nerdexam
PECB

LEAD-AUDITOR · Question #228

After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; however, their decisio

The correct answer is B. No, the decision of the auditee to accept the risk instead of implementing corrective actions should. According to ISO/IEC 27001 standards, if the auditee decides to accept the risk instead of implementing corrective actions for a nonconformity, this decision should be justified and documented. Documenting such decisions is essential for maintaining the integrity of the ISMS and

Closing an ISMS Audit

Question

After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; however, their decision was not documented. Is this acceptable?

Options

  • AYes, the auditee's management can decide to accept the risk instead of implementing corrective
  • BNo, the decision of the auditee to accept the risk instead of implementing corrective actions should
  • CNo, the auditee must implement corrective actions for all the observations documented during the

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    89% (25)
  • C
    7% (2)

Explanation

According to ISO/IEC 27001 standards, if the auditee decides to accept the risk instead of implementing corrective actions for a nonconformity, this decision should be justified and documented. Documenting such decisions is essential for maintaining the integrity of the ISMS and for demonstrating that the decision was made based on informed judgment.

Topics

#risk acceptance#corrective action#nonconformity documentation#audit conclusions

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice