Why Clause 7 Trips Up So Many Auditors
Clause 7 sits in the Support section of every major ISO standard. It covers resources, competence, awareness, communication, and documented information. On paper, it looks straightforward. In practice, it is one of the clauses where auditors most often either miss genuine nonconformities or raise findings that do not hold up.
On this page
The reason is simple. Clause 7 is heavily people and paper focused. There are no machines to inspect, no processes to walk through, no outputs to measure directly. You are asking whether the right people are competent, whether they know why their work matters, and whether the documents supporting the system are properly controlled. All three require specific techniques to audit well.
This article covers practical audit techniques for Clause 7 across ISO 9001, ISO 14001, ISO 45001, and ISO 27001. The requirements are consistent across these standards because of the harmonised structure, so the approach applies broadly. Where there are meaningful differences, those are noted.
Understanding What Clause 7 Actually Requires
Before you can audit Clause 7 effectively, you need to be clear about what it requires. Many auditors conflate the subclauses or treat them as a single block. They are not.
Clause 7.1: Resources
The organisation must determine and provide the resources needed for the management system. This includes people, infrastructure, environment for the operation of processes, and monitoring and measurement resources. In ISO 9001, it also includes organisational knowledge under Clause 7.1.6.
Clause 7.2: Competence
The organisation must determine the competence required for people doing work under its control that affects performance. It must ensure those people are competent based on education, training, or experience. It must take action where competence gaps exist, and retain documented information as evidence.
Clause 7.3: Awareness
Relevant persons must be aware of the policy, relevant objectives, their contribution to system effectiveness, and the implications of not conforming. This is not the same as competence. Awareness is about understanding context and consequence, not just knowing how to do a task.
Clause 7.4: Communication
The organisation must determine what to communicate, when, to whom, and how. ISO 14001 and ISO 45001 add external communication requirements. ISO 45001 also requires worker consultation and participation, which is addressed under Clause 5.4 but connects closely to communication.
Clause 7.5: Documented Information
The organisation must create, update, and control documented information. This includes both documents (instructions, procedures, policies) and records (evidence that something happened). Clause 7.5.2 covers creating and updating. Clause 7.5.3 covers control, including access, protection, and retention.
Exemplar Global Recognised Training ProviderRTP No. 310970Auditing Clause 7.2 Competence: Where to Start
Competence is the most audited subclause in Clause 7 and also the most commonly mishandled. The standard does not prescribe how competence must be demonstrated. It requires that the organisation determines what competence is needed and then verifies it exists.
Step One: Understand the Competence Framework
Start your audit by asking management to walk you through how they determine competence requirements. Look for a competence matrix, position descriptions, or a training needs analysis. The format does not matter. What matters is that there is a systematic way of identifying what competence is needed for each role.
Ask questions like:
- How do you decide what qualifications or experience a person needs for this role?
- What happens when someone new joins? How do you assess whether they meet the requirements?
- How are competence requirements reviewed when processes or risks change?
Step Two: Test the Records Against Reality
Once you understand the framework, pull records for a sample of people. This is where many auditors stop too early. They see a training register and tick the box. But the training register only tells you what training occurred. It does not tell you whether the person is actually competent.
Look for evidence of evaluation. Did someone assess whether the training was effective? Was there a test, a supervised period, a sign off? Ask the auditee directly: how do you know this person is competent to do the task?
A common finding is that an organisation has training records but no evidence of evaluation of effectiveness. The standard at Clause 7.2(d) explicitly requires that the organisation evaluates the effectiveness of the actions taken. This is a genuine requirement, not a technicality.
Step Three: Interview the Workers
Go to the floor. Pick two or three workers at random and ask them about their role. Ask what training they received, whether they felt prepared for the task, and whether they know where to find work instructions or procedures. This serves two purposes. It tests awareness (which overlaps with Clause 7.3) and it provides triangulation for the records you reviewed.
If the training register says a person completed forklift operator training six months ago but they cannot tell you the last time they were assessed or what the key safety requirements are, you have a gap worth exploring further. You can read more about effective interview techniques in our guide to audit interviewing techniques.
Common Clause 7.2 Nonconformities
- Training records exist but there is no evidence of effectiveness evaluation
- Competence requirements are not defined for certain roles, particularly contractors or temporary workers
- A person is performing a task requiring specific competence but their records show only attendance at a general induction, not role specific training
- The competence matrix has not been updated to reflect a change in process or technology
Auditing Clause 7.3 Awareness: More Than a Poster
Awareness is consistently one of the weakest areas in management systems. Organisations often confuse communication with awareness. Sending an email or putting a policy on the noticeboard does not mean people are aware of what it means for their work.
The standard requires that relevant persons are aware of four things: the policy, relevant objectives, how their work contributes to system effectiveness, and the implications of not conforming to requirements.
How to Test Awareness Properly
The only reliable way to test awareness is to ask people directly. This makes some auditors uncomfortable because it feels confrontational or like a trap. It is neither. You are not testing whether someone can recite the policy word for word. You are testing whether they understand the intent and their role within it.
Useful questions include:
- Can you tell me what the quality policy (or environmental policy, or OH&S policy) is trying to achieve?
- What does that mean for your day to day work?
- What would happen if you did not follow the procedure for this task?
- What are the main quality (or environmental, or safety) objectives that apply to your team?
You are looking for genuine understanding, not rehearsed answers. If every person you speak to gives you the exact same scripted response, that is worth noting. It may indicate the organisation has briefed staff specifically for the audit, which is not the same as genuine awareness.
Awareness in Different Standards
In ISO 45001, awareness has a specific additional requirement. Workers must be aware of the OH&S hazards and risks relevant to their work, and they must know their right to remove themselves from work situations they consider dangerous. This is a concrete, testable requirement. Ask workers whether they know what to do if they feel unsafe. If they cannot answer, or if they say they would just keep working and report it later, that is a finding worth raising.
In ISO 14001, awareness includes understanding the significant environmental aspects relevant to the person's work and the environmental consequences of not following procedures. A maintenance worker at a manufacturing plant should know which activities could cause a spill, what the spill response procedure is, and why it matters.
Auditing Clause 7.4 Communication: Testing the System
Communication is often treated as a formality in audits. Auditors look at a communication plan, confirm it exists, and move on. A better approach is to test whether the communication system actually works.
What to Look For
The standard requires the organisation to determine what to communicate, when, to whom, and how. Start by reviewing the communication plan or equivalent. Then test it by tracing a specific communication through the system.
For example, if the organisation recently updated its quality objectives, ask: how were these communicated? To whom? When? Then ask a worker in a relevant team whether they know the objectives have changed. If the communication plan says monthly toolbox talks cover safety objectives but workers cannot tell you what was discussed at the last one, you have a gap between the plan and reality.
For ISO 14001 and ISO 45001, check external communication as well. Does the organisation have a process for responding to external enquiries about environmental or safety performance? Is there documented information showing this has been applied?
Auditing Clause 7.5 Documented Information: The Detail That Matters
Document control audits have a reputation for being tedious. They do not need to be. The key is to focus on whether documented information is actually serving its purpose, not just whether it exists.
Creating and Updating: Clause 7.5.2
When reviewing documents, check for identification (title, date, version number or equivalent), format, and review and approval. These are the three elements in Clause 7.5.2. A document with no version number or no evidence of approval is a legitimate finding, not a paperwork technicality. If people are working from a procedure that has not been reviewed in five years and the process has changed significantly, that is a real risk to conformity.
Control of Documented Information: Clause 7.5.3
Clause 7.5.3 requires that documented information is available where it is needed, protected from loss of confidentiality or inappropriate use, and controlled for distribution, access, retrieval, and retention. It also requires that documents of external origin are identified and controlled.
In practice, test this by asking workers how they access the procedures they need. Can they find the current version quickly? Is there any risk they could be working from an outdated version? In organisations using shared drives or document management systems, check whether old versions are still accessible. If a worker can open a superseded procedure from a shared folder, that is a control failure.
Retention of records is another area worth checking carefully. Ask the organisation to show you their retention schedule. Then pick a record type and check whether records are being retained for the required period. For calibration records, for example, the organisation should be able to produce records going back to the beginning of the current certification cycle at minimum.
Our article on auditing documented information: a Clause 7.5 checklist approach goes deeper on this specific subclause if you want more detail.
External Origin Documents
One area that is frequently overlooked is the control of externally originated documents. This includes legislation, standards, customer specifications, and supplier technical documents. The organisation must identify these and control them. Ask whether the organisation has a register of external documents. Ask how they know when a standard or regulation they rely on has been updated. If there is no process for this, it is worth raising.
Connecting Clause 7 to the Rest of the System
One of the most effective audit techniques for Clause 7 is to audit it in connection with other clauses rather than in isolation. Competence, awareness, and documented information are not standalone requirements. They support everything else in the system.
When you are auditing a process under Clause 8, ask about the competence of the people running it. When you are reviewing corrective actions under Clause 10.2, check whether training was identified as a root cause response and whether that training was evaluated for effectiveness. When you are auditing an incident under ISO 45001, trace back to the awareness requirements: did the worker know the hazard, the risk, and the correct procedure?
This connected approach produces much richer audit findings than treating Clause 7 as a standalone checklist exercise. It also demonstrates to the auditee that the management system is being assessed as an integrated whole, not as a series of disconnected boxes to tick. For a broader look at this approach, see our article on common ISO 9001 Clause 7 nonconformities auditors keep finding.
Sampling Strategy for Clause 7
Because Clause 7 involves people and records, your sampling strategy matters. A common mistake is to sample only the records the auditee presents to you. They will naturally show you the best examples. Push for a broader sample.
- Ask for the full training register and select records yourself, rather than asking the auditee to pull specific files
- Choose a mix of long serving staff and recent starters, and include contractors if they are doing work under the organisation's control
- Select workers from different shifts, departments, or sites if the organisation operates across multiple locations
- Pick roles that are critical to the management system, not just administrative roles
For documented information, do not limit yourself to the documents the auditee shows you in the management system. Ask to see what documents workers actually use on the floor. Sometimes the documents in the system and the documents people actually work from are not the same thing.
You can read more about building effective sampling approaches in our guide to audit sampling strategies.
Writing Clause 7 Findings That Hold Up
Clause 7 findings are sometimes challenged because they can feel subjective. To write a finding that holds up, you need to be specific about three things: the requirement, the evidence, and the gap.
A weak finding says: Training records were incomplete.
A strong finding says: Clause 7.2(d) requires the organisation to retain documented information as evidence of competence. During the audit, records for three of five sampled production operators (Operator A, B, and C) showed attendance at induction training but no evidence of evaluation of effectiveness. The organisation was unable to provide evidence that competence had been verified for these individuals before they commenced unsupervised work.
The second version is specific, references the requirement, names the evidence, and explains the gap. It cannot be dismissed as a paperwork observation. It is a genuine conformity question.
Exemplar Global Recognised Training ProviderRTP No. 310970Building Clause 7 Into Your Audit Plan
Many auditors allocate a fixed block of time to Clause 7 and treat it as a separate audit session. A more effective approach is to weave Clause 7 checks into every part of the audit.
When you visit a department, always ask about competence and awareness as part of that visit. When you review a process, check the documented information supporting it. This approach takes no extra time and produces far better coverage. It also means that if you find a Clause 7 issue, you can connect it directly to the process or outcome it affects, which makes the finding much more meaningful.
If you are building your internal audit skills and want to get better at planning and executing audits across all clauses, the internal auditor competence requirements article is worth reading alongside this one.
Developing Your Clause 7 Audit Skills
Clause 7 auditing is a skill that improves with practice. The more workers you interview, the better you get at reading the difference between genuine awareness and rehearsed answers. The more document systems you review, the faster you spot control weaknesses. The more training records you examine, the better you understand what evaluation of effectiveness actually looks like in practice.
At Audit Workshop, our internal auditor and lead auditor training courses cover Clause 7 in practical depth, including how to plan your audit approach, what questions to ask, how to evaluate evidence, and how to write findings that drive real improvement. If you are looking to build these skills in a structured way, our courses across ISO 9001, ISO 14001, ISO 45001, and ISO 27001 are designed by practitioners who have conducted hundreds of real audits, not just academics who have read the standard.













