
Introduction
Auditors rarely ask, "Did this person attend training?" They ask a harder question: can this person actually do the job?
That gap trips up quality teams constantly. A technician's certificate says "complete." Their actual performance on the floor says otherwise. During AS9100D, ISO 9001, and ISO 13485 audits, that mismatch turns into a finding.
Most organizations don't have a clean answer. Instead, they have scattered training certificates, sign-off sheets buried in a supervisor's desk, and tribal knowledge that lives in one person's head. None of that holds up when an auditor asks for objective evidence.
This guide covers:
- What a competency matrix is
- Why regulated industries use one for audit readiness
- Core components of an effective matrix
- How to build one step by step
- How it differs from a training matrix
Key Takeaways
- Maps skills and proficiency by role — proves capability, not course completion
- ISO 9001, AS9100D, and ISO 13485 require competence evidence, not training attendance alone
- Build one in five steps: define roles, list competencies, set a scale, assess, close gaps
- Competency matrices track proficiency; training matrices track completion status
- Regular review turns a static spreadsheet into a living, audit-ready capability record
What Is a Competency Matrix (Skills Matrix)?
A competency matrix is a grid that maps employees or roles against the specific skills their job requires, scored by demonstrated proficiency rather than a simple "done" or "not done" checkbox. It answers a different question than a training log: not "did they show up," but "can they perform this task independently, under pressure, without a mistake?"
The compliance requirement is direct. ISO 9001:2015 Clause 7.2 requires organizations to determine the competence needed for quality-affecting roles, ensure people have it, act on gaps, evaluate whether that action worked, and retain evidence of all of it.
ISO 9001's competence and awareness requirements list a competence matrix alongside training records and verification through testing or observation as acceptable evidence formats.
AS9100D builds on the same ISO 9001 structure and adds aerospace-specific requirements, so Clause 7.2 logic applies there too. ISO 13485 places the same competence obligation in Clause 6.2, not 7.2. That distinction matters if you're writing procedures against the medical device standard.
Typical Structure
Most competency matrices follow a simple layout:
- Rows: roles or employees
- Columns: required competencies for that role
- Cells: a proficiency score or color-coded rating (green/yellow/red, or a numeric scale)
Typical users include:
- Quality directors building audit packages
- Plant and EHS managers planning coverage
- Training coordinators tracking status
- Auditors looking for objective evidence that competence is actively managed
Competency Matrix vs. Training Matrix vs. Skills Matrix
A training matrix tracks whether a required course or certification was completed. A competency matrix measures what happened after that course ended: the resulting proficiency.
An employee can show "complete" on a training matrix and still land on "developing" on a competency matrix. Completion proves attendance. It doesn't prove capability.
"Competency matrix" and "skills matrix" are generally interchangeable terms in quality management literature.
Many organizations skip the distinction and build one combined "competency and training matrix" that tracks course status and proficiency together—one source of truth instead of two disconnected documents.
Example: What a Simple Competency Matrix Looks Like
Picture five machine operators as rows and four role-critical competencies as columns: blueprint reading, CNC setup, first-article inspection, and nonconformance reporting. Each cell holds a 1–5 score, where 1 means "no exposure" and 5 means "can train others."
In aerospace, defense, and medical device settings, those column headers can't be generic. Each competency should trace back to a specific standard clause, job description requirement, or process step: "AS9100D Clause 8.5.1 setup verification," not just "quality skills." That traceability is what makes the matrix defensible in front of an auditor.

Why Competency Matrices Matter for Audit-Ready Teams
A well-built matrix gives auditors what they're actually looking for: proof that competence is being actively managed, not assumed. Instead of a vague assurance that "everyone's trained," you hand over a document showing who is qualified for what, backed by evidence.
The pressure behind this isn't abstract. The 2024 Deloitte and Manufacturing Institute Talent Study projects U.S. manufacturing may need as many as 3.8 million additional workers between 2024 and 2033, with as many as 1.9 million of those roles potentially unfilled.
That's a workforce capability gap, not just a hiring problem. It lands directly on quality teams trying to prove competence with a thinning bench.
A matrix also exposes risk you can't see in a headcount report. According to South Carolina's NIST MEP affiliate, a production line with only one qualified operator is one sick day away from a bottleneck. A skills matrix surfaces which critical tasks have zero backup coverage, so cross-training happens before a shutdown.
Beyond audits, this same data drives succession planning:
- Who's ready for a promotion this quarter?
- Who can cover a critical role during an extended absence?
- Where is capability concentrated in one person instead of spread across the team?
Pairing the matrix with the right training turns those gaps into capability. Generic training closes a box on a checklist. It doesn't close a verified gap.
QMS Learning's role-specific pathways, scoped to the standard a team is audited against (AS9100D, ISO 9001, and others), target the proficiency the matrix flagged as weak. The AI Workbench diagnoses the real problem behind a gap (process issue, isolated incident, supplier change) and routes the person to the correct method instead of another round of classroom content that may not apply.
That spreads capability across the team instead of bottlenecking every hard decision on one senior person.
Key Components of an Effective Competency Matrix
A matrix earns its place as audit evidence when it includes these six elements:
- Roles or job groups: Group by function, not individual, so the matrix scales with headcount instead of adding a row per hire
- Required skills/competencies: Technical, soft skills, and compliance items pulled from job descriptions and the applicable standard
- Proficiency scale: A consistent scale (1–5, or novice/competent/expert) with clear level definitions so assessors score the same way
- Assessment method and evidence: How proficiency was verified (observation, exam, sign-off) and what documentation backs each score
- Gap visualization: Color coding or scoring that flags under-qualified roles or competencies about to expire
- Review cadence and ownership: Who updates the matrix and how often, tied to role changes, process updates, or a fixed cycle
Skip any one of these and the matrix loses credibility fast. A proficiency scale without evidence is just an opinion. A matrix without a review cadence goes stale within a quarter.

How to Build a Competency Matrix Step-by-Step
A working competency matrix comes from six deliberate steps. Complete them in order so the finished matrix holds up in an audit and actually drives training decisions.
Step 1: Define Roles, Not Individuals
Group employees by function (CNC operator, inspector, welder) rather than building a separate profile for every person. Roles change slowly. Headcount doesn't. A role-based matrix survives turnover; a person-based one needs rebuilding every time someone leaves.
Step 2: List the Competencies Each Role Needs
Pull requirements straight from job descriptions, the applicable standard (ISO 9001, AS9100D, ISO 13485), and process documentation. Guessing at what "sounds important" leads to matrices that are either bloated with irrelevant skills or missing the ones an auditor will actually ask about.
Step 3: Choose and Standardize a Proficiency Scale
Pick one scale and define every level in writing before anyone starts scoring. A common structure:
- Untrained
- In training
- Competent
- Able to train others
Whatever you choose, document it once and apply it everywhere. Inconsistent scoring across departments is one of the fastest ways to lose credibility with an auditor.
Step 4: Assess Current Skill Levels
Use observation, testing, or a formal competency assessment — then keep the paper trail. Sign-offs, scores, and dates are what turn a rating into evidence instead of a guess. If you can't show how a score was determined, an auditor has no reason to trust it.
Step 5: Map Gaps to a Closure Plan
Every gap on the matrix needs an assigned action, not just a red cell. This is the step where generic training usually falls short. Assigning the same course to everyone with a "developing" score treats different problems as if they were identical.
QMS Learning's AI Workbench approaches this differently. It diagnoses the problem behind a low score, selects from ten compliance methods (5-Why, FMEA, CAPA, gap analysis, supplier qualification, and others), and generates the matching artifact.
A recurring supplier defect, for example, gets routed to 5-Why and Supplier CAPA, not a blanket refresher course. The Manager Dashboard then tracks which capability gaps remain open and which standards each person is fluent in, so the closure plan stays visible instead of living in someone's inbox.
Step 6: Set a Review Cycle
Build in triggers, not just a calendar date: a role change, a revised standard, a new process, or a failed reassessment. Reviewing the matrix only once a year during audit prep turns it into a scramble instead of a working management tool.

Common Mistakes to Avoid When Building a Competency Matrix
Even well-intentioned matrices fail audits for predictable reasons:
- Building around individuals instead of roles. This creates a maintenance burden that grows with every hire and departure, and it doesn't scale past a handful of employees.
- Using vague proficiency labels like "okay" or "good." Different assessors interpret these differently, and an auditor will notice the inconsistency immediately. Stick to defined, observable levels.
- Letting the matrix go stale. A matrix updated once a year, or only before an audit, stops reflecting reality. Pair that with a spreadsheet that has no version control, and you lose any trail of who changed what and when.
That last point matters more than it looks. A spreadsheet someone edits directly, with no history, gives an auditor nothing to verify.
Systems with built-in evidence tracking (timestamped activity, revision history, and linked assessment records) hold up under scrutiny in a way a static file never will. QMS Learning's Document Management System, for example, keeps one live revision of every controlled document, preserves prior versions, and logs per-person acknowledgments so the trail behind a competency score stays intact.
Frequently Asked Questions
What is a training matrix?
A training matrix tracks which courses or certifications are required for a role and whether each person has completed them. It complements a competency matrix but doesn't measure the proficiency that results from that training.
Can you provide an example of a training matrix?
Picture employees or roles as rows and required courses as columns, with each cell showing a status like "complete," "in progress," or "overdue." It's a completion tracker, not a proficiency assessment.
What is the 70-20-10 rule for training and development?
It's a development heuristic suggesting roughly 70% of learning comes from on-the-job experience, 20% from coaching and mentoring, and 10% from formal training. It reinforces why course completion alone rarely produces real competence.
What's the difference between a competency matrix and a skills matrix?
In practice, the two terms are used interchangeably. Both measure demonstrated proficiency level by role rather than tracking course completion.
How often should a competency matrix be updated?
Update it whenever a role changes, a standard is revised, or a new process is introduced — plus on a set periodic cycle, such as quarterly or annually. Waiting until audit prep to update it defeats the purpose.
What proficiency scale should I use in a competency matrix?
Use a simple, consistently applied scale like 1–5 or novice/competent/expert, with a written definition for each level. The scale matters less than making sure every assessor applies it the same way.


