How to build an auditor competence matrix that scheduling can use
How to build an auditor competence matrix that planners and software can trust: fields, granularity, status, evidence dates and the common mistakes.
An auditor competence matrix is a structured record of which auditors are authorised for which standard, technical area and role, with the status and the dates that keep each authorisation valid. To be usable for scheduling it needs one row per auditor, one column per standard and technical area, a status for each cell and an expiry or next-evaluation date.
Key takeaways
- A matrix that says only 'qualified' cannot support ISO/IEC 17021-1, which asks for criteria per technical area and per function.
- Every cell needs a status, the evidence behind it and the date it stops being valid.
- Technical areas should be narrow enough to reflect real processes and mapped back to IAF codes or scheme categories.
- A matrix only helps scheduling if it is checked automatically, on the audit date, for every team member.
What is an auditor competence matrix?
An auditor competence matrix records, for each auditor, what they are authorised to do: which standards, which technical areas, which roles and under which scheme approvals. It is the bridge between your competence procedure and the audit plan.
Most certification bodies already have one, often a spreadsheet kept by the technical team. The problem is that it was built to answer an assessor's question about one person, and planners need it to answer a different one: who, of everyone available that week, can do this audit? That needs structure, status and dates.
The requirements behind it are set out in auditor competence under ISO/IEC 17021-1.
What should an auditor competence matrix contain?
Think of each cell as a small record, and give each record the same fields.
| Field | Example | Why scheduling needs it |
|---|---|---|
| Standard and version | ISO 14001:2015 | Transitions change who can audit |
| Technical area | 17a: welding and fabrication | Narrower than the IAF code, per ISO/IEC 17021-1 clause 7.1.2 |
| Code or category link | IAF 17, or an ISO 22003-1 category | Links competence to accreditation scope |
| Role | Lead auditor, auditor, technical expert, evaluator | Controls which seat the person can fill |
| Status | Authorised, in training, suspended | Only authorised people count as auditors |
| Evidence and approver | Witnessed audit on a named date, approved by the technical manager | What an assessor asks to see |
| Valid until | Next on-site evaluation or scheme re-registration date | Prevents allocations that lapse before the audit |
| Accreditation body | UKAS, DAkkS, ANAB and so on | Some clients need a certificate under a specific body |
What does a usable matrix look like?
Here is a slice of a matrix built this way. Each square is one auditor in one technical area; the legend is the status.
| 17a Fabrication | 19b Electronics assembly | 28a Civil works | 33a Software services | |
|---|---|---|---|---|
| Auditor A | ||||
| Auditor B | ||||
| Auditor C | ||||
| Auditor D |
AuthorisedIn trainingNot authorised
For a civil works audit, the pool is C and D. For electronics, A alone, with C as a trainee under A as evaluator. The same view also shows your development gaps: electronics depends on one person. Scheduling trainee auditors explains how to close gaps like that.
How do you build an auditor competence matrix step by step?
- List your functionsApplication review, lead auditor, auditor, technical expert, certification decision, per ISO/IEC 17021-1 Annex A.
- Define technical areasSplit each IAF code or scheme category you are accredited for into areas with common processes.
- Write criteria per cellEducation, experience, training and audit experience for each technical area and function.
- Load the evidenceFor each auditor, file the evidence and the approval date; mark anything missing as not authorised.
- Add validity datesRecord the next on-site evaluation, scheme re-registration or training deadline for each authorisation.
- Connect it to schedulingMake the planner's tool read the matrix directly, so nobody re-types statuses into a second list.
How granular should technical areas be?
IAF ID 1:2023 says the use of IAF scope headings as technical areas is limited. Too broad, and an auditor authorised for 'code 17' appears competent for a steel mill and a precision machine shop alike. Too narrow, and every audit becomes a one-person pool and the matrix becomes impossible to maintain.
A workable test: two sites in the same technical area should share the main processes, hazards or aspects an auditor must understand. If an experienced auditor would say 'those are different jobs', split the area. See IAF codes explained for the full code list.
Food shows the trade-off. Code 3 covers food products, beverages and tobacco, yet a dairy, an abattoir and a bakery have different hazards, hygiene zones and processes. Splitting code 3 into three or four technical areas gives planners realistic pools without creating a column for every product. Review the split when assessment findings, complaints or new clients show that an area is hiding real differences.
How do you keep the matrix current?
A matrix decays from the day it is built. Authorisations lapse, trainees progress and suspensions happen after complaints. Keep it on a cycle.
- EvaluateWitnessed audits and on-site evaluations
- AuthoriseTechnical manager approves each cell
- AllocateScheduling reads status on the audit date
- MonitorReport review, client feedback, complaints
- UpdateSuspend, extend or re-authorise
Common auditor competence matrix mistakes
MythA tick is enough.
RealityA tick without a date and evidence cannot show the auditor was authorised on the audit date.
MythTechnical experts belong in the auditor columns.
RealityRecord experts separately. They support the team but do not count as auditors or audit time.
MythStatus can be checked when the audit is booked.
RealityCheck again for the audit date. An on-site evaluation or scheme approval can lapse in between.
MythSubcontractors can live in a separate file.
RealityExternal auditors need the same criteria and evidence, and planners need them in the same pool. See managing subcontracted auditors.
How scheduling software uses the matrix
Once the matrix is structured, software can check every cell for every team member in every audit. ScheduleAI reads competence per standard, technical area, role and accreditation body as scheduling parameters. When a global assurance provider loaded its data, the engine found 46 competence gaps in historical allocations that manual checks had missed. Planners still decide; the matrix makes those decisions checkable. See competence verification on every allocation.
ScheduleAI is the audit scheduling software certification bodies use to plan ISO programmes from stage 1 to recertification.
ScheduleAI reads your competence matrix as structured parameters (standard, technical area, role, accreditation body and validity dates) and checks every team member on every proposed allocation before a planner approves it.
Book a demo Estimate your savingsQuestions
What is an auditor competence matrix?
A structured record of which auditors are authorised for which standards, technical areas and roles, with status, evidence and validity dates.
Is a competence matrix required by ISO/IEC 17021-1?
The standard does not name a matrix, but it requires documented criteria per technical area and function and records of evaluation, which a matrix organises.
Should I record competence by IAF code?
Record it by technical area and link each area to its IAF code. IAF ID 1 says codes have limited use as technical areas.
How often should the matrix be updated?
Whenever an authorisation changes, and at least whenever evaluations, scheme approvals or training deadlines fall due.
Who should approve changes to the matrix?
The person your procedure names for authorising personnel, usually the technical manager. Planners should read the matrix, not edit it, so allocation and authorisation stay separate.
Can a spreadsheet work as a competence matrix?
For a small team, yes, if it holds status and dates per cell. At scale it becomes hard to check every allocation; see audit planning spreadsheet risks.