What this is
What is a credential audit?
What is a credential audit?
A credential audit is an independent sampling exercise that checks a subset of worker records against primary evidence: does the certificate physically exist, is it legible and complete, does it match the register, has it not expired, was it verified with the issuing body, and does it match what the person is doing. It is separate from the register, which only records what someone claims to hold.
Who should carry out a credential audit?
Someone independent of the training function that issued or logged the credentials. A trainer auditing their own records will find what they expect to find. Independence is what makes the audit worth running rather than a second look at the same file by the same eyes.
What does a credential audit check that a register does not?
A register is a claim: it says somebody holds a certificate. An audit tests the claim against primary evidence, checks it was verified with the issuer rather than taken on trust, and checks the credential against the task actually performed, which a register-only check has nothing to say about.
Scope
When is a credential audit required?
A credential audit tests other records; it does not replace them. Using it as a substitute for the register or for verification at the point of issue produces an audit trail that looks rigorous but tests nothing.
Use this template when
- A scheduled audit is due, as set by the audit programme or the stated interval
- A finding elsewhere, an incident, a near miss, a complaint, suggests the credential system may have a systemic gap
- A new site or business unit is being brought under the training programme and its baseline needs establishing
- A significant change to the workforce has occurred, such as a large intake of agency labour or a site transfer
- A linked record needs this one to exist: results feed the certification register and any corrective action
Do not use it for
- Certification Register, which is the primary record of what each worker holds; the audit samples it, it does not maintain it.
- Licence Verification, the point-of-issue check with the issuing body, done once when a credential is first logged rather than sampled later.
- Certification Renewal Record, which tracks a specific renewal in progress, not the state of the wider population.
- Expiry Review, the operational check that catches lapses before they happen, run more often and by the training function itself.
- Anything outside KnowTrain, which belongs in the workspace that owns that process
Compliance mapping
Which ISO 19011 requirements does this satisfy?
ISO 19011 does not certify anything; it is the method behind how an audit like this one is planned, run and reported, so defensibility rests on following that method rather than on holding a certificate.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.4 | Audit principles: independence, integrity and an evidence-based approach | Header |
| ISO 19011 cl.6.2 | Initiating the audit: objectives, scope and criteria defined before evidence is collected | Header |
| ISO 19011 cl.6.3 | Preparing audit activities, including a sampling plan proportionate to population and risk | Header |
| ISO 19011 cl.6.4 | Conducting audit activities: collecting and verifying information against the audit criteria | Records checked |
| ISO 45001 cl.9.2.2 | Internal audit programme implemented, with results reported to relevant management | Result |
| ISO 19011 cl.6.5 | Preparing and distributing the audit report, including findings and required actions | Result |
| ISO 19011 cl.7 | Competence and evaluation of auditors: competent in the process under examination and independent of it | Header |
| ISO 19011 cl.6.6 | Completing the audit and retaining its records for the required period | Systemic checks |
What it does not cover
- Certification Register, which holds each worker's certifications, tickets and licences with expiry dates as an ongoing record, not a sampled test of it.
- Licence Verification, which confirms a specific licence is genuine at the point it is first logged, by checking with the issuing body.
- Certification Renewal Record, which documents a renewal in progress against its own deadline.
- Competency Matrix, which maps who is trained and authorised for what, and which the audit tests rather than populates.
- The corrective action itself, which belongs in the action record raised from the audit, not the audit document.
Global
Credential Audit requirements by country
No jurisdiction mandates a credential audit by that name. What is close to universal is a duty to hold evidence that people are competent, and an expectation that the evidence is checked rather than merely filed.
OSHA standard-specific training and certification requirements, e.g. 29 CFR 1910.178(l) for powered industrial trucks
No general audit standard, but specific standards require documented evidence of operator training and evaluation, retrievable on request.
An inspector who cannot be shown that a certificate was ever checked against the person doing the job is looking at the gap a credential audit exists to close.
Management of Health and Safety at Work Regulations 1999; sector guidance on competent persons under LOLER and PUWER
Employers must ensure people are competent for tasks carrying risk, with several regimes naming a competent or authorised person specifically.
HSE asks how competence claims are checked, not just whether a register exists, and an independent sample is the practical answer.
ISO 45001 cl.9.2 internal audit; ISO 19011 as the method
A certified management system requires an internal audit programme, and ISO 19011 sets out how that programme is planned and run.
Certification auditors ask whether the credential audit was conducted to a defined method by someone independent of the process, before asking what it found.
How to complete it
How to complete a credential audit, step by step
Most of what makes a credential audit defensible sits outside the fields a template prompts for by default.
A certificate that looks genuine and one that is genuine are different findings, and only checking with the issuer confirms which. Sampling primary evidence without that step tests legibility, not authenticity.
The register asks whether a certificate exists. The audit asks whether it covers the work in front of the person holding it. Someone authorised for a counterbalance truck operating a reach truck passes every register check and fails the one that matters.
A clean sample from a population with no expiry monitoring and no process for capturing new starters is a clean sample from a system that will not stay clean. A good result on the people you looked at says little about the people you did not.
Their certificates are most often assumed to exist because someone else vouches for them, and least often actually held on file. An audit sampling only permanent staff has sampled the population least likely to produce a finding.
What auditors find
Most common credential audit findings
Credential audit findings are unusual in that the register almost always looks fine. The findings concern what it does not, and cannot, show.
| Finding | Clause | What fixes it |
|---|---|---|
| Certificate on file but never verified with the issuing body. | ISO 19011 cl.6.4 | Contact the issuer directly for sampled records; record the date and outcome of verification, not just its intention. |
| Certificate does not match the task the person is actually performing. | ISO 45001 cl.7.2 | Cross-check the credential against the specific equipment or activity observed, not the job title. |
| Agency or contractor certifications assumed rather than held. | ISO 19011 cl.6.3 | Require agency certificates to be collected and filed before the person starts, not confirmed verbally. |
| Register not reconciled against people who have left. | ISO 19011 cl.6.6 | Link leaver notifications to the register directly, so an exit removes the record rather than leaving it stale. |
| Expiry monitoring exists on paper but is not catching lapses before they occur. | ISO 45001 cl.9.1.1 | Test the monitoring by sampling a credential due to expire and confirming an alert was raised. |
| Auditor is not independent of the function that issued the credentials being audited. | ISO 19011 cl.4 | Assign the audit to someone outside the training function's reporting line before the sample is drawn. |
Case in point
Case in point: the register that passed and the audit that did not
A distribution site's forklift register showed every operator current, every certificate on file, and every expiry date in the future. The annual credential audit sampled twelve of the forty-one names on it. Eleven matched exactly. The twelfth held a valid certificate for a counterbalance truck, was rostered as a counterbalance operator, and had been observed by the auditor driving a reach truck in the narrow-aisle racking at the back of the warehouse.
The register had never been wrong in the sense a register check would catch: the file existed, was legible, and had not expired. It was wrong in the sense the audit exists to catch: nobody had checked what the certificate authorised against what the person was doing, and an informal shift pattern had put him on the reach truck without either record being updated.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
4 sections
- Reference
- TRN-034
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Compliance percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011
- Links
- Links Worker, Certification
- Tags
- Credentials, Audit
- Sections
- 4
- Fields
- 46
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 4
Header
13 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date and Time*
Delivered By*
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Audit Date*
Auditor*
Independent Of Training Function*
- Yes3 pts
- No0 pts
The Register Is Not The Evidence
A register says somebody holds a certificate. This audit checks whether the certificate exists, is genuine, is current, and matches what the person is actually doing.
Sample Size*
Population Size*
Sample Method*
- Random3 pts
- Risk based3 pts
- Convenience0 pts
Records checked
Repeats10 fieldsWorker*
Person ID*
Format PER-0000.
Links to FDN-003 Person ID
Certification Claimed*
Certificate On File*
- Yes3 pts
- No0 pts
Certificate Legible And Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Details Match Register*
- Yes3 pts
- Minor discrepancy1 pt
- No0 pts
Currently Valid*
- Yes3 pts
- Expired0 pts
Verified With Issuer*
- Yes3 pts
- No0 pts
Matches Tasks Actually Performed*
The real test. Somebody driving a reach truck on a counterbalance ticket is a finding.
- Yes3 pts
- Partly1 pt
- No0 pts
Finding ID
Links to FDN-015 Finding ID
Systemic checks
6 fieldsRegister Complete*
- Yes3 pts
- Partly1 pt
- No0 pts
Expiry Monitoring Working*
- Yes3 pts
- Partly1 pt
- No0 pts
New Starters Captured*
- Yes3 pts
- Partly1 pt
- No0 pts
Leavers Removed*
- Yes3 pts
- Partly1 pt
- No0 pts
Agency And Contractor Records Held*
Agency workers are the most common gap. Their certificates are often assumed rather than held.
- Yes3 pts
- Partly1 pt
- No0 pts
Records Retained For Required Period*
- Yes3 pts
- No0 pts
Result
17 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Records With Discrepancies*
People Working Beyond Authorisation*
Immediate Suspensions Required*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Next Audit Due*
Auditor*
Signature*
Site Manager*
Second Signature*
TRN-034 · record IDs look like AUD-2026-000 · Links Worker, Certification
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit itself is the easy part to run once a year. Keeping the sample independent, chasing verification with the issuer and closing findings is where credential audits typically lose their value.
Holds the certification register and audit history against it, and flags which sites are due, overdue, or carrying open findings.
Cross-references credentials against the equipment and permits they authorise, so a mismatch between certificate and task surfaces before an incident.
Keeps certificate images and issuer correspondence attached to the record they support, so verification evidence is retrievable rather than remembered.

Watches audit due dates and open findings across the workspace, and raises the next audit or escalates an overdue action rather than waiting to be asked.
This template lives in KnowTrain — training and credentials. Induction, competency, toolbox talks, refreshers and expiry tracking.
Meet KnowTrain→Glossary
Credential Audit definitions and key terms
- Credential
- A certificate, ticket or licence authorising a specific person to carry out a specific activity, distinct from attendance, which only records participation.
- Verification
- Confirming a credential directly with the body that issued it, as opposed to accepting the document on file at face value.
- Sample method
- The approach used to select which records are checked: random, spreading exposure evenly, or risk-based, weighting selection toward higher-risk roles.
- Systemic finding
- A gap in the process that produces or hides errors across the whole population, such as broken expiry monitoring, distinct from one bad record.
- Working beyond authorisation
- Performing a task that the person's current, valid credential does not cover, regardless of how long they have done it without incident.
FAQ
Frequently asked questions about credential audit
What is the credential audit template based on?+
It is built against ISO 19011, the standard for auditing management systems: how an audit is planned, conducted and reported, and how auditor competence is judged. It is a method, not a certifiable standard, so defensibility rests on following it.
What sections does the credential audit contain?+
Four sections: header, records checked, systemic checks and result. Header sets the scope and sampling approach, records checked holds the per-worker sample, systemic checks tests the register and its processes, and result rolls the audit into a score and any action required.
How often is a credential audit raised?+
On the audit schedule, and wherever a finding elsewhere suggests the credential system may have a systemic gap. Each one is given an ID in the form AUD-2026-00000, so it can be traced and referenced from other records.
Which programme does the credential audit belong to?+
It is part of Worker Competency and Credentials, whose outcome is a competency matrix reflecting observed practice rather than attendance. The audit is the independent check on whether that matrix, and the register beneath it, can be trusted.
How is a credential audit scored?+
A compliance percentage across the sample, where high is good, with a separate completeness percentage so a high score on a half-finished audit is not read as a high score. Items marked not applicable leave the denominator rather than counting against it.
What is the difference between a credential audit and a register check?+
A register check confirms a claim is present and looks complete. A credential audit tests whether the claim is true: whether the certificate is genuine, was verified with the issuer, is current, and matches the work the person is doing. It exists precisely because a register cannot answer that last question about itself.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Worker Competency and Credentials
Competency Framework Register
Holds the competencies the organisation recognises, with what each one means and how it is assessed
Driver Licence and Entitlement Check
Checks driver licence validity, categories, endorsements and any restrictions with the issuing authority
Electrical Competency Authorisation
Authorises a named person to carry out defined electrical activities on this site, with the limits stated
Competency Matrix
Shows which skills and training each role requires and who currently holds them
Skills Assessment
Assesses whether a worker can actually perform a task to standard, by watching them do it
Training Needs Analysis
Works out the gap between the skills a role needs and the skills people have
More in Credentials
Certification Register
Holds each worker's external certifications, tickets and licences with expiry dates
Certification Renewal Record
Records the renewal of a certification before it expires
Licence Verification
Confirms a licence or ticket is genuine and current, by checking with the issuing body
External Training Record
Records training delivered by an outside provider, with certificate attached
Competency Card Issue
Issues a physical or digital card showing what a worker is authorised to do
Expiry Review
Reviews all certifications due to expire in the coming period

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018 — Guidelines for auditing management systems, clauses 4 to 7
- ISO 45001:2018 clause 9.2, internal audit
- OSHA 29 CFR 1910.178(l), powered industrial truck operator training and evaluation (US)
- HSE guidance on competent persons under LOLER and PUWER (GB)
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.