What Clause 7.2 Requires
Clause 7.2 sets four obligations, and they apply to anyone doing work under the organization's control that affects its information security performance — employees, but equally contractors and outsourced staff. First, determine the competence those people need. Second, ensure they actually possess it, on the basis of appropriate education, training, or experience. The determination comes first for a reason: you cannot evidence competence against requirements you never defined.
Third, where gaps exist, take action to acquire the missing competence — the standard itself suggests a menu running from training, mentoring, and reassignment of current staff through to hiring or contracting competent people — and then evaluate whether the action worked. That evaluation step is the most-missed obligation in the clause. Fourth, retain documented information as evidence of competence: this is one of ISO 27001's explicitly mandatory records.
Why This Clause Exists
To ensure the people operating ISMS-affecting work can actually do it — and that the organization can prove it with retained evidence rather than assumption.
What This Really Means
Clause 7.2 and clause 7.3 are siblings that audits constantly see confused. Awareness (7.3) is for everyone: know the policy exists, know your part in it, know what happens if you ignore it. Competence (7.2) is for the operators: the people whose work directly affects security performance must be demonstrably capable of that work. Nobody flies the plane because they watched the safety briefing.
Scope it honestly. ISMS-affecting roles typically include the ISMS manager, internal auditors, system and cloud administrators, developers, incident responders, the HR people running screening and onboarding, and — the perennial blind spot — contractors and managed-service staff doing any of the above under your direction. Not every employee needs defined competence; pulling everyone in dilutes the effort and produces a records mountain nobody maintains.
The working tool is a competence matrix: roles down the side, required competences across the top — education, certifications, skills, experience — and in each cell how the current holder meets the requirement, plus a pointer to the evidence. Gaps become actions: a training booking, a mentoring arrangement, a reassignment, a hire. Then comes the step most organizations skip: evaluate whether the action worked. An attendance certificate proves presence; a passed assessment, a competent tabletop performance, or a supervisor's sign-off after observed work proves competence.
What auditors treat as the heart of 7.2: sampled roles where the requirement was defined, the evidence exists, and gap-closing actions were evaluated. Two files get pulled on almost every audit — the internal auditor's, because their competence underwrites the credibility of the whole clause 9.2 program, and the ISMS lead's, because everything else rests on them.
Why It Matters
Control failures are usually capability failures wearing a technical costume. The misconfigured storage bucket, the incident response that burned hours in confusion, the internal audit that found nothing in a system full of findings — behind each one is somebody doing security-affecting work without the competence it required. Clause 7.2 is the standard's answer to the gap between owning controls and being able to operate them.
For certification, the stakes are concrete because evidence of competence is mandatory documented information. At Stage 2, a sampled ISMS-affecting role with no defined requirements or no retained evidence is a straightforward nonconformity. An internal auditor who cannot demonstrate audit competence is worse — it puts every internal audit result in doubt and typically drags clause 9.2 into the same finding.
Where competence gaps surface:
- •A direct documentation finding – evidence of competence is a mandatory record; an empty file for a sampled role is among the easiest nonconformities an auditor writes
- •Internal audit credibility collapse – an unqualified internal auditor can invalidate the audit program's results, compounding a 7.2 finding with a 9.2 one
- •Incidents made worse – responders without training or rehearsal lose the hours that matter and miss regulatory reporting clocks
- •The contractor blind spot – "under the organization's control" includes outsourced administrators and MSP staff, and missing evidence for them is a classic finding
- •Training theater – courses purchased, attended, and never evaluated for effect: spend without proof, and a miss on the clause's explicit evaluation step
Regional Compliance Context
Privacy regulation is quietly raising the competence bar for specific roles. India's DPDP Act requires Significant Data Fiduciaries to appoint a Data Protection Officer, and Gulf regimes — Saudi Arabia's PDPL among them — similarly expect named, accountable privacy roles in defined circumstances; for those positions, retained competence evidence does double duty as ISMS record and regulatory readiness. CERT-In's six-hour incident-reporting window adds a parallel pressure: responders for India-connected systems must be demonstrably able to detect, classify, and report inside that clock, which makes incident-response competence evidence worth particular care.
Documented Information Required
Evidence of competence (training records, certifications, CVs)
MandatoryRetained records demonstrating each ISMS-affecting role holder is competent — certificates, training completions, assessment results, CVs and experience summaries. Kept current and tied to the role's defined requirements; this is explicitly mandatory documented information.
Competence matrix
RecommendedRoles mapped against required competences, with current status and evidence pointers — the cleanest demonstration that the "determine" step actually happened.
Training plan with effectiveness evaluations
RecommendedPlanned gap-closing actions plus the post-action evaluation — assessment scores, practical results, supervisor confirmations — proving each action achieved the competence it targeted.
Job descriptions with security competence requirements
RecommendedRole definitions stating the qualifications, skills, and experience that security-relevant positions require — these feed both hiring and the matrix.
See the full ISO 27001 mandatory documents checklist for every document and record the standard requires.
How to Implement Clause 7.2
Identify the Roles That Affect Security Performance
List them from your control ownership and process documents: ISMS manager, internal auditors, system and cloud administrators, developers, incident responders, HR staff running screening and onboarding — plus the contractors or managed-service staff doing equivalent work. Resist listing every employee; that is awareness territory under clause 7.3.
Define Required Competence per Role
For each role, record the education, certification categories, skills, and experience genuinely needed — proportionate to the role, not aspirational. A document controller does not need a security certification; your internal auditor needs demonstrable audit training. Capture the requirements in a competence matrix or in job descriptions.
Assess Current Holders Against the Requirements
Collect what already exists — CVs, certificates, training histories — and have supervisors assess observed capability honestly. The output is a gap list, and an honest gap list is healthy evidence: it shows the determination is real rather than retro-fitted to whoever is in post.
Close Gaps with Deliberate Actions
Choose per gap: training, mentoring by a stronger peer, reassignment, hiring, or contracting the competence in. Prioritize the roles where failure is most expensive — the internal auditor, incident response, the ISMS lead — over blanket programs.
Evaluate the Effectiveness of Every Action
Decide before the action what success looks like, then check: an assessment score, a practical exercise such as tabletop performance, or a supervisor sign-off after thirty days of observed application. Record the evaluation — attendance lists are not effectiveness evidence, and this is the step audits most often find missing.
Retain the Evidence Somewhere Auditable
One repository — an HRIS, an LMS, or a structured drive — holding per-person evidence mapped to roles. Cover contractors through evidence collected at onboarding or a contractual obligation on the supplier to maintain records and produce them on request.
Refresh When Roles, Technology, or Rules Change
Re-run the determination when scope expands, platforms change, or new regulations arrive, and review the matrix annually. Wire it into your joiner-mover-leaver process so a role change triggers a fresh competence check rather than a quiet inheritance of access without capability.
Audit Evidence
During Stage 1 and Stage 2 of your ISO 27001 certification audit, auditors will expect the following evidence to demonstrate conformity with Clause 7.2:
Documentation
- A competence matrix or documented competence requirements for ISMS-affecting roles
- Training records, certificates, and CVs for sampled role holders, mapped to the defined requirements
- Effectiveness evaluations for completed training and other gap-closing actions
- The internal auditor's competence file — audit training, qualifications, and audit history
- Contractor and MSP competence evidence, or supplier agreements obligating its maintenance
Interviews
- The ISMS manager on how necessary competence was determined and how gaps are identified and closed
- The internal auditor on their training and audit method — the interview itself doubles as a live competence check
- A sampled control operator (a cloud administrator, an incident responder) on how they were prepared and assessed for the role
Observations
- Quality of work products as competence proxies — internal audit reports, incident records, configuration standards
- The records system live: navigating from a role to its requirements to the person to their evidence
- Cross-checks between what a role description demands and what the incumbent's file actually shows
Practitioner Insights

A competence matrix for a fifty-person company is one sheet with ten rows — the failure mode is not missing tooling, it is collecting attendance certificates and calling them competence. Add a five-question assessment at the end of training, or a supervisor confirmation thirty days later that the person applies what they learned, and you have satisfied the evaluation step most organizations fail. For contractors the fix is even simpler: ask for certificates and a CV during onboarding and file them. The finding I see is almost never poor evidence — it is absent evidence.

The first file I pull on almost every audit is the internal auditor's, because two clauses stand or fall together there: if the person who wrote the ISMS procedures also audits them, with no audit training and no independence arrangement, 7.2 and 9.2 fail in the same finding. The second pattern is decay — a senior hire whose evidence is a certification from a decade ago and nothing since, while the entire technology estate changed underneath them. Maintain living evidence for the handful of roles the ISMS genuinely depends on, and the rest of the clause looks after itself.
Common Challenges & Solutions
Challenge
No one has defined what competence each role actually requires, so the records are a pile of unrelated certificates.
Solution
Build the matrix top-down from your 5–10 most ISMS-critical roles before collecting anything. Define requirements proportionate to each role, then map the existing evidence against them — the gaps that emerge are the work plan, and the mapping itself is the "determine" evidence auditors ask for first.
Challenge
Training happens, but nobody evaluates whether it produced competence.
Solution
Attach an evaluation to every action when it is booked, not after: a scored assessment, a practical exercise, or a documented supervisor confirmation once the skill has been applied. One line of recorded judgment per action closes the clause's most-missed requirement.
Challenge
The internal auditor is also the ISMS implementer and has no audit training.
Solution
Either train them through a recognized internal-auditor or lead-auditor course and arrange for someone independent to audit the areas they own, or bring in an external internal-audit resource. Document the objectivity arrangement explicitly — competence and independence get probed together.
Challenge
Contractors and managed-service staff do security-critical work with no competence evidence on file.
Solution
Collect certificates and CVs at engagement onboarding, or put a clause in the supplier agreement obligating the provider to maintain records and produce them on request. Either route works; having neither is the finding.
Challenge
Records go stale — people change roles, certifications expire, and the matrix describes last year's team.
Solution
Tie the matrix to the joiner-mover-leaver process so role changes trigger a competence check, track expiry dates on certifications, and review the whole matrix annually alongside the training plan. A dated review note on the matrix is cheap evidence of a living process.