ISO-IEC-27001-LEAD-AUDITOR · Question #88
Drag and Drop Question You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be required to undertake…
The correct answer is An internal audit; A certification audit; A combined audit; A joint audit; A follow-up audit; A surveillance audit. ISMS Audit Types - Drag & Drop Explanation This question draws from ISO 19011 (Guidelines for Auditing Management Systems) and ISO/IEC 17021 (certification body requirements). The six audit types map to standard definitions an ISMS auditor must know. --- The Correct Arrangement…
Question
Drag and Drop Question You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be required to undertake. Match the following audit types to the descriptions. To complete the table click on the blank section you want to complete so that It is highlighted In fed, and then click on the applicable text from the options below. Alternatively, you may drag and drop each option to the appropriate blank section. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- An internal audit
- A certification audit
- A combined audit
- A joint audit
- A follow-up audit
- A surveillance audit
Explanation
ISMS Audit Types - Drag & Drop Explanation
This question draws from ISO 19011 (Guidelines for Auditing Management Systems) and ISO/IEC 17021 (certification body requirements). The six audit types map to standard definitions an ISMS auditor must know.
The Correct Arrangement & Why
1. An Internal Audit
First-party audit - conducted by or on behalf of the organization on itself, for internal purposes (e.g., management review input, readiness checks). This anchors the list as the most foundational audit type - it's where every organization starts before seeking external certification.
Common mistake: Assuming internal means "informal." Internal audits must still follow ISO 19011 rigor.
2. A Certification Audit
Third-party audit - conducted by an accredited certification body (e.g., BSI, DNV) to determine whether the ISMS conforms to ISO/IEC 27001 and to award/renew certification. This follows logically after internal audits establish readiness.
Common mistake: Confusing this with a surveillance audit - certification audits are the initial or recertification (3-year cycle) event.
3. A Combined Audit
Auditing two or more management systems (e.g., ISO 27001 + ISO 9001) of the same organization simultaneously by one audit team. Placed here because it's a variant of a standard audit - same team, different standards.
Common mistake: Confusing with a joint audit. Combined = multiple standards, one team. Joint = multiple audit teams.
4. A Joint Audit
Two or more auditing organizations cooperate to audit a single auditee together. The key differentiator is the auditing side - multiple bodies auditing as partners (e.g., two certification bodies auditing a shared supplier).
Common mistake: Thinking joint and combined are interchangeable - the distinction is who is doing the auditing, not what is being audited.
5. A Follow-Up Audit
Conducted after a previous audit identified nonconformities. Its sole purpose is to verify that corrective actions were implemented and are effective. It is triggered by findings, not a schedule.
Common mistake: Thinking follow-up audits are optional. Where major nonconformities exist, they are required before certification can be granted or maintained.
6. A Surveillance Audit
Periodic monitoring audits conducted between certification audits (typically annually in years 1 and 2 of a 3-year certification cycle). They verify the ISMS continues to conform but do not re-examine the full scope.
Common mistake: Assuming surveillance audits cover everything. They are intentionally scoped narrower than certification audits.
Key Memory Aid
| # | Type | Trigger |
|---|---|---|
| 1 | Internal | Self-initiated |
| 2 | Certification | External, scope = full ISMS |
| 3 | Combined | Multiple standards, one team |
| 4 | Joint | Multiple audit teams, one auditee |
| 5 | Follow-up | Nonconformity corrective action |
| 6 | Surveillance | Scheduled, between certifications |
The arrangement moves logically from who initiates (self → external body) through structural variants (combined, joint) to lifecycle events (follow-up, surveillance).
Topics
Community Discussion
No community discussion yet for this question.
