nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #117

You are an audit team leader who has just completed a third-party audit of a mobile telecommunication provider. You are preparing your audit report and are just about to complete a section headed…

The correct answer is A. Although we advise the client the report is confidential we can decide to release it to third if we F. Any auditor employed by the auditing organisation can access the audit report G. Our duty of confidentiality is not something that lasts forever. As a certification body, we can H. Subcontracted auditors are considered to be third parties regarding confidentiality and are. The audit report is a confidential document that contains sensitive information about the auditee's ISMS and its performance. The audit team has a duty to protect the confidentiality of the audit report and only disclose it to authorized parties, such as the audit client, the…

Audit Principles, Preparation and Initiation

Question

You are an audit team leader who has just completed a third-party audit of a mobile telecommunication provider. You are preparing your audit report and are just about to complete a section headed 'confidentiality'. An auditor in training on your team asks you if there are any circumstances under which the confidential report can be released to third parties. Which four of the following responses are false?

Options

  • AAlthough we advise the client the report is confidential we can decide to release it to third if we
  • BThe report can be released to third parties but only with the explicit, prior approval of the audit
  • CThere are no circumstances under which the report can be released to a third party. Confidential
  • DThe starting position is always that third parties have no automatic right to access an audit report
  • EIf the third party has gained a legal notice for us to disclose the report then we must do so. In all
  • FAny auditor employed by the auditing organisation can access the audit report
  • GOur duty of confidentiality is not something that lasts forever. As a certification body, we can
  • HSubcontracted auditors are considered to be third parties regarding confidentiality and are

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    4% (1)
  • C
    7% (2)
  • D
    4% (1)

Explanation

The audit report is a confidential document that contains sensitive information about the auditee's ISMS and its performance. The audit team has a duty to protect the confidentiality of the audit report and only disclose it to authorized parties, such as the audit client, the certification body, and the accreditation body. Therefore, the following responses are false: A: The audit team cannot decide to release the report to third parties without the consent of the audit client, as this would breach the confidentiality agreement and the audit code of conduct. The audit team should always inform the audit client before disclosing the report to any third party, and obtain their explicit, prior approval. F: Not every auditor employed by the auditing organization can access the audit report, as this would violate the principle of need-to-know. Only auditors who are involved in the audit process, such as the audit team leader, the audit team members, the audit programme manager, and the certification decision maker, can access the audit report. Other auditors who are not related to the audit have no legitimate reason to access the report, and should be prevented from doing so by appropriate security measures. G: The duty of confidentiality does not expire after a certain period of time, as this would compromise the trust and integrity of the audit process. The audit report remains confidential indefinitely, unless there is a legal or contractual obligation to disclose it, or the audit client agrees to release it. Third parties cannot access the audit report by making a subject access request, as this would infringe the privacy and data protection rights of the audit client and the auditee. H: Subcontracted auditors are not considered to be third parties regarding confidentiality, as they are part of the audit team and have a contractual relationship with the auditing organization. Subcontracted auditors are typically bound by the same confidentiality agreement and audit code of conduct as the employed auditors, and have the same rights and responsibilities to access and protect the audit report.

Topics

#audit report confidentiality#third party disclosure#audit ethics#confidentiality obligations

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice