Internal Audit.
Independent assurance that PCI’s certification system works as designed.
Overview
Internal audit gives PCI objective evidence that its certification, examination and governance processes are followed and effective — not just documented. It is how the institute holds itself to account.
At a glance
What audits cover
- Eligibility handling and decision-making
- Examination development and security
- Impartiality and conflict management
- Complaints, appeals and records
- Use of AI in PCI’s own operations
How findings are handled
PCI applies this consistently and records what it does, so the process can be checked and improved. The detail is governed by the related policies linked below and is published as the institute matures.
Common questions
Who carries out audits?
Competent people independent of the area being reviewed, to keep the assessment objective.
What happens to findings?
Non-conformities trigger corrective action with verified close-out, feeding continuous improvement.
How often does it happen?
On a planned, risk-based cycle, with results informing management review.
Why this matters
This matters because a credential earns its value from substance, not marketing — clear standards, fair process, transparent governance and honesty about status. Everything here is written to that test: useful to professionals and employers, and never claiming more than is true today.
PCI builds in the open. That means being candid about what is in place and what is still developing, designing around the ISO/IEC 17024 personnel-certification principles, and never implying recognition it does not yet hold. That honesty is part of how trust is earned.
- Substance over marketing
- Fair, transparent process
- Honesty about our status
- Responsible, governed use of AI
Founding-stage document · Version 1.0 — effective date to be confirmed · Reviewed under PCI governance. PCI makes no claims of accreditation or recognition beyond what is true today.
How an audit actually runs
An internal audit is a structured examination, not a walkthrough. It begins with planning: areas are selected on risk — where a failure would do most damage to candidates or to the credential — and the auditor defines what evidence would demonstrate conformity before looking at any of it.
- Plan — scope, criteria and evidence needs agreed on a risk basis
- Examine — records sampled end-to-end, people interviewed, decisions traced from input to outcome
- Report — findings stated with the evidence behind them, not as impressions
- Act — non-conformities move into corrective action with owners and root-cause analysis
- Verify — close-out is checked for effectiveness, not just completion
- Review — results feed management review, closing the loop
Not every finding is a failure
Non-conformity
Practice departs from what policy requires. Always triggers corrective action, with the root cause addressed and the fix verified.
Opportunity for improvement
Conformant but improvable — a process that works yet could be clearer, faster or better evidenced. Feeds continuous improvement rather than mandatory action.
Good practice
Something worth repeating elsewhere. Recording strengths is part of an honest picture — audit that only ever finds fault teaches people to hide things.
Holding ourselves to the standard we certify
PCI certifies professionals in the governed use of AI, so its own use of AI is squarely inside audit scope. Auditors examine where AI assists the institute's operations, whether each use is documented and approved, whether human oversight is real rather than nominal — a person genuinely able to question and override the output — and whether records show who decided what. The test applied is the same one the PCI certifications teach: AI may inform a decision, but a named, accountable human makes it. An institute that asked candidates to meet that bar while exempting itself would not deserve to assess them.
Keep going
What gets audited, and what happens with findings
The audit cycle samples the processes that carry certification risk: eligibility verification, examination administration and security, results handling, credential issue, appeals and records. Auditors are independent of the process they examine, work to a written scope, and report findings with evidence — not impressions.
Findings are graded, assigned an owner and a deadline, and tracked to closure through corrective action. Repeat findings escalate. A summary of audit activity is reported to governance so problems cannot quietly persist.