Guidance: auditors should have the knowledge and skills to achieve the intended results of their audits, combining generic competence with discipline and sector-specific competence; team leaders need additional leadership competence. Generic knowledge and skills cover audit principles, processes and methods (risk-based approach, planning, time management, prioritisation, communication, interviewing, listening, observing and reviewing records, sampling and its consequences, using technical experts, auditing a process end to end including interfaces, verifying information, judging sufficiency of evidence, assessing reliability, documenting and reporting, confidentiality); management system standards and references and their application, interactions and priority; the organization and its context (interested parties, governance, size, structure, business and management concepts, cultural and social aspects); and applicable statutory, regulatory and other requirements (agencies, legal terminology, contracting and liability), without implying legal expertise. Discipline and sector-specific competence covers the relevant requirements and principles, the fundamentals of the discipline and sector, its methods, techniques and practices for assessing conformity, and its risk principles. Team leaders should be able to plan and assign tasks by competence, discuss strategic issues with top management, maintain team collaboration, manage the process (resources, uncertainty, team health and safety, direction, guiding trainees, resolving conflicts), represent the team, lead it to conclusions and prepare and complete the report. Multi-discipline auditing requires understanding of the interactions between systems and recognition of the limits of one's competence in each discipline.
This control maps to 12 controls across 11 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 12 it maps to, and the evidence behind each claim, over MCP and REST.