Auditor Competence
Auditor competence is the demonstrated ability to apply knowledge and skills to achieve intended audit results. Within an ISO/IEC 27001 audit programme, it is the basis for credible, consistent and impartial conclusions about an Information Security Management System (ISMS). ISO 19011:2018, Clause … Auditor competence is the demonstrated ability to apply knowledge and skills to achieve intended audit results. Within an ISO/IEC 27001 audit programme, it is the basis for credible, consistent and impartial conclusions about an Information Security Management System (ISMS). ISO 19011:2018, Clause 7, provides the main guidance. Certification bodies must also meet the competence requirements of ISO/IEC 17021-1 and ISO/IEC 27006-1. Competence has three dimensions. The first is personal behaviour. Auditors should be ethical, open-minded, diplomatic, observant, perceptive, versatile, tenacious, decisive, self-reliant, culturally sensitive and able to act with fortitude. The second is generic audit knowledge and skills. These include audit principles, processes and methods, sampling, risk-based auditing, evidence evaluation, and familiarity with management system standards, the auditee's organizational context and applicable legal, regulatory and contractual requirements. The third is discipline-specific knowledge. ISMS auditors must understand information security risk assessment and treatment, the Statement of Applicability, Annex A controls and ISO/IEC 27002 guidance, and security technologies such as access control, cryptography, network security and incident management. They must also understand relevant sector risks and privacy obligations. Audit team leaders need additional competence. This includes planning audits, using resources effectively, leading and mentoring the team, managing conflict, communicating with top management, and preventing and resolving problems. The audit programme manager must define competence criteria based on audit objectives, scope, complexity and risk. Competence is acquired through education, work experience, auditor training and audit experience. It should be evaluated with a combination of methods: reviewing records, gathering positive and negative feedback, interviews, observation during witnessed audits, testing, and post-audit review. When assigning teams, the manager ensures that the team collectively has the required competence. Technical experts may be added where gaps exist, but they work under an auditor's direction. Finally, competence must be maintained and improved through continual professional development, regular audit participation, and staying current with evolving threats, technologies and revisions to standards such as ISO/IEC 27001:2022. Without demonstrated competence, audit findings lack reliability and the programme cannot fulfil its objectives.
Auditor Competence in ISO/IEC 27001 Audit Programs: A Complete Guide for Lead Auditors
Introduction
Auditor competence is one of the central themes of managing an ISO/IEC 27001 audit program. An audit is only as reliable as the people who carry it out. If auditors lack the right knowledge, skills or personal behaviour, findings may be wrong, nonconformities may be missed, and the organisation may gain false confidence in its Information Security Management System (ISMS). This guide explains what auditor competence is, why it matters, how it is defined, evaluated and maintained, and how to answer exam questions on it.
1. What Is Auditor Competence?
ISO 19011:2018 (Guidelines for auditing management systems) defines competence as the ability to apply knowledge and skills to achieve intended results. Competence is not only having a certificate or qualification. It is the proven ability to perform an audit effectively. ISO 19011 Clause 7 is the main reference for auditor competence. For certification bodies, ISO/IEC 17021-1 and ISO/IEC 27006 add extra requirements specific to ISMS audits.
Auditor competence has two broad parts:
a) Personal behaviour, the attributes that allow an auditor to act according to the principles of auditing.
b) Knowledge and skills, both generic (all management system audits) and discipline-specific (information security).
2. Why Is Auditor Competence Important?
Reliability of audit conclusions: Competent auditors gather sufficient, appropriate audit evidence and reach objective, evidence-based conclusions.
Confidence for interested parties: Top management, customers, regulators and certification bodies rely on audit results to make decisions.
Achievement of audit program objectives: ISO 19011 Clause 5 requires the person managing the audit program to make sure the audit team has the competence needed for each audit.
Risk management of the audit program: Lack of competence is a key risk to the audit program. ISO 19011 lists the selection of audit team members with insufficient competence as an example of risk.
Credibility of certification: In third-party audits, ISO/IEC 17021-1 and ISO/IEC 27006 require certification bodies to show that auditors are competent. Without this, accreditation may be at risk.
Complexity of information security: ISMS audits involve risk assessment, technical controls (Annex A of ISO/IEC 27001:2022), legal and regulatory requirements, cloud services and cyber threats. This needs specialised knowledge.
3. Personal Behaviour (ISO 19011 Clause 7.2.2)
Auditors should have the attributes needed to act according to the principles of auditing. A competent auditor is expected to be:
- Ethical: fair, truthful, sincere, honest and discreet
- Open-minded: willing to consider other ideas or points of view
- Diplomatic: tactful when dealing with people
- Observant: actively aware of the physical surroundings and activities
- Perceptive: aware of and able to understand situations
- Versatile: able to adjust readily to different situations
- Tenacious: persistent and focused on achieving objectives
- Decisive: able to reach timely conclusions based on logical reasoning and analysis
- Self-reliant: able to act and function independently while interacting effectively with others
- Able to act with fortitude: willing to act responsibly and ethically, even when this is unpopular and may lead to disagreement or confrontation
- Open to improvement: willing to learn from situations
- Culturally sensitive: respectful of the culture of the auditee
- Collaborative: interacting effectively with others, including team members and auditee personnel
4. Knowledge and Skills (ISO 19011 Clause 7.2.3)
a) Generic knowledge and skills of management system auditors:
- Audit principles, processes and methods: planning, conducting, risk-based approach, sampling, evaluating evidence, reporting
- Management system standards and other references: ISO/IEC 27001, the harmonised structure, related standards such as ISO/IEC 27002
- The organisation and its context: structure, governance, business functions, size, culture
- Applicable legal and contractual requirements: such as data protection laws (for example GDPR), contractual obligations and regulatory requirements
b) Discipline- and sector-specific competence (Clause 7.2.3.3): For ISMS auditors this includes:
- Information security management concepts: confidentiality, integrity and availability
- Information security risk assessment and risk treatment methods (for example ISO/IEC 27005)
- Annex A controls and how to verify their effectiveness
- Technology such as networks, cryptography, access control, cloud, logging and monitoring
- Threats, vulnerabilities and incident management
- Business continuity aspects of information security
- Measurement and monitoring of ISMS performance
c) Generic competence of the audit team leader (Clause 7.2.3.4): The audit team leader needs extra competence to:
- Plan the audit and assign tasks according to the competence of team members
- Discuss strategic issues with top management of the auditee
- Build and maintain collaborative working relationships within the team
- Manage the audit process, including use of resources, uncertainty and risk
- Represent the audit team in communications with the audit client and auditee
- Lead the team to reach audit conclusions
- Prevent and resolve conflicts
- Prepare and complete the audit report
d) Auditing multiple disciplines (Clause 7.2.3.5): For combined or integrated audits, auditors should understand how the different management systems interact.
5. How Auditor Competence Is Achieved (Clause 7.2.4)
Competence can be acquired through a combination of:
- Successful completion of training programs covering generic auditor knowledge and skills (for example an ISO/IEC 27001 Lead Auditor course)
- Experience in a relevant technical, managerial or professional position involving judgement, decision making and problem solving
- Education or training and experience in a specific management system discipline and sector
- Audit experience gained under the supervision of a competent auditor in the same discipline
The audit team leader gains extra competence through audit experience, ideally by acting as team leader under the direction and guidance of another audit team leader.
6. How Auditor Competence Is Evaluated (Clauses 7.3 to 7.5)
ISO 19011 describes a structured process for evaluating auditors.
Step 1: Determine the competence needed (Clause 7.3). The audit program manager considers audit objectives, scope, criteria, the complexity of the auditee's ISMS, risks and opportunities, legal requirements and the sector.
Step 2: Establish evaluation criteria (Clause 7.4). Criteria can be qualitative, such as demonstrated behaviour or knowledge during training or in the workplace, or quantitative, such as years of work experience, number of audits conducted or hours of training.
Step 3: Select appropriate evaluation methods (Clause 7.5). ISO 19011 Table 3 lists these methods:
- Review of records: education, training, employment, professional credentials and audit experience
- Feedback: surveys, questionnaires, personal references, testimonials, complaints, performance evaluation, peer review
- Interview: personal interviews
- Observation: role playing, witnessed audits, on-the-job performance
- Testing: oral and written exams, psychometric testing
- Post-audit review: review of the audit report, feedback from the audit team leader, team members and the auditee
A combination of methods gives a more reliable result than any single method.
Step 4: Conduct the evaluation (Clause 7.5). Compare the collected information against the criteria. If the person does not meet the criteria, more training, work or audit experience is needed, followed by re-evaluation.
7. Maintaining and Improving Competence (Clause 7.6)
Competence is not permanent. Auditors and team leaders should keep improving through:
- Continual Professional Development (CPD): keeping up with changes such as the move from ISO/IEC 27001:2013 to 2022, new threats and new technologies
- Regular participation in audits
- Feedback and periodic re-evaluation by the audit program manager
- Changes in the needs of the organisation, the auditing practice, standards and other requirements
8. Competence of the Person Managing the Audit Program (Clause 5.4.2)
The individuals managing the audit program also need competence. This covers:
- Audit principles, methods and processes
- Management system standards and reference documents
- Information about the auditee and its context
- Applicable legal and other requirements
- Risk management, project and process management, and information technology where relevant
They should also maintain this knowledge through CPD.
9. Selecting the Audit Team (Clause 5.5.4)
When forming an audit team, the audit program manager considers:
- The overall competence needed to achieve the audit objectives
- The complexity of the audit and whether it is combined or joint
- The selected audit methods
- Legal and contractual requirements
- The need for independence from the activities being audited and to avoid conflict of interest
- The ability of team members to work together and interact with auditee representatives
- Language and the auditee's social and cultural characteristics
- The type and complexity of the processes being audited
Technical experts may be added where auditors lack specific knowledge, for example cryptography or industrial control systems. Technical experts work under the direction of an auditor and do not act as auditors.
Auditors-in-training may join the team but should not audit without direction and guidance.
10. Certification Body Context (ISO/IEC 17021-1 and ISO/IEC 27006)
For third-party certification audits:
- ISO/IEC 17021-1 requires the certification body to define competence criteria for each function in the certification process.
- ISO/IEC 27006 adds ISMS-specific requirements. Auditors need knowledge of information security management, ISMS standards, risk management, Annex A controls, and relevant legal and regulatory requirements.
- Certification bodies must keep records of auditor competence and monitor performance, for example through witnessed audits and report reviews.
11. Practical Example
A global bank asks for an ISO/IEC 27001 audit of its cloud-based payment platform. The audit program manager:
1. Identifies the needed competence: payment security (for example PCI DSS awareness), cloud security, cryptography, and the banking regulatory environment.
2. Reviews the auditor pool: Auditor A is a certified ISO/IEC 27001 Lead Auditor with cloud experience. Auditor B has banking regulatory expertise but limited ISMS auditing experience.
3. Assigns Auditor A as team leader and Auditor B as a team member, and adds a cryptography technical expert.
4. Checks independence and confirms that nobody on the team took part in designing the platform.
5. After the audit, collects feedback from the auditee and team, reviews the report, and records results for each auditor's competence file.
12. Common Misconceptions
- "A Lead Auditor certificate alone proves competence." False. Certification is evidence of training, but competence also needs applied experience and suitable behaviour.
- "Technical experts can audit and raise nonconformities." False. They support auditors. Audit findings remain the responsibility of auditors.
- "Once competent, always competent." False. Competence must be maintained and re-evaluated.
- "Every auditor must have all the competence required for the audit." False. The audit team as a whole must have the necessary competence.
- "Internal auditors do not need to be competent to the same principles." False. ISO/IEC 27001 Clause 7.2 requires competence of persons doing work affecting ISMS performance, and Clause 9.2 requires auditors to be objective and impartial.
13. Link to ISO/IEC 27001 Requirements
- Clause 7.2 Competence: The organisation must determine the competence needed, ensure people are competent through education, training or experience, take actions to acquire competence, and retain documented information as evidence. This applies to internal auditors.
- Clause 9.2 Internal audit: Auditors must be selected and audits conducted in a way that ensures objectivity and impartiality.
- During an audit, a Lead Auditor may ask for evidence of internal auditor competence, such as training records, CVs and evaluations. Missing evidence may be a nonconformity against Clause 7.2.
Exam Tips: Answering Questions on Auditor Competence
Tip 1: Know the definition. Competence is the ability to apply knowledge and skills to achieve intended results. If an answer option describes only knowledge, or only qualifications, it is usually incomplete.
Tip 2: Remember the two pillars. Personal behaviour plus knowledge and skills. Questions often describe a behaviour such as "the auditor kept investigating despite resistance" and ask which attribute it shows. That example shows tenacious behaviour, or fortitude if the auditor acted ethically despite pressure.
Tip 3: Learn the behaviour list well. Exams often test the difference between similar terms:
- Observant means aware of physical surroundings. Perceptive means understanding situations.
- Decisive means timely conclusions based on logic. Tenacious means persistence.
- Diplomatic means tact. Collaborative means working well with others.
Tip 4: Team competence, not individual completeness. Choose answers stating that the audit team as a whole should have the needed competence, supported by technical experts if needed.
Tip 5: Technical experts do not audit. If a scenario has a technical expert raising nonconformities or interviewing alone without direction, recognise that as incorrect practice.
Tip 6: Use multiple evaluation methods. When asked how to evaluate an auditor, the best answer usually combines methods, such as review of records, observation or witnessed audit, and feedback. Know the six method categories from ISO 19011 Table 3.
Tip 7: Separate the roles. Know the differences between auditor, audit team leader, technical expert, observer, guide and auditor-in-training. Team leader competence includes planning, leading, conflict resolution, communicating with top management and reporting.
Tip 8: Competence is ongoing. Answers that mention CPD, regular audit participation and periodic re-evaluation are usually correct for questions on maintaining competence.
Tip 9: Link to independence and impartiality. A highly competent auditor who audits their own work is still not appropriate. Competence and objectivity are both required, as ISO/IEC 27001 Clause 9.2 states.
Tip 10: For scenario or essay questions, use a structured answer:
1. Identify the issue, such as a competence gap or unsuitable behaviour.
2. Reference the standard: ISO 19011 Clause 7, ISO/IEC 27001 Clauses 7.2 and 9.2, or ISO/IEC 27006 for certification bodies.
3. Explain the risk to audit reliability and the audit program.
4. Recommend actions: training, supervised audits, adding a technical expert, reassigning roles, or re-evaluation.
5. Mention documented evidence: records of competence must be retained.
Tip 11: Watch for absolute words. Options with "always", "only" or "never", such as "a certificate is the only proof of competence", are often wrong. ISO 19011 is guidance, so it uses "should". ISO/IEC 27001 uses "shall".
Tip 12: Spot the nonconformity. In audit scenarios, if the organisation cannot show records of internal auditor training or competence evaluation, the likely finding is a nonconformity against ISO/IEC 27001 Clause 7.2, specifically the need to retain documented information as evidence of competence. If internal auditors audit their own areas, the finding is against Clause 9.2 (objectivity and impartiality).
Tip 13: Consider context when determining competence. The needed competence depends on the audit objectives, scope, criteria, complexity, sector, legal requirements and risks. Answers that say competence should be determined case by case are usually stronger than generic answers.
Sample Exam Question
An audit program manager must audit a company's ISMS covering industrial control systems. None of the available auditors has OT security experience. What is the most appropriate action?
A) Cancel the audit
B) Assign the most senior auditor and proceed
C) Include a technical expert in OT security working under the direction of an auditor
D) Let the technical expert lead the audit
Correct answer: C. ISO 19011 allows technical experts to provide specific knowledge to the team. They work under the direction of an auditor, and the team as a whole then meets the competence needed.
Summary
Auditor competence combines personal behaviour with generic and discipline-specific knowledge and skills. It is gained through education, work experience, auditor training and supervised audit experience. It is evaluated through defined criteria and multiple methods, and maintained through continual professional development. For the audit program manager, making sure each audit team is competent, independent and well balanced is essential for reliable audit results and a credible ISMS audit program. In the exam, anchor your answers in ISO 19011 Clause 7, ISO/IEC 27001 Clauses 7.2 and 9.2, and the principle that competence is the demonstrated ability to achieve intended results.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!