The Annual Credential Audit SOP
Purpose
To reconcile the shop's credential register against three independent sources once a year, so that what the register says a person or the company holds is what the issuing authority actually shows, and so that nobody on payroll is missing a row entirely.
This is not the renewal process, which runs per credential as each one comes due. This is the once-a-year check that the renewal process has not been quietly drifting. A register maintained only by renewals decays in one direction: it keeps the rows it knows about and never notices the rows it never had, or the ones an authority changed without telling you.
Scope
Covers every credential the shop relies on to perform, sell, or insure work: company licences and registrations, individual trade licences, federal certifications, vendor certifications where a warranty or network depends on them, and the bonds and insurance certificates that ride alongside a licence.
Excludes internal competency records, training completions, and skills sign-offs. Those are audited on their own cycle and by different criteria. See related: The Skills Gap Audit SOP.
Excludes per-job permits and inspections, which are a workflow matter, not a credential matter.
Roles and responsibilities
| Role | Responsibility |
|---|---|
| Owner or licence holder | Owns the outcome, signs off the completed audit, decides on any stop-work call |
| Register keeper (office) | Runs the reconciliation, pulls authority verifications, records every discrepancy |
| Each credential holder | Supplies anything the authority will only release to the individual, confirms their own row list |
| Bookkeeper or payroll | Supplies the current payroll roster used for the third reconciliation direction |
Definitions
Register. The single list of every credential the shop depends on, one row per credential per holder, with issuing authority, identifier, issue date, expiry date, and a link to proof. See related: How to Build a Credential Register for a Small Shop.
Authority of record. The body that issued the credential and that a customer or inspector would check. A provider's completion certificate is not the authority of record for a licence.
Stop-work row. A row whose absence or expiry would stop work, void insurance coverage, or make a sale unlawful. Everything else is an informational row.
Discrepancy. Any difference between the register and the authority of record, in either direction, including a date that differs by a single day.
Procedure
1. Freeze the register and take a copy. Export or copy the register as it stands on the audit start date and work from the copy. Auditing a list that people are still editing produces findings nobody can reproduce.
2. Classify every row as stop-work or informational, and count both. Do this before verifying anything, because the classification sets the sampling rule and it must not be adjusted after you see results. If a row's classification is genuinely arguable, classify it stop-work.
3. Verify all stop-work rows against the authority of record. Census, no sampling. Every stop-work row, every year, checked against the issuing body's own record rather than against the certificate in your folder. A certificate proves an issue happened; only the authority shows current standing, and a suspension does not mail you a replacement certificate.
4. Sample the informational rows. Verify a sample of at least 5 rows or 20 percent of the informational rows, whichever is greater, rounded up to a whole row. Draw the sample across holders rather than all from one person, or you are auditing a person instead of a register.
5. Apply the escalation gate. If the informational sample returns 2 or more discrepancies, verify the remaining informational rows as a census. The unit is discrepancies in the sample, not the rate, and the Boolean is a plain threshold on the count. Two errors in a small sample means the register's informational half is not reliable, and there is no useful way to estimate how unreliable from a sample that size.
6. Reconcile in the second direction: authority to register. For each authority the shop deals with, pull what that authority shows the company and its people holding, and look for anything it lists that your register does not. This is the direction that finds the credential someone earned and never told the office about, and the registration you are still paying for on work you stopped doing.
7. Reconcile in the third direction: payroll to register. Take the current payroll roster and confirm every person who performs credential-gated work has at least the rows their role requires. This is the direction that finds a person entirely, not just a row. A hire who came in during a busy stretch is the usual catch.
8. Classify every discrepancy and assign one required action. Use these classes, and do not invent a fifth on the day:
| Class | What it means | Required action |
|---|---|---|
| Expired | Authority shows lapsed, register showed current | Stop the affected work today, start recovery |
| Date drift | Both show current, dates differ | Correct the register to the authority, check the reminder that was built on the wrong date |
| Missing row | Authority or payroll shows something the register does not | Add the row with proof, then ask how it was missed |
| Stale proof | Register current, no linked document or document superseded | Obtain current proof within the audit window |
| Orphaned | Register holds a row for a credential the shop no longer needs | Confirm with the holder, then retire the row with a reason and a date |
9. Escalate on the stop-work rule. Any Expired class on a stop-work row goes to the owner the same day it is found, not in the audit summary at the end. The audit does not get to sit on a live exposure because it is only half finished.
10. Record the audit itself. Date, who ran it, row counts by class, sample size, whether the escalation gate fired, discrepancy counts by class, and the sign-off. Next year's audit starts by reading this record, and a discrepancy class that repeats two years running is a process defect rather than a one-off.
Worked example: a shop that thought it had nine people, one audit, the gate fires
The register holds 41 rows. Step 2 classifies 12 as stop-work (company licence, two individual trade licences, refrigerant certifications, a firm registration, bonds and the general liability certificate) and 29 as informational (vendor certifications, manufacturer network memberships, and several completion records nobody relies on).
Step 3, census of 12 stop-work rows. Eleven match the authority of record exactly. One does not: the register shows an expiry two months later than the authority does, because the renewal confirmation email was filed on the date it arrived rather than the date printed on the licence. Class: date drift, on a stop-work row. Not an emergency, but the reminder built on that date would have fired two months late, which is how a lapse happens to a shop that thinks it is on top of this.
Step 4, sample of the 29 informational rows. Twenty percent of 29 is 5.8, which rounds up to 6, and 6 is greater than the floor of 5, so the sample is 6 rows drawn across five holders.
Step 5, the gate. The sample returns 2 discrepancies: one vendor certification that lapsed eleven months ago and one row with no proof attached at all. Two is at the threshold of 2 or more, so the gate fires and the remaining 23 informational rows are verified as a census.
The census of 23. It returns 3 more discrepancies: two orphaned rows for a service line the shop dropped, and one more lapsed vendor certification.
Totals, stated against their own base. Informational discrepancies: 5 of 29 rows, about 17 percent. Stop-work discrepancies: 1 of 12 rows. Across the whole register, 6 of 41 rows, about 15 percent. No row in the audit was Expired on a stop-work row, so step 9 never fired, but the single date-drift finding on a stop-work row is the one the owner should read first.
Step 6 finds one more thing. Pulling the authority's own listing turns up a company registration renewed on autopay that the register never carried, for a work type the shop stopped doing two years ago. It is orphaned, and it has been renewing itself quietly ever since.
Step 7 finds a person. Payroll lists ten people; the register covers nine. The tenth was hired mid-season and never got rows created. They perform credential-gated work. This is the audit's most valuable finding and the one no per-credential renewal process could ever surface, because a renewal process only ever looks at rows that already exist.
Run the result back through the stated rule once: the gate said escalate at 2 or more discrepancies in the sample, the sample returned exactly 2, and the census was run. The escalation fired correctly.
Exceptions
An authority that will only confirm standing to the individual, not the employer, is common. In that case the holder pulls their own record while you watch, or supplies a dated authority-generated document rather than a screenshot of a logged-in page. Record which rows were verified this way, because it is a weaker verification and it should be visible as such.
An authority whose public lookup is down during the audit window does not become an untested row. Note it, set a date, and close it out separately rather than letting it wash into the totals.
Records and retention
Keep the frozen register copy, the discrepancy log, and the sign-off together as one dated set. Keep the prior two years accessible, because the useful question is not what this year's audit found but which classes keep recurring.
References
- Trade-standard practice for licence and registration verification against the issuing authority of record
- See related: The Credential Renewal SOP, How to Build a Credential Register for a Small Shop, The Credential Proof Packet SOP, How to Recover From a Lapsed Credential