Overview
ISO/IEC TS 17021-13:2021 is a Technical Specification that defines competence requirements for personnel involved in the audit and certification of compliance management systems (CMS). As Part 13 of the ISO/IEC 17021 series, it complements ISO/IEC 17021‑1 by specifying the knowledge and skills needed by audit teams and other certification personnel to assess CMS implemented according to ISO 37301. This TS was published in 2021 and is intended for certification bodies, accreditation bodies, auditors and organisations seeking CMS certification.
Key topics and requirements
- Scope and relationship to ISO/IEC 17021‑1: Complements the generic competency requirements in ISO/IEC 17021‑1 and is aligned with ISO 37301 (CMS requirements).
- Generic competence baseline: All personnel must meet the generic competence elements required by ISO/IEC 17021‑1 and understand ISO 37301.
- Auditor team competence:
- Understanding the organisation’s context and how business activities relate to compliance obligations and risks.
- Knowledge of laws, regulations and different legal systems relevant to the audit scope.
- Skills to identify applicable legal and other requirements (e.g., codes, contracts, industry standards) and assess their relevance.
- Competence in compliance risk assessment, risk treatment methods and evaluation of compliance controls.
- Specific CMS knowledge: drivers and indicators of a compliance culture, leadership roles, the compliance function, compliance training, monitoring/measurement/reporting, whistleblowing and investigation processes.
- Team-level competence: not every auditor must hold every skill, but the collective team must cover all required competencies for the audit.
- Other certification personnel:
- Personnel who review applications, select audit teams, determine audit time, review reports or make certification decisions must also possess CMS-related knowledge, including organisational context and the CMS requirements described above.
Applications and who uses it
- Certification bodies: to define role-based competency criteria, select and train auditors, and demonstrate competence during accreditation.
- Accreditation bodies: to assess whether certification bodies meet CMS-specific competency requirements when accrediting CMS schemes.
- Lead auditors and audit teams: to plan audits with the right mix of legal, risk and CMS expertise.
- Organisations seeking CMS certification: to understand auditor expectations and prepare documentation and controls for assessment.
- Training providers: to design CMS auditor training aligned with ISO 37301 and ISO/IEC TS 17021-13.
Related standards
- ISO/IEC 17021‑1:2015 - General requirements for bodies providing audit and certification of management systems.
- ISO 37301:2021 - Requirements and guidance for compliance management systems (CMS).
- ISO 19011 - Guidance on auditing management systems (useful for audit principles and techniques).
Keywords: ISO/IEC TS 17021-13:2021, compliance management systems, CMS certification, competence requirements, auditor competence, ISO 37301, ISO/IEC 17021‑1.