Most organizations have policies. Most medium-to-large sized organizations have security policies. I hope that yours does! Policies are a cornerstone to a security program. People need to know what to do and policy is that high-level guidance.
Of course, people need to read those policies!
Many organizations will have staff sign a form that states they have read and understood the policies. Sometimes this happens just once. Sometimes it's annually, perhaps at the same time as an annual performance review. Sometimes it's when a person joins the organization, or shortly thereafter.
But does that work? What is the goal? I say that doesn't work! No one has ever "read and understood"!