nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #88

Drag and Drop Question You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be required to undertake…

The correct answer is An internal audit; A certification audit; A combined audit; A joint audit; A follow-up audit; A surveillance audit. ISMS Audit Types - Drag & Drop Explanation This question draws from ISO 19011 (Guidelines for Auditing Management Systems) and ISO/IEC 17021 (certification body requirements). The six audit types map to standard definitions an ISMS auditor must know. --- The Correct Arrangement…

Audit Program Management

Question

Drag and Drop Question You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be required to undertake. Match the following audit types to the descriptions. To complete the table click on the blank section you want to complete so that It is highlighted In fed, and then click on the applicable text from the options below. Alternatively, you may drag and drop each option to the appropriate blank section. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #88 exhibit

Answer Area

Drag items

A joint auditA surveillance auditAn internal auditA combined auditA follow-up auditA certification audit

Correct arrangement

  • An internal audit
  • A certification audit
  • A combined audit
  • A joint audit
  • A follow-up audit
  • A surveillance audit

Explanation

ISMS Audit Types - Drag & Drop Explanation

This question draws from ISO 19011 (Guidelines for Auditing Management Systems) and ISO/IEC 17021 (certification body requirements). The six audit types map to standard definitions an ISMS auditor must know.


The Correct Arrangement & Why

1. An Internal Audit

First-party audit - conducted by or on behalf of the organization on itself, for internal purposes (e.g., management review input, readiness checks). This anchors the list as the most foundational audit type - it's where every organization starts before seeking external certification.

Common mistake: Assuming internal means "informal." Internal audits must still follow ISO 19011 rigor.


2. A Certification Audit

Third-party audit - conducted by an accredited certification body (e.g., BSI, DNV) to determine whether the ISMS conforms to ISO/IEC 27001 and to award/renew certification. This follows logically after internal audits establish readiness.

Common mistake: Confusing this with a surveillance audit - certification audits are the initial or recertification (3-year cycle) event.


3. A Combined Audit

Auditing two or more management systems (e.g., ISO 27001 + ISO 9001) of the same organization simultaneously by one audit team. Placed here because it's a variant of a standard audit - same team, different standards.

Common mistake: Confusing with a joint audit. Combined = multiple standards, one team. Joint = multiple audit teams.


4. A Joint Audit

Two or more auditing organizations cooperate to audit a single auditee together. The key differentiator is the auditing side - multiple bodies auditing as partners (e.g., two certification bodies auditing a shared supplier).

Common mistake: Thinking joint and combined are interchangeable - the distinction is who is doing the auditing, not what is being audited.


5. A Follow-Up Audit

Conducted after a previous audit identified nonconformities. Its sole purpose is to verify that corrective actions were implemented and are effective. It is triggered by findings, not a schedule.

Common mistake: Thinking follow-up audits are optional. Where major nonconformities exist, they are required before certification can be granted or maintained.


6. A Surveillance Audit

Periodic monitoring audits conducted between certification audits (typically annually in years 1 and 2 of a 3-year certification cycle). They verify the ISMS continues to conform but do not re-examine the full scope.

Common mistake: Assuming surveillance audits cover everything. They are intentionally scoped narrower than certification audits.


Key Memory Aid

#TypeTrigger
1InternalSelf-initiated
2CertificationExternal, scope = full ISMS
3CombinedMultiple standards, one team
4JointMultiple audit teams, one auditee
5Follow-upNonconformity corrective action
6SurveillanceScheduled, between certifications

The arrangement moves logically from who initiates (self → external body) through structural variants (combined, joint) to lifecycle events (follow-up, surveillance).

Topics

#audit types#first-party audit#second-party audit#third-party audit

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice