Skip to main contentChat with us

ISO 27001:2022 Requirements  ·  Support

Clause 7.2
Competence

To ensure the people operating ISMS-affecting work can actually do it — and that the organization can prove it with retained evidence rather than assumption.

Last reviewed: June 12, 2026  ·  Authored by TÜV SÜD & BSI Certified Lead Auditors

What Clause 7.2 Requires

Clause 7.2 sets four obligations, and they apply to anyone doing work under the organization's control that affects its information security performance — employees, but equally contractors and outsourced staff. First, determine the competence those people need. Second, ensure they actually possess it, on the basis of appropriate education, training, or experience. The determination comes first for a reason: you cannot evidence competence against requirements you never defined.

Third, where gaps exist, take action to acquire the missing competence — the standard itself suggests a menu running from training, mentoring, and reassignment of current staff through to hiring or contracting competent people — and then evaluate whether the action worked. That evaluation step is the most-missed obligation in the clause. Fourth, retain documented information as evidence of competence: this is one of ISO 27001's explicitly mandatory records.

Why This Clause Exists

To ensure the people operating ISMS-affecting work can actually do it — and that the organization can prove it with retained evidence rather than assumption.

What This Really Means

Clause 7.2 and clause 7.3 are siblings that audits constantly see confused. Awareness (7.3) is for everyone: know the policy exists, know your part in it, know what happens if you ignore it. Competence (7.2) is for the operators: the people whose work directly affects security performance must be demonstrably capable of that work. Nobody flies the plane because they watched the safety briefing.

Scope it honestly. ISMS-affecting roles typically include the ISMS manager, internal auditors, system and cloud administrators, developers, incident responders, the HR people running screening and onboarding, and — the perennial blind spot — contractors and managed-service staff doing any of the above under your direction. Not every employee needs defined competence; pulling everyone in dilutes the effort and produces a records mountain nobody maintains.

The working tool is a competence matrix: roles down the side, required competences across the top — education, certifications, skills, experience — and in each cell how the current holder meets the requirement, plus a pointer to the evidence. Gaps become actions: a training booking, a mentoring arrangement, a reassignment, a hire. Then comes the step most organizations skip: evaluate whether the action worked. An attendance certificate proves presence; a passed assessment, a competent tabletop performance, or a supervisor's sign-off after observed work proves competence.

What auditors treat as the heart of 7.2: sampled roles where the requirement was defined, the evidence exists, and gap-closing actions were evaluated. Two files get pulled on almost every audit — the internal auditor's, because their competence underwrites the credibility of the whole clause 9.2 program, and the ISMS lead's, because everything else rests on them.

Why It Matters

Control failures are usually capability failures wearing a technical costume. The misconfigured storage bucket, the incident response that burned hours in confusion, the internal audit that found nothing in a system full of findings — behind each one is somebody doing security-affecting work without the competence it required. Clause 7.2 is the standard's answer to the gap between owning controls and being able to operate them.

For certification, the stakes are concrete because evidence of competence is mandatory documented information. At Stage 2, a sampled ISMS-affecting role with no defined requirements or no retained evidence is a straightforward nonconformity. An internal auditor who cannot demonstrate audit competence is worse — it puts every internal audit result in doubt and typically drags clause 9.2 into the same finding.

Where competence gaps surface:

  • A direct documentation finding – evidence of competence is a mandatory record; an empty file for a sampled role is among the easiest nonconformities an auditor writes
  • Internal audit credibility collapse – an unqualified internal auditor can invalidate the audit program's results, compounding a 7.2 finding with a 9.2 one
  • Incidents made worse – responders without training or rehearsal lose the hours that matter and miss regulatory reporting clocks
  • The contractor blind spot – "under the organization's control" includes outsourced administrators and MSP staff, and missing evidence for them is a classic finding
  • Training theater – courses purchased, attended, and never evaluated for effect: spend without proof, and a miss on the clause's explicit evaluation step

Regional Compliance Context

Privacy regulation is quietly raising the competence bar for specific roles. India's DPDP Act requires Significant Data Fiduciaries to appoint a Data Protection Officer, and Gulf regimes — Saudi Arabia's PDPL among them — similarly expect named, accountable privacy roles in defined circumstances; for those positions, retained competence evidence does double duty as ISMS record and regulatory readiness. CERT-In's six-hour incident-reporting window adds a parallel pressure: responders for India-connected systems must be demonstrably able to detect, classify, and report inside that clock, which makes incident-response competence evidence worth particular care.

Documented Information Required

Evidence of competence (training records, certifications, CVs)

Mandatory

Retained records demonstrating each ISMS-affecting role holder is competent — certificates, training completions, assessment results, CVs and experience summaries. Kept current and tied to the role's defined requirements; this is explicitly mandatory documented information.

Competence matrix

Recommended

Roles mapped against required competences, with current status and evidence pointers — the cleanest demonstration that the "determine" step actually happened.

Training plan with effectiveness evaluations

Recommended

Planned gap-closing actions plus the post-action evaluation — assessment scores, practical results, supervisor confirmations — proving each action achieved the competence it targeted.

Job descriptions with security competence requirements

Recommended

Role definitions stating the qualifications, skills, and experience that security-relevant positions require — these feed both hiring and the matrix.

See the full ISO 27001 mandatory documents checklist for every document and record the standard requires.

How to Implement Clause 7.2

1

Identify the Roles That Affect Security Performance

List them from your control ownership and process documents: ISMS manager, internal auditors, system and cloud administrators, developers, incident responders, HR staff running screening and onboarding — plus the contractors or managed-service staff doing equivalent work. Resist listing every employee; that is awareness territory under clause 7.3.

2

Define Required Competence per Role

For each role, record the education, certification categories, skills, and experience genuinely needed — proportionate to the role, not aspirational. A document controller does not need a security certification; your internal auditor needs demonstrable audit training. Capture the requirements in a competence matrix or in job descriptions.

3

Assess Current Holders Against the Requirements

Collect what already exists — CVs, certificates, training histories — and have supervisors assess observed capability honestly. The output is a gap list, and an honest gap list is healthy evidence: it shows the determination is real rather than retro-fitted to whoever is in post.

4

Close Gaps with Deliberate Actions

Choose per gap: training, mentoring by a stronger peer, reassignment, hiring, or contracting the competence in. Prioritize the roles where failure is most expensive — the internal auditor, incident response, the ISMS lead — over blanket programs.

5

Evaluate the Effectiveness of Every Action

Decide before the action what success looks like, then check: an assessment score, a practical exercise such as tabletop performance, or a supervisor sign-off after thirty days of observed application. Record the evaluation — attendance lists are not effectiveness evidence, and this is the step audits most often find missing.

6

Retain the Evidence Somewhere Auditable

One repository — an HRIS, an LMS, or a structured drive — holding per-person evidence mapped to roles. Cover contractors through evidence collected at onboarding or a contractual obligation on the supplier to maintain records and produce them on request.

7

Refresh When Roles, Technology, or Rules Change

Re-run the determination when scope expands, platforms change, or new regulations arrive, and review the matrix annually. Wire it into your joiner-mover-leaver process so a role change triggers a fresh competence check rather than a quiet inheritance of access without capability.

Audit Evidence

During Stage 1 and Stage 2 of your ISO 27001 certification audit, auditors will expect the following evidence to demonstrate conformity with Clause 7.2:

Documentation

  • A competence matrix or documented competence requirements for ISMS-affecting roles
  • Training records, certificates, and CVs for sampled role holders, mapped to the defined requirements
  • Effectiveness evaluations for completed training and other gap-closing actions
  • The internal auditor's competence file — audit training, qualifications, and audit history
  • Contractor and MSP competence evidence, or supplier agreements obligating its maintenance

Interviews

  • The ISMS manager on how necessary competence was determined and how gaps are identified and closed
  • The internal auditor on their training and audit method — the interview itself doubles as a live competence check
  • A sampled control operator (a cloud administrator, an incident responder) on how they were prepared and assessed for the role

Observations

  • Quality of work products as competence proxies — internal audit reports, incident records, configuration standards
  • The records system live: navigating from a role to its requirements to the person to their evidence
  • Cross-checks between what a role description demands and what the incumbent's file actually shows

Practitioner Insights

Saundhi Chauhan

A competence matrix for a fifty-person company is one sheet with ten rows — the failure mode is not missing tooling, it is collecting attendance certificates and calling them competence. Add a five-question assessment at the end of training, or a supervisor confirmation thirty days later that the person applies what they learned, and you have satisfied the evaluation step most organizations fail. For contractors the fix is even simpler: ask for certificates and a CV during onboarding and file them. The finding I see is almost never poor evidence — it is absent evidence.

Saundhi Chauhan · ISO 27001, 27701 Lead Auditor
Surendra Pal Singh

The first file I pull on almost every audit is the internal auditor's, because two clauses stand or fall together there: if the person who wrote the ISMS procedures also audits them, with no audit training and no independence arrangement, 7.2 and 9.2 fail in the same finding. The second pattern is decay — a senior hire whose evidence is a certification from a decade ago and nothing since, while the entire technology estate changed underneath them. Maintain living evidence for the handful of roles the ISMS genuinely depends on, and the rest of the clause looks after itself.

Surendra Pal Singh · CISO, DPO, CISA, ISO 27001, 27701, 42001 Lead Auditor

Common Challenges & Solutions

Challenge

No one has defined what competence each role actually requires, so the records are a pile of unrelated certificates.

Solution

Build the matrix top-down from your 5–10 most ISMS-critical roles before collecting anything. Define requirements proportionate to each role, then map the existing evidence against them — the gaps that emerge are the work plan, and the mapping itself is the "determine" evidence auditors ask for first.

Challenge

Training happens, but nobody evaluates whether it produced competence.

Solution

Attach an evaluation to every action when it is booked, not after: a scored assessment, a practical exercise, or a documented supervisor confirmation once the skill has been applied. One line of recorded judgment per action closes the clause's most-missed requirement.

Challenge

The internal auditor is also the ISMS implementer and has no audit training.

Solution

Either train them through a recognized internal-auditor or lead-auditor course and arrange for someone independent to audit the areas they own, or bring in an external internal-audit resource. Document the objectivity arrangement explicitly — competence and independence get probed together.

Challenge

Contractors and managed-service staff do security-critical work with no competence evidence on file.

Solution

Collect certificates and CVs at engagement onboarding, or put a clause in the supplier agreement obligating the provider to maintain records and produce them on request. Either route works; having neither is the finding.

Challenge

Records go stale — people change roles, certifications expire, and the matrix describes last year's team.

Solution

Tie the matrix to the joiner-mover-leaver process so role changes trigger a competence check, track expiry dates on certifications, and review the whole matrix annually alongside the training plan. A dated review note on the matrix is cheap evidence of a living process.

Frequently Asked Questions

What is the difference between competence (clause 7.2) and awareness (clause 7.3)?
Awareness is for everyone under the ISMS: knowing the policy, your contribution, and the consequences of ignoring it. Competence is for the people whose work directly affects security performance — they must be demonstrably capable, with retained evidence. Annual awareness training does not make your cloud administrator competent, and a stack of admin certifications does not satisfy the awareness requirement for the wider workforce; the clauses are siblings, not substitutes.
Is a competence matrix mandatory for ISO 27001?
No — the mandatory element is retained evidence of competence. The matrix is simply the cleanest way to show the "determine" step happened: roles mapped to requirements mapped to evidence. Auditors accept any mechanism that demonstrates the same chain, but a matrix answers in one artifact what would otherwise take a dozen questions.
Do we need staff with specific certifications to get ISO 27001 certified?
No certification is mandated for any role — competence can rest on any appropriate mix of education, training, and experience. The practical exception is the internal auditor, who needs demonstrable audit competence, for which a recognized internal-auditor or lead-auditor course is the common and convenient evidence. For other roles, define what the role genuinely needs and evidence that; do not collect certificates for their own sake.
How do we evaluate training effectiveness in a way auditors accept?
Define success before the action, then test against it: a scored assessment, a practical exercise such as a tabletop or a supervised task, or a documented supervisor confirmation after the person has applied the skill for a few weeks. Record the evaluation alongside the training record. Attendance certificates alone fail this step — they prove presence, not capability.
Does clause 7.2 apply to contractors and outsourced staff?
Yes — the clause covers persons doing work under the organization's control that affects security performance, regardless of employment status. Collect competence evidence at onboarding (certificates, CVs) or oblige the supplier contractually to maintain and produce records on request. The contractor with privileged access and an empty file is one of the most common 7.2 findings.
Which roles do auditors sample for competence evidence?
The internal auditor first, almost without exception, because their competence underwrites the clause 9.2 program; then the ISMS manager, and one or two operational roles — a system or cloud administrator, an incident responder, sometimes a developer. For each sampled role they want the same chain: defined requirements, evidence the person meets them, and evaluated actions where gaps were closed.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations