Knowella

Credential Audit

A credential audit does not ask whether the register looks complete. It asks whether a sample of the records it describes are genuine, current, and match what the people holding them are actually doing. Its recurring failure is trusting the file: a certificate that exists, is legible and has not expired still says nothing about whether the person is doing the job it authorises, or whether the issuer was ever asked.

KnowTrainAuditTRN-034Pinned in navigation46 fields across 4 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011
Workspace
KnowTrain
Form type
Audit
Completed by
Someone independent of the training function
Cadence
Run yearly, plus whenever a finding elsewhere suggests a systemic gap

The short version

  • A credential audit is a sampling exercise, not a re-read of the register. It tests whether the certificate exists, is legible, matches the register, is current, was verified with the issuer, and matches the task performed.
  • Independence from the training function is the control that makes the audit mean something. An auditor checking their own team's records confirms a belief rather than testing one.
  • The most consequential finding is a person working beyond what their certification covers, such as someone authorised for a counterbalance truck operating a reach truck.
  • Agency and contractor records are the most common systemic gap. Their certificates are frequently assumed rather than actually held on file.
  • The audit also tests the system: whether the register is complete, whether expiry monitoring works, and whether leavers are removed and new starters captured.
  • Scoring is a compliance percentage, but a high score on a partly completed audit is not a high score; completeness is tracked separately.

What this is

What is a credential audit?

What is a credential audit?

A credential audit is an independent sampling exercise that checks a subset of worker records against primary evidence: does the certificate physically exist, is it legible and complete, does it match the register, has it not expired, was it verified with the issuing body, and does it match what the person is doing. It is separate from the register, which only records what someone claims to hold.

Who should carry out a credential audit?

Someone independent of the training function that issued or logged the credentials. A trainer auditing their own records will find what they expect to find. Independence is what makes the audit worth running rather than a second look at the same file by the same eyes.

What does a credential audit check that a register does not?

A register is a claim: it says somebody holds a certificate. An audit tests the claim against primary evidence, checks it was verified with the issuer rather than taken on trust, and checks the credential against the task actually performed, which a register-only check has nothing to say about.

Scope

When is a credential audit required?

A credential audit tests other records; it does not replace them. Using it as a substitute for the register or for verification at the point of issue produces an audit trail that looks rigorous but tests nothing.

Use this template when

  • A scheduled audit is due, as set by the audit programme or the stated interval
  • A finding elsewhere, an incident, a near miss, a complaint, suggests the credential system may have a systemic gap
  • A new site or business unit is being brought under the training programme and its baseline needs establishing
  • A significant change to the workforce has occurred, such as a large intake of agency labour or a site transfer
  • A linked record needs this one to exist: results feed the certification register and any corrective action

Do not use it for

  • Certification Register, which is the primary record of what each worker holds; the audit samples it, it does not maintain it.
  • Licence Verification, the point-of-issue check with the issuing body, done once when a credential is first logged rather than sampled later.
  • Certification Renewal Record, which tracks a specific renewal in progress, not the state of the wider population.
  • Expiry Review, the operational check that catches lapses before they happen, run more often and by the training function itself.
  • Anything outside KnowTrain, which belongs in the workspace that owns that process

Compliance mapping

Which ISO 19011 requirements does this satisfy?

ISO 19011 does not certify anything; it is the method behind how an audit like this one is planned, run and reported, so defensibility rests on following that method rather than on holding a certificate.

ClauseRequirementWhere it lands
ISO 19011 cl.4Audit principles: independence, integrity and an evidence-based approachHeader
ISO 19011 cl.6.2Initiating the audit: objectives, scope and criteria defined before evidence is collectedHeader
ISO 19011 cl.6.3Preparing audit activities, including a sampling plan proportionate to population and riskHeader
ISO 19011 cl.6.4Conducting audit activities: collecting and verifying information against the audit criteriaRecords checked
ISO 45001 cl.9.2.2Internal audit programme implemented, with results reported to relevant managementResult
ISO 19011 cl.6.5Preparing and distributing the audit report, including findings and required actionsResult
ISO 19011 cl.7Competence and evaluation of auditors: competent in the process under examination and independent of itHeader
ISO 19011 cl.6.6Completing the audit and retaining its records for the required periodSystemic checks

What it does not cover

  • Certification Register, which holds each worker's certifications, tickets and licences with expiry dates as an ongoing record, not a sampled test of it.
  • Licence Verification, which confirms a specific licence is genuine at the point it is first logged, by checking with the issuing body.
  • Certification Renewal Record, which documents a renewal in progress against its own deadline.
  • Competency Matrix, which maps who is trained and authorised for what, and which the audit tests rather than populates.
  • The corrective action itself, which belongs in the action record raised from the audit, not the audit document.

Global

Credential Audit requirements by country

No jurisdiction mandates a credential audit by that name. What is close to universal is a duty to hold evidence that people are competent, and an expectation that the evidence is checked rather than merely filed.

United States

OSHA standard-specific training and certification requirements, e.g. 29 CFR 1910.178(l) for powered industrial trucks

No general audit standard, but specific standards require documented evidence of operator training and evaluation, retrievable on request.

An inspector who cannot be shown that a certificate was ever checked against the person doing the job is looking at the gap a credential audit exists to close.

United Kingdom

Management of Health and Safety at Work Regulations 1999; sector guidance on competent persons under LOLER and PUWER

Employers must ensure people are competent for tasks carrying risk, with several regimes naming a competent or authorised person specifically.

HSE asks how competence claims are checked, not just whether a register exists, and an independent sample is the practical answer.

International

ISO 45001 cl.9.2 internal audit; ISO 19011 as the method

A certified management system requires an internal audit programme, and ISO 19011 sets out how that programme is planned and run.

Certification auditors ask whether the credential audit was conducted to a defined method by someone independent of the process, before asking what it found.

How to complete it

How to complete a credential audit, step by step

Most of what makes a credential audit defensible sits outside the fields a template prompts for by default.

Verify with the issuer, not just the file

A certificate that looks genuine and one that is genuine are different findings, and only checking with the issuer confirms which. Sampling primary evidence without that step tests legibility, not authenticity.

Match the credential to the task actually performed

The register asks whether a certificate exists. The audit asks whether it covers the work in front of the person holding it. Someone authorised for a counterbalance truck operating a reach truck passes every register check and fails the one that matters.

Rate the system, not just the sample

A clean sample from a population with no expiry monitoring and no process for capturing new starters is a clean sample from a system that will not stay clean. A good result on the people you looked at says little about the people you did not.

Treat agency and contractor records as the default risk, not the exception

Their certificates are most often assumed to exist because someone else vouches for them, and least often actually held on file. An audit sampling only permanent staff has sampled the population least likely to produce a finding.

What auditors find

Most common credential audit findings

Credential audit findings are unusual in that the register almost always looks fine. The findings concern what it does not, and cannot, show.

FindingClauseWhat fixes it
Certificate on file but never verified with the issuing body.ISO 19011 cl.6.4Contact the issuer directly for sampled records; record the date and outcome of verification, not just its intention.
Certificate does not match the task the person is actually performing.ISO 45001 cl.7.2Cross-check the credential against the specific equipment or activity observed, not the job title.
Agency or contractor certifications assumed rather than held.ISO 19011 cl.6.3Require agency certificates to be collected and filed before the person starts, not confirmed verbally.
Register not reconciled against people who have left.ISO 19011 cl.6.6Link leaver notifications to the register directly, so an exit removes the record rather than leaving it stale.
Expiry monitoring exists on paper but is not catching lapses before they occur.ISO 45001 cl.9.1.1Test the monitoring by sampling a credential due to expire and confirming an alert was raised.
Auditor is not independent of the function that issued the credentials being audited.ISO 19011 cl.4Assign the audit to someone outside the training function's reporting line before the sample is drawn.

Case in point

Case in point: the register that passed and the audit that did not

A distribution site's forklift register showed every operator current, every certificate on file, and every expiry date in the future. The annual credential audit sampled twelve of the forty-one names on it. Eleven matched exactly. The twelfth held a valid certificate for a counterbalance truck, was rostered as a counterbalance operator, and had been observed by the auditor driving a reach truck in the narrow-aisle racking at the back of the warehouse.

The register had never been wrong in the sense a register check would catch: the file existed, was legible, and had not expired. It was wrong in the sense the audit exists to catch: nobody had checked what the certificate authorised against what the person was doing, and an informal shift pattern had put him on the reach truck without either record being updated.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

46fields
4 sections
Reference
TRN-034
Archetype
Audit
Record ID
AUD-2026-000
Scoring
Compliance percent
Direction
High is good
Singleton
No
Basis
ISO 19011
Links
Links Worker, Certification
Tags
Credentials, Audit
Sections
4
Fields
46
Follow up fields
3
Repeating sections
1
Links out
4
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

13 fields
Text

Audit ID*

Generated on save

Auto sequence. Format AUD-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date and Time*

Users

Delivered By*

Pick List

Site*

From FDN-001 Site NameFilter: Status is Active
Text

Site ID*

Linked

Format SITE-000.

Links to FDN-001 Site ID

Date & Time

Audit Date*

Users

Auditor*

Single Choice

Independent Of Training Function*

Scored
  • Yes3 pts
  • No0 pts
Info

The Register Is Not The Evidence

A register says somebody holds a certificate. This audit checks whether the certificate exists, is genuine, is current, and matches what the person is actually doing.

Numeric Answer

Sample Size*

Numeric Answer

Population Size*

Single Choice

Sample Method*

Scored
  • Random3 pts
  • Risk based3 pts
  • Convenience0 pts

Records checked

Repeats10 fields
Pick List

Worker*

From FDN-003 Worker NameFilter: Site matches, Status is Active
Text

Person ID*

Linked

Format PER-0000.

Links to FDN-003 Person ID

Single Choice

Certification Claimed*

ForkliftFirst aidFire wardenConfined spaceWorking at heightFood hygiene
Single Choice

Certificate On File*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Certificate Legible And Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Details Match Register*

Scored
  • Yes3 pts
  • Minor discrepancy1 pt
  • No0 pts
Single Choice

Currently Valid*

Scored
  • Yes3 pts
  • Expired0 pts
Single Choice

Verified With Issuer*

Scored
  • Yes3 pts
  • No0 pts
Single Choice

Matches Tasks Actually Performed*

Scored

The real test. Somebody driving a reach truck on a counterbalance ticket is a finding.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Text

Finding ID

OptionalLinked

Links to FDN-015 Finding ID

Systemic checks

6 fields
Single Choice

Register Complete*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Expiry Monitoring Working*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

New Starters Captured*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Leavers Removed*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Agency And Contractor Records Held*

Scored

Agency workers are the most common gap. Their certificates are often assumed rather than held.

  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Records Retained For Required Period*

Scored
  • Yes3 pts
  • No0 pts

Result

17 fields
Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Numeric Answer

Records With Discrepancies*

Scored
Numeric Answer

People Working Beyond Authorisation*

Scored
Numeric Answer

Immediate Suspensions Required*

Scored
Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Date & Time

Next Audit Due*

Users

Auditor*

Signature

Signature*

Users

Site Manager*

Signature

Second Signature*

TRN-034 · record IDs look like AUD-2026-000 · Links Worker, Certification

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The audit itself is the easy part to run once a year. Keeping the sample independent, chasing verification with the issuer and closing findings is where credential audits typically lose their value.

KnowTrain

Holds the certification register and audit history against it, and flags which sites are due, overdue, or carrying open findings.

KnowSafe

Cross-references credentials against the equipment and permits they authorise, so a mismatch between certificate and task surfaces before an incident.

KnowComply

Keeps certificate images and issuer correspondence attached to the record they support, so verification evidence is retrievable rather than remembered.

Ella
Ella

Watches audit due dates and open findings across the workspace, and raises the next audit or escalates an overdue action rather than waiting to be asked.

This template lives in KnowTrain — training and credentials. Induction, competency, toolbox talks, refreshers and expiry tracking.

Meet KnowTrain→

Glossary

Credential Audit definitions and key terms

Credential
A certificate, ticket or licence authorising a specific person to carry out a specific activity, distinct from attendance, which only records participation.
Verification
Confirming a credential directly with the body that issued it, as opposed to accepting the document on file at face value.
Sample method
The approach used to select which records are checked: random, spreading exposure evenly, or risk-based, weighting selection toward higher-risk roles.
Systemic finding
A gap in the process that produces or hides errors across the whole population, such as broken expiry monitoring, distinct from one bad record.
Working beyond authorisation
Performing a task that the person's current, valid credential does not cover, regardless of how long they have done it without incident.

FAQ

Frequently asked questions about credential audit

What is the credential audit template based on?+

It is built against ISO 19011, the standard for auditing management systems: how an audit is planned, conducted and reported, and how auditor competence is judged. It is a method, not a certifiable standard, so defensibility rests on following it.

What sections does the credential audit contain?+

Four sections: header, records checked, systemic checks and result. Header sets the scope and sampling approach, records checked holds the per-worker sample, systemic checks tests the register and its processes, and result rolls the audit into a score and any action required.

How often is a credential audit raised?+

On the audit schedule, and wherever a finding elsewhere suggests the credential system may have a systemic gap. Each one is given an ID in the form AUD-2026-00000, so it can be traced and referenced from other records.

Which programme does the credential audit belong to?+

It is part of Worker Competency and Credentials, whose outcome is a competency matrix reflecting observed practice rather than attendance. The audit is the independent check on whether that matrix, and the register beneath it, can be trusted.

How is a credential audit scored?+

A compliance percentage across the sample, where high is good, with a separate completeness percentage so a high score on a half-finished audit is not read as a high score. Items marked not applicable leave the denominator rather than counting against it.

What is the difference between a credential audit and a register check?+

A register check confirms a claim is present and looks complete. A credential audit tests whether the claim is true: whether the certificate is genuine, was verified with the issuer, is current, and matches the work the person is doing. It exists precisely because a register cannot answer that last question about itself.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018 — Guidelines for auditing management systems, clauses 4 to 7
  • ISO 45001:2018 clause 9.2, internal audit
  • OSHA 29 CFR 1910.178(l), powered industrial truck operator training and evaluation (US)
  • HSE guidance on competent persons under LOLER and PUWER (GB)

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.