The reason is that if you have a security incident, it is useful (and good proof for the auditor) to reinforce people to do the training again, for a refresh of information. Admins should be able to request that employees complete the training again.
