Exampractice
Costs & Renewal

How Certification Audits Work

Why certification bodies audit applications and CPE claims, how candidates are selected, and what the main audit types involve across PMI, ISC2 and others.

Aisha Rahman · 8 min read
Conceptual illustration of one certification application folder being selected at random for audit from a moving line of folders

Nobody proctors your CV. That is the quiet problem at the heart of experience-based certifications: an exam can be supervised, recorded and scored, but the claim that you led projects for 36 months, or worked five years in security domains, arrives on a form as unverified text. Audits are how certification bodies close that gap — by pulling a slice of applications and renewal claims aside and asking for proof.

If you have been selected for an audit and want the step-by-step walkthrough of what happens next, go straight to what happens during a certification audit. This article covers the layer underneath: why audit programmes exist, how selection works, and the distinct audit types you may meet across the major providers.

Why certification bodies audit at all

A certification is only worth what employers believe it verifies. Exam security handles one half of that — proctoring, identity checks, room scans. Audits handle the other half: the prerequisites and maintenance claims that no proctor ever sees.

Three claims in a typical certification lifecycle rest on the honour system until audited:

  • Experience claims. PMI's Project Management Professional (PMP) requires 36 or 60 months of project leadership experience depending on your education path. ISC2's Certified Information Systems Security Professional (CISSP) requires five years of cumulative paid work in its domains. Both figures are self-reported at application time.
  • Education claims. Degrees, the PMP's 35 contact hours of project management training, and similar prerequisites are declared, not automatically checked.
  • Continuing-education claims. After certification, bodies such as ISC2, ISACA and PMI let you renew by logging continuing-education activity — Continuing Professional Education (CPE) credits or Professional Development Units (PDUs) — rather than re-testing. Those logged hours are also self-reported.

Without a credible chance of verification, every one of those claims would be an invitation to exaggerate, and the credential's value would erode for the honest majority who earned it. The audit programme is not really aimed at you as an individual; it is aimed at keeping the whole system honest. That is why audit selection is dominated by randomness rather than suspicion.

How candidates get selected

Random selection is the norm

The major providers select most audits at random from the eligible pool. ISC2 states plainly that random application audits occur as part of its endorsement process. PMI likewise selects a portion of PMP applications for audit before granting exam eligibility. Neither publishes its selection rate or the full workings of its selection model, so treat any "X per cent of applications get audited" figure you see elsewhere as folklore — the honest answer is that selection odds are not published, and you should apply as if selection were certain.

Random selection has a practical implication people miss: being audited is not feedback. It does not mean your application looked weak, your experience seemed thin, or someone reported you. A flawless application and a shaky one draw from the same lottery.

Can anything raise your odds?

Providers do not publish triggers, so nobody outside their audit teams can say definitively what — if anything — flags an application beyond the random draw. What is verifiable is what audits check: consistency between what you claimed and what your employers, supervisors and training providers can confirm. Applications with internal inconsistencies obviously fare worse once selected, whatever got them selected. The errors that commonly cause trouble at that point — overlapping dates, unreachable contacts, vague role descriptions — are catalogued in our guide to common certification application mistakes.

The three audit types you may meet

"Certification audit" covers three distinct checks, which land at different points in the credential lifecycle.

1. Application audits (before you test)

This is the PMP-style audit. You submit your application, PMI reviews it, and a selected subset must verify their claims — experience, education and contact hours — with supporting documentation before exam eligibility is granted. The application sits on hold until the audit is cleared. For a candidate this is the highest-stakes audit type, because it stands between you and the exam itself, and it arrives on the provider's timeline, not yours.

2. Endorsement and post-exam audits (after you pass)

ISC2 inverts the order. You sit the CISSP (or CCSP, SSCP and so on) first; then, within nine months of passing, you submit an endorsement application in which an ISC2-certified professional in good standing vouches for your claimed experience — or ISC2 itself endorses you after employment verification. ISC2 audits a random selection of these endorsement applications. Passing the exam therefore proves knowledge, endorsement asserts experience, and the audit spot-checks that assertion. A candidate without the experience can still pass the exam and hold Associate of ISC2 status while earning it — the audit regime is precisely why the full credential cannot be shortcut.

3. Continuing-education audits (while you renew)

The least discussed and, across a long career, the most likely to reach you. Renewal by continuing education runs on self-reported activity logs: ISC2 members log CPE credits (120 per three-year cycle for CISSP), ISACA requires 120 CPE hours per cycle with a 20-hour annual minimum reported each year, and PMI members log 60 PDUs per cycle. Providers audit samples of these submissions, asking for evidence that claimed activities — courses, conference attendance, self-study, teaching — actually happened. Because a CPE audit can look back across a full cycle, it rewards people who kept records as they went. Building that habit is the subject of how to prepare for a certification audit.

How the audit types compare

Application audit (e.g. PMP)Endorsement audit (e.g. ISC2)CE/CPE audit (ISC2, ISACA, PMI)
When it landsAfter submission, before exam eligibilityAfter passing, during endorsementDuring or after a renewal cycle
What is verifiedExperience, education, contact hoursClaimed domain experience backed by an endorserLogged CPE/PDU activities
Who confirms your claimsSupervisors, employers, training providersYour endorser and/or employment verificationCertificates, records, activity evidence you retained
What is at stakeExam eligibilityThe credential being issuedThe credential staying active
Best defenceAccurate application, warned contactsHonest experience claims, a reachable endorserEvidence filed at the moment each activity happens

What audits mean for how you apply

Two of the standard pieces of application advice exist purely because audits do.

First, write your application as if it will be audited — because it may be, and you will not know in advance. Practically, that means: only claim experience your named contacts would recognise and confirm; keep dates consistent with what an employer's records would show; and tell your listed supervisors they might be contacted, so an audit email does not catch them cold. A candidate who does this loses nothing if no audit comes and loses no sleep if one does.

Second, keep the documents behind every claim. Degree certificates, training completion certificates, and — once certified — evidence for every CPE or PDU you log. The renewal-side habit matters most, because a continuing-education audit can ask about an activity you completed years earlier. If you are building a system for staying current across one or more credentials, our guide to keeping your certifications current covers tracking CE efficiently; the audit-proofing angle is simply "file the certificate the day you earn it".

A realistic sketch: an IT programme manager applies for the PMP, listing three projects across two employers over four years. Her application is selected for audit. Because her listed supervisors already knew they were named and her contact-hours certificate was saved alongside the application, the audit is an administrative errand rather than a crisis. Her colleague, audited on an application naming a supervisor who left the company with no forwarding contact, faces a genuinely harder problem — not because he lied, but because he treated the application as a formality.

Do audits happen everywhere?

No — and the pattern is logical. Programmes with no experience prerequisite have nothing to audit at application time. Microsoft role-based certifications, CompTIA certifications and AWS certifications are earned by examination alone, so there is no application audit; identity and exam integrity are enforced at the test itself through proctoring. ISC2's entry-level Certified in Cybersecurity (CC) similarly has no experience requirement or endorsement. The audit burden tracks the prerequisite burden: the more a credential asserts about your career, the more its issuer must be able to verify.

Frequently asked questions

What percentage of applications get audited?

The major providers do not publish selection rates, and third-party percentages are guesses. Plan on the assumption that any application can be selected.

Is an audit an accusation of dishonesty?

No. Selection is predominantly random. It is quality control on the certification system, not a judgement about your application.

Can I be audited after I am already certified?

Yes — continuing-education audits verify the CPE or PDU activity you log to renew, and they can arrive during or after a renewal cycle. This is the main reason to retain CE evidence throughout each cycle.

What happens if an audit finds a problem?

Outcomes depend on the provider and on whether the issue is an error or a misrepresentation — consequences range from clarification requests to denial. The process and its possible endings are covered in what happens during a certification audit; for a failed application outright, see what to do if your certification application is rejected.

The audit is the price of the shortcut you didn't take

Every audited claim — experience, education, continuing education — is something the provider agreed to take your word for instead of making you prove it up front. Audits are the mechanism that makes that trust affordable, and random selection is what makes it fair. Apply accurately, warn your references, file your evidence as you earn it, and an audit becomes what it is designed to be: a routine check that the system, and your credential's value, are working. While an application audit holds your file, the study clock need not stop — the certification exams directory links to practice material for the exam waiting on the other side of approval.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like