Why Clause 7 Matters More Than Most Auditors Realise
Ask most auditors what ISO 19011 is about and they will tell you it covers how to plan and conduct audits. That is true, but it is only part of the story. Clause 7 of ISO 19011:2026 deals with something more fundamental: the competence of the people doing the auditing. It answers the question that sits behind every audit programme but rarely gets asked out loud. Are the auditors themselves actually qualified to do this work?
On this page
Competence in auditing is not just about holding a certificate. It is about having the right combination of knowledge, skills, and personal attributes to conduct audits that produce reliable, consistent, and useful results. Clause 7 sets out what that looks like in practice, how organisations should determine what competence is needed, how they evaluate whether auditors have it, and what happens when gaps are identified.
This article walks through Clause 7 of ISO 19011:2026 in detail. Whether you are managing an internal audit programme, selecting auditors for supplier audits, or working toward your own auditor credentials, understanding what this clause requires will sharpen how you think about auditor quality.
The Structure of Clause 7
Clause 7 is titled Competence and evaluation of auditors. It is broken into several subclauses that move logically from the general to the specific. The clause begins with an overview of the competence model, then addresses the general knowledge and skills auditors need, the discipline and sector specific knowledge required, and finally the methods and criteria for evaluating auditor competence.
One important thing to understand before diving in: ISO 19011 is a guidance standard, not a requirements standard. It uses the word should rather than shall. That means nothing in Clause 7 is mandatory in the way that ISO 9001 Clause 9.2 is mandatory for organisations seeking certification. However, guidance from ISO 19011 is widely adopted by certification bodies, audit programme managers, and professional auditor registration schemes. If you want your audit programme to be credible, Clause 7 is the benchmark you should be measuring against.
Exemplar Global Recognised Training ProviderRTP No. 310970The Competence Model: Knowledge, Skills and Personal Attributes
ISO 19011:2026 frames auditor competence as a combination of three things: knowledge and skills gained through education and experience, personal attributes that make someone effective in the auditing role, and the ability to apply both in the specific context of an audit.
This is a useful model because it stops organisations from treating competence as a box to tick. Completing a lead auditor course gives you knowledge. Conducting audits builds skill. But personal attributes, things like integrity, open mindedness, diplomacy, and the ability to observe carefully without jumping to conclusions, are harder to develop and harder to measure. Clause 7 explicitly names these attributes and treats them as a genuine component of auditor competence, not an afterthought.
Personal Attributes ISO 19011 Identifies
The standard lists a set of personal attributes that effective auditors should demonstrate. These include:
- Ethical conduct, meaning fairness, truthfulness, and discretion
- Open mindedness, being willing to consider alternative views and evidence
- Diplomacy, the ability to interact with people tactfully
- Observational awareness, actively noticing what is happening around them
- Perceptiveness, understanding situations quickly and intuitively
- Versatility, adapting to different contexts and auditees
- Tenacity, staying focused and persistent without becoming inflexible
- Decisiveness, drawing conclusions based on logical reasoning and evidence
- Self reliance, the ability to act independently while working effectively within a team
- Acting with fortitude, being willing to raise concerns even when it is uncomfortable
If you have conducted enough audits, you will recognise that some of these attributes are what separate a good auditor from a mediocre one. Tenacity matters when an auditee is being evasive. Decisiveness matters when you need to call a nonconformity on a process that the organisation has been running for years. Open mindedness matters when your initial read of a situation turns out to be wrong.
General Knowledge and Skills Required of All Auditors
Clause 7 identifies a set of general competencies that apply to all auditors regardless of which standard they are auditing against. These fall into several categories.
Audit Principles, Procedures and Methods
Auditors need to understand the principles that underpin auditing, the procedures that structure an audit from initiation through to closure, and the methods used to gather and evaluate evidence. This includes knowledge of audit planning, checklist development, interviewing, sampling, observation, and report writing. Without this foundation, an auditor cannot conduct a structured, reproducible audit.
Management System Standards and Reference Documents
Auditors need to understand how management system standards work. This includes the High Level Structure used across modern ISO standards, the intent behind clauses, and how requirements interact with each other. An auditor who treats each clause as an isolated checklist item will miss systemic issues. The standard expects auditors to understand the why behind requirements, not just the what.
Organisational Context
Effective auditors understand how organisations function. They understand governance, decision making structures, business processes, and the relationship between an organisation and its interested parties. This matters because auditing is not done in a vacuum. A finding about a documented procedure means something different in a five person business than it does in a multinational with a dedicated quality team.
Applicable Laws, Regulations and Other Requirements
Auditors should have sufficient awareness of the legal and regulatory environment relevant to the organisation being audited. For ISO 14001 audits in Australia, that means understanding relevant environmental legislation at state and federal level. For ISO 45001 audits, it means familiarity with the Work Health and Safety Act and associated regulations. Auditors do not need to be lawyers, but they need enough awareness to recognise when a compliance obligation has not been addressed.
Information and Communication Technology
ISO 19011:2026 has updated its treatment of technology compared to earlier editions. Auditors are now expected to have competence in using digital tools relevant to audit activities. This includes remote auditing platforms, electronic document management systems, and data analysis tools. The 2026 edition also acknowledges that auditors may encounter AI systems, automated decision making, and digital operational controls during audits. Competence in understanding these systems at a sufficient level to audit them effectively is now part of the general competence picture.
Discipline Specific and Sector Specific Competence
Beyond general auditing knowledge, Clause 7 recognises that auditors also need knowledge specific to the discipline and sector they are auditing. This is where the distinction between a competent auditor and a truly effective one often shows up.
Discipline Specific Knowledge
Discipline specific competence refers to knowledge of the particular management system standard being audited. An auditor conducting ISO 9001 audits needs a thorough understanding of quality management principles, process approach thinking, and the specific requirements of ISO 9001. An auditor working on ISO 45001 audits needs to understand occupational health and safety risk management, hazard identification methods, and the specific obligations that standard places on organisations. This knowledge cannot be assumed from general auditing training alone.
Sector Specific Knowledge
Sector specific competence refers to knowledge of the industry or operational context being audited. An auditor conducting a certification audit of a construction company needs to understand how construction projects are managed, what the typical risks are, and what effective controls look like in that environment. Without that context, an auditor may accept responses that a more experienced person would recognise as inadequate.
This is one of the reasons certification bodies assign auditors based on their sector experience, and why audit programmes should consider sector knowledge when selecting internal auditors for specific processes. An internal auditor with a finance background auditing the warehouse operations may need a technical expert alongside them to ensure the audit is meaningful.
Maintaining and Improving Auditor Competence
Clause 7 does not just describe the competence auditors need at a point in time. It also addresses how that competence should be maintained and improved over time. This is an important distinction. An auditor who completed a lead auditor course five years ago and has not kept up with standard revisions, emerging risks, or new audit methodologies is not the same auditor they were when they qualified.
The standard encourages auditors to engage in continual professional development. This includes staying current with changes to the standards they audit against, participating in training and peer review activities, seeking feedback from audit programme managers and auditees, and reflecting on their own performance after each audit.
For organisations managing audit programmes, this means building in mechanisms to support auditor development. That might look like annual refresher training, participation in audit team activities where less experienced auditors work alongside more experienced ones, or structured review of audit reports to identify areas where auditing quality could improve.
For individual auditors, it means taking professional development seriously rather than treating initial qualification as the finish line. The auditing landscape is changing. Standards are being revised. New risks, including digital transformation, AI deployment, and climate related impacts, are emerging as audit considerations. Auditors who keep pace with these changes will be far more effective than those who do not.
Evaluating Auditor Competence: Methods and Criteria
One of the most practically useful sections of Clause 7 is its guidance on how to evaluate auditor competence. This applies both to initial evaluation before someone is approved to conduct audits, and to ongoing evaluation throughout their auditing career.
Evaluation Methods
ISO 19011:2026 describes several methods that can be used to evaluate auditor competence. These include:
- Review of records: Examining training records, qualifications, work history, and evidence of prior audit experience
- Feedback from peers and auditees: Gathering structured input from people who have observed the auditor at work
- Interview: Discussing audit scenarios and approach with the auditor to assess their reasoning and knowledge
- Observation during auditing: Directly observing the auditor conduct an audit or part of an audit, sometimes called a witness audit
- Post audit review: Reviewing the quality of audit reports, nonconformity statements, and findings to assess whether they reflect competent judgement
- Testing or examination: Formal assessment of knowledge through written or oral examination
No single method gives a complete picture. The most reliable evaluations combine multiple methods. A witness audit combined with a review of the resulting report and structured feedback from the auditee will tell you far more about an auditor's competence than a training record alone.
Establishing Evaluation Criteria
Before you can evaluate competence, you need criteria to evaluate against. Clause 7 expects audit programme managers to define what competence looks like for the auditors in their programme. This means specifying the knowledge, skills, personal attributes, and experience required for each type of audit being conducted.
In practice, this often takes the form of a competence profile or auditor competence matrix. For each auditor role, you define what is required, then assess each individual against that profile. Gaps become the basis for development planning. This approach turns competence evaluation from a one time exercise into an ongoing management activity.
The Lead Auditor and Audit Team Leader Considerations
Clause 7 gives particular attention to the competence requirements for audit team leaders and lead auditors. Leading an audit team requires competencies beyond those needed to participate in an audit. The team leader needs to plan the audit, allocate work across the team, manage relationships with the auditee, make real time decisions about scope and depth, and produce a coherent audit report that reflects the work of the whole team.
This is why the distinction between internal auditor and lead auditor training matters. Lead auditor courses specifically develop the skills needed to manage an audit, not just participate in one. If you are responsible for selecting or developing lead auditors within your programme, Clause 7 provides a useful framework for thinking about what additional competencies you are looking for.
Applying Clause 7 to Your Internal Audit Programme
For quality managers and HSE managers running internal audit programmes, Clause 7 has direct practical implications. Here is how to apply it without overcomplicating things.
Start by defining what competence your internal auditors actually need. Consider the standards being audited, the processes covered, and the sectors involved. Document a basic competence profile for your internal auditors. Then assess each auditor against that profile. Identify gaps and put development activities in place to address them.
Build evaluation into your programme rather than treating it as a one time exercise. After each audit cycle, review the quality of reports and findings. Ask auditees for feedback. Observe auditors at work where you can. Use what you learn to improve both individual auditor performance and the programme as a whole.
If you are wondering what ISO expects from internal auditor competence in more specific terms, the answer is grounded in exactly this kind of structured, ongoing approach rather than a one time training event.
What Has Changed in the 2026 Edition
The 2026 edition of ISO 19011 has refined Clause 7 in a few meaningful ways compared to the 2018 edition. The treatment of technology related competence has been expanded to reflect the growing role of digital tools, remote auditing platforms, and AI systems in both audit practice and the organisations being audited.
There is also greater emphasis on the auditor's ability to evaluate risk based thinking as it is applied within management systems, which requires auditors to understand risk management concepts well enough to assess whether an organisation's approach is genuinely effective rather than just documented. This connects to the broader shift in ISO 19011:2026 toward auditing for effectiveness, not just conformity.
The 2026 edition also reinforces the importance of impartiality and ethical conduct as components of competence, not just professional obligations. An auditor who lacks integrity is not a competent auditor, regardless of their technical knowledge. This framing helps organisations understand that the principles of auditing established in Clause 4 and the competence requirements of Clause 7 are closely connected.
Common Gaps in Auditor Competence Programmes
In practice, most organisations fall short in one or more of the following areas when it comes to Clause 7.
- No defined competence criteria: Auditors are selected based on availability rather than assessed against defined criteria
- Training treated as sufficient: Completing a course is treated as evidence of competence rather than as one input into a broader evaluation
- No ongoing evaluation: Competence is assessed once at the start and never revisited, even as standards change and auditors take on new scope
- Personal attributes ignored: Technical knowledge is assessed but behavioural attributes are not, leading to auditors who know the standard but cannot conduct an effective interview or handle a difficult auditee
- Sector knowledge gaps unaddressed: Auditors are assigned to processes or industries where they lack the contextual knowledge to audit meaningfully
Addressing these gaps does not require a complex system. It requires a deliberate approach to defining what competence means in your context, evaluating auditors against that definition, and supporting ongoing development.
Exemplar Global Recognised Training ProviderRTP No. 310970Building Your Own Competence as an Auditor
If you are an individual auditor rather than an audit programme manager, Clause 7 is equally relevant to you. It describes the standard against which your competence will be evaluated, whether by a certification body, an audit programme manager, or a prospective employer.
Use it as a self assessment tool. Review the knowledge and skills it describes and be honest about where your gaps are. If you are strong on technical knowledge but less confident in your interviewing skills, seek out opportunities to develop those. If you have solid auditing skills in one sector but want to expand into another, think about what sector specific knowledge you need to build.
For those pursuing formal auditor credentials through schemes like Exemplar Global or IRCA, the competence framework in Clause 7 maps closely to the criteria those schemes use to assess applicants. Understanding Clause 7 well will help you present your experience and development in a way that demonstrates genuine competence rather than just a list of audits completed.
If you are at an earlier stage of your auditing career and working out where to start, the path from internal auditor to lead auditor is well established and the competence framework in Clause 7 provides useful signposts along the way.
Conclusion
Clause 7 of ISO 19011:2026 is not the most talked about part of the standard, but it may be the most important. It defines what it actually means to be a competent auditor, not just someone who has attended a course or completed a certain number of audits. It covers the knowledge, skills, personal attributes, and ongoing development that together determine whether an auditor can be trusted to produce reliable, useful, and honest audit results.
For organisations running audit programmes, Clause 7 provides a practical framework for selecting, evaluating, and developing auditors. For individual auditors, it is a mirror that reflects what genuine professional competence looks like and what you should be working toward throughout your career.
At Audit Workshop, our training courses for Foundation, Internal Auditor, and Lead Auditor levels are built around the competence framework that ISO 19011 describes. Whether you are starting out or looking to formalise and deepen your existing skills, our courses are designed by practitioners who have conducted hundreds of real audits and understand what competence looks like beyond the classroom.










