ISO-IEC-27001-LEAD-AUDITOR · Question #99
Drag and Drop Question The audit lifecycle describes the ISO 19011 process for conducting an individual audit. Drag and drop the steps of the audit lifecycle into the correct sequence. Answer:
The correct answer is Audit initiation; Audit preparation; Conducting the audit; Preparing and distributing the audit report; Audit completion; Audit follow-up. ISO 19011 Audit Lifecycle - Sequence Explained ISO 19011 defines a structured, six-step process for conducting an individual audit. Here's why each step falls where it does: --- 1. Audit Initiation Why first: This is the trigger - the audit program manager assigns an audit…
Question
Drag and Drop Question The audit lifecycle describes the ISO 19011 process for conducting an individual audit. Drag and drop the steps of the audit lifecycle into the correct sequence. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Audit initiation
- Audit preparation
- Conducting the audit
- Preparing and distributing the audit report
- Audit completion
- Audit follow-up
Explanation
ISO 19011 Audit Lifecycle - Sequence Explained
ISO 19011 defines a structured, six-step process for conducting an individual audit. Here's why each step falls where it does:
1. Audit Initiation
Why first: This is the trigger - the audit program manager assigns an audit, appoints the audit team leader, and establishes the scope, objectives, and criteria. Nothing else can happen without formal authorization and a defined mandate. The client and auditee are contacted to confirm feasibility.
2. Audit Preparation
Why second: Once the audit is formally initiated, the team prepares before any on-site work begins. This includes reviewing documented information, developing the audit plan, assigning tasks to team members, and preparing checklists. You cannot conduct an audit without a plan.
3. Conducting the Audit
Why third: This is the actual execution phase - opening meeting, gathering evidence through interviews, observation, and document review, then the closing meeting. It logically follows preparation and precedes any reporting.
4. Preparing and Distributing the Audit Report
Why fourth: The report documents findings and conclusions drawn from the evidence gathered in step 3. It cannot be written until the audit is conducted. Distribution to relevant parties (client, auditee) is part of this same step.
5. Audit Completion
Why fifth: The audit is formally closed once the report is distributed and all planned activities are finished. This is an administrative closure step - records are retained, confidentiality obligations are confirmed. It marks the official end of this audit.
6. Audit Follow-up
Why last: Follow-up only occurs after the audit is complete. It involves verifying that corrective actions taken by the auditee in response to findings have been implemented effectively. This may happen days or weeks later and may be a separate mini-audit.
Common Mistakes & Misconceptions
| Misconception | Correction |
|---|---|
| Swapping Initiation and Preparation | Initiation is the authorization step; Preparation is the planning step. Authorization must come first. |
| Placing Audit Completion after Follow-up | Completion closes the current audit formally; Follow-up is a subsequent activity that verifies corrective actions. |
| Treating Report Distribution as part of Completion | ISO 19011 separates these - distributing the report is its own discrete step before formal closure. |
| Thinking Follow-up is optional/not part of the lifecycle | ISO 19011 includes it as a formal step, even though it may be delegated or occur much later. |
Memory aid: Initiate → Plan → Do → Report → Close → Verify maps directly to the six steps.
Topics
Community Discussion
No community discussion yet for this question.
