Why Auditor Competence Is Not Just About Training Hours
ISO auditor competence requirements are one of those topics that get talked about a lot but rarely explained with any precision. People assume that completing a lead auditor course makes them competent. Others think years of industry experience is enough on its own. Neither is quite right.
On this page
Competence, as ISO defines it, is the ability to apply knowledge and skills to achieve intended results. For auditors, that means being able to plan and conduct an audit, gather objective evidence, make sound judgements, and communicate findings clearly. It is a combination of what you know, what you can do, and how you behave under pressure.
This article breaks down exactly what ISO expects from auditors in terms of competence, where those requirements come from, and what they mean in practice for anyone building an auditing career in Australia.
Where the Competence Requirements Come From
The primary source of auditor competence guidance is ISO 19011, the international guidelines for auditing management systems. Clause 7 of ISO 19011 deals specifically with auditor competence and evaluation. It is not a requirement standard in the sense that ISO 9001 is, but certification bodies and professional schemes treat it as the benchmark for what a competent auditor looks like.
Beyond ISO 19011, you will find competence requirements embedded in the management system standards themselves. ISO 9001 Clause 7.2, ISO 14001 Clause 7.2, and ISO 45001 Clause 7.2 all require that persons doing work affecting conformity are competent. For internal auditors, Clause 9.2 of each of these standards requires the audit programme to address auditor competence. If your internal auditors are not competent, any nonconformity they raise can be challenged.
Professional certification schemes like Exemplar Global and IRCA build on ISO 19011 to create structured pathways. They translate the general competence framework into specific criteria for registration at different auditor grades. Understanding both the standard and the scheme requirements gives you the full picture.
For a deeper look at how the auditing guidelines are structured, see our article on how the ISO 19011 guidelines shape modern audit practice.
Exemplar Global Recognised Training ProviderRTP No. 310970The Three Dimensions of Auditor Competence
ISO 19011 frames auditor competence across three interconnected dimensions. You need all three. Weakness in any one of them will show up during an audit, and experienced auditees will notice.
Generic Knowledge and Skills
Generic competence applies to all auditors regardless of which standard they are auditing against. It includes understanding of audit principles, audit process steps, audit techniques, and management system concepts. An auditor who does not understand the difference between a major and minor nonconformity, or who cannot explain what objective evidence means, is not yet competent at the generic level.
This is where foundation and internal auditor training sits. A well designed internal auditor course builds this generic foundation. It covers how to plan an audit, how to gather evidence, how to interview people without putting words in their mouths, and how to document what you find in a way that is clear and defensible.
Discipline Specific Knowledge and Skills
Discipline specific competence relates to the particular management system standard being audited. An ISO 9001 auditor needs to understand quality management principles, the process approach, and what each clause of ISO 9001 actually requires. An ISO 45001 auditor needs to understand hazard identification, risk assessment, legal obligations under Australian WHS legislation, and the concepts of worker participation and consultation.
You cannot audit what you do not understand. This is why lead auditor courses are structured around a specific standard. The course teaches you the standard in depth, not just the auditing process. When you sit in front of a safety manager and ask about their hazard identification process, you need to know enough about the subject to recognise whether their answer is credible.
Sector Specific Knowledge
Sector knowledge is the third dimension and the one most often underestimated by new auditors. It covers the industry context in which the audit takes place. An auditor who has never worked in or around construction will struggle to assess whether a construction company's quality management system is genuinely effective, even if they know ISO 9001 inside out.
This is why certification bodies often assign auditors with relevant sector codes to specific clients. It is also why experienced auditors with a background in a particular industry often find it easier to pick up auditing work in that sector. Your existing knowledge of how the work actually gets done is a genuine asset.
The Personal Attributes ISO Expects
ISO 19011 does not just describe knowledge and skills. It also sets out the personal attributes that auditors are expected to demonstrate. These are not soft extras. They are part of the competence definition.
The attributes listed in ISO 19011 include being ethical, open minded, diplomatic, observant, perceptive, versatile, tenacious, decisive, and self reliant. Behind each of these is a practical auditing behaviour.
Being open minded means you do not walk into an audit having already decided what you will find. You follow the evidence. Being tenacious means you do not accept a vague answer and move on. You probe until you have enough evidence to form a conclusion. Being diplomatic means you can deliver an uncomfortable finding without creating a confrontation that shuts down the rest of the audit.
These attributes are harder to teach in a classroom than clause knowledge, but they can be developed with experience and reflection. Many new auditors are technically sound but struggle with the interpersonal side of auditing. Recognising this gap is the first step to addressing it.
Our article on the auditor competency triangle: knowledge, skills and behaviour explores this in more detail.
How Competence Is Evaluated
ISO 19011 Clause 7.6 describes how auditor competence should be evaluated. This is relevant both to organisations managing an internal audit programme and to professional certification schemes assessing candidates for registration.
Methods for Evaluating Competence
The standard identifies several evaluation methods. These include review of records such as qualifications, training and work history, feedback from colleagues and auditees, post audit review, interviews, role plays, and observation of auditing in practice. No single method is sufficient on its own. A robust evaluation uses a combination.
For internal audit programmes, this means you should not simply send someone on a course and declare them competent. You should observe them conducting at least one audit, review the quality of their nonconformity reports, and get feedback from the auditees they interviewed. This takes more effort than ticking a training box, but it is what ISO 9001 Clause 9.2 and ISO 19011 actually expect.
Witness Audits
For professional certification schemes, the witness audit is the most demanding competence evaluation method. A witness audit involves an assessor observing you conduct a real audit and rating your performance against defined criteria. Exemplar Global requires witness audits for registration at the Lead Auditor level. IRCA has similar requirements built into its certification pathway.
Witness audits test everything at once. Your planning, your interview technique, your ability to follow an audit trail, your judgement in grading findings, and your conduct in the closing meeting are all visible to the assessor. It is the most honest test of whether someone can actually audit.
Audit Logs
Both Exemplar Global and IRCA require candidates to demonstrate a history of auditing activity. This is tracked through an audit log. The log records the audits you have conducted, the standards audited against, the duration, and your role. For Lead Auditor registration, you typically need to demonstrate a minimum number of audit days as a team member and as a lead, in addition to completing an approved training course.
Keeping an accurate and detailed audit log from the beginning of your auditing career is important. Gaps or inconsistencies in your log will slow down your registration application.
Maintaining and Developing Competence
Competence is not a destination. ISO 19011 is explicit that auditor competence needs to be maintained and developed through continuing professional development. Standards change. Industry practices evolve. New audit techniques emerge. An auditor who completed their lead auditor training five years ago and has done nothing since is not keeping pace.
Continuing Professional Development
CPD for auditors covers a wide range of activities. Attending training courses, reading updated standards, participating in professional association events, conducting audits in new sectors, and reviewing audit findings with more experienced colleagues all count. What matters is that you are actively working to maintain and extend your capability.
Professional schemes like Exemplar Global require evidence of CPD as a condition of maintaining registration. This is not bureaucratic box ticking. It reflects a genuine expectation that certified auditors stay current. If you are auditing against ISO 14001 and the standard has just been revised, you need to understand what changed and how that affects your audit criteria.
For a practical look at CPD requirements and how to meet them, see our article on CPD for ISO auditors: requirements and easy ways to meet them.
Expanding Across Standards
Many auditors begin with a single standard and expand their scope over time. An ISO 9001 lead auditor who adds ISO 14001 and ISO 45001 to their credentials becomes significantly more valuable in the market. Integrated management system audits are common in Australia, and organisations often prefer auditors who can cover all three standards in a single visit.
Expanding your scope requires discipline specific training in the new standard, not just an assumption that your existing auditing skills transfer automatically. The process skills do transfer, but the clause knowledge and sector context for each standard are distinct.
What This Means for Internal Auditors Specifically
Internal auditors face a specific competence challenge. They often audit colleagues and processes they work alongside every day. This creates both an advantage and a risk. The advantage is sector knowledge. The risk is bias and a reluctance to raise findings that create conflict.
ISO 9001 Clause 9.2.2 requires that internal auditors be objective and impartial. They must not audit their own work. But objectivity goes beyond just avoiding self auditing. It means approaching every audit with an open mind and being willing to document what you actually find, even when it is uncomfortable.
Organisations running internal audit programmes should treat internal auditor competence as a programme management responsibility. That means selecting auditors with the right knowledge base, providing appropriate training, evaluating their performance after each audit, and maintaining records that demonstrate competence. If a certification body auditor asks how you determined that your internal auditors are competent, you need a better answer than pointing to a training certificate.
Our article on internal auditor competence: what ISO expects covers the internal audit specific requirements in detail.
Competence Requirements for Lead Auditors
Lead auditors carry additional competence requirements beyond those expected of team members. A lead auditor is responsible for planning the audit, directing the audit team, managing the audit programme activities on site, making audit conclusions, and communicating those conclusions to top management. These responsibilities require a broader and more developed skill set.
In terms of knowledge, a lead auditor needs to understand not just the standard being audited but also audit programme management, risk based audit planning, multi site audit considerations, and how to evaluate the systemic effectiveness of a management system rather than just checking individual clauses for conformity.
In terms of skills, a lead auditor needs to manage people. This includes directing less experienced team members, managing time across a complex audit schedule, and handling difficult situations such as a defensive auditee or a disputed finding. These are skills that develop through experience, not just through training.
The lead auditor course is the entry point, not the finishing line. Formal training gives you the framework. The competence develops through conducting audits, making mistakes, reflecting on what went wrong, and improving. Most experienced lead auditors will tell you that their first few audits as lead were uncomfortable and that they learned more from those experiences than from any classroom.
Exemplar Global Recognised Training ProviderRTP No. 310970Practical Steps to Build and Demonstrate Competence
If you are working towards auditor competence, whether as an internal auditor or aiming for professional certification, here are the practical steps that actually move you forward.
- Complete appropriate training at the right level for your current role. Foundation training if you are new to management systems. Internal auditor training if you will be conducting audits. Lead auditor training when you are ready to lead audit teams.
- Start your audit log immediately. Record every audit you participate in, including the date, the standard, the organisation type, the duration, and your role. Do not wait until you are applying for certification to reconstruct this history.
- Seek observation opportunities. Ask to accompany an experienced auditor on a real audit. Even as an observer, you will learn more in a single day on site than in hours of self study.
- Request feedback after every audit you conduct. Ask the audit client, the auditees, and any co auditors what you did well and what you could improve. This is the fastest route to genuine competence development.
- Stay current with the standards you audit against. Read the updates, attend briefings when standards are revised, and adjust your checklists and audit criteria accordingly.
- Reflect on your findings. After each audit, review your nonconformity reports. Are they clear? Are they well evidenced? Would they stand up to challenge? If not, identify what you need to do differently next time.
How Audit Workshop Supports Auditor Competence Development
Audit Workshop courses are designed around the competence framework described in ISO 19011 and the requirements of professional certification schemes. The training covers not just clause knowledge but the practical auditing skills that ISO expects: interview technique, evidence gathering, nonconformity writing, and audit management.
Dilawar Laghari, who delivers the training, has conducted over 500 external ISO certification audits across Australia, the Middle East, and South Asia. The examples in the courses come from real audits. The scenarios used in exercises reflect the situations you will actually encounter. If you want to build genuine auditor competence rather than just collect a certificate, that practical grounding makes a significant difference.
Courses are available at Foundation, Internal Auditor, and Lead Auditor levels across ISO 9001, ISO 14001, and ISO 45001, in both live and self paced formats. You can explore the full range of training options at auditworkshop.com.













