Forge University
Governance & Risk

A Certificate on the Wall Isn't Audit Evidence. A Current One Is.

September 21, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

Filing cabinet drawer with folder tabs fading from crisp to faded, representing aging compliance records

Auditors checking staff competence do not accept a certification exam pass from five years ago as proof of current skill. They want a record showing the credential is still active, tied to a named person, a specific role, and a renewal cycle that has not lapsed. If your compliance file cannot produce that, the certification does not count as evidence, no matter how impressive the exam was to pass.

What Evidence Do Auditors Actually Check for Staff Competence?

They check for a live link between a role, a person, and documented proof that person still meets the skill bar for that role today. Under ISO 27001, this is not a formality. Clause 7.2 requires organizations to maintain records of personnel competence, including training certificates, qualifications, and evidence that gaps identified in an assessment were closed with real training, not just noted and forgotten.

Auditors sampling this control do not stop at whether a certificate exists somewhere in a folder. They ask whether the required competencies were defined for the role in the first place, whether the person's current skills were assessed against that bar, and whether any shortfall triggered documented remediation. A certification that expired eighteen months ago and was never renewed is a flag, not a pass, because it shows the organization stopped tracking whether the person still meets the standard it set for the role.

Federal systems work the same way through a different control family. NIST SP 800-53's AT-3 control requires role-based security training before someone is authorized to touch a system, repeated at an organization-defined interval after that. The companion control, AT-4, goes further and requires the organization to document and monitor those training activities and retain the individual records, not just assert that training happened at some point in the past. Between the two, the standard is explicit: training is not a one-time event you check off a box for. It is a maintained record with a shelf life.

Why Does a Certification's Renewal Cycle Matter More Than the Exam Date?

Because the renewal cycle is the only part of the record that proves the person is still current, and most GRC teams track the pass date instead. ISC2, which administers CGRC, CISSP, and several other credentials your team likely holds, requires members to earn continuing professional education credits across a three-year cycle and pay an annual maintenance fee to stay in good standing. ISC2's member policies state plainly that both the CPE credits and the annual maintenance fee must be current for a certification to remain valid. Miss either one and the certification lapses, whether or not the person still remembers how to pass the original exam.

This matters for procurement and audit purposes because a lapsed certification is functionally the same as no certification at all, even though the resume still lists it. ISC2 frames CPE activity as the mechanism that keeps a credential holder current with a field that does not stand still, which is exactly the property an auditor is trying to verify when they ask for competence evidence. A staffing roster that lists "CISSP" or "CGRC" next to a name without a renewal date attached is an unverified claim, not a control.

Most compliance teams do not fail this check because their staff lack skills. They fail it because nobody owns the task of checking renewal status against the audit sample before the auditor asks. The fix is not more training spend. It is a registry that tracks certification status the same way you track patch status or access reviews, as a living state rather than a one-time event.

The Registry Gap Most Compliance Teams Don't Track

Here is where the gap usually shows up in practice, mapped against the frameworks that ask for it.

Framework or ControlWhat It RequiresCommon Gap
ISO 27001 Clause 7.2Documented competence tied to defined role requirementsCertificates on file with no link to a current competence matrix
NIST SP 800-53 AT-3 / AT-4Role-based training before access, repeated at intervals, records retainedTraining logged once at hire, never refreshed or re-verified
ISC2 CPE / AMF cycleOngoing credits and fees to keep a certification activeRoster lists the credential, nobody checks if it lapsed

The pattern across all three rows is the same. The organization did the right thing once, then stopped verifying that the right thing was still true. An auditor sampling personnel files during an ISO surveillance audit or a NIST-aligned assessment does not care how good the original hire looked. They care whether the file in front of them, today, shows a current, verifiable credential attached to the person doing the work.

Building a Competence Record That Survives Audit Sampling

A defensible record needs three things that most rosters are missing: the certification's expiration or renewal date, proof of the CPE or maintenance activity that kept it active, and a link between that credential and the specific role it is meant to satisfy. None of this requires new software. It requires someone treating certification status as a control to monitor rather than a line item on a resume.

For a GRC function specifically, this is where a credential like ISC2's CGRC certification earns its keep as documentation, not just as a skill signal. CGRC is built around the frameworks examiners actually cite, including FedRAMP, FISMA, and NIST risk management processes, so a current CGRC on a governance analyst's file maps directly to the competence language auditors are trained to look for in Clause 7.2 or AT-3 reviews. That direct mapping is what turns a certification from a nice-to-have into evidence a reviewer can act on.

If your team is deciding which credential to prioritize for staff who own governance documentation, system authorization packages, or risk register maintenance, it helps to see the full domain breakdown and how it lines up with your existing control set before committing budget. The curriculum overview and FAQ covers what each domain maps to in practice, which is useful groundwork before you present a training plan to a budget owner who wants to see the audit payoff, not just a course title.

What This Means for the Next Audit Cycle

None of this changes what your team already knows how to do. It changes what you can prove about what your team knows how to do, which is the actual question an auditor, examiner, or procurement reviewer is asking. A certification that lapsed without anyone noticing is worse than no certification claimed at all, because it suggests the organization is not monitoring the very control it is being assessed on.

The practical fix is smaller than it sounds. Build a simple registry that tracks renewal dates and CPE status alongside role assignments, review it on the same cadence as your access reviews, and treat a credential nearing expiration the same way you would treat an overdue patch. If your staff need a structured path to earn or renew a governance-focused credential that actually maps to the language your auditors use, you can start training built around the specific domains your framework requires rather than a generic study plan.

Regulated industries are not short on people who passed an exam once. They are short on documented, current proof that the person sitting in the seat today still meets the bar the organization set for that seat. That distinction is what separates a resume line from audit evidence, and it is worth building a process around before the next reviewer asks for one.

Start training free at Forge University