LEAD-AUDITOR · Question #98
You are an experienced ISMS audit team leader conducting a third-party surveillance visit. You notice that although the auditee is claiming conformity with ISO/IEC 27001:2022 they are still referring
The correct answer is C. Raise it as an opportunity for improvement. The correct action to take in this situation is to raise it as an opportunity for improvement. This is because the auditee is not violating any requirement of the standard, but rather using outdated terminology that does not reflect the current version of the standard. An opportu
Question
You are an experienced ISMS audit team leader conducting a third-party surveillance visit. You notice that although the auditee is claiming conformity with ISO/IEC 27001:2022 they are still referring to Improvement as clause 10.2 (as it was in the 2013 edition) when this is now clause 10.1 in the 2022 edition. You have confirmed they are meeting all of the 2022 requirements set out in the standard. Select one option of the action you should take.
Options
- ANote the issue in the audit report
- BRaise a nonconformity against clause 7.5.3 - Control of documented information
- CRaise it as an opportunity for improvement
- DBring the matter up at the closing meeting
How the community answered
(15 responses)- A7% (1)
- B7% (1)
- C73% (11)
- D13% (2)
Explanation
The correct action to take in this situation is to raise it as an opportunity for improvement. This is because the auditee is not violating any requirement of the standard, but rather using outdated terminology that does not reflect the current version of the standard. An opportunity for improvement is a suggestion for enhancing the performance or effectiveness of the ISMS. It is not a nonconformity, which is a failure to fulfil a requirement.
Topics
Community Discussion
No community discussion yet for this question.