Summary
In short
- The framework defines requirements; the matrix reports coverage against them. Confusing the two produces a matrix that is accurate about the wrong thing.
- Requirements should be stated as observable capability rather than as course names, because a course can be replaced and the capability remains the requirement.
- Every competency needs a stated evidence type: observation, qualification, experience or knowledge check. Without it the framework specifies a goal and no way of reaching it.
- Validity periods should reflect skill decay and consequence, not administrative convenience. Rarely performed safety-critical tasks decay fastest and are usually given the longest intervals.
- The register decays through equipment and process change. New machinery creates a requirement that no framework mentions until someone updates it.
- Scope competencies to equipment and product where that matters, because a general designation conceals the specific gap.
What it is
What it is
What is a competency framework register?
The definitive list of competencies each role requires, what evidences each one, how it is assessed, and how long it remains valid. It is the reference from which training plans, assessments and the competency matrix are all derived.
Why does it need its own register?
Because without one, requirements live inside individual training records and matrices, and the definition of what a role needs becomes whatever was last recorded against someone in it. Change then propagates by accident rather than by decision.
When to use it
When to use it, and when not to
This defines what roles require. It does not record what individuals hold.
Use it for
- Defining the competencies each role requires, with evidence type and validity per competency
- Introducing a new role, or restructuring existing ones
- Following equipment, process or product changes that alter what a role must be able to do
- Establishing legal and scheme-driven requirements per role, so they are visible rather than assumed
- Reviewing whether requirements still describe the work as performed
Not for
- The competency matrix, which reports which individuals hold which competencies and where the gaps are
- Individual training records, which evidence delivery to a person
- Skills assessments, which record observed performance against criteria
- Job descriptions, which describe responsibilities rather than assessable capability
- Succession and development planning, which uses this as an input
Standards
What it is built against
Competency frameworks sit under the same competence clauses as training records, with the framework supplying the determination step.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.7.2(a) | Determine the necessary competence of workers affecting OH&S performance | Competencies |
| ISO 45001 cl.7.2(b) | Ensure workers are competent on the basis of education, training or experience | Competencies |
| ISO 9001 cl.7.2 | Determine necessary competence and retain documented information as evidence | Related records |
| ISO 22000 cl.7.2 | Competence requirements including for externally provided personnel | Competencies |
| ISO 45001 cl.7.3 | Awareness requirements, which sit alongside competence and apply more broadly | Competencies |
| OSHA task standards | Task-specific training and qualification requirements which the framework should capture per role | Competencies |
| ISO 45001 cl.9.1 | Monitoring and measurement, which requires the framework to be current to be meaningful | Register health |
| ISO 19011 cl.7 | Auditor competence, an example of role-specific competence defined by scope | Competencies |
What it does not cover
- The competency matrix, which reports individual coverage against these requirements.
- Training records, which evidence what was delivered to whom.
- Skills assessments, which record observed performance.
- Job descriptions, which describe responsibility rather than assessable capability.
- Succession planning, which consumes this register rather than producing it.
Filling it in
Filling it in well
Four decisions per competency, and one discipline that keeps the register alive.
Write what the person must be able to do, observably. This keeps the requirement stable when training provision changes, allows experience or an equivalent qualification to serve as evidence, and makes assessment possible. Course names are a means, and they belong in the training plan rather than in the requirement.
Observation, external qualification, documented experience, or knowledge check. Different competencies warrant different evidence, and a framework that does not say which produces inconsistent practice: some competencies assessed rigorously, others accepted on attendance, with no principle distinguishing them.
How quickly the skill degrades without practice, and how bad the consequence of failure is. Rarely performed emergency response tasks decay fastest and carry the highest consequence, and they are routinely assigned the longest refresh intervals because they are also the least convenient to practise.
New equipment, modified processes, new products and regulatory change all alter what a role must be able to do. Where the framework is not connected to management of change, it describes the operation as it was when someone last reviewed it, and the matrix built on it reports confidently against obsolete requirements.
Audit findings
Common audit findings
Findings here propagate, because everything downstream inherits them.
| Finding | Clause | What fixes it |
|---|---|---|
| Requirements expressed as course names rather than capabilities. | ISO 45001 cl.7.2 | State observable capability; the course is a means, not the requirement. |
| No evidence type specified per competency. | ISO 9001 cl.7.2 | Specify observation, qualification, experience or knowledge check for each. |
| Framework not updated after new equipment was introduced. | ISO 45001 cl.7.2(a) | Link to management of change; new equipment creates requirements silently. |
| Validity periods set by administrative convenience. | ISO 45001 cl.7.2 | Set from skill decay and consequence; rarely used emergency skills decay fastest. |
| Competencies not scoped to equipment or product where it matters. | ISO 45001 cl.7.2 | Scope explicitly; a general designation conceals the specific gap. |
| Legal and scheme requirements not identified within the framework. | ISO 45001 cl.6.1.3 | Mark which requirements are legally mandated so they cannot be deprioritised silently. |
| Externally provided personnel not covered by any framework. | ISO 22000 cl.7.2 | Agency and contractor roles need defined requirements too. |
| Matrix reporting full coverage against obsolete requirements. | ISO 45001 cl.9.1 | Green reporting against a stale framework is worse than an obvious gap. |
| No owner for the framework, so nobody maintains it. | ISO 45001 cl.5.3 | Assign ownership; a definition layer with no owner decays quietly. |
| Awareness requirements confused with competence requirements. | ISO 45001 cl.7.3 | Awareness applies more broadly and requires different evidence. |
Worked case
Case in point: a green matrix against the wrong requirements
A site reported 97 percent competency coverage for two years running. The matrix was well maintained, gaps were chased, and the figure was presented at management review as evidence of a healthy programme.
During an audit the assessor asked which competencies applied to a packing line that had been installed eighteen months earlier. The framework did not mention it. The line had replaced two older machines whose competencies remained in the framework, and operators were recorded as competent on equipment that no longer existed while holding no defined requirement for the machine they actually ran.
The matrix had been accurate throughout. It was reporting coverage against a definition of the job that had stopped being true a year and a half earlier, and the reporting being green was precisely why nobody had looked.
Definitions
Definitions and key terms
- Competency framework
- The definitive statement of what capabilities each role requires, with evidence type and validity per competency.
- Competency matrix
- The report showing which individuals hold which competencies against the framework, and where the gaps are.
- Evidence type
- How a competency is demonstrated: observation, external qualification, documented experience or knowledge check.
- Skill decay
- Loss of capability through lack of practice, fastest for complex rarely performed tasks such as emergency response.
- Scope of competency
- The specific equipment, product or conditions to which a competency applies.
- Awareness requirement
- What people must know without needing assessed competence, applying to a broader population under ISO 45001 clause 7.3.
- Framework currency
- Whether the register still describes the work as it is performed, measured by what has changed rather than by review date.
- Mandated competency
- A requirement arising from law or a certification scheme, which cannot be deprioritised on operational grounds.
FAQ
Frequently asked questions
What is the difference between the framework and the matrix?+
The framework defines what each role requires. The matrix reports which people hold those competencies and where the gaps are. Confusing them produces a matrix that is scrupulously accurate about requirements that no longer describe the job, and because the reporting looks healthy, nobody examines the definitions underneath.
Why not list courses?+
Because a course is a means of achieving a capability, not the capability itself. When the provider changes or the course is replaced, a course-name requirement changes silently with it. Stating observable capability keeps the requirement stable, allows experience or an equivalent qualification to serve as evidence, and makes assessment possible.
How should validity periods be set?+
From how quickly the skill decays without practice and how serious the consequence of failure is. Complex, rarely performed, high-consequence tasks, emergency response above all, decay fastest and warrant the shortest intervals. In practice they usually receive the longest, because practising them is inconvenient.
What keeps the framework accurate?+
A link to management of change. New equipment, modified processes, new products and regulatory changes all alter what a role must be able to do, and none of them announce themselves as competence events. Without that link the framework describes the operation as it was when someone last sat down with it.
Is high coverage a good sign?+
Not by itself. Near-complete coverage can indicate a healthy programme or a stale framework, and the two look identical in the reporting. The more informative question is when the framework last changed and what changed it. In an operation that has installed or modified equipment, a framework untouched for two years is describing a different site.
The agents
What the agents do with it
The framework is the definition layer. What fails is the equipment change that never reached it, and the green reporting that discouraged anyone from looking.
Holds requirements as capabilities with evidence type and validity per competency, and drives the matrix from them rather than the reverse.
Connects equipment, process and product changes to the framework, and flags requirements untouched while the operation has changed.
Marks legally mandated and scheme-driven competencies so they are visible and cannot be deprioritised without a decision.
Extends defined requirements to agency and contractor roles performing the same work, which site frameworks routinely omit.
This template lives in General — control tower. The orchestration layer. Registries and engines every other workspace reads from.
Meet General→Sources
Sources
- ISO 45001:2018 clauses 7.2 and 7.3, competence and awareness
- ISO 9001:2015 clause 7.2, competence
- ISO 22000:2018 clause 7.2, including externally provided personnel
- IATF 16949:2016 clause 7.2, competence and on-the-job training
- ISO 19011:2018 clause 7, competence and evaluation of auditors
