02.6
Competence of whoever is assuring
Do the people performing this assurance understand the thing they are examining, and where they do not, is the gap covered by someone who does?
What goes wrong without it
A reviewer who cannot read a programme, price a variation or interpret a technical query will examine the controls surrounding those activities and report on the controls. That is a real finding about a real control environment, and it is not a finding about the programme. The distinction is rarely drawn in the report, so the reader concludes the programme was examined when the paperwork around it was.
What to examine
- Read the team composition against the subject matter. Then read the conclusions and ask which of them required knowledge the team did not have.
- Where a specialist was used, check the reviewer retained responsibility for the conclusion rather than adopting the specialist opinion wholesale.
- Establish whether competence requirements were determined and documented before the work was scoped.
- Check whether the assurance provider has ever declined a scope on competence grounds. A provider that never has may not be assessing it.
Required by
- ISO 55001:2024, Clause 7.2, competence, requiring the organisation to determine necessary competence and retain documented information as evidence.
- ISO 55012, people involvement and competence in asset management.
- Global Internal Audit Standards, Institute of Internal Auditors, effective 9 January 2025, on proficiency and due professional care.
- ISA 620, using the work of an auditor’s expert, and ISA 610, using the work of internal auditors.
Read the sources
- ISO 55001:2024, asset management system requirements2024 edition; read 2026-09-26.ISO’s product page: the publication details and ISO’s own summary of the standard, not the requirement text. The contents, foreword and introduction cited in this publication are taken from the standard’s preview pages hosted on the ANSI webstore, not from this page.
In the asset lifecycle method
The steps of the two methods that this domain examines.
- Controlled baseline, change, deviation and configuration
- Testing and documentationLifecycle review method