LEAD-AUDITOR · Question #228
After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; however, their decisio
The correct answer is B. No, the decision of the auditee to accept the risk instead of implementing corrective actions should. According to ISO/IEC 27001 standards, if the auditee decides to accept the risk instead of implementing corrective actions for a nonconformity, this decision should be justified and documented. Documenting such decisions is essential for maintaining the integrity of the ISMS and
Question
After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; however, their decision was not documented. Is this acceptable?
Options
- AYes, the auditee's management can decide to accept the risk instead of implementing corrective
- BNo, the decision of the auditee to accept the risk instead of implementing corrective actions should
- CNo, the auditee must implement corrective actions for all the observations documented during the
How the community answered
(28 responses)- A4% (1)
- B89% (25)
- C7% (2)
Explanation
According to ISO/IEC 27001 standards, if the auditee decides to accept the risk instead of implementing corrective actions for a nonconformity, this decision should be justified and documented. Documenting such decisions is essential for maintaining the integrity of the ISMS and for demonstrating that the decision was made based on informed judgment.
Topics
Community Discussion
No community discussion yet for this question.