Skill Monitoring
Compliance

Skill Monitoring Ekibi · Competency & training management · July 20, 2026 · updated July 31, 2026 · 7 min read

Training records in an ISO 45001 audit: the 5 most common findings

Clause 7.2 says "competence", not "training". What the auditor wants is not an attendance sheet but evidence of competence. The five most common nonconformities.

Clause 7.2 of ISO 45001 is a short piece of text, yet it produces more audit findings than almost any other. Its critical detail escapes most organisations: the clause requires competence, not training.

Training is a means. The auditor's question is not "did you deliver training" but "how do you know this person is competent".

The five points below are the nonconformities most frequently raised against training records.

1. An attendance sheet exists, evidence of competence does not

This is the most common finding by far. The file contains a signed attendance list; nothing in it shows that the person can actually do the work afterwards.

Attendance is not evidence of learning. A person may have sat in the room and absorbed nothing.

What to do: measure the output of the training — an exam, a practical assessment, or a structured field observation. Link that result to the attendance record. For mandatory and high-risk work, never rely on attendance alone.

2. No competence definition, therefore no criterion

The auditor asks "which competencies does this job require?". If the answer is "we have a training plan", the finding is certain.

Clause 7.2 requires the necessary competence to have been determined. In other words, first define what someone doing this job must know, then measure the person against it.

What to do: build job-based competency profiles. Attach mandatory competencies to each job so that assigning a person to a job automatically determines what is expected of them.

3. Expired competencies still counted as valid

The certificate expired last year, but the record still reads "training completed". The matrix shows 90% proficiency while reality is far lower.

This finding carries serious weight in an audit, because it shows the system itself is unreliable.

What to do: define a renewal period for every competency and make the score invalidate automatically on expiry. A date tracked by hand will eventually be missed.

4. Who changed what, when, and on what basis — unknown

The auditor looks at a cell and asks "who awarded this score?". In a spreadsheet there is no answer. How many copies of the file are circulating, which one is current, who made the last change — none of it is knowable.

What to do: record every score change as who, when, old value to new value. This is the practical form of the standard's "documented information" requirement, and is necessary for data protection compliance too.

5. The training plan is disconnected from the real gap

An annual training plan is produced, but it is a copy of last year's plan. It bears no relation to the actual competency gap.

When the auditor asks "on what basis did you plan this training?", there is no answer.

What to do: derive the training plan from the gap in the matrix. Which competency is missing in which job, how many people it affects, which of them are mandatory — the plan should fall out of those three facts. That makes it both defensible and genuinely useful.

A short pre-audit checklist

If you can answer yes to all six, clause 7.2 will not be a problem.

Skill Monitoring was built to answer each of those six systemically: job-competency profiles, a defined scale, evidence attachments, automatic validity, a full audit trail, and gap-driven training planning.

Frequently asked questions

What exactly does ISO 45001 clause 7.2 require?
That the organization ensures people doing work affecting OH&S performance are competent, and that it can evidence this. An attendance sheet alone is not evidence of competence; there must be an assessment and a decision following the training.
What do auditors most often fail to find in training records?
The link between training and competence. Attendance exists, certificates exist, but there is no written answer to: was this person deemed competent for this task, against which criterion, and who decided?
How is an expired competency treated in an audit?
As invalid. The problem is usually not a wrong record but that it does not drop automatically when it expires: it keeps showing as valid and planning assumes it still holds.
Which records should be ready before an audit?
The job-to-competency mapping, a criterion and validity period per competency, current status per person, evidence and justification for each score, a change trail (who, when, old→new), and the training plan that closes the gap.