Human Resource Management Procedure: The Proven Blind Spot

SOP-003 · Human Resource Management

Determine. Demonstrate. Maintain.

A human resource management procedure is usually the shortest document in the management system, because the clause it is written against is the shortest requirement in the standard. That leanness is the problem. Not one of the five ISO standards MSI works in keeps its competence requirements in a single place, and a human resource management procedure written against Clause 7.2 stops exactly where Clause 7.2 stops.

Direct Answer

A human resource management procedure is the documented process that determines what people need to be able to do and why, ensures they can do it on the basis of education, training or experience, proves the action taken actually worked, and makes people aware of how their own work affects the management system. Every ISO management system standard requires all four things. None of them keeps all four in one clause — which is why a human resource management procedure built from the competence clause alone is structurally incomplete before anyone writes a word of it.

This article covers what a human resource management procedure inherits from Clause 7.2 across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101; the determination almost nobody runs and the structural reason it goes missing; two worked examples from processes that were fully documented and fully staffed by competent people; where each standard diverges from the others; why a ninety-five percent pass rate on a training quiz is a warning rather than a result; and the eight things a working human resource management procedure contains.

The claim underneath all of it is one sentence: the competence clause is lean because the requirements were distributed, not because there are few of them. Read the five standards side by side and the distribution becomes visible. Read any one of them alone and it does not.


The Shared Floor

What does a human resource management procedure have to determine?

Determine. Ensure. Act. Retain.

Direct Answer

Across all five standards, a human resource management procedure must do four things: determine the competence necessary for people whose work affects performance, ensure those people are competent on the basis of education, training or experience, take action where competence is missing and evaluate whether that action worked, and retain documented evidence of competence. Those four are the shared floor. Everything that separates a compliant human resource management procedure from a working one sits above them.

Every human resource management procedure in this family is built on those four. Take them in order, because each one carries a trap that a thin human resource management procedure walks straight into.

Determine the competence necessary

The verb is determine, and determination is an activity with an input and an output. Most human resource management procedures record only the output — a training matrix listing roles down one axis and courses across the other — and never document the input that produced it. That matters because the matrix is then unfalsifiable. Nobody can tell whether a role needs a course because the work demands it or because the role held it last year. A human resource management procedure that skips the determination step inherits every assumption baked into the matrix it started from, and inherits them permanently.

Ensure competence on the basis of education, training or experience

The conjunction is or, and every one of the five standards uses it. Experience is a legitimate basis for competence in ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101 alike. Yet almost no organization records it, because experience does not arrive with a certificate attached. The practical consequence is that the most capable people in the building — the ones with fifteen years on a process and no course code against their name — show up in the competence register as gaps. Then somebody books them onto training they do not need to close a hole that was never real.

A register that cannot record experience will always report its most experienced people as its largest risk.

Take action, and evaluate the effectiveness of the action

This is where the largest single category of finding lives. The standards do not ask whether training was delivered. They ask whether it worked. Delivery is an activity; effectiveness is an outcome, and the two are measured in different places by different people at different times. A human resource management procedure that treats the signed attendance sheet as the effectiveness record has answered a question nobody asked. MSI's work on why training methods decide whether learning survives contact with the job sets out why the gap between the two is structural rather than administrative.

Retain documented information as evidence

Evidence of competence, not evidence of training. The distinction is doing real work: a certificate is evidence that a course was attended, and only becomes evidence of competence when the human resource management procedure says what the course was supposed to establish and how that was confirmed. ISO 14001:2026 has quietly changed the shape of this obligation, which is covered in its own section below. The ISO 10015:2019 guidelines for competence management and people development are the ISO-published companion here — not certifiable, not required, and genuinely useful when the question is what a determination process should look like in practice.

Related Reading

The strategy layer above this document — how hiring, onboarding, performance review and worker engagement align to the people clauses as a whole — is covered in MSI's guide to ISO HR standardization. This article is the document that strategy produces.


The Missing Determination

Why does the human resource management procedure almost always miss the training-needs determination?

Registers. Matrices. Separate rooms.

Direct Answer

The determination that should drive a human resource management procedure — walking the register of processes, environmental aspects or hazards and asking which of them depend on a person — is missing from most management systems for a structural reason, not a careless one. The registers live with one function and the training matrix lives with another. Nothing in a clause-by-clause review forces those documents into the same room, because each clause is assessed against its own owner's evidence. Everyone passes their own section, and the join between them belongs to nobody.

Here is the shape of it. An organization running an integrated system holds three registers. The process register or risk register belongs to quality. The environmental aspect register belongs to the environmental manager. The hazard register belongs to safety. Each is maintained, reviewed and defensible. The training matrix belongs to human resources, and it too is maintained, reviewed and defensible.

The requirement that connects them is a question: for each entry in these registers, does control of it depend on a person doing something correctly, and if so, what does that person need to be able to do? Answering it produces the competence requirements. Nobody owns the question, because it sits between four documents owned by three functions and is asked by none of the clauses those functions are assessed against. The matrix therefore gets built the way matrices get built — from job titles, from last year's version, from what the training provider offers — and the registers never touch it.

The standards do not treat this uniformly, and the difference explains why the omission is so persistent. ISO 14001:2026 states the determination plainly inside Clause 7.2, requiring the organization to determine the training needs associated with its environmental aspects and its environmental management system. ISO 45001 assembles the same obligation out of several clauses in different parts of the standard, so it is easier to miss even though the consequence is more severe. ISO 9001 does not require the determination in those words at all — which does not make the gap smaller, only less visible.

What it costs, stated concretely

The clearest consequence is in occupational health and safety, because there the arithmetic is explicit. Where the hierarchy of controls selects training or instruction as the control for a hazard, the training is the control. There is no engineered barrier behind it. If the training has not been delivered, or was delivered and never verified, or was verified two years ago against a method that has since changed, then the control recorded against that hazard is not in place. The residual risk rating calculated on the assumption that it was in place is wrong.

That rating has been signed, circulated to supervisors, and used to decide what else was needed. A risk assessment is the first document anyone asks for when something goes wrong. The question is never whether the paperwork existed. It is whether the number on it was true.

This is not a warning about what an assessor will find. It is a statement about what the organization currently knows. A management system that cannot answer why a particular person needs a particular competence is carrying an assumption it has never tested — and it is carrying that assumption inside a document it relies on to make decisions. MSI's pillar on the risk management procedure covers the register side of this join, and the ISO 45001 job hazard identification procedure template carries the documented methodology that makes the hazard side auditable.

The fix is a cross-reference, not a rewrite

The correction is smaller than the problem suggests. The human resource management procedure needs one step that no organization can complete without opening the other registers: for every significant aspect, every hazard with a training or administrative control, and every process whose output cannot be fully verified afterwards, name the competence the control depends on and record it in the competence requirement. Inside the human resource management procedure that single step converts the training matrix from a list of courses into an output of the management system. It also gives the determination an owner, which is the part that makes it survive a change of personnel.


Worked Example A

The failure the system diagnosed wrongly, three times

Competent. Careful. Still wrong.

An assembly operator with eleven years on the same cell fits a component the wrong way round. It happens roughly once a month. Each occurrence is raised as a nonconformity, investigated, and closed. All three investigations reach the same conclusion: operator error. All three specify the same corrective action: retrain the operator. She has now been retrained three times.

She is demonstrably competent. Between errors she fits several hundred of the same component correctly. The component is symmetrical to the eye and asymmetrical in function, and it can be seated either way without resistance. When somebody finally looks at the part rather than the person, the fix is a locating pin costing under an hour of workshop time. Twelve months later there has been no recurrence.

A person who cannot do a task has a competence problem, and training may fix it. A competent person who occasionally does it wrongly has a different failure, and repeating the training will not change the rate.

The distinction is not a nicety. It is a requirement in exactly one of the five standards. ISO 9001 Clause 8.5.1 g) requires the organization to implement actions to prevent human error — a requirement with no predecessor in the 2008 edition, which is why it fell through most transition correspondence tables and is absent from a great many procedures adapted from an older base. ISO 13485, ISO 14001 and ISO 45001 have no counterpart to it at all. MSI's pillar on the production and service provision procedure traces that clause and what it demands of the operational side.

Read as a record against the human resource management procedure, the three retraining events are three ineffective corrective actions and a documented history of the organization misdiagnosing the same failure three times. That is the honest reading, and it is available to anybody who lines the three nonconformities up next to each other. The reason nobody did is that a human resource management procedure which treats every people-related failure as a training gap has no route to any other answer. It has one tool, so every problem is shaped like a course.

The correction to the human resource management procedure is a decision point, not a new form. Before training is selected as the corrective action for a human-performance failure, the human resource management procedure requires one question to be answered and recorded: has this person performed this task correctly before? If the answer is yes, training is the wrong control and the investigation continues into the task, the tooling, the instruction or the environment. That question takes a minute. It would have saved two retraining cycles and eleven months of monthly scrap.


ISO 9001

What four requirements does ISO 9001 put outside Clause 7.2?

Qualify. Prevent. Communicate. Capture.

Direct Answer

An ISO 9001 human resource management procedure has to reach four requirements that sit outside the competence clause: qualification of persons for processes whose output cannot be verified afterwards (8.5.1 e), actions to prevent human error (8.5.1 g), communication of competence requirements to external providers (8.4.3), and organizational knowledge (7.1.6). Each is a people requirement. None is in Clause 7.2, and a human resource management procedure assembled clause-by-clause will not find them.

Qualification, which is not the same word as competence

Clause 8.5.1 e) requires the appointment of qualified persons where a process output cannot be verified by subsequent monitoring or measurement — welding, adhesive bonding, sterilization, heat treatment, soldering, any process where the only way to check the result is to destroy it. Qualification here is a formal, named, recorded status held by an individual against a specific process, usually with an expiry. Competence is a broader judgement about a person's ability. The two are related and are not interchangeable, and the standard uses them deliberately. A human resource management procedure that records competence and never records qualification has satisfied 7.2 and missed 8.5.1 e) entirely.

Human error prevention, the clause that arrived without a predecessor

Clause 8.5.1 g) is the requirement behind Worked Example A above. It is new in the 2015 edition and has no equivalent in ISO 13485, ISO 14001 or ISO 45001. It obliges the organization to implement actions to prevent human error — poka-yoke, forcing functions, checklists, physical asymmetry, sequence locks — and its practical effect is that “retrain the operator” stops being a permissible universal answer. The incoming ISO/FDIS 9001 retains it, and the FDIS was approved on 15 July 2026 with publication anticipated in September 2026. Treat that date as anticipated rather than fixed until ISO publishes.

The 2026 edition also brings a Clause 5.1 obligation on top management to promote a quality culture — a requirement with no 2015 predecessor, and one that lands squarely on the awareness half of this human resource management procedure. MSI's analysis of how the 2026 transition arithmetic actually works sets out why the organizations that fold this into normal revision cycles pay a fraction of what the late movers pay.

Competence requirements communicated to external providers

Clause 8.4.3 requires the organization to communicate to external providers its requirements for the competence, including any required qualification, of persons those providers use. This is the clause that pulls contractors, agency workers and outsourced processes inside the boundary of the human resource management procedure. It is routinely missed because contractor management lives in purchasing and competence lives in human resources — the same split that produces the missing determination. Organizations that place workers rather than employ them face this from the other direction, which MSI covers in its work on ISO for staffing agencies and on ISO on active construction sites, where contractor competence is the operative control.

Organizational knowledge

Clause 7.1.6 requires the organization to determine the knowledge necessary to operate its processes, maintain it, and make it available. It is the only clause in any of the five standards that asks what the organization knows rather than what individuals can do, and it is the clause that Worked Example B below turns on. It is also the one most often satisfied with a sentence and a link to a shared drive. A human resource management procedure that takes it seriously ties it to a trigger — a departure, a retirement, a role change — because that is when undocumented knowledge is about to leave and the cost of asking is one conversation.


ISO 13485

Where does ISO 13485 diverge, and why does it change the document?

Documented. Proportionate. Inspectable.

ISO 13485 does not share the harmonized ten-clause structure. It predates it, and retained the older architecture deliberately, because the device community concluded that regulatory stability mattered more than structural symmetry with ISO 9001. Competence therefore does not live at 7.2. It lives at Clause 6.2, Human Resources, inside the resource management clause. Anybody mapping an ISO 9001 checklist across will find the numbers do not line up, and the requirements with no ISO 9001 equivalent will simply not appear on the sheet. MSI's ISO 13485 gap analysis resource covers that architectural divergence in full.

Three things at Clause 6.2 change what a human resource management procedure has to contain in a device context.

First, the process must be documented. ISO 13485 requires a documented process for establishing competence, providing needed training and ensuring awareness. ISO 9001 requires the outcome and leaves the form to the organization. In a device context the human resource management procedure is not optional documentation; it is a required output of the standard.

Second, effectiveness evaluation is tied to risk. The standard's note makes the methodology for checking effectiveness proportionate to the risk associated with the work the training relates to. That is a stronger instruction than it appears. It means the human resource management procedure cannot use a single verification method for everything: a quiz may be adequate for a document control refresher and is plainly inadequate for aseptic technique or final release. The method has to be chosen from the risk of the work, in advance, and written down.

Third, competence obligations appear elsewhere in the standard. Clause 7.5.6 places personnel qualification inside process validation, so validating a process includes qualifying the people who run it — and revalidation raises the question of whether their qualification still holds. Clause 6.4.1 requires the organization to document requirements for health, cleanliness and clothing of personnel where contact could affect product, and to ensure people working in special conditions are competent or supervised by someone who is.

Since 2 February 2026 this is a regulatory document as well as a certification one. The FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820. For devices marketed in the United States, the competence records this human resource management procedure generates are inspectable federal records.

That shift is the single strongest argument for building the device version of this document properly rather than adapting a quality-based one. The ISO 13485 human resource management procedure template is written to Clause 6.2 as its own document rather than as an ISO 9001 procedure with a device paragraph bolted on, and organizations running both standards can take the ISO 9001 and ISO 13485 integrated version instead, which carries the integration decision record showing why each requirement was satisfied once rather than twice. MSI's work on design control metrics makes the parallel point about training completion rates: they measure awareness, and they are uncorrelated with the thing anybody actually cares about.


ISO 45001

Where does ISO 45001 diverge, and why is the obligation harder to see?

Assembled. Distributed. Consequential.

ISO 45001 has the same four sub-clauses at 7.2 as ISO 9001 and ISO 14001, with one significant addition: competence has to account for hazards and the risks associated with the person's work. What it does not have is a single clause instructing the organization to determine training needs from its hazards. That instruction exists, but it is assembled from pieces sitting in four different parts of the standard.

Clause 6.1.2 requires hazard identification. Clause 6.1.4 requires the planning of actions to address the risks identified, including the determination of controls. Clause 8.1.2 requires the hierarchy of controls to be applied, with administrative controls and training named explicitly as a tier. Clause 5.4 requires training to be provided for worker consultation and participation, at no cost and during working hours where possible. Put those together and you have the determination. Read them one at a time, each in its own audit session with its own owner, and you have four separate conformities and no join.

ISO 14001 says the thing in one sentence. ISO 45001 makes you build the sentence out of five clauses. The obligation is the same; the odds of a human resource management procedure containing it are not.

The awareness clause diverges too. ISO 45001 Clause 7.3 requires workers to be aware of incidents and their outcomes, of hazards and risks relevant to them, and — the limb that surprises people — of their ability to remove themselves from work situations they consider to present an imminent and serious danger, together with the arrangements protecting them from undue consequences for doing so. That is an awareness requirement with a procedural dependency: the arrangements have to exist before workers can be made aware of them. Note also that the statutory position on refusing dangerous work is narrower and more conditional than the ISO clause suggests, and varies by jurisdiction; the clause is a management system requirement, not a statement of employment law, and organizations should confirm their own position with counsel. OSHA sets out the federal position for United States workplaces.

Two further points belong in the safety version of the human resource management procedure. First, ISO 45001 requires that training be provided at no cost to workers and, where practicable, during working hours — an explicit requirement no other standard in this set carries. Second, several occupational training obligations are statutory rather than voluntary, and the competence register has to reflect both: OSHA training requirements and specific standards such as the personal protective equipment training and retraining rule at 29 CFR 1910.132(f) impose frequencies and verification duties that no ISO clause specifies. The ISO 45001 human resource management procedure template carries the assembled determination as a single documented step, which is the whole point of writing it to this standard rather than adapting a quality procedure. MSI's coverage of the coming ISO 45001 revision and its psychosocial-risk emphasis is worth reading alongside it, since competence for psychosocial hazards is where the next set of determinations will land.


ISO 14001:2026

What changed for the human resource management procedure in ISO 14001:2026?

Available. Not merely retained.

Direct Answer

ISO 14001:2026 published on 15 April 2026 and keeps competence at Clause 7.2, including the explicit requirement to determine training needs associated with environmental aspects — the determination ISO 9001 never states. The change most relevant to a human resource management procedure is a shift in the evidence obligation toward information being available rather than merely retained. That is a different test, and a harder one: a record filed where nobody can reach it satisfies retention and fails availability.

The 2026 edition replaced ISO 14001:2015 together with the 2024 climate amendment, and moved the standard onto the current harmonized structure. Sources report the transition deadline slightly differently — commonly the end of April 2029 — and the governing document is the transition rule published by your own accreditation body rather than any secondary summary. Note also that Global Accreditation Cooperation Incorporated replaced the IAF and ILAC effective 1 January 2026, so oversight of how these clauses are assessed now sits with a single cooperation body; in the United States ANAB remains the accreditation body for many certificate holders.

Three consequences for the human resource management procedure specifically. First, the training-needs determination is stated rather than assembled, so an environmental human resource management procedure has no excuse for omitting it — the aspect register is named as the input. Second, the emergency preparedness clause requires the organization to provide relevant training in response to potential emergency situations, which is a competence requirement living outside Clause 7 entirely. Third, the renumbering in Clause 6.1 means procedures cross-referencing the 2015 clause numbers now point at the wrong text; risks and opportunities and the planning of actions have moved, and every cross-reference has to be re-walked rather than assumed.

For EHS Managers Mid-Transition

Take a working ISO 14001:2015 system to the 2026 edition in a week, not a quarter

The ISO 14001:2026 Procedure Templates and Guides were built for experienced environmental managers who already run a functioning system and need the documented spine revised against the 2026 text — the renumbered cross-references, the climate and biodiversity context inputs, the new change-planning clause, and the availability test on competence evidence. Editable Word, mapped change by change, with the judgment calls already made. You are adapting a proven set, not rebuilding from a blank page.

See the ISO 14001:2026 transition templates →

For the people document on its own, the ISO 14001:2026 human resource management procedure template carries the aspect-to-competence determination as a worked step. Organizations running environment and safety together will usually want the integrated ISO 14001:2026 and ISO 45001 version, because the aspect register and the hazard register feed one determination rather than two, and there is a real saving in running them as a single step. MSI's guidance on building an integrated management system properly covers where that consolidation pays and where it costs.


ISO 7101

Why does ISO 7101 go furthest of the five?

Recruit. Credential. Staff.

ISO 7101:2023 is the first international management system standard written for healthcare organizations, and its competence clause asks for materially more than the other four. Three things stand out.

A documented recruitment process. No other standard in this set requires one. ISO 7101 pulls hiring itself inside the management system, which means the human resource management procedure in a healthcare organization has to reach upstream of the competence register into how people are selected in the first place — and downstream into orientation and performance evaluation, both of which the clause names.

Staffing levels as a quality requirement. ISO 7101 treats the adequacy of staffing as a management system matter rather than a budgeting one. That is a genuinely unusual move: it makes the number of competent people on a shift a subject of the quality system, not only their individual competence. A perfectly competent workforce at inadequate density is a nonconformity the other four standards have no language for.

Named training topics and fixed frequencies. The standard names specific subjects the workforce must be trained in, and in places fixes the interval — infection prevention and control training is set at annual. Every other standard in this set leaves frequency to the organization's own determination. Combined with the workforce wellbeing requirements in Clause 8, the effect is that a healthcare human resource management procedure has to carry a training calendar with externally fixed dates in it, which is a structurally different document from its manufacturing equivalent.

Credentialing and privileging sit alongside all of this. In a clinical setting, verifying that a licence is current and that an individual is privileged to perform a specific procedure is a competence control with legal weight, and it belongs in the human resource management procedure rather than in a parallel medical staff office system nobody in the quality function can see. The ISO 7101 human resource management procedure template is written against the healthcare clause set rather than adapted from a quality base, which matters more here than anywhere else in the family.


Worked Example B

The failure the system could not see

Complete. Controlled. Incomplete.

A heat treatment process has run for nineteen years without a customer complaint. The setter who runs it retires in March. The work instruction is current, approved, on the controlled document register, and states the furnace program and the soak time. Everything about this process would survive any audit anyone cared to run.

What the instruction does not say is that he adjusts the ramp rate by season. Incoming material arrives colder in winter, and the instruction was written assuming a workshop temperature that stopped being true when the loading bay doors were replaced. He noticed, he compensated, and it never occurred to him that this was information rather than judgement. It has been in his head for eleven years.

Everyone involved was fully competent. The documentation was complete. Nothing was missing that anybody could point to — which is precisely why nothing found it.

ISO 9001 Clause 7.1.6 is the only clause in any of these five standards that asks the question that surfaces this: what knowledge does the operation of this process actually depend on, and is it available? The competence half of a human resource management procedure cannot find it, because competence was never absent. Document control cannot find it, because the document was correct as written. Internal audit cannot find it, because the audit trail is clean. Only a question addressed to the organization's knowledge rather than to any individual's ability reaches it.

The procedural fix costs one conversation per departure. A human resource management procedure that ties Clause 7.1.6 to a leaver trigger asks the departing person one thing: what do you do that is not written down, and what would go wrong if the next person did it exactly as documented? Most people answer that question well when it is asked. Almost nobody is ever asked it, because the exit process belongs to human resources and the knowledge requirement belongs to quality — the same structural split that produces the missing determination three sections up. MSI's work on the ISO onboarding process covers the arrival side of the same problem; this is the departure side, and it is the one nobody builds.

Between them the two worked examples make the case. The first is a failure the competence system answered confidently and got wrong three times. The second is one it could not see at all, because nothing was absent. Neither is reachable from Clause 7.2 alone, and both are ordinary.


Effectiveness

How should a human resource management procedure evaluate effectiveness?

Choose. Delay. Observe.

Direct Answer

A human resource management procedure should evaluate effectiveness by a method chosen in advance from the risk of the work, applied away from the training room and after a delay. Observation of the task, supervised performance, error rates before and after, and independent verification of output all measure whether behaviour changed. An end-of-session quiz measures whether the session just happened. Where a human resource management procedure names the method per competence rather than using one method for everything, the evaluation becomes evidence rather than paperwork.

Start with the diagnostic that gives this part of the human resource management procedure its point. A training quiz on which ninety-five percent of participants pass is not a good result. It is an uninformative one. A test everybody passes discriminates between nobody, which means it cannot tell you which of your people can do the work and which cannot — the exact question the record is supposed to answer. Worse, it produces a file full of green ticks that makes the competence register look strong precisely where it is weakest.

An assessment that everybody passes is not an assessment. It is an attendance record with a percentage printed on it.

Three design rules make the evaluation real, and all three belong in the human resource management procedure rather than in the training plan.

Choose the method before delivering the training. Deciding afterwards guarantees the method that is easiest to run, which is always the quiz. Choosing in advance forces the question the standards actually ask: what would count as proof that this person can now do this? For high-risk work the honest answer is usually supervised performance against a checklist, watched by someone qualified to judge it. ISO 13485 makes this proportionality explicit; the other standards permit it and rarely get it.

Evaluate after a delay, in the workplace. Competence that evaporates in three weeks is not competence, and an assessment taken while the slides are still on screen cannot detect the difference. A delayed check — thirty days, sixty, at the first real instance of the task — measures retention and transfer rather than short-term recall.

Record what the evaluation showed, not that it happened. “Effectiveness verified” is not a finding. “Observed performing the task unsupervised on 14 March; sequence correct; two prompts required on the verification step; re-check scheduled” is a finding, and it is also the input that tells the next determination something useful. MSI's corporate ISO training license exists partly for this reason: when training is billed per seat, managers ration it and evaluate it thinly, and the record degrades in exactly the way described here.

The results of this evaluation are also a management review input in every one of the five standards. Where competence data never reaches the review, leadership is making resourcing decisions without the one measure that tells them whether the resourcing worked. MSI's step-by-step guide to the management review procedure covers what has to arrive at that table and in what form.


The Working Document

What does a human resource management procedure that works actually contain?

Eight marks. No filler.

Direct Answer

A working human resource management procedure contains eight things: a documented determination that starts from the registers, a competence requirement per role that records experience as a valid basis, a qualification route for unverifiable processes, an effectiveness method chosen per competence from risk, an awareness scope naming what people must know, an external-provider clause covering contractors, a knowledge-capture trigger tied to departures, and a re-evaluation rule with named triggers. Everything else in a human resource management procedure is formatting.

Taken one at a time, and against the standards each human resource management procedure answers to:

1. A determination step with a named input. Not “competence needs are determined” but “the process register, the significant aspect register and the hazard register are walked, and for each entry dependent on human performance the required competence is recorded.” Owner named. Frequency named.

2. A competence requirement per role that admits experience. Education, training or experience — with a stated method for evidencing experience, since that is the limb that has no certificate.

3. A qualification route, separate from competence. Which processes require formally qualified persons, who awards the qualification, on what evidence, and when it lapses.

4. An effectiveness method chosen from risk. A short table mapping competence categories to verification methods, so nobody has to decide under pressure and default to the quiz.

5. An awareness scope. What every person must be aware of — policy, objectives, their contribution, the implications of not conforming, and under ISO 45001 the incident and imminent-danger limbs. Awareness is a separate obligation from competence and is routinely folded into it and lost.

6. An external provider clause. How competence requirements reach contractors and agency staff, and how conformance is verified on site rather than assumed at contract.

7. A knowledge capture trigger. Clause 7.1.6 tied to leavers, retirements and role changes, with the question written into the exit process so it survives whoever runs it.

8. A re-evaluation rule with triggers. Not an annual sweep. Process change, method change, equipment change, extended absence, a nonconformity implicating human performance, a statutory frequency — each names a re-check.

Notice that six of the eight marks of a human resource management procedure cross a functional boundary. That is not incidental — it is the finding of this whole article restated as a table of contents. The human resource management procedure is the document where quality, environment, safety and human resources are obliged to agree on something, and most versions of it avoid the obligation by staying inside one function's language. Teams that build it jointly tend to find the disagreements early, which is uncomfortable for a week and cheaper than every alternative. MSI's work on the five stages of team development is a useful frame for why that week is worth scheduling deliberately.


Start From a Working Document

Eight of these are already written, with the judgment calls made

MSI's ISO procedure templates and guides are complete working procedures written as filled-in worked examples rather than outlines — editable Microsoft Word, built to a sixteen-section architecture, each carrying its records, its register, and a desk-level work instruction. The human resource management family covers all five standards plus three integrated combinations, and the determination step described in this article is written into every one of them.

ISO 9001  · 
ISO 13485  · 
ISO 14001:2026  · 
ISO 45001  · 
ISO 7101
ISO 9001 + 13485 integrated  · 
ISO 14001:2026 + 45001 integrated  · 
ISO 9001 + 14001:2026 + 45001 integrated

See the full procedure template library →

If the determination step is the part you want built with you rather than handed over, that is an ISO consulting conversation rather than a document purchase. MSI runs planning sessions that walk your registers against your training matrix and produce the determination as a working output — call 760-434-9141. For teams still deciding how far to take this, the ISO Executive Decision Briefs are short leadership sessions you can watch before committing resources, and SurePath and SureResults cover the certification and maintenance routes respectively.


FAQ

Human resource management procedure: frequently asked questions

Ask. Answer. Advance.

Is ISO 9001 or ISO 13485 stricter on competence?

Neither, consistently — which is the answer most people get wrong. ISO 13485 is stricter on the competence process itself: it requires the process to be documented and makes effectiveness evaluation proportionate to risk. ISO 9001 is wider on everything around it, carrying qualification for unverifiable processes, human error prevention, external provider competence and organizational knowledge, none of which ISO 13485 matches. An organization running both should build to the union, not pick a winner.

Does experience count as competence, or do we need training records?

Experience counts. All five standards allow competence to rest on education, training or experience. The practical difficulty is evidencing it, since experience produces no certificate — so the human resource management procedure has to state a method, typically a documented assessment of demonstrated performance signed by someone qualified to judge it. Organizations that skip this show their most capable long-service people as competence gaps and then train them unnecessarily.

What changed about competence evidence in ISO 14001:2026?

The obligation moves toward evidence being available rather than merely retained. That is a different test, not a weaker one: a record that exists but cannot be reached by the people who need it now fails, where before it passed. ISO 14001:2026 published on 15 April 2026 and clause numbering shifted within Clause 6.1, so any human resource management procedure carrying 2015 cross-references needs them re-walked rather than assumed correct.

Do contractors need to be in our competence register?

Not necessarily in the same register, but their competence requirements have to be determined, communicated and verified. ISO 9001 Clause 8.4.3 requires competence requirements to be communicated to external providers. ISO 45001 goes further in practice, since contractors on site are exposed to your hazards and covered by your controls. The usual failure is a contract clause requiring competence with no verification step behind it — a requirement stated and never checked.

How often should competence be re-evaluated?

No ISO standard in this set names a general frequency, so the human resource management procedure has to define one — and triggers work better than a calendar. Process or method change, new equipment, extended absence from the task, a nonconformity implicating human performance, and any statutory or standard-fixed interval each justify a re-check. ISO 7101 is the exception that fixes certain intervals directly, notably annual infection prevention and control training. An annual blanket sweep satisfies nobody and consumes the budget that should fund the triggered checks.

Is a training matrix enough on its own?

No. A training matrix is an output, and on its own it is an undocumented one. It shows which courses map to which roles but not why, which means it cannot demonstrate the determination the standards require and cannot be tested for correctness. A matrix plus a documented determination plus an effectiveness method is a system. A matrix alone is a list that nobody can defend and nobody can improve.

Does a human resource management procedure have to be a single document?

Only ISO 13485 requires a documented process at all; the others require the outcome and leave the form open. In practice one document works better than several, because the requirements this article traces are distributed across the standards and splitting the procedure reproduces the split that loses them. Organizations running multiple standards usually gain most from a single integrated version with a record of which requirement each section satisfies for each standard.

Where does awareness sit relative to competence?

They are separate obligations and are commonly merged, which loses one of them. Competence answers whether a person can do the task. Awareness answers whether they understand the policy, the objectives, their own contribution and the implications of not conforming — and under ISO 45001, incident outcomes and the arrangements around removing themselves from imminent danger. Awareness applies to everyone; competence applies to those whose work affects performance. The populations are different sizes.


References and further reading

· ISO — ISO 9001 Quality management
· ISO — ISO/FDIS 9001
· ISO — ISO 13485 Medical devices
· ISO — ISO 14001 Environmental management
· ISO — ISO 45001 Occupational health and safety
· ISO — Quality management in healthcare (ISO 7101)
· ISO 10015:2019 — Competence management and people development
· ANSI — ISO 10015:2019 explained
· ANSI — ISO 9001:2026 revision status
· eCFR — 21 CFR Part 820 Quality Management System Regulation
· OSHA — Training requirements
· OSHA — 29 CFR 1910.132 PPE training and retraining
· OSHA — Workers' right to refuse dangerous work
· Global Accreditation Cooperation Incorporated
· ANAB — ANSI National Accreditation Board
· ASQ — ISO 9001 quality resources
· NIST — Manufacturing Extension Partnership
· U.S. Department of Labor — Apprenticeship

About Management Systems International (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

msi-international.com  ·  760-434-9141

Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 13 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply