Checklist for Clause 7.2 of ISO/IEC 42001 (AIMS): Competence

1. Introduction

Below is a certification-grade, auditor-ready tabular checklist for Clause 7.2 of ISO/IEC 42001 - Competence, built directly from the PECB auditing slides provided and expanded into clear, testable, evidence-based audit criteria aligned with PECB / IAS-accredited audit practice.

This checklist ensures competence is defined, acquired, evidenced, monitored, and effective for all personnel influencing AI performance and outcomes.

2. ISO/IEC 42001 - Clause 7.2: Competence

Audit Checklist (Capability Definition, Enablement & Evidence)

# Clause 7.2 Requirement Area Audit Objective Audit Questions (Checklist) Expected Evidence Conformance (Y/N/Partial) Findings / Gaps Risk Rating Improvement Actions
7.2-1 Competence Procedure Confirm formal approach Has the organization established documented procedures to determine, achieve, and maintain competence for AIMS roles? Competence procedure; HR policy     
7.2-2 Role-Based Competence Identification Validate completeness Has the organization identified required competencies for personnel affecting AI performance (e.g. developers, operators, reviewers, managers)? Role-competence matrix     
7.2-3 Alignment to AIMS Needs Ensure relevance Are identified competencies appropriate to the organization's AI systems, risks, and objectives? Competence rationale; AIMS mapping     
7.2-4 Education Requirements Confirm baseline capability Are education requirements defined where applicable for AIMS roles? Job profiles; qualification criteria     
7.2-5 Training Requirements Validate enablement Are training needs identified to address gaps in AI competence? Training needs analysis (TNA)     
7.2-6 Experience Requirements Ensure practical capability Are experience requirements defined and considered for AIMS-related roles? CVs; experience criteria     
7.2-7 Competence Acquisition Actions Confirm execution Has the organization taken actions (training, mentoring, hiring) to acquire required competencies? Training plans; onboarding records     
7.2-8 Effectiveness of Actions Validate outcomes Is there evidence that competence actions are effective (skills applied in practice)? Post-training assessments; audits     
7.2-9 Performance Indicators Confirm measurement Has the organization established performance indicators or targets related to AI competence? KPIs; scorecards     
7.2-10 Competence Evaluation Ensure ongoing assessment Is personnel competence evaluated periodically (e.g. reviews, testing, observations)? Evaluation records; appraisal results     
7.2-11 Risk-Critical Roles Focus on impact Are risk-critical AI roles subject to enhanced competence requirements and oversight? Risk-role mapping     
7.2-12 External Personnel Extend coverage Are external personnel (contractors, vendors) affecting AIMS competence managed and assessed? Contracts; competence attestations     
7.2-13 Awareness of Limits Prevent misuse Are personnel aware of their competence limits and escalation requirements? Interviews; SOP acknowledgements     
7.2-14 Documentation of Competence Confirm evidence Is documented information retained to demonstrate competence (education, training, experience)? Certificates; records in DMS     
7.2-15 Record Control Ensure integrity Are competence records controlled, current, and protected? DMS controls; retention schedules     
7.2-16 Change-Driven Competence Ensure adaptability Are competence needs re-assessed when AI systems, risks, or roles change (Clause 6.3)? Change impact assessments     
7.2-17 Management Oversight Confirm governance Is competence adequacy reviewed by management as part of AIMS oversight? Management review minutes     
7.2-18 Continual Improvement Promote maturity Does the organization continually improve competence based on incidents, audits, or performance gaps? Improvement actions; lessons learned     


3. Auditor's Conclusion - Clause 7.2

Assessment Area Conclusion
Overall Conformance Status ☐ Conform ☐ Minor NC ☐ Major NC
Adequacy of AI Competence ☐ Adequate ☐ Marginal ☐ Inadequate
Effectiveness of Competence Development ☐ Effective ☐ Partially Effective ☐ Ineffective
Risk of Competence-Related Failure ☐ Low ☐ Medium ☐ High

4. Common Auditor Findings (Clause 7.2)

Auditors frequently raise findings where:

  • Competence is assumed rather than defined
  • Training occurs but effectiveness is not evaluated
  • High-risk AI roles lack formal competence criteria
  • External contractors are not assessed for competence
  • Records exist but are outdated or uncontrolled

This checklist explicitly prevents those nonconformities.

5. ISOLTX Operational Alignment

Clause 7.2 is operationalised through:

  • PERFORMANCE → Competence KPIs & targets
  • ERMS → Risk-critical role identification
  • DMS → Controlled competence records
  • AUDIT → Competence effectiveness testing
  • CAS/CAL → External competence requirements

It ensures AI competence is verifiable, defensible, and aligned to risk.

6. Contact Us Today

Are you looking to grow into an Artificial Intelligence (AI) trusted company?

Contact Crest Advisory Africa today for expert guidance on implementing ISO 42001 frameworks tailored to your organization's needs.

Start your journey today. Visit crestadvisoryafrica.com or contact us at +27 (0) 764034307 or nico@crestadvisoryafrica.com.

Let's make 2026 the year of your professional breakthrough!