Skip to main content
Category: Internal Audit

Proficiency

Also known as: Skill Proficiency, Proficiency Level
Simply put

Proficiency is the level of knowledge and skill a person or team has reached in performing a specific task or role. It reflects demonstrated ability rather than mere familiarity, and it can be measured against defined benchmarks or standards. In a GRC setting, proficiency describes how capable staff are at carrying out the responsibilities assigned to them.

Formal definition

Proficiency denotes the degree of expertise an individual or group has attained in performing a defined job, task, or discipline, typically assessed against established benchmarks or proficiency-level criteria. It is commonly evidenced through documented demonstration that a required level of knowledge and skill has been met, and it may be graduated across levels to indicate progression from basic to advanced capability. Proficiency should be distinguished from competency: competency generally refers to the underlying set of knowledge, skills, and behaviors required for a role, whereas proficiency refers to the measured level of mastery actually achieved in applying them. This entry addresses the general concept and does not prescribe specific assessment methodologies, tooling, or role-based competency requirements, which vary by organization, function, and jurisdiction.

Why it matters

In a GRC context, the effectiveness of governance structures, risk management activities, and compliance programs depends heavily on whether the people assigned to them can actually perform their responsibilities to the required standard. A role may be well-defined and a control well-designed, but if the staff executing them have not reached an adequate level of proficiency, the intended outcome may not be achieved. Proficiency therefore provides a way to move beyond assuming capability toward demonstrating it against defined benchmarks or proficiency-level criteria.

Distinguishing proficiency from mere familiarity matters because assurance functions, management, and regulators increasingly look for documented evidence that required knowledge and skill have been met, rather than self-asserted experience. Proficiency levels allow organizations to describe progression from basic to advanced capability, which can inform decisions about task assignment, oversight intensity, and where additional development or supervision may be needed.

Proficiency should not be conflated with competency. Competency generally refers to the underlying set of knowledge, skills, and behaviors required for a role, whereas proficiency refers to the measured level of mastery actually achieved in applying them. Treating the two as interchangeable can lead an organization to believe it has capable staff simply because roles and competency requirements are documented, without confirming the level of ability actually demonstrated.

Who it's relevant to

Governance and human capital leads
Those responsible for defining roles and decision rights use proficiency to confirm that individuals assigned to governance responsibilities have demonstrated the required level of skill, rather than assuming capability from documented role definitions alone.
Risk managers
Risk professionals may consider the proficiency of staff performing risk activities when judging how much reliance to place on their work and where additional oversight or development may be warranted.
Compliance officers
Compliance teams can use proficiency benchmarks and documented evidence to support that staff carrying out compliance responsibilities have met required knowledge and skill levels, distinguishing demonstrated ability from familiarity.
Internal auditors and assurance functions
Assurance providers may evaluate whether personnel executing controls have attained an adequate level of proficiency, keeping their assessment independent from the management activities and controls being reviewed.
Learning and development functions
Those designing capability programs use graduated proficiency levels to describe progression from basic to advanced capability and to identify where further development is needed, drawing on the distinction between competency requirements and measured proficiency.

Inside Proficiency

Knowledge
The body of technical understanding relevant to a role or engagement, such as familiarity with applicable frameworks, standards, regulations, and the organization's processes and risks. In an assurance context, this includes understanding of auditing standards and the subject matter under review.
Skills
The practical abilities to apply knowledge effectively, including analytical, evaluative, and communication capabilities needed to perform work to an expected standard.
Competencies
The combination of knowledge, skills, and behaviors that enable an individual or function to carry out assigned responsibilities. Proficiency is commonly assessed against defined competency expectations for a role.
Collective proficiency
Where an individual does not possess all required proficiency, it may be obtained at the function or engagement-team level, or by drawing on external specialists or advisors, so that the required competence is available in aggregate.
Due professional care
A related but distinct concept: proficiency concerns the competence to perform work, while due professional care concerns the diligence and reasonable judgment applied when performing it. The two are typically treated together in professional standards but are not interchangeable.
Continuing professional development
The ongoing maintenance and enhancement of proficiency over time, commonly supported by continuing education, training, and relevant experience, to keep pace with changes in standards, regulations, and practices.

Common questions

Answers to the questions practitioners most commonly ask about Proficiency.

Is proficiency the same as holding a professional certification?
No. Proficiency refers to the demonstrated ability to apply knowledge, skills, and competencies effectively in practice, whereas a certification is one form of evidence that may support a proficiency assessment. Holding a credential does not by itself establish that an individual can apply the relevant knowledge to the specific engagements or context at hand. In many assurance standards, proficiency is assessed at the level of the function or engagement team collectively, not solely through individual qualifications, and it typically must be maintained over time rather than treated as a one-time achievement.
Does an internal auditor need to be an expert in every subject they audit to be considered proficient?
Not necessarily. Proficiency does not require that each auditor personally possess deep expertise in every domain examined. In many frameworks, it is commonly interpreted at the collective level, meaning the engagement team or function as a whole should have, or be able to obtain, the competencies needed. Where specialized knowledge is lacking, proficiency may be satisfied by obtaining competent advice and assistance, such as engaging a subject-matter specialist, while the practitioner retains responsibility for the overall work.
How can an assurance function demonstrate that its staff are proficient?
Evidence commonly includes a mix of relevant qualifications, documented experience, competency frameworks or skills matrices mapped to the function's scope, continuing professional development records, and quality assurance results. Some functions use competency assessments tied to specific engagement types. The appropriate evidence varies by organization, industry, and applicable standards, and the emphasis is typically on demonstrated ability to apply knowledge rather than credentials alone. This entry does not prescribe specific tools or a mandatory assessment method.
What can a function do when an engagement requires competencies its team does not have?
Options commonly include obtaining competent advice and assistance from internal or external specialists, supplementing the team with individuals who have the needed skills, providing targeted training where time permits, or adjusting the scope in consultation with relevant stakeholders. Where specialists are used, the practitioner generally remains responsible for directing the work and evaluating whether the specialist's contribution is sufficient for the engagement objectives. The suitability of each approach depends on the nature of the work and applicable standards.
How does proficiency relate to independence and objectivity in an assurance function?
Proficiency and independence are distinct requirements that both typically apply to assurance functions. Proficiency concerns capability, the knowledge and skills to perform the work competently, while independence and objectivity concern freedom from conditions and biases that could impair judgment. A practitioner may be highly proficient yet lack objectivity for a particular engagement, or be independent yet insufficiently skilled. Both are commonly assessed separately when planning and staffing engagements.
How often should proficiency be reviewed and maintained?
Proficiency is generally treated as an ongoing requirement rather than a fixed status, because relevant laws, standards, technologies, and business practices change over time. Many functions maintain it through continuing professional development, periodic competency reviews, and consideration of proficiency needs during engagement planning. The specific frequency and mechanisms vary by organization, sector, and applicable professional standards, and this entry does not set a required review interval.

Common misconceptions

Proficiency means a single individual must personally possess every skill required for an engagement.
In many professional frameworks, required proficiency may be met collectively at the team or function level, including through the use of external specialists, rather than residing wholly in one person.
Proficiency and due professional care are the same thing.
They are distinct. Proficiency refers to having the necessary knowledge, skills, and competencies, whereas due professional care refers to the diligence and reasonable judgment exercised when applying them. A proficient professional can still fail to exercise due care, and vice versa.
Once attained, proficiency is a permanent qualification.
Proficiency is typically expected to be maintained and updated over time, commonly through continuing professional development, because relevant standards, regulations, and organizational risks evolve.

Best practices

Define the knowledge, skills, and competencies expected for each role or engagement, and assess individuals and teams against those expectations before assigning work.
Where an individual lacks required proficiency, address the gap at the function level or by engaging qualified specialists or advisors so the necessary competence is available collectively.
Support ongoing proficiency through continuing professional development, keeping current with changes in applicable frameworks, standards, and regulations.
Distinguish proficiency from due professional care in your quality processes, evaluating both the competence to perform work and the diligence applied when performing it.
For assurance functions, document how proficiency requirements are met while preserving the independence and objectivity distinctions between assurance and management activities.
Periodically review competency requirements as roles, risks, and regulatory expectations change, rather than treating proficiency as a one-time attainment.
Application Security Isn’t Optional Anymore.