Auditor competence under ISO/IEC 17021-1: what certification bodies must prove
ISO 17021-1 auditor competence explained for planners: criteria per technical area, witnessed evaluation, monitoring and how it shapes every allocation.
ISO/IEC 17021-1 requires a certification body to set documented competence criteria for each technical area and each function, evaluate every auditor against them before use (including a competent evaluator observing an audit), and keep monitoring performance. For planners, ISO 17021-1 auditor competence means every allocation must match a current, evidenced authorisation for the standard, technical area and role.
Key takeaways
- Clause 7.1.2 asks for competence criteria per technical area and per function, so a single 'qualified' flag is too coarse.
- An auditor's initial evaluation must include a competent evaluator observing them conduct an audit.
- Monitoring combines on-site evaluation, report review and client or market feedback, per type of management system.
- The audit team as a whole must be competent; technical experts support but do not count as auditors or audit time.
What does ISO 17021-1 auditor competence require?
ISO 17021-1 auditor competence rests on three duties in clause 7 of ISO/IEC 17021-1:2015. The certification body must have processes that ensure personnel have the right knowledge and skills (7.1.1). It must document competence criteria for each technical area and each function (7.1.2). And it must run documented processes for initial evaluation and ongoing monitoring of competence and performance (7.1.3).
Competence has to be demonstrated before someone takes on the role. An assessor will pick a sample of audits and ask you to show, for each team member, the criteria, the evidence and the authorisation that were valid on the audit date.
- 7.2.4: processes for selecting, training and formally authorising auditors, and for selecting technical experts. The initial evaluation includes a competent evaluator observing (witnessing) the auditor conduct an audit.
- 7.2.10: monitoring of each auditor for each type of management system, using on-site evaluation, review of audit reports and feedback from clients or the market.
- 7.2.11: periodic on-site evaluation of each auditor, at a frequency based on need determined from all monitoring information.
- 7.3: written agreements with external auditors and technical experts covering the same policies.
The standard defines it as an area characterised by commonalities of processes relevant to a specific type of management system. The certification body decides how its technical areas are drawn, and they are usually narrower than an IAF code.
The 2015 edition is still the current issue at the time of writing; check the ISO catalogue before your next procedure review.
Which functions need their own competence criteria?
Annex A of ISO/IEC 17021-1 tabulates the knowledge and skills needed by function, and part standards add discipline-specific requirements: ISO/IEC 17021-3:2017 for quality, Part 2 for environmental and ISO/IEC TS 17021-10:2018 for occupational health and safety. Sector schemes add more, such as ISO/IEC 27006-1 for information security and ISO 22003-1 for food safety.
| Function | What the criteria cover | Scheduling impact |
|---|---|---|
| Application review | Deciding the competence the team needs, selecting the team and setting audit time | The reviewer's output is the brief every allocation must meet |
| Audit team leader | Leading the team, managing the plan, reaching conclusions | Only authorised leaders can be placed in the lead seat |
| Auditor | Generic auditing plus the technical area of the client | Match the technical area as well as the standard |
| Technical expert | Specific knowledge supporting the team | Adds knowledge, never replaces an auditor or audit time |
| Certification decision | Evaluating audit processes and the team's recommendations | Decision-makers must be independent of the audit team |
For how audit time interacts with team size, see how IAF MD 5 sets audit duration.
How do technical areas and IAF codes fit together?
Many bodies record competence against IAF codes because codes appear on accreditation scopes. IAF ID 1:2023 warns that using those scope headings as technical areas is limited, giving nuclear fuel as a rare heading that could stand as a technical area on its own. Most bodies therefore split codes into narrower technical areas and map each one back to its code. IAF codes explained covers the 39 codes in detail.
| ISO 9001 auditor | TA 17a: metal fabrication | TA 3b: dairy | Team leader | On-site evaluation in date | |
|---|---|---|---|---|---|
| Auditor A | |||||
| Auditor B | |||||
| Auditor C |
AuthorisedIn trainingNot authorised
Read across a row and you see why a single 'qualified' flag fails. Auditor C can lead a team but has an overdue on-site evaluation. Auditor B can lead but is still in training for metal fabrication. Building this record well is covered in how to build an auditor competence matrix.
How must competence be evaluated and monitored?
The standard sets the evidence, and your procedure sets the numbers. A defensible cycle looks like this.
- Set criteriaWrite criteria per function and technical area: education, work experience, training, audit experience.
- Collect evidenceFile CVs, certificates, audit logs and sector experience against each criterion.
- Witness an auditA competent evaluator observes the auditor conducting an audit before first authorisation.
- Authorise formallyRecord the decision per standard, technical area and role, with the date and who approved it.
- Monitor continuouslyReview reports, collect client feedback and act on complaints and assessment findings.
- Evaluate on-site periodicallySet the frequency from monitoring information, and cover each type of management system.
On the last step, a European Accreditation FAQ (question 43.1) records an ISO/CASCO clarification from March 2022: each type of management system under 7.2.10 is considered in the on-site evaluation under 7.2.11, although the on-site evaluation itself looks at general audit performance.
How does competence shape audit team selection?
Clause 9.2.2.1 asks you to select a team whose combined competence meets the audit objectives. A single auditor must hold all of it. Technical experts may fill a knowledge gap, but they do not act as auditors, and clause 9.1.4 excludes their time, and that of observers, interpreters and auditors-in-training, from the audit duration.
Worked example: an integrated audit
A 4-day ISO 9001 and ISO 14001 recertification at a metal fabricator. Auditor A holds both standards and the fabrication technical area but cannot lead. Auditor B leads and holds ISO 9001 but only ISO 14001 generic competence. Together they cover every requirement, so the team works; alone, neither does.
If Auditor A is unavailable, adding a technical expert to Auditor B does not restore the audit time. You still need 4 auditor-days from competent auditors, which changes who you can pick. Audit team selection for integrated audits walks through more cases.
Where do competence findings usually come from?
Accreditation assessors rarely find that a body has no criteria. They find allocations that the records do not support.
MythA lead auditor course certificate means the person is authorised.
RealityA course is training evidence. Authorisation needs the body's own evaluation, including a witnessed audit under 7.2.4.
MythAn IAF code on the record proves technical competence.
RealityCodes describe accreditation scope. Assessors look for criteria and evidence for the technical area actually audited.
MythA technical expert can cover for a missing auditor.
RealityExperts support the team; their time does not count toward audit duration.
MythOne on-site evaluation covers every standard.
RealityMonitoring must consider each type of management system the auditor works in.
What should planners check before approving an allocation?
Run these checks for every team member on every audit, using the authorisation status valid on the audit date, not the booking date.
- ✓Authorised for the standard and the version being audited
- ✓Authorised for the client's technical area, which is narrower than the IAF code
- ✓Authorised for the role: lead, auditor, technical expert or evaluator
- ✓On-site evaluation and other monitoring not overdue
- ✓Scheme approvals in date where a scheme owner registers auditors
- ✓No conflict of interest or rotation limit with this client
- ✓Team competence complete without counting experts or trainees as auditors
- ✓Evidence filed so an assessor can trace the decision
A spreadsheet can hold this for a few auditors. At scale, the checks need to run automatically; see auditor competence verification on every allocation.
How ScheduleAI applies ISO 17021-1 auditor competence rules
ScheduleAI stores competence per standard, technical area, role and accreditation body, and checks it on every allocation alongside rotation, conflicts, languages and travel. When a global assurance provider ran its integrated programme through the engine, it scheduled 305 audits in 11 min 24 s, formed 22 teams and surfaced 46 competence gaps in its historical allocations. Planners review and approve every proposal.
ScheduleAI is audit scheduling software built for testing, inspection and certification (TIC) organisations, with a planner approving every plan.
ScheduleAI checks every allocation against competence per standard, technical area and role, accreditation body, rotation and conflicts of interest, and records why each auditor was chosen so planners can approve with evidence.
Book a demo Estimate your savingsQuestions
What does ISO/IEC 17021-1 require for auditor competence?
Documented criteria for each technical area and function, an initial evaluation that includes a witnessed audit, and ongoing monitoring of competence and performance.
Is there a fixed frequency for on-site evaluation of auditors?
ISO/IEC 17021-1 asks for periodic on-site evaluation at a frequency based on need from all monitoring information. Your procedure, scheme rules or accreditation body may set a fixed interval, so check those.
Can a technical expert replace an auditor on the team?
No. Technical experts support the team but do not act as auditors, and their time does not count toward audit duration.
Are IAF codes the same as technical areas?
Not usually. IAF ID 1 says the use of scope codes as technical areas is limited, so most bodies define narrower technical areas mapped to codes. See IAF codes explained.
Who can be the evaluator for an auditor's witnessed audit?
A person the body has judged competent to evaluate, typically an authorised lead auditor for the same standard and technical area.
How do I prove competence at an accreditation assessment?
Show, for each sampled audit, the criteria, the evidence, the authorisation valid on the audit date and why that auditor was chosen. An audit trail for scheduling decisions helps.