ISO-IEC-27001-LEAD-AUDITOR · Question #146
Drag and Drop Question An organisation is looking for management system initial certification. Please identify the sequence of the activities to be undertaken by the organisation. To complete the…
The correct answer is Establish the management system; Select a Certification Body and agree terms for stage 1 and 2 audit; Conduct internal audits; Revise the audit programme; Complete corrective actions. Management System Initial Certification - Sequence Explained This question tests knowledge of the pre-certification process under ISO management system standards (e.g., ISO 9001, ISO 14001, ISO 45001). --- The Correct Sequence and Why 1. Establish the management system The…
Question
Drag and Drop Question An organisation is looking for management system initial certification. Please identify the sequence of the activities to be undertaken by the organisation. To complete the sequence click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the options to the appropriate blank section. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Establish the management system
- Select a Certification Body and agree terms for stage 1 and 2 audit
- Conduct internal audits
- Revise the audit programme
- Complete corrective actions
Explanation
Management System Initial Certification - Sequence Explained
This question tests knowledge of the pre-certification process under ISO management system standards (e.g., ISO 9001, ISO 14001, ISO 45001).
The Correct Sequence and Why
1. Establish the management system
The logical starting point. You cannot audit, certify, or review something that doesn't exist. This step involves implementing all required processes, documented information, policies, objectives, and controls required by the standard. Everything else depends on this foundation.
2. Select a Certification Body and agree terms for stage 1 and 2 audit
Selecting the Certification Body (CB) early is deliberate - agreeing on scope, audit terms, and scheduling before the internal audit allows the internal audit programme to be aligned with what the CB will assess. It also sets expectations and timelines for the whole certification journey.
Common mistake: Students often place this step after internal audits, thinking you only contact the CB when you're "ready." In practice, early engagement helps structure your preparation correctly.
3. Conduct internal audits
ISO standards mandate internal audits as a requirement (e.g., ISO 9001:2015 Clause 9.2). Before an external CB can certify your system, you must demonstrate that you can self-assess it. Internal audits verify that the system is implemented and effective across all relevant areas.
4. Revise the audit programme
Internal audit results generate lessons learned - some areas may need more frequent auditing, scope may need to expand, or risk profiles may have changed. The audit programme is a living document and must be updated to reflect what the internal audits revealed. This step closes the PDCA loop on the auditing process itself.
Common mistake: Students may think the audit programme is fixed after being written. It must be revised based on findings and results - this is an explicit requirement in most standards.
5. Complete corrective actions
Internal audits will almost certainly identify nonconformities or weaknesses. These must be resolved before the CB conducts Stage 1 and Stage 2 audits. Demonstrating effective corrective action is itself evidence that the management system is functioning as intended.
Why the Distractors Don't Belong
| Distractor | Why It's Wrong |
|---|---|
| Manage a Management Review | A real requirement, but it falls after internal audits and corrective actions - and is not part of this specific 5-step pre-audit sequence being tested. |
| Display a Certification Body for stage 1 and stage 2 | Poorly worded/nonsensical distractor. Sounds like "Select a Certification Body" but "display" has no meaning in this context. |
| Contact supplier audit | Second-party (supplier) audits are unrelated to your own organisation's initial certification sequence. |
The Core Logic
The sequence follows PDCA (Plan-Do-Check-Act):
- Plan/Do → Establish the system, engage the CB
- Check → Internal audits
- Act → Revise the programme, complete corrective actions
This prepares the organisation for the CB's Stage 1 (documentation readiness review) and Stage 2 (full conformity assessment).
Topics
Community Discussion
No community discussion yet for this question.
