Quick Read
SPK DDMS2000:2026 Section 9.3 requires organisations to establish role-specific competence matrices that go beyond training attendance, with tiered authorisation tied directly to due diligence risk levels and module-specific expertise rather than generic competence across all functions. The standard mandates that competence be verified through assessed casework and qualified reviewer sign-off, maintained continuously, and documented as a hard conformance requirement—not a human resources formality. Organisations adopting the standard must distinguish between different due diligence roles (AML/KYC analysts, export control specialists, HREDD assessors, and others) and ensure that authorisation decisions are recorded and current for each tier and module.
Why This Whitepaper Exists
Most due diligence programmes that fail do not fail because the wrong policy was written. They fail because the person doing the work did not know what they were looking at — could not tell a primary source from an aggregated screening result, did not recognise a red flag pattern they had never been trained on, or reached a conclusion nobody with more experience ever reviewed.
SPK DDMS2000:2026 treats this as a first-order problem rather than a footnote. Section 9.3 (Competencies) is one of the most detailed clauses in the entire standard — eleven separate requirements governing who is allowed to do due diligence work, how their competence is verified, how it is maintained, and what happens when it fails. This whitepaper exists because organisations adopting the standard consistently ask the same question: what does a competency matrix that actually satisfies Section 9.3 look like in practice?
A due diligence management system is only as good as the competence of the people operating it. Section 9.3 treats competence as a hard conformance requirement, not a general HR matter.
What Section 9.3 Actually Requires
Before building a matrix, it is worth being precise about what the standard requires, because several of its requirements are easy to under-implement without noticing.
Role-specific competence, not generic competence
Section 9.3.1 requires the organisation to define competence requirements for each applicable module separately — distinguishing, at minimum, AML/KYC analysts, export control specialists, HREDD supplier assessors, forced-labour and import-compliance investigators, background-check administrators, anti-bribery third-party reviewers, and brand/reputational reviewers. Competence in one module is not assumed to transfer to another without a demonstrated basis. An analyst who is genuinely skilled at supplier human-rights due diligence is not automatically competent to assess export control classification risk; the two require different source material, different red-flag literacy, and different regulatory grounding.
Tiered authorisation
Section 9.3.2 ties authorisation directly to the DD tier established under Section 6.4. Anyone conducting Tier 3 or Tier 4 due diligence must hold demonstrated competence appropriate to that tier before being authorised to work unsupervised, and the organisation must maintain a current record of who is authorised, at which tier, per module. A matrix that only records “has completed training” does not satisfy this — it needs to record an authorisation decision.
Verification beyond attendance
Section 9.3.3 is explicit that competence must be verified through means beyond training attendance: assessed casework, sign-off by a qualified reviewer, a recognised third-party qualification where one exists for the module in question, or a documented internal competency assessment. The organisation must retain evidence of how competence was verified, not only that training occurred. This is the single most common gap organisations bring to a Sentinel readiness assessment — a training log exists, but nothing demonstrates that anyone confirmed the person could actually do the work.
Independent second-level review
Section 9.3.4 requires a second-level qualified review and sign-off for Tier 3 and Tier 4 findings before they are relied upon for a decision, performed by someone other than the analyst who did the underlying research. No high-tier finding rests on one person's uncorroborated work.
Ongoing maintenance, not a one-time credential
Section 9.3.5 requires minimum ongoing competence maintenance — periodic refresher training, exposure to a minimum volume of live casework, and awareness updates tied to regulatory change tracked in the standard's Annex D — and requires that an individual's authorisation to conduct unsupervised DD be suspended if these are not maintained. Competence, under this standard, has an expiry date unless actively renewed.
Parity for outsourced providers
Section 9.3.6 requires that the same competence requirements apply to third-party or outsourced DD providers as to internal staff, and that the organisation remains accountable for the competence of anyone performing DD on its behalf. This connects directly to Section 10.17 (Vendor and Outsourced DD Provider Management), which requires competence verification of vendor personnel through vendor attestation, sample review of vendor work product, or independent audit — and states plainly that a vendor's high price or brand recognition is not itself evidence of competence.
Feeding the improvement loop
Section 9.3.7 requires that competence failures — missed findings, methodology not followed, red flags not escalated — be treated as a category of nonconformity under Section 14.2, feeding back into the individual's authorisation status and, where the failure is systemic, into the organisation's training and hiring standards.
AI-output evaluation as its own competence
Section 9.3.8 requires that where AI-assisted tools support DD research, a competent human remains accountable for reviewing and accepting the output, with the full AI governance requirements set out at Section 10.16. Section 9.3.9 goes further, naming research methodology and source-evaluation competence as its own explicit requirement — distinguishing primary from secondary sources, assessing source currency and independence, and corroborating a material adverse finding across more than one independent source before it is relied upon, consistent with the evidence and source quality standard at Section 10.4.8. An analyst who cannot recognise a plausible-sounding but unsupported AI output, or who treats a single aggregated screening hit as sufficient corroboration for a Tier 3 finding, is not competent for the purposes of this standard — regardless of how much training they have attended.
Calibration, not just individual sign-off
Section 9.3.10 requires periodic calibration exercises, in which two or more analysts independently assess the same case or a standardised test case and their conclusions and tier determinations are compared. This tests whether competence produces consistent outcomes across individuals, rather than depending on who happens to be assigned the file. Material inconsistency identified through calibration is addressed as a nonconformity under Section 14.2.
Suspension is not the same as decertification
Section 9.3.11 draws a specific distinction between suspension — temporary, pending remediation such as retraining — and decertification, which is a formal withdrawal of authorisation requiring the individual to requalify from the competence-verification step at Section 9.3.3 before being reauthorised. Decertification applies where a competence failure is repeated, severe, or indicates the original verification itself was inadequate.
Designing the Matrix Itself
A competency matrix built to satisfy Section 9.3 needs to answer five questions for every person who touches due diligence work, not just the compliance team: who is this person, what are they authorised to do, how was that authorisation earned, when does it expire, and what happens if it lapses or fails.
The table below illustrates one way to structure this. It is illustrative only — organisations should adapt the roles, modules, and cadences to their own scope determination under Section 5.2 and risk appetite under Section 6.6, consistent with the standard's general approach to illustrative models.
Role | Modules covered | Max DD tier authorised | Verification method | Maintenance cadence |
|---|---|---|---|---|
Tier 1–2 screening analyst | AML/KYC, Export control, Sanctions (screening only) | Tier 2 | Assessed casework sample; internal sign-off | 12 months |
Tier 3–4 senior analyst | Assigned module(s) per specialisation | Tier 4 | Assessed casework, second-level reviewer sign-off, recognised qualification where available | 12 months + calibration |
Second-level reviewer | All modules within scope of review authority | Reviews Tier 3–4 | Independent competency assessment; demonstrated calibration consistency | 12 months + calibration |
Export control / sanctions specialist | Export control, Sanctions | Tier 4 | Recognised qualification or documented internal assessment; ownership distinct from AML/KYC | 12 months |
Personnel/background-check administrator | Personnel and hiring | Role-sensitivity based | Documented internal assessment; privacy/employment law competence | 12 months |
AI-assisted research user (any module) | As per primary module assignment | As per primary module | Demonstrated ability to critically evaluate AI-assisted output | 12 months |
DD Function Owner / module owner | Oversight across assigned modules | N/A — oversight role | Governance and escalation competence; not casework-verified | 24 months |
A few design principles worth calling out
Authorisation, not attendance. Every row in the matrix should represent an authorisation decision — someone with the authority to do so concluded this person is competent to work at this tier, in this module — not a record that a course was completed.
Separate export control and sanctions ownership where the risk profile justifies it. Section 10.7.6 and Section 10.20.6 both explicitly allow — and in higher-risk organisations, expect — a distinct accountable owner for export control and sanctions compliance separate from the general AML/KYC owner. The matrix should reflect this separation where it exists rather than collapsing all screening-adjacent competence into one row.
Build calibration into the cadence, not just refresher training. A matrix that only tracks training completion dates has not built in the mechanism Section 9.3.10 actually requires. Calibration exercises — blind comparison of independent conclusions on the same case — need their own tracked cadence and their own evidence trail.
Record verification method, not just verification outcome. “Competent” without a method behind it does not satisfy Section 9.3.3. The matrix should show whether competence was verified through assessed casework, qualification, or internal assessment, because this is precisely what a certification assessment will test.
Track the suspension/decertification distinction explicitly. A matrix that has only two states — authorised or not authorised — cannot demonstrate conformance with Section 9.3.11, which requires the two to be handled as genuinely different processes with different re-entry requirements.
Common Gaps Worth Checking Before an Assessment
Training records exist, but nothing shows anyone verified the person could actually apply what was taught (Section 9.3.3).
Tier 3/4 authorisation is informal — senior staff are simply assumed to be competent because of seniority, with no documented authorisation decision (Section 9.3.2).
Second-level review exists on paper but is regularly performed by someone who was involved in the original research, undermining the independence Section 9.3.4 requires.
Outsourced providers are assumed competent because of reputation or cost, with no vendor-side verification evidence retained (Section 9.3.6, Section 10.17.4).
No calibration exercise has ever been run — competence is verified once, at onboarding, and never tested for consistency again (Section 9.3.10).
A competence failure was identified during QA sampling but was treated as a one-off correction rather than logged as a nonconformity with a suspension or decertification decision attached (Section 9.3.7, Section 9.3.11).
How Speeki Sentinel Certification Assesses This
Certification against SPK DDMS2000:2026 is a single-outcome assessment: an organisation either satisfies the standard's requirements, including the full set at Section 9.3, or it does not. During assessment, evidence of competence is tested directly against the matrix an organisation maintains — not against training records alone. An assessor will expect to see the authorisation decision, the verification method behind it, evidence of calibration activity, and a working distinction between suspension and decertification in practice, not only in policy language.
Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may adopt SPK DDMS2000:2026 and build their own competency matrix independently of Sentinel; certification itself is a separate, optional step an organisation can pursue once it believes its DDMS — including its competency matrix — is ready to be independently tested.
Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.
Closing Note
Competence is the clause organisations most often under-build, because it looks like an HR process rather than a due diligence control. Section 9.3 treats it as neither — it treats competence as a control in its own right, with the same evidentiary rigour the standard applies to sanctions screening, supplier evidence, or remediation records. A matrix built to answer who, what, how, until when, and what happens next, for every person who touches due diligence work, is not a bureaucratic artefact. It is the mechanism that determines whether the rest of the management system actually works.