We're a fairly small organization with only a few employees and a handful of 3rd parties helping us out with sales, compliance etc.
We have used the "Statement of Acceptance of ISMS Documents". Could that be sufficient for "awareness training"? I mean that they sign this after reading all the documentation? Or we could add a few questions related to the policies that they were required to answer when submitting the statement?
Would this be sufficient? Or is it expected by the auditors that we've bought some online tool to manage this such as the awareness training you and other companies offer?