Forge University
CISA

The Qualified Individual Clause: What Regulators Actually Check Before They Trust Your Audit Team

September 18, 2026

Ric Hall, CRO— AI-assisted and reviewed prior to publication.

A single illuminated doorway stands out among a long row of closed, unmarked doors in muted blue tones.

A CISA on the audit team is not a resume line examiners skim past. Regulators and standard-setters from the FFIEC to the PCAOB to NYDFS explicitly evaluate whether the people performing IT audit and control-testing work are qualified to do it, and a recognized credential is the fastest way to document that qualification when someone asks you to prove it.

What do bank examiners actually check about your audit staff?

Examiners do not just review your audit findings. They review whether the people who produced those findings were competent to produce them. The FFIEC's IT Examination Handbook tells examiners to weigh the "expertise and size of the audit staff relative to the IT environment" as a core factor in judging whether an institution's IT audit function is effective at all.

That is a staffing question dressed up as a process question. An examiner looking at your audit charter, your workpapers, and your finding-remediation tracker is also silently asking whether the analyst who signed off on a control test actually understood the control. A certification does not replace judgment, but it gives the examiner a documented, third-party-validated answer instead of a verbal assurance from a manager who has a reason to say yes.

Why does a certification become audit evidence instead of just a skill?

Because regulators keep writing "qualified" into binding text, and someone eventually has to prove what that word means. New York's cybersecurity regulation is explicit about this: covered entities must designate a "qualified individual" to oversee and enforce the cybersecurity program, and during an exam or a post-incident review, the burden falls on the institution to show its documentation for that word.

The same logic runs through auditing standards that have nothing to do with cybersecurity specifically. When an external auditor wants to rely on work done by an organization's internal audit function, PCAOB AS 2605 requires the external auditor to first "assess the internal auditors' competence and objectivity" before using any of that work to reduce audit scope. Competence has to be demonstrated, not assumed, and a credential with a defined body of knowledge and continuing education requirement is the cleanest artifact available for that demonstration.

The defense contracting world made this even more literal. Under the Department of War's CMMC program, only professionals holding the CMMC Certified Assessor credential are permitted to "perform formal CMMC Level 2 certification assessments" on organizations handling controlled unclassified information. There, the certification is not supporting evidence of competence. It is the legal gate that determines whose signature on an assessment counts at all.

Where else does staffing certification show up as a control, not a preference?

The pattern repeats across frameworks that never mention "audit" in their titles. The following comparison shows how differently worded regulatory and standards text converges on the same expectation: that the people doing the work are demonstrably qualified to do it.

Framework or regulatorWhat it requires of staff
FFIEC IT Examination HandbookExaminers weigh audit staff expertise against the size and complexity of the IT environment being audited
PCAOB AS 2605External auditors must assess internal auditors' competence before relying on their work
NYDFS 23 NYCRR 500Covered entities must designate a "qualified individual" to run the cybersecurity program
CMMC (DoW)Only CMMC Certified Assessors may perform Level 2 certification assessments
Federal Reserve third-party guidanceBanks must review a vendor's staffing levels, qualifications, and "requisite certifications and licenses"

None of these frameworks say "hire a CISA." What they say, in different words, is that someone in the chain of accountability has to be able to point to a defined, external, verifiable standard for staff competence when a regulator, external auditor, or board member asks who checked the work.

Does this apply to vendor oversight too, or just internal audit staff?

It applies to both, and increasingly the two obligations sit in the same file. The Federal Reserve's May 2024 guidance on third-party risk management tells banks to review a prospective vendor's "staffing levels and qualifications" and confirm that key personnel carry the "requisite certifications and licenses" for the work being outsourced.

That means the same question you would ask about your own internal audit team, a bank's third-party risk office is now asking about you if you sell IT audit, assessment, or assurance services into a regulated client. A team that can show CISA holders in its audit roster is answering a due-diligence question before it is even asked, which shortens vendor-onboarding cycles and reduces the number of follow-up questionnaires that come back from a client's risk committee.

This is also where the cost of skipping the documentation shows up first, not in a headline breach but in a stalled contract. A procurement team that cannot produce a current staffing-and-certification roster on request will get a follow-up questionnaire, then a call, then a delay to the go-live date while someone assembles the answer under time pressure. Building that roster before the first request costs a fraction of what it costs to build it during one.

What CISA actually documents, beyond the acronym

The credential's value as evidence depends on what it actually tests, not just that it exists. ISACA's CISA exam content outline covers five job-practice domains built from audit process, IT governance, systems acquisition and implementation, operations and resilience, and asset protection, all validated by working practitioners rather than written in the abstract.

That mapping matters to a compliance officer building a staffing file, because it lets you point a regulator to the specific competencies a CISA holder has already been tested on, rather than describing them in a job description you wrote yourself. If your organization is deciding where to start building that documentation, a look at the CISA certification prep curriculum shows how closely the exam domains track the actual audit engagement lifecycle, from planning and risk assessment through fieldwork and reporting.

Building the staffing case before an examiner asks for it

Waiting for an exam letter to start documenting staff qualifications is the wrong order of operations. The institutions that move through exams and vendor due-diligence reviews with the fewest follow-up requests are the ones that already maintain a current roster mapping each audit or assessment role to a named credential, renewal date, and continuing-education record. That roster is not paperwork for its own sake. It is what an examiner, a PCAOB-reviewed external auditor, or a client's third-party risk analyst actually pulls when they need to close a finding without a second round of questions.

Getting that roster in order usually surfaces gaps you did not know you had, whether that is an audit lead whose certification lapsed two renewal cycles ago or a new hire performing control testing with no credential on file at all. A curriculum overview and FAQ is a reasonable place to start scoping what a gap actually requires to close, since the answer differs depending on whether you are certifying a first-time auditor or refreshing someone who already has years of fieldwork experience.

The gap is rarely evenly distributed across a team. Larger institutions tend to have certification coverage concentrated in senior audit leadership and thin among the staff actually running fieldwork, which is precisely the group whose competence PCAOB and FFIEC guidance asks you to demonstrate. Closing that gap is a scheduling problem more than a budget problem, since exam windows and study time have to be planned around an existing audit calendar rather than layered on top of it without adjustment.

None of this is about collecting a credential to satisfy a checkbox. It is about giving the people above you in the accountability chain, your CFO, your audit committee, your examiner, something concrete to point to when they are asked whether the audit function can be trusted. If you are the one responsible for building or defending that staffing case, signing up to start training toward the CISA is the more direct route than assembling the argument from job descriptions and tenure alone.

The organizations that treat certification as staffing infrastructure, not an individual career perk, are the ones that answer examiner questions about competence in one meeting instead of three. That difference shows up in the length of an exam cycle, the number of matters requiring attention on a report, and how quickly a vendor risk questionnaire clears committee. None of those outcomes depend on the acronym itself. They depend on whether the acronym is backed by a file someone can actually produce.

Start training free at Forge University