nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #99

Drag and Drop Question The audit lifecycle describes the ISO 19011 process for conducting an individual audit. Drag and drop the steps of the audit lifecycle into the correct sequence. Answer:

The correct answer is Audit initiation; Audit preparation; Conducting the audit; Preparing and distributing the audit report; Audit completion; Audit follow-up. ISO 19011 Audit Lifecycle - Sequence Explained ISO 19011 defines a structured, six-step process for conducting an individual audit. Here's why each step falls where it does: --- 1. Audit Initiation Why first: This is the trigger - the audit program manager assigns an audit…

Conducting an Audit

Question

Drag and Drop Question The audit lifecycle describes the ISO 19011 process for conducting an individual audit. Drag and drop the steps of the audit lifecycle into the correct sequence. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #99 exhibit

Answer Area

Drag items

Audit preparationAudit initiationAudit completionConducting the auditPreparing and distributing the audit reportAudit follow-up

Correct arrangement

  • Audit initiation
  • Audit preparation
  • Conducting the audit
  • Preparing and distributing the audit report
  • Audit completion
  • Audit follow-up

Explanation

ISO 19011 Audit Lifecycle - Sequence Explained

ISO 19011 defines a structured, six-step process for conducting an individual audit. Here's why each step falls where it does:


1. Audit Initiation

Why first: This is the trigger - the audit program manager assigns an audit, appoints the audit team leader, and establishes the scope, objectives, and criteria. Nothing else can happen without formal authorization and a defined mandate. The client and auditee are contacted to confirm feasibility.


2. Audit Preparation

Why second: Once the audit is formally initiated, the team prepares before any on-site work begins. This includes reviewing documented information, developing the audit plan, assigning tasks to team members, and preparing checklists. You cannot conduct an audit without a plan.


3. Conducting the Audit

Why third: This is the actual execution phase - opening meeting, gathering evidence through interviews, observation, and document review, then the closing meeting. It logically follows preparation and precedes any reporting.


4. Preparing and Distributing the Audit Report

Why fourth: The report documents findings and conclusions drawn from the evidence gathered in step 3. It cannot be written until the audit is conducted. Distribution to relevant parties (client, auditee) is part of this same step.


5. Audit Completion

Why fifth: The audit is formally closed once the report is distributed and all planned activities are finished. This is an administrative closure step - records are retained, confidentiality obligations are confirmed. It marks the official end of this audit.


6. Audit Follow-up

Why last: Follow-up only occurs after the audit is complete. It involves verifying that corrective actions taken by the auditee in response to findings have been implemented effectively. This may happen days or weeks later and may be a separate mini-audit.


Common Mistakes & Misconceptions

MisconceptionCorrection
Swapping Initiation and PreparationInitiation is the authorization step; Preparation is the planning step. Authorization must come first.
Placing Audit Completion after Follow-upCompletion closes the current audit formally; Follow-up is a subsequent activity that verifies corrective actions.
Treating Report Distribution as part of CompletionISO 19011 separates these - distributing the report is its own discrete step before formal closure.
Thinking Follow-up is optional/not part of the lifecycleISO 19011 includes it as a formal step, even though it may be delegated or occur much later.

Memory aid: Initiate → Plan → Do → Report → Close → Verify maps directly to the six steps.

Topics

#audit lifecycle#audit process sequence#ISO 19011#audit phases

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice