nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #199

You are an experienced ISMS audit team leader. You are currently conducting a third-party surveillance audit of an international haulage organisation. You have sampled four internal audit reports…

The correct answer is A. I would be concerned as to whether criteria for grading nonconformities are in existence in this B. I would be concerned as to whether the auditors understand the difference between corrections D. I would be concerned that no grading is recorded for Report 3. This could indicate that the auditor F. I would be concerned that timing for addressing the nonconformities is significantly different in the. Four concerns stand out on closer inspection of the reports. A is correct because the inconsistent grading across reports (e.g., a Minor gets 9 months in Report 1 but 12 months in Report 2, and a Major gets only 1 week in Report 4) strongly suggests the organisation lacks…

Internal Audit Process (Clause 9.2)

Question

You are an experienced ISMS audit team leader. You are currently conducting a third-party surveillance audit of an international haulage organisation. You have sampled four internal audit reports which state:

Report 1 - Auditor: Mr James. Over the year the organisation has failed to meet its promised delivery dates on 23 occasions out of 100. This is against a target of '95% of deliveries on time'. Grading - Minor Corrective Action due: Within 9 months. Report 2 - Auditor: Mr James. Between January and March, it was noted 125 complaints were received about the Service Desk Team. Clients accused them of being rude and unresponsive. Grading - Minor Corrective Action due: Within 12 months. Report 3 - Auditor: Mr James. Of the 40 customer orders received last month, 38 were correctly processed. Of the remaining 2, one was missing a signature and one was missing a date. Grading - Corrections due: Within 3 weeks Report 4 - Auditor: Mr Rogers. Of the 30 personnel records examined, 26 were found to be fully completed whilst the remaining 4 were all missing the individual's start date. Grading - Major Corrections due: Within 1 week Which four of the options demonstrate the concerns you would have about these reports?

Options

  • AI would be concerned as to whether criteria for grading nonconformities are in existence in this
  • BI would be concerned as to whether the auditors understand the difference between corrections
  • CI would be concerned because action taken to address a major nonconformity should always be
  • DI would be concerned that no grading is recorded for Report 3. This could indicate that the auditor
  • EI would be concerned that the auditors focussed only on information security processes
  • FI would be concerned that timing for addressing the nonconformities is significantly different in the
  • GI would have a concern that no nonconformity review was conducted
  • HI would have a concern that one auditor appeared to be conducting most of the internal audits

How the community answered

(34 responses)
  • A
    65% (22)
  • C
    18% (6)
  • E
    6% (2)
  • G
    3% (1)
  • H
    9% (3)

Explanation

Four concerns stand out on closer inspection of the reports. A is correct because the inconsistent grading across reports (e.g., a Minor gets 9 months in Report 1 but 12 months in Report 2, and a Major gets only 1 week in Report 4) strongly suggests the organisation lacks documented, agreed criteria for classifying and timing the resolution of nonconformities. B is correct because "Corrections" (immediate fixes to the specific problem) and "Corrective Actions" (addressing root causes to prevent recurrence) are distinct ISO concepts - Reports 3 and 4 use the word "Corrections" for what appears to be graded nonconformities, suggesting the auditors do not understand this critical difference. D is correct because Report 3 assigns no Minor or Major grading at all, just a remediation deadline - this omission could mean the auditor did not know how to classify the finding, undermining the integrity of the audit output. F is correct because even within the same grade (Minor), the allowed resolution time jumps from 9 to 12 months with no apparent justification, indicating the timing is arbitrary rather than risk-based and consistently applied.

The distractors fail because: C is wrong - ISO standards do not prescribe a universal fixed deadline for major nonconformities, so 1 week is not inherently improper; E is wrong - the audit sampled delivery, complaints, order processing, and HR records, which are all legitimate scope areas for an ISMS in a haulage context; G is wrong - nonconformities were clearly identified and graded, so a review did occur; H is wrong - having one auditor cover multiple reports from a sample of four is not inherently a problem and is not flagged as an issue by the evidence given.

Memory tip: Think "CBDF = Criteria, Basics, Definition, Fixed-timing" - the auditors lack Criteria for grading, misunderstand the Basics (corrections vs. corrective actions), left Report 3's Definition blank, and applied Fixed but inconsistent timeframes. Any time you see grading or timing that looks random across audit reports, those two themes (A and F) should fire immediately.

Topics

#nonconformity grading#corrective actions#internal audit reports#audit programme

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice