copying existing entries rather than a scramble.

Writing a CPD record that stands up
A record that survives an audit usually has four parts:
- What you did, briefly. One or two sentences. The activity is context, not the point.
- Why you did it. The gap or need that prompted it, ideally linked to your role or the organisation’s priorities.
- What you learned. Specific, including anything that surprised you or contradicted what you expected.
- What you are doing differently. The concrete change — a clause redrafted, a conversation handled differently, a manager briefed, a process altered.
Length is not the measure. Three honest paragraphs about one real situation beat a page about a conference you attended and forgot.
Using the Profession Map
The CIPD’s Profession Map describes the knowledge, behaviours and specialist areas that make up the profession, and its self-assessment tool is designed to show where you sit against them. Used properly, it turns “I should do some CPD” into a specific plan: assess, find the gaps that matter for the role you have or want, and build development around those rather than around whatever training happens to be offered.
It is also the natural route to membership upgrades, because an upgrade is assessed against the same standards rather than against hours accumulated.
The legal duties your CPD should probably cover
Separate from CIPD membership, HR carries organisational duties that have moved in the last two years. Three areas come up repeatedly:
Preventing sexual harassment
Since 26 October 2024, employers have had a preventative duty under the Worker Protection Act to take reasonable steps to prevent sexual harassment of their workers. This is a proactive duty: it is not enough to respond well to complaints. Tribunals can uplift compensation in successful sexual harassment claims where the duty has not been met, and the EHRC can enforce it. Training, policy and risk assessment are the visible evidence that reasonable steps were taken. See our guide to sexual harassment in the workplace.
Equality, diversity and inclusion
The Equality Act 2010 makes employers liable for discrimination and harassment by their employees in the course of employment, unless they can show they took all reasonable steps to prevent it. That defence is evidenced, in part, by training that people actually completed — see what EDI means in practice.
Employee data
HR holds the most sensitive personal data in most organisations: health information, disciplinary records, pay, references, right-to-work documents. UK GDPR duties around lawful basis, retention, access requests and breach reporting fall squarely on the team handling them — see our GDPR guide.
CPD for you, and training records for everyone else
HR usually owns two distinct things: personal CPD, and the organisation’s training evidence. They get confused, and the second is where the legal risk sits.
When a tribunal asks whether reasonable steps were taken, or an inspector asks whether staff were competent, the answer comes from the organisation’s training records — who completed what, when, and whether it was refreshed. Dated, verifiable certificates matter for that purpose in a way they never do for your own reflective log.
It is worth keeping the two systems separate in your own mind. Your CPD record is about your thinking. The training record is about the organisation’s evidence. Neither substitutes for the other.
Membership levels and upgrading
CIPD membership runs from Foundation through Associate to Chartered Member and Chartered Fellow. Upgrades are assessed against the standards in the Profession Map — the knowledge, behaviours and impact expected at each level — rather than against a volume of training.
That makes ongoing CPD records doubly useful. The same reflective entries that satisfy the annual requirement are the raw material for an upgrade application, because both are asking the same question: what do you do, at what level of complexity, and with what effect on the organisation? Members who log continuously find upgrading straightforward. Members who log nothing spend weeks reconstructing evidence.
Keeping up with legal change
Employment law moves faster than most other compliance areas, and HR is usually the function expected to notice first. Rather than trying to remember everything, it is worth having a small set of primary sources you check regularly:
- Acas for codes of practice and practical guidance, which tribunals refer to
- The EHRC for equality and harassment guidance, including the technical guidance behind the preventative duty
- GOV.UK and legislation.gov.uk for the legislation itself, rather than a summary of it
- The ICO for employment practices and data protection
Checking a primary source takes a few minutes and settles the question. Reading a provider’s summary of a change — including ours — tells you what someone else understood it to mean.
Five things that weaken an HR CPD log
- Only recording formal training. The richest learning in HR comes from cases, not courses, and the CIPD’s framing explicitly allows for it.
- Describing rather than reflecting. If a record has no sentence beginning “as a result”, it is a diary entry.
- Writing everything in December. Reconstructed reflection is thin, and an audit request can arrive before you get to it.
- Generated text. The CIPD checks, and the record is worthless to you anyway.
- Confusing your CPD with the organisation’s training records. They serve different purposes and are evidence for different audiences.
Building a training matrix that survives scrutiny
For the organisation’s side of the job, a training matrix is simply a grid of who needs what, when they last did it, and when it is next due. It is unglamorous and it is the single document most likely to be requested when something goes wrong.
A defensible matrix usually has four columns beyond the name: the topic, the date completed, the evidence reference (certificate number or file), and the review date. Two refinements make it far more useful:
- Tie each topic to why it is there — the duty, policy or risk assessment it answers. A matrix that cannot explain why a topic is on it tends to accumulate training nobody needs while missing the training that matters.
- Record role changes. Most gaps appear when someone moves into a role with new risks and keeps only their old training. New responsibilities are exactly the trigger for fresh training in most compliance regimes.
Refresher intervals are usually a matter of policy rather than law. Where you set one, set it for a reason you could explain, and apply it consistently — an interval that is ignored is worse evidence than no interval at all.
Which courses suit an HR team?
The set that maps onto the duties above, and doubles as evidence for the organisation:
- Sexual Harassment in the Workplace — the preventative duty and what reasonable steps look like
- Equality, Diversity and Inclusion Awareness — the Equality Act 2010 in daily practice
- Data Protection and GDPR Awareness — the employee data HR holds
Those three together cost £18 rather than £27, because any three courses trigger the pay-for-2-get-3 offer. Add them to the cart and the discount applies automatically. Teams often add Bullying and Harassment, Conflict Management or Mental Health Awareness for Managers for line managers.
An honest note on how these count for you personally: completing a course is an activity, not a CPD record. What the CIPD wants is the reflection afterwards — what you learned and what you changed. The certificate evidences the activity; the record is still yours to write.
Frequently asked questions
How many CPD hours do CIPD members need?
None. The CIPD does not set a minimum number of CPD hours. It asks members to submit a minimum of three CPD records a year, with the CPD year running from January to December, and to take responsibility for identifying their own learning needs, planning, acting and reflecting. The standard is reflection and application rather than time served.
Does the CIPD audit CPD records?
Yes. The CIPD carries out an annual audit by selecting a random sample of members. Those selected are notified by email, asked to submit three CPD records, and given around two months to do so. Selection is a sample rather than an accusation, but the records need to already exist, which is the practical case for logging as you go.
Can I use AI to write my CIPD CPD records?
No. The CIPD requires reflections to be in your own words and checks for AI use when auditing CPD records, asking members to resubmit any records that were not written by them. Beyond the audit risk, a generated reflection defeats the purpose, because the value of the record is that it captures your own thinking and what you changed as a result.
What counts as CPD for an HR professional?
Almost anything relevant that you can reflect on and apply: handling a grievance or disciplinary case that changed how you read a policy, working through a legislative change or tribunal decision, redesigning a process, coaching a line manager, courses and webinars, reading and professional networks. The CIPD's test is what you learned and what you are doing differently, not the format of the activity.
What is the employer duty to prevent sexual harassment?
Since 26 October 2024 employers have had a preventative duty under the Worker Protection Act to take reasonable steps to prevent sexual harassment of their workers. It is proactive, so responding well to complaints is not enough on its own. Tribunals can uplift compensation in successful claims where the duty has not been met, and training, policy and risk assessment are the visible evidence that reasonable steps were taken.
Is a CPD certificate enough for a CIPD CPD record?
No. The certificate evidences that you completed an activity. A CIPD CPD record is the reflection that follows: why you did it, what you learned, and what you are doing differently as a result. Completing a course without writing the reflection leaves you with evidence of attendance and no CPD record.
HR and compliance courses
£9 per course. CPD accredited, 100% online, verifiable e-certificate. Pay for 2, get 3 — any 3 courses for £18.
This article is general information, not legal advice or a statement of CIPD policy. A CPD awareness course is not a CIPD qualification and does not by itself confer or maintain membership. Employment law changes; always confirm current duties with the CIPD, Acas, the EHRC or your own legal advisers.
