What a role map is not
A role map is orientation — not a job description, a competency framework, or a statement of what any employer expects of you.
Companies pay you to look hard at them, or at their suppliers, and to say plainly what you find. Fixing it is somebody else’s job.
You audit against a standard the client engages you to apply, report findings with their evidence, and hand the report over. Classification, remediation and closure belong to the audited party and to whoever commissioned the audit.
You are the outside eye an organisation buys precisely because it cannot see itself — and the value collapses the moment you acquire an interest in the answer.
YOUR NEIGHBOURHOOD, IN ONE CONNECTED SYSTEM
Between the party commissioning the audit and the party being audited, belonging to neither.
ASSESSMENT · AUTHORITY TO FIND, NOT TO FIX
Working across clients
The eight facets above describe a role inside one organisation. Contract Auditor is not in one, so these are the boundaries that replace a reporting line.
WHOSE SYSTEM GOVERNS
The audited party’s system, read against a standard the commissioning client selects — and naming both, in the report, is the work. An audit that does not state which standard was applied and whose procedures were examined cannot be relied on by anyone downstream.
AUTHORITY
- What was found, with the evidence that supports it
- Where a control does not do what the procedure claims it does
- How the client classifies a finding, or what it does about the supplier
- Whether a finding is closed — closure belongs to the audited party
- What the audited party tells its own regulator
BETWEEN ENGAGEMENTS
- Audit method, and knowing which questions expose a weak control quickly
- Familiarity with the standard being applied
- Findings, evidence or documents from any other audit
- The identity of an audited party’s problems, in any form another client could recognise
- The report, held by the commissioning client and usually by the audited party
- A record of what could not be examined, which is as material as what was
- Auditing a system you designed, wrote or remediated
- Auditing where you or your firm hold a continuing consulting relationship with the audited party
- Accepting an engagement whose fee depends on the outcome of the audit
- A qualification decision, a due-diligence request, or an inspection the client is preparing for
- The client’s decision on the supplier
- Remediation the audited party executes
- A scope and standard agreed before the audit
- Access granted by the audited party
- Evidence you can see for yourself rather than be told about
- The commissioning client, for a decision about a supplier
- The audited party, for a fair account
- The findings and the evidence under each one
- The accuracy and the fairness of the report
- The classification the client applies to your findings
- Whether anything is remediated
- The commercial relationship your report affects
- The commissioning client, immediately, for anything indicating patient risk or falsified data
- Withdrawal, where access is restricted so far that an opinion cannot be supported
- The audit report and its evidence trail
- A record of scope, standard and any access limitation encountered
WHAT THIS ROLE CAN EVIDENCE · 0
No published competency maps to Contract Auditor yet. 14 are published across the registry, and this role is not among the ones they name.
Read the standard and its stated coverage →A role map is Locate, moment 2 of 5: what surrounds your work, what you own, and what you escalate. It does not teach the practice or test it. Next is Learn — the Quality Assurance pathway. No scenario exercises this role yet, so Practise comes later for it, then what any of it evidences. Skip any of them — the order does not change.
The regulations and standards this pathway anchors on. SPEQ decodes and cites each one; the authoritative text lives at the official source.
- 21 CFR Part 211Current Good Manufacturing Practice for Finished PharmaceuticalsFDA · last revised 2023-04-01
- ICH Q9(R1)Quality Risk ManagementICH · last revised 2023-01-18
- ICH Q10Pharmaceutical Quality SystemICH · last revised 2008-06-01
- ISO 9001:2015Quality Management Systems — RequirementsISO · last revised 2015-09-15