Competence domains
Qualification is multi-disciplinary
The source policy covers AI and machine-learning architecture, safety and trust controls, the Clause 5 Framework, regulatory mapping, data governance and privacy, audit methodology, evidence evaluation, independence, ethical conduct, and sector-specific risk.
Qualification tiers
Authorization grows with demonstrated competence
Auditors-in-training work under direct supervision. Certified Auditors may conduct engagements and classify findings within their authorized scope. Lead Auditors may supervise and lead complex work. Technical Specialists support defined domains but do not independently classify findings or recommend certification outcomes.
Training and experience
Education alone is not enough
Recognized education or experience establishes a foundation. Clause5afe-specific training, practical exercises, supervised engagements, internal assessment, and approval are required before independent authorization. Engagement count does not create automatic advancement.
Continuing competence
Calibration and development continue after qualification
The source policy requires annual continuing professional development and ongoing review of methodology adherence, documentation quality, finding accuracy, independence compliance, and inter-rater reliability. Deficiencies can trigger calibration, supervision, restricted assignment, retraining, suspension, or removal.
Assignment controls
Role, sector, and risk must match
A controlled competence register records qualification, authorized domains, engagement history, training, continuing development, calibration, and status. Client-specific personnel records, assessment scores, examination material, and performance investigations remain confidential.
Reviewers and certification decision-makers require role-specific authorization in addition to subject-matter competence. Their records must show that they can evaluate the work independently and apply the governing decision criteria.
Repeated work with the same organization or team is reviewed for familiarity threats. Rotation, additional independent review, or reassignment is required when continued assignment could reasonably impair objectivity.
Authority boundary
What this policy does not authorize
Public transparency can explain how competence is established and maintained. It does not expose individual personnel files, test materials, performance investigations, or client-confidential engagement records.
Controlled information
What remains outside the public layer
- Individual personnel records
- Assessment scores and performance investigations
- Confidential training and examination materials