Internal Auditor Competence, Training and Independence
Auditor Competence in Brief
ISO 19011 sets out the principles for auditor competence - knowledge of the standard, the discipline being audited, audit techniques and personal attributes. Auditors must be independent of the work they are auditing.
Auditor competence and independence
An audit is only as good as the auditor doing it. The standards recognise this by requiring internal auditors to be both competent - they understand what they are auditing and how to audit it - and impartial and objective - they are not auditing their own work and they bring no bias to what they find.
ISO 9001 Clause 9.2.2c and the equivalent clauses in the other ISO standards require the organisation to select auditors and conduct audits to ensure objectivity and the impartiality of the audit process. The wording is short, but it is the source of more practical difficulty in small and medium organisations than almost any other audit requirement.
What auditor competence covers
Auditor competence has three components.
Audit technique. How to plan an audit, how to ask open questions, how to gather evidence, how to record findings, how to write up an audit report. This is generic auditing knowledge - the same regardless of which process or standard is being audited. It is usually acquired through training or coaching.
Knowledge of the relevant ISO standard(s). Understanding what the standard requires, where individual clauses apply, and how the requirements link together. An auditor who does not understand the standard cannot identify a non-conformity against it.
Knowledge of the area being audited. The auditor needs to understand enough about the process being audited to know whether what is being described is reasonable and matches what the procedure says. This does not mean being a subject matter expert - that would conflict with independence - but understanding the basics of the process is necessary.
Generic audit competence is the core of the auditor role. Standard knowledge is acquired through training and reading the standard. Process knowledge is usually picked up through induction in each audit area before the audit starts.
Demonstrating competence
The standards require competence to be evidenced, not just claimed. There are several practical ways to do this and most organisations use a combination.
Internal audit training. A formal training course - either external (delivered by a training provider) or internal (using toolkit training materials). Records of attendance and any assessment feed the staff training matrix.
Lead auditor or internal auditor qualifications. Some auditors hold IRCA-accredited or equivalent qualifications. These are not required for internal auditing but provide strong evidence of competence where they exist.
Mentoring or shadowing. A new auditor accompanies an experienced one for one or two audits before leading their own. This is often the most effective competence development for organisations that audit frequently.
Periodic refresher training. Standards update - ISO 27001 moved from 2013 to 2022, climate change considerations were added across multiple standards in 2024 - and auditors need to keep up. Annual or biennial refreshers are normal practice.
The training matrix or competency record should show that internal auditors have been trained and that the training is current. Auditors who have not been trained for several years and where standards have moved on are a regular finding in surveillance audits.
What independence and impartiality require
The independence requirement is simple in principle: auditors do not audit their own work. The person responsible for purchasing does not audit purchasing. The person who maintains the document register does not audit document control. The person who runs management review does not audit management review.
The reasoning is practical rather than abstract. Someone auditing their own work is unlikely to find the problems that need finding, partly because they cannot see them and partly because raising them would be raising problems against themselves.
Beyond their own direct work, auditors should also be aware of indirect biases - close working relationships with the person whose process is being audited, family connections, financial interests in the area being audited. None of these are formally prohibited, but auditors should declare them and the organisation should consider whether to assign a different auditor.
The small organisation problem
Independence is the requirement that small organisations struggle with most. In a ten-person business, the same person may run document control, internal communications and competence management. Anyone available to audit one of those areas is probably also responsible for one of the others.
Three approaches usually solve this in practice.
Cross-coverage. Two or three people are trained as auditors and audit each other's areas. Even where one person is the main owner of a process, a colleague who does not run it day to day can audit it. This is the most common solution.
External auditors for specific areas. Some small organisations bring in an external consultant to audit areas where independence is genuinely impossible internally - particularly the management system itself, where the owner is often the only person familiar enough with it to audit it credibly. The external auditor does not become the certification body, but their findings count as internal audit evidence.
Process design. Where the same person inevitably owns and audits an area, the audit can be designed around objective evidence (records, dates, documented checks) rather than the auditor's interpretation. This is a fallback rather than a preferred solution and certification bodies will scrutinise it.
The IMS1 framework typically nominates a different person for the management system audit than for the management system as a whole, with the audit owner trained as an internal auditor.
Auditor records
Each internal auditor should have a record showing they are competent and what they have been trained on. This usually sits on the staff training matrix or competency register, alongside other role-based competence requirements.
Audit reports usually identify the auditor, which closes the loop with the competence record. An auditor identified on a report should be a trained auditor on the matrix, and the matrix should show training current to the standards being audited.
Independence is the audit requirement I challenge most often. I am not looking to catch out small organisations - the standards recognise that pure independence is harder when there are fewer people. I am looking for the organisation to have thought about it and to be honest about how it is being managed.
The findings I raise are usually where someone is plainly auditing their own work and there is no acknowledgement of it - no compensating control, no second pair of eyes, no honesty in the audit report about the constraint. A small organisation that explains how it manages independence with the people available is usually fine.
Two trained auditors who can audit each other's areas is enough for most small companies. You do not need a department of auditors. What you do need is the basic training - how to ask questions, how to gather evidence, how to write up findings - and a consistent approach to who audits what.
For client organisations setting up internal audit competence for the first time, I usually recommend training two people rather than one. It distributes the workload, builds in independence by default, and gives the organisation continuity if one person leaves or moves into the role being audited. Single-auditor setups are fragile in a way that is easy to underestimate.
Refresher training is also worth being honest about. Annual is overkill for most organisations, but every two or three years is sensible - particularly when standards are updated.
Practical compliance guidance
IMS1 Section 5.3.2 Internal Audits covers the requirement for competent and independent auditors, with auditor training and competence records held on the staff training matrix.
The toolkit provides internal audit training materials, a certificate template and the policy and guidance documents covering audit competence and independence.
| alphaZ document | How to use it |
|---|---|
| Internal Audit Training Course Toolkit | Full training course toolkit for developing internal audit competence within the organisation, suitable for delivering in-house auditor training. |
| Internal Audit Training Presentation | PowerPoint presentation covering audit principles, technique and practice for use in internal training sessions. |
| Introduction to ISO Audits and Certification | Briefing presentation introducing ISO audits and certification, useful as background context before auditor-specific training. |
| Internal Auditing Certificate Template | Template certificate for issue to staff after completing internal audit training, providing evidence of trained auditor status. |
| PP-1-10 Internal Auditing and ISO Compliance Policy | Policy and procedure setting out auditor competence and independence requirements and how they are managed. |
| GG-1-10 Internal Audits Guidance | Plain-language guidance on auditor competence, independence and the practical management of internal audit resourcing. |
Note - all the above files can be downloaded with an alphaZ subscription.
Frequently Asked Questions
UK Legislation relevant to auditor competence
UK legislation does not directly specify auditor competence requirements for ISO internal audits, but several laws require organisations to make sure people performing safety-critical or compliance-critical roles are competent for what they are doing. Organisations outside the UK should identify the equivalent legislation in their jurisdiction.
