What this is
What is an auditor competency record?
What is an auditor competency record?
An auditor competency record is the standing evidence that a named person is competent to conduct internal audits within a defined scope. It holds their auditor training and certificate, the standards trained against, the process areas they know well enough to audit, the audits shadowed, led under supervision and led alone, an evaluation of how those went, and the resulting authorisation with an expiry date. It is a living record, updated as the person is trained and used, not a form completed the day the course finished.
What makes an internal auditor competent?
ISO 19011 clause 7.2 breaks competence into three parts, and all three have to be present. There is generic audit knowledge and skill: how to plan, sample, interview, gather evidence and write a finding. There is discipline and sector-specific knowledge: enough understanding of the process, the standard and the hazards to recognise when an answer is wrong. And there is personal behaviour, which the standard names explicitly and which decides whether the auditor records what they saw when pushed back on.
Who evaluates an internal auditor?
The person managing the audit programme, working from criteria set before the evaluation rather than after it. It should not be the auditor's own line manager, because the point of the audit function is that it reports independently of the areas it examines. The evidence used is the auditor's own output: their reports, the findings raised, how those graded against peers, and whether a lead auditor watched them work.
Scope
When is an auditor competency record required?
This record holds the standing competence of one auditor. Its boundaries blur easily, because three neighbouring templates touch auditor capability from different directions: the course, the assignment, and the health of the programme.
Use this template when
- A person has completed internal auditor training and needs authorising before going on the schedule
- An existing auditor's authorisation is approaching expiry, or their refresher has lapsed
- An auditor is being extended into a new process area or a new standard and the scope needs re-cutting
- A lead auditor has evaluated someone's audit work and the outcome needs recording against them
- A certification or customer audit is due and the audit team's competence has to be evidenced on demand
Do not use it for
- The auditor training course itself, which belongs in Internal Auditor Training (TRN-054) where the syllabus, provider, dates and assessment result live
- Deciding who audits what and when, which belongs in the Internal Audit Programme (CMP-001) and the Audit Plan (CMP-003) where independence is applied to an assignment
- Judging whether the audit programme has enough auditors and enough coverage, which is the Audit Programme Review (CMP-008)
- Evaluating a certification body's own auditors, which is the Certification Body Performance Review (CMP-047) and follows a different framework
- General role competence for operational staff, which belongs in the training records for that role, not in an audit-specific record
Compliance mapping
Which ISO 19011 cl.7 requirements does this satisfy?
Auditor competence is one of the few areas where the standards are explicit. ISO 19011 devotes a whole clause to it, and the management system standards each carry a hard requirement that auditors be selected so the audit process stays objective, which makes this record a certification-audit target rather than an internal nicety.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.7.2.3 | Auditor knowledge and skills, generic and discipline or sector-specific, determined for the audits to be performed | Process knowledge |
| ISO 19011 cl.7.2.4 | Competence achieved through a combination of education, work experience, auditor training and audit experience | Training |
| ISO 19011 cl.7.2.2 | Personal behaviour expected of an auditor, including diplomatic, perceptive, tenacious and decisive | Demonstrated capability |
| ISO 19011 cl.7.3 | Auditor evaluation criteria established, qualitative and quantitative, related to the audits to be conducted | Demonstrated capability |
| ISO 19011 cl.7.5 | Evaluation conducted against the criteria, using records, feedback, interview or witnessed audit | Demonstrated capability |
| ISO 19011 cl.7.2.5 | Audit team leader competence gained through additional audit experience in the leader role under direction | Authorisation |
| ISO 19011 cl.7.6 | Competence maintained and improved through continual participation in audits and professional development | Authorisation |
| ISO 9001 cl.9.2.2 and ISO 45001 cl.9.2.2 | Auditors selected and audits conducted so objectivity and impartiality of the audit process are ensured | Process knowledge |
What it does not cover
- The internal auditor training record, which evidences the course, provider, syllabus and assessment result in TRN-054; this record consumes that evidence rather than replacing it.
- Independence for a specific audit, which is decided when the team is appointed in the audit plan, because a person can be independent of one area and not another on the same day.
- The audit programme's adequacy, which asks whether there are enough competent auditors for the coverage required and belongs to the programme review.
- General competence for the person's operational role, which lives in the training matrix for that job and is a different evaluation against different criteria.
- Certification body auditor qualification, which is governed by ISO/IEC 17021-1 and the accreditation body, and is assessed rather than granted by the client.
Global
Auditor Competency Record requirements by country
Almost nowhere is internal auditor competence a statutory duty in its own right. It becomes enforceable by two other routes: certification schemes that require it as a condition of the certificate, and food and safety regulations attaching competence duties to named roles carrying out control activities.
FSMA Preventive Controls for Human Food, 21 CFR 117.3 and 117.180
Defines the qualified auditor and the preventive controls qualified individual by training or experience, not by certificate.
Where a supplier verification audit is the control, the auditor's technical expertise has to be documented, so the competency record becomes a regulatory record rather than a scheme one.
Management of Health and Safety at Work Regulations 1999, reg.7
Competent persons must be appointed to assist with statutory health and safety duties; no equivalent duty exists for internal auditors.
Internal auditor competence is enforced commercially through UKAS-accredited certification and retailer schemes, where the evidence expected is closer to ISO 19011 than to any regulation.
Regulation (EU) 2017/625 on official controls, Article 6
Competent authorities must carry out internal audits, or have them carried out, subject to independent scrutiny.
That expectation of independently scrutinised audit sets the tone inspectors apply to a business audit function, and an auditor auditing their own department reads badly against it.
Safe Food for Canadians Regulations, SOR/2018-108, preventive control plan requirements
Requires persons carrying out control activities to be competent for the task, with the preventive control plan evidencing it.
Where internal verification is part of the preventive control plan, the auditor's competence is inspectable by CFIA, not only by the certification body.
Food Standards Code Standard 3.2.2A; model WHS Regulations
Statutory competence attaches to named roles such as the food safety supervisor and to competent persons for specified WHS tasks.
Internal auditor competence rides on JAS-ANZ accredited certification rather than legislation, so the certificate is the enforcement point and this record defends it.
ISO 19011:2018 cl.7; IATF 16949 cl.7.2.3; BRCGS Food Safety cl.3.4
Explicit requirements for auditor competence, evaluation and, in the automotive and food schemes, documented competency records.
IATF and the GFSI-benchmarked schemes ask to see the record itself, so a missing or unevaluated record is a finding in its own right.
How to complete it
How to complete an auditor competency record, step by step
The form collects training, experience, evaluation and authorisation. Whether the finished record defends anything depends on four judgements the fields do not force, each a decision about scope rather than a box to tick.
The form says it plainly in its own guidance: an auditor needs audit technique and enough knowledge of the process to know when an answer is wrong. Those are different competences, from different places, and a strong score on one does not compensate for a zero on the other. A quality manager with excellent technique and no maintenance knowledge should show as competent for quality and not for maintenance, which is what the areas competent to audit field is for.
Areas excluded due to independence is the most valuable field in the record, and the one most often left blank because it is optional and the answer feels obvious. It is not obvious to whoever builds the schedule in eleven months. Write the department by name, add the areas where the person owns the procedure, approves the spend or manages the people, and treat it as a hard constraint the programme reads.
Evaluated by lead auditor, findings well evidenced, grading consistent with peers and report quality carry the weight of ISO 19011 clause 7.5, and are worthless as unsupported opinions. Base them on named audits: which reports were reviewed, which findings compared against which peer's grading, whether the lead auditor witnessed a session or only read the output. Grading consistency is a calibration measurement, not an impression, and needs two auditors on comparable scopes to mean anything.
Authorisation valid until, audits per year required to stay current and audits completed this year exist as a set, and only work if the middle one is set honestly. Four to six audits a year keeps technique alive for most internal auditors; two does not. When the count falls below the minimum, the correct outcome is supervised only or a re-evaluation, not a quiet extension of the expiry date, and the record should raise that rather than hide it.
What auditors find
Most common auditor competency record findings
Competency records are rarely absent, because everyone knows the certification auditor asks for them. The findings concern what is inside them, and almost all are visible from the audit reports rather than from the record itself.
| Finding | Clause | What fixes it |
|---|---|---|
| Competence evidenced only by a training certificate, with no evaluation recorded. | ISO 19011 cl.7.5 | Evaluate against criteria set in advance, using the auditor's own reports and a witnessed audit. |
| Auditor authorised for all areas, with no scope stated against process knowledge. | ISO 19011 cl.7.2.3 | Cut authorisation to the areas actually known and record the rest as not yet authorised. |
| Auditor scheduled to audit their own department; independence exclusion field blank. | ISO 9001 cl.9.2.2 | Record the excluded areas by name and block them in the programme rather than relying on memory. |
| Refresher overdue, but authorisation still shown as valid. | ISO 19011 cl.7.6 | Let refresher status drive authorisation, so a lapse suspends rather than warns. |
| No record of shadowed or supervised audits before independent authorisation. | ISO 19011 cl.7.2.4 | Require a stated number of shadowed and supervised audits, and record the audit IDs not a count. |
| Lead auditor authorised without additional experience in the leader role. | ISO 19011 cl.7.2.5 | Evidence audits led under direction first; being the most senior person present is not qualification. |
| Grading inconsistent with peers: one condition raised as an observation by one auditor and a major by another. | ISO 19011 cl.7.3 | Calibrate the team against worked examples annually and record it as part of the evaluation. |
| Auditor completed one audit in the year against a stated minimum of four. | ISO 19011 cl.7.6 | Reduce the auditor pool to the number the programme can keep current, and use those people more. |
| Personal behaviour not assessed; auditor known to withdraw findings after pushback. | ISO 19011 cl.7.2.2 | Assess how the auditor handles challenge, and check whether draft findings survive to the final report. |
| Competency record exists but is not reflected in the matrix used to build the schedule. | ISO 19011 cl.5.5.4 | Make the matrix a view of the records rather than a spreadsheet maintained by hand. |
Case in point
Case in point: two clean years and then four majors
A food manufacturing site ran a full internal audit programme against its scheme standard. Four internal auditors, all with accredited training certificates on file, all with competency records showing training completed, certificate held and authorised to audit. Over two years the programme produced fifty-one audits and thirty-eight findings, none graded above minor, and each annual programme review concluded the system was performing well.
The certification audit raised four majors, two on maintenance and engineering. The auditor then did something the site had not expected: they read the internal audit reports for those areas and found all six had been conducted by the site's own maintenance planner. His competency record showed extensive operational experience and no entry against areas excluded due to independence, because the field was optional and the answer had seemed obvious. His reports were the shortest in the set, and every finding a documentation observation.
Nothing in the record was false. The training was real, the certificate was real, and the operational experience was exactly why he had been chosen. What was missing was the recognition that the knowledge making him useful there made him unusable there, and an evaluation reading his output rather than his credentials. The corrective action was not more training. It was recording the exclusion, swapping maintenance and quality audits between two auditors, and adding a lead auditor review of three reports per auditor per year.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- CMP-006
- Archetype
- Record
- Record ID
- ACOMP-2026-000
- Scoring
- Competency achieved
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011 cl.7
- Links
- Links Worker, Course
- Tags
- Audit, Competency
- Sections
- 5
- Fields
- 42
- Follow up fields
- 3
- Repeating sections
- 0
- Links out
- 4
Header
9 fieldsRecord ID*
Auto sequence. Format ACR-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Completed By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Auditor*
Person ID*
Format PER-0000.
Links to FDN-003 Person ID
Two Things, Both Needed
An auditor needs audit technique and enough knowledge of the process to know when an answer is wrong. Either one alone produces poor audits.
Training
6 fieldsAuditor Training Completed*
- Yes3 pts
- Partly1 pt
- No0 pts
Training Provider
Certificate Held*
- Yes3 pts
- No0 pts
Standards Trained On*
Lead Auditor Qualified*
- Yes3 pts
- No1 pt
Refresher Current*
- Yes3 pts
- Overdue0 pts
Process knowledge
4 fieldsAreas Competent To Audit*
Operational Experience*
- Extensive4 pts
- Some2 pts
- None0 pts
Food Safety Knowledge
- Strong3 pts
- Basic1 pt
- None0 pts
Areas Excluded Due To Independence
Their own department. Record it so the programme never schedules them there.
Demonstrated capability
9 fieldsAudits Shadowed*
Audits Led Under Supervision*
Audits Led Independently
Evaluated By Lead Auditor*
- Yes3 pts
- No0 pts
Findings Well Evidenced*
- Yes3 pts
- Partly1 pt
- No0 pts
Grading Consistent With Peers*
- Yes3 pts
- Mostly2 pts
- No0 pts
Interview Technique*
- Strong3 pts
- Adequate2 pts
- Weak0 pts
Report Quality*
- Clear and evidenced3 pts
- Adequate2 pts
- Poor0 pts
Manages Difficult Conversations*
Auditors get pushed back on. Somebody who folds under pressure records fewer findings than exist.
- Yes3 pts
- Sometimes1 pt
- No0 pts
Authorisation
14 fieldsAuthorised To Audit*
- Yes3 pts
- Supervised only1 pt
- No0 pts
Authorised To Lead*
- Yes3 pts
- Not yet1 pt
Authorisation Valid Until*
Audits Per Year Required To Stay Current
Auditors who audit twice a year lose the skill. Set a minimum.
Audits Completed This Year
Recorded In Matrix*
- Yes3 pts
- No0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Auditor*
Second Signature*
CMP-006 · record IDs look like ACOMP-2026-000 · Links Worker, Course
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The record is easy. What fails around it is the schedule that assigns an auditor to their own department, the refresher that expires without suspending anything, and the competency matrix that stopped matching the records two years ago.
Holds the auditor pool against the audit programme, blocks assignments into excluded areas, and surfaces the team's competence when a certification body asks.
Tracks the auditor course, the certificate and the refresher due date, and pushes a lapse into the competency record rather than a separate reminder.

Watches audits completed against the currency minimum, flags auditors drifting below it, and pulls the reports an evaluator needs before signing an authorisation.
Compares finding grades across auditors covering comparable scopes, turning grading consistency from an opinion into a measurement.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Auditor Competency Record definitions and key terms
- Competence
- The ability to apply knowledge and skills to achieve intended results, which in auditing means arriving at sound conclusions rather than completing a checklist.
- Discipline and sector-specific knowledge
- Knowledge of the standard, the processes and the hazards of the area audited, sufficient to recognise when an answer given is wrong.
- Personal behaviour
- The attributes ISO 19011 names for auditors, including ethical, open-minded, diplomatic, perceptive, tenacious, decisive and self-reliant.
- Audit team leader
- The auditor accountable for a specific audit, requiring additional experience in that role before authorisation.
- Impartiality
- The absence of bias or conflict of interest in the audit process, a property of the assignment that has to be re-established for each one.
- Witnessed audit
- An audit observed by an evaluator while it happens, the only evaluation method that sees interview technique rather than its written residue.
- Auditor evaluation criteria
- The qualitative and quantitative measures set in advance against which competence is judged, required by ISO 19011 clause 7.3.
- Currency
- Continued participation in audits at a frequency sufficient to retain technique, distinct from holding a valid certificate.
FAQ
Frequently asked questions about auditor competency record
Does an internal auditor need an accredited lead auditor course?+
No, and treating it as the entry requirement is how organisations end up with too few auditors. ISO 19011 lists auditor training as one contributor to competence, not the gate. A good internal course delivered by someone who audits for a living, followed by shadowed and supervised audits and a real evaluation, beats a certificate with nothing behind it.
Can an auditor audit their own department?+
No. Every management system standard requires auditors to be selected so objectivity and impartiality of the audit process are ensured, and auditing an area you own, resource or manage defeats that however honest you are. The practical answer for small sites is a swap: two auditors cover each other's areas. Where a site is too small, use a peer from another site and record why.
How many audits does someone need before being authorised alone?+
There is no number in the standard, and organisations that invent one usually pick two because that fits the schedule. A workable pattern is two audits shadowed, two led under supervision with the lead auditor present for the opening, the sampling and the closing, and an evaluation of both reports. What matters is that the supervised audits covered a real scope with a chance of finding something.
Should authorisation have an expiry date?+
Yes, and short enough to force the conversation, typically one to two years. The expiry is not a claim that skills evaporate on a date; it makes someone look at refresher status, audits completed this year and the last evaluation together. Without it the authorised population only grows, and half of them have not audited anything since the year they were trained.
What evidence will a certification auditor actually ask for?+
The competency records for whoever conducted the internal audits in scope, and then the audits themselves. They check two things: that a documented basis for authorisation exists, and that the audits produced findings a competent person would have found. A complete record plus audits that found nothing in a system with open non-conformities is worse than an incomplete record, because it evidences a process that ran and did not work.
Is this the same as the training record for the auditor course?+
No, and keeping them separate is deliberate. Internal Auditor Training records one event: the course, the provider, the dates, the assessment. This record holds the standing position, which changes as the person shadows, leads, is evaluated, gains an area, loses one to a role change, and drifts out of currency. Merging them produces a record correct on the day it was created and stale after.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Internal Audit and Certification
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause
More in Internal Audits
Internal Audit Programme
Sets out what will be audited, when, by whom and against which standard, across the year
Internal Audit Report
Records an internal audit against a standard or process, with findings and evidence
Audit Plan
Sets out the scope, criteria, schedule and people involved for a single audit
Audit Finding Record
Records a single audit finding with its evidence, clause reference and classification
Audit Follow Up Record
Checks whether audit findings have actually been closed and the fixes work
Process Audit Record
Audits a specific process end to end rather than a standard clause by clause

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 clause 7, competence and evaluation of auditors, including 7.2.2, 7.2.3, 7.3, 7.5 and 7.6
- ISO 19011:2018 clause 5.5.4, selecting and determining audit team members
- ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 clause 9.2.2, internal audit programme and auditor selection
- IATF 16949:2016 clause 7.2.3, internal auditor competency
- BRCGS Food Safety Issue 9 clause 3.4, internal audits
- 21 CFR 117.3 and 117.180, qualified auditor and preventive controls qualified individual (US FSMA)
- ISO/IEC 17021-1, requirements for bodies providing management system certification
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.