← Public Policy Library

Independence safeguards

Auditor and Evaluator Competence Policy

Defines competence domains, qualification stages, supervised experience, calibration, continuing development, and performance oversight for certification personnel.

Controlling public principle

The rule an outsider should be able to rely on

Certification work may be assigned only to people whose documented technical, regulatory, methodological, sector, and independence competence matches the system and role.

Competence domains

Qualification is multi-disciplinary

The source policy covers AI and machine-learning architecture, safety and trust controls, the Clause 5 Framework, regulatory mapping, data governance and privacy, audit methodology, evidence evaluation, independence, ethical conduct, and sector-specific risk.

Qualification tiers

Authorization grows with demonstrated competence

Auditors-in-training work under direct supervision. Certified Auditors may conduct engagements and classify findings within their authorized scope. Lead Auditors may supervise and lead complex work. Technical Specialists support defined domains but do not independently classify findings or recommend certification outcomes.

Training and experience

Education alone is not enough

Recognized education or experience establishes a foundation. Clause5afe-specific training, practical exercises, supervised engagements, internal assessment, and approval are required before independent authorization. Engagement count does not create automatic advancement.

Continuing competence

Calibration and development continue after qualification

The source policy requires annual continuing professional development and ongoing review of methodology adherence, documentation quality, finding accuracy, independence compliance, and inter-rater reliability. Deficiencies can trigger calibration, supervision, restricted assignment, retraining, suspension, or removal.

Assignment controls

Role, sector, and risk must match

A controlled competence register records qualification, authorized domains, engagement history, training, continuing development, calibration, and status. Client-specific personnel records, assessment scores, examination material, and performance investigations remain confidential.

Reviewers and certification decision-makers require role-specific authorization in addition to subject-matter competence. Their records must show that they can evaluate the work independently and apply the governing decision criteria.

Repeated work with the same organization or team is reviewed for familiarity threats. Rotation, additional independent review, or reassignment is required when continued assignment could reasonably impair objectivity.

Authority boundary

What this policy does not authorize

Public transparency can explain how competence is established and maintained. It does not expose individual personnel files, test materials, performance investigations, or client-confidential engagement records.

Controlled information

What remains outside the public layer

  • Individual personnel records
  • Assessment scores and performance investigations
  • Confidential training and examination materials

Connected governance

Follow the policy into the institution.