Mock Exam Flashcards
Which three best describe the ‘Do’ phase in the PDCA cycle according to ISO 9001:2015? (2 Marks)
A. Implement the established plans.
B. Monitor and measure processes.
C. Execute tasks based on resources allocated.
D. Create a plan to capture identified opportunities.
E. Act on feedback received.
F. Ensure alignment with the organization’s policies.
Correct Answer:A, C, F
Explanation:The ‘Do’ phase emphasizes implementing what was planned, executing tasks, and ensuring policy alignment.
Audit concepts and auditor responsibilities
Select three roles from the list below that are commonly involved in the audit process according to ISO 19011-2018: (1 Mark)
A. Management representative
B. Audit supplier
C. Lead auditor
D. Observer
E. Audit reviewers
F. Guides
Correct Answers:A, C, F
Explanation:
The “Management Representative” is the main contact for the audit team within the auditee’s organization, making option A correct.
“Lead auditor” has the responsibility to lead and manage the audit, thus option C is correct.
“Guides” assist the audit team, especially with logistical arrangements, making option F correct.
In the context of auditor responsibilities, select four factors that should be considered when identifying the appropriate personnel for the audit: (2 Marks)
A. Personal preferences of the auditee.
B. Auditor’s knowledge of the relevant management system discipline.
C. Familiarity with the organization’s competitors.
D. Awareness of the industry sector specific context.
E. Auditor’s previous audit findings.
F. Knowledge of relevant regulations and legislation.
Correct Answers:B, D, E, F
Explanation:
An auditor’s knowledge of the management system discipline ensures that they understand the specific domain they are auditing, making option B correct.
Awareness of the industry sector specific context ensures that the audit is relevant and contextual, making option D correct.
Auditors should consider previous audit findings to ensure continuity and follow-up on past issues, making option E correct.
Knowledge of relevant regulations and legislation ensures that the audit addresses all legal and statutory requirements, making option F correct.
You are a 3rd party auditor planning to audit “EcoAuto,” a company specializing in electric vehicles. While reviewing their provided internal audit reports in preparation for the audit, you notice that the reports lack any evidence of management review or follow-up actions.
What should you do in this case?(1 Mark)
A. Exclude internal audit reports from the scope of your audit.
B. Delay the audit until EcoAuto can provide complete internal audit reports.
C. Request EcoAuto to provide evidence of management review prior to the audit.
D. Proceed with the audit but consider this as a potential area for nonconformity.
E. Report EcoAuto to the certification body for failing to provide complete documents.
Correct Answer: C
Explanation:Requesting EcoAuto to provide evidence of management review prior to the audit aligns with the need for preparedness and verifying compliance with ISO 9001:2015, Clause 9.3.3. This step ensures that you have all necessary documented information for a comprehensive audit.
You are leading an audit for a global e-commerce company, WebShop, which has data centers in multiple countries. During the planning phase, you are informed that one of the data centers in Europe is under investigation for not complying with local data protection laws.
What is the most suitable action for you to take as the audit team leader?(2 Marks)
A. Exclude the European data center from the audit scope and proceed as planned
B. Postpone the audit until the investigation is complete.
C. Replace the European data center with another area of focus within the company that has similar risks.
D. Continue with the audit as planned, including the European data center.
E. Cancel the audit as the investigation poses too much of a risk for an accurate assessment.
Correct Answer: D
Explanation: Option D is the best choice because it allows the audit to proceed while also capturing the risks associated with the ongoing investigation. This approach provides a more comprehensive view of the organization’s compliance with data protection laws, which is critical for a global e-commerce company like WebShop.
You are auditing a pharmaceutical company that specializes in the production of vaccines. You engage with various departments during your audit, including R&D, Production, and Quality Control. You learn that the company has recently expedited developing and producing a new vaccine due to rising health concerns. The R&D department asserts that they have followed all protocols, and the Quality Control team confirms that the new vaccine meets all regulatory requirements. However, you notice that documentation related to this expedited process needs to be completed. The Production Manager assures you that the situation’s urgency justified certain “shortcuts” in the usual procedures.
What three records would you seek to confirm whether management processes related to the expedited development and production of the new vaccine are being effectively implemented? (3 Marks)
A. R&D project plans and milestone achievements.
B. Regulatory approval documents for the new vaccine.
C. Internal audit reports on the expedited development process.
D. Minutes of meetings discussing the expedited development and risks.
E. Employee training records on emergency development protocols.
F. Inventory records of vaccine ingredients and supplies.
G. Customer feedback and adverse event reports.
Correct Answers:C, D, G
Correct Answer Explanation:
Internal audit reports on the expedited development process (C): These reports would provide evidence of internal oversight and adherence to protocols, even during expedited development.
Minutes of meetings discussing the expedited development and risks (D): These would offer insights into management’s strategic approach and risk assessment related to the expedited vaccine development.
Customer feedback and adverse event reports (G): These records are crucial for understanding how the vaccine is performing post-market and would indicate whether the expedited development led to any overlooked quality or safety issues.
Incorrect Answer Explanation:
R&D project plans and milestone achievements (A): While these would show planning stages, they may not provide comprehensive insights into the quality and risk management of the expedited process.
Regulatory approval documents for the new vaccine (B): These are important for legal compliance but may not reflect the internal management processes that were followed during expedited development.
Employee training records on emergency development protocols (E): These would indicate staff preparedness but may not provide a full picture of how effectively overall management processes were carried out.
Inventory records of vaccine ingredients and supplies (F): While important for traceability and production, these records may not directly indicate the effectiveness of the expedited management processes.
You are auditing a pharmaceutical company that has recently expanded its operations to include the production of vaccines. During the audit, you encounter the Head of Operations who seems anxious and mentions that they are currently undergoing multiple regulatory inspections. He expresses concern about the team’s bandwidth to accommodate the audit without affecting daily operations.
In light of the Head of Operations’ concerns and the company’s recent operational expansion, what two approaches would you adopt to build rapport with the auditee and effectively assess the quality management of the new vaccine production line?(3 Marks)
A. Propose a phased audit approach to minimize disruption to daily operations.
B. Request access to recent internal quality audits related to vaccine production.
C. Offer to coordinate audit activities with other ongoing regulatory inspections.
D. Recommend a joint meeting with the quality and operations teams to outline the scope and objectives of the audit.
E. Suggest deferring less critical audit activities to focus on the new vaccine production line.
F. Initiate a dialogue to understand the specific challenges tied to the vaccine production expansion.
Correct Answers:C, F
Correct Answer Explanation:
Offer to coordinate audit activities with other ongoing regulatory inspections: This approach is likely to ease the Head of Operations’ concerns about team bandwidth and shows sensitivity to the company’s current situation.
Initiate a dialogue to understand the specific challenges tied to the vaccine production expansion: Opening a conversation about the particular challenges related to the new vaccine line helps in establishing a trusting relationship and ensures that the audit is focused on key areas.
Incorrect Answer Explanation:
Propose a phased audit approach to minimize disruption to daily operations: While this is a considerate approach, it may not directly address the immediate concerns about team bandwidth and ongoing regulatory inspections.
Request access to recent internal quality audits related to vaccine production: Although valuable for the audit, asking for this data upfront could add to the concerns about team bandwidth.
Recommend a joint meeting with the quality and operations teams to outline the scope and objectives of the audit: While this could be beneficial in a normal situation, it may be too demanding given the current multiple inspections.
Suggest deferring less critical audit activities to focus on the new vaccine production line: This could be seen as bypassing important aspects of a comprehensive audit, potentially leading to gaps in the evaluation.
You are conducting an audit at a food processing company that specializes in organic products. The company is looking to renew its ISO 9001 certification and has recently implemented a new inventory management system. You are auditing the organization’s supply chain department and are in a discussion with the Supply Chain Manager (SCM).
Discussion with Supply Chain Manager (SCM):
You:”Can you describe how the new inventory management system supports traceability?”
SCM:”The system assigns a unique identifier to each batch of products, and we can trace each product back to its source.”
You:”What measures are in place to ensure the accuracy of inventory records?”
SCM:”We conduct cycle counts every month, and discrepancies are investigated and corrected.”
Question:
You need to determine the extent to which ISO 9001 requirements are met concerning inventory management.
Which of the following statements is false?(2 Marks)
A. You would confirm that the unique identifiers are documented and traceable.
B. You would verify the effectiveness of the monthly cycle counts.
C. You would assess if cycle counts are only conducted by senior management.
D. You would examine the corrective actions taken for inventory discrepancies.
E. You would check if the inventory management system is validated regularly.
Correct Answer:C. You would assess if cycle counts are only conducted by senior management.
Correct Answer Explanation:
This statement is false as ISO 9001:2015 does not specify that cycle counts should only be conducted by senior management. The relevant clause in ISO 9001:2015 (Clause 7.1.6) deals with organizational knowledge, not specifically who should conduct cycle counts.
Incorrect Answer Explanation:
A. Confirming that unique identifiers are documented and traceable aligns with ISO 9001’s requirements for documented information (Clause 7.5).
B. Verifying the effectiveness of the monthly cycle counts aligns with ISO 9001’s focus on monitoring, measurement, analysis, and evaluation (Clause 9.1).
D. Examining corrective actions aligns with ISO 9001’s requirements for dealing with nonconformities and corrective actions (Clause 10.2).
E. Regular validation of the inventory management system is part of the requirements for control of production and service provision (Clause 8.5.1).
You are auditing a construction company that specializes in commercial buildings. The company is in the process of renewing its ISO 9001 certification. You are auditing the company’s safety protocols and are in a discussion with the Safety Manager (SM).
Discussion with Safety Manager (SM):
You:”How are safety objectives aligned with the company’s overall quality policy?”
SM:”Safety objectives are formulated in line with our quality policy and are reviewed quarterly by the management team.”
You:”How do you ensure that safety objectives are measurable?”
SM:”Each safety objective is tied to specific metrics, like incident rates and employee training completion rates.”
Question:
You need to evaluate the company’s arrangements for planning, focusing on how safety objectives are consistent with the quality policy and are measurable.
Which of the following statements are true?(3 Marks)
A.You would confirm that safety objectives are aligned with the company’s quality policy.
B. You would check if safety objectives are only communicated to the management team.
C. You would verify that metrics for safety objectives include both leading and lagging indicators.
D. You would assess whether safety objectives are subject to change without notice.
E. You would examine if the safety objectives are reviewed and updated on a quarterly basis.
Correct Answers:
A. You would confirm that safety objectives are aligned with the company’s quality policy.
E. You would examine if the safety objectives are reviewed and updated on a quarterly basis.
Correct Answer Explanation:
A. This statement is true, as ISO 9001:2015 emphasizes the need for aligning specific objectives, like safety, with the overall quality policy.
E. This statement is true because ISO 9001:2015 requires regular review and updating of objectives, consistent with the scenario.
Incorrect Answer Explanation:
B. This statement is false because ISO 9001:2015 encourages broad communication of objectives to all relevant parties, not just the management team.
C. This statement is not explicitly supported or contradicted by the scenario or ISO 9001:2015. The standard requires measurable objectives but doesn’t specify the types of indicators.
D. This statement is false as ISO 9001:2015 encourages planned changes and does not support objectives being subject to change without notice.
You are auditing an aerospace manufacturing company that specializes in jet engine components. The company is in the process of renewing its ISO 9001 certification. You are auditing the company’s quality control department and are in discussion with the Quality Control Manager (QCM).
Discussion with Quality Control Manager (QCM):
You:”How are you monitoring and measuring the performance of the quality management system?”
QCM:”We utilize various KPIs such as ‘Product Defect Rate,’ ‘On-Time Delivery,’ and ‘Customer Satisfaction.’ We also conduct internal audits bi-annually to assess our compliance with policies and objectives.”
You:”How do you analyze and evaluate this data?”
QCM:”We use statistical tools for analysis, and the results are reviewed in quarterly management reviews. We then compare these against our planned objectives and quality policy.”
You:”What is the internal audit frequency and scope?”
QCM:”Internal audits are conducted twice a year, covering all processes and departments.”
Question:
Based on your audit responsibilities, which of the following actions would you undertake to evaluate the auditee’s arrangements for monitoring, measuring, analysis, and evaluation of the quality management system?(3 Marks)
A. Verify that statistical tools are used for the analysis and evaluation of data.
B. Check if the internal audits are focused only on the quality control department.
C. Confirm that KPIs like ‘Product Defect Rate’ and ‘On-Time Delivery’ are being used.
D. Review whether the results of the KPIs are considered during quarterly management reviews.
E. Assess if the internal audits are conducted more frequently than stated.
Correct Answers:
C. Confirm that KPIs like ‘Product Defect Rate’ and ‘On-Time Delivery’ are being used.
D. Review whether the results of the KPIs are considered during quarterly management reviews.
Correct Answer Explanation:
C. Aligns with ISO 9001:2015 clause on monitoring, measurement, analysis, and evaluation. Confirming the use of specific KPIs is essential for evaluating the effectiveness of the quality management system.
D. Also aligns with ISO 9001:2015 clause on monitoring, measurement, analysis, and evaluation. Ensuring that KPI results are reviewed in management reviews is critical for continual improvement.
Incorrect Answer Explanation:
A. While statistical tools are used for analysis, confirming their use is not directly tied to the effectiveness of the quality management system itself.
B. This is incorrect as the scenario states that internal audits cover all processes and departments, not just the quality control department.
E. The internal audit frequency is bi-annual, as stated, making this option incorrect for evaluation.
You are conducting an ISO 9001 audit of a manufacturing company that produces automotive parts. During the audit, you discover that the organization has not maintained documented information to demonstrate that their monitoring and measuring equipment is calibrated. You raised a nonconformity against clause 7.1.5 of ISO 9001.
Select the words that best complete the sentence:(2 Marks)
“The organization failed to maintain documented information for the________and________of monitoring and measuring________.”
Options:
calibration/equipment/verification/conformance/tools/validation/inspection/certification
Correct Answer:
“The organization failed to maintain documented information for the calibration and verification of monitoring and measuring equipment.”
Explanation:
“Calibration”: This is the correct choice as it specifically refers to the adjustment or grading of equipment, which is aligned with ISO 9001:2015 Clause 7.1.5 that deals with monitoring and measuring resources.
“Verification”: This is the correct choice as it pertains to the checking that something (in this case, equipment) meets specified requirements, also covered under ISO 9001:2015 Clause 7.1.5.
“Equipment”: This is the correct choice as it is the general term referring to what is being calibrated and verified, consistent with the requirements of ISO 9001:2015 Clause 7.1.5.
You are conducting an ISO 9001 audit of a company specializing in the design and manufacture of electronic devices. During the audit, you review the company’s internal audit procedures and find that although they conduct internal audits, the audit results are not reported to relevant management. Furthermore, there is no documented evidence to show that corrective actions are taken based on the audit findings. You raised a nonconformity against clause 9.2.
Select the words that best complete the sentence:(2 Marks)
“The company conducts internal audits but fails to_____the results to relevant management and lacks documented evidence of________actions based on the________.”
Options:
report/preventive/resolutions/discuss/recommendations/share/findings/corrective
Correct Answer:
“The company conducts internal audits but fails to report the results to relevant management and lacks documented evidence of corrective actions based on the findings.”
Explanation:
“Report”: This is the correct as the scenario states that the internal audit results are not reported to relevant management. This is in line with ISO 9001:2015 Clause 9.2, which discusses the need for internal audits and reporting the results.
“Corrective”: This is the correct as the scenario highlights the absence of documented evidence to show that corrective actions are taken. This aligns with ISO 9001:2015 Clause 9.2.
“Findings”: This is the correct as it refers to the audit findings based on which actions should be taken. This is consistent with ISO 9001:2015 Clause 9.2.
You’re an auditor evaluating a manufacturing company’s quality management system for automotive components. This company relies on both its in-house staff and external suppliers to carry out various processes. Throughout your audit, you’ve noticed two critical shortcomings. Firstly, the company has not conducted any evaluations of its external providers’ performance. Secondly, there is no established system in place to manage changes to products provided by external suppliers. (2 Marks)
Audit Evidence:
No performance assessment criteria for external providers. ______(ISO 9001:2015 Clause 8 extract)
Lack of a system for managing changes to externally provided products. ________
Controlled conditions for in-house production processes are well-documented _________
There is a gap in monitoring the quality of externally provided components __________
ISO 9001:2015 Clause 8 extract:
8.4.1 controls to be applied to externally provided processes
8.4.3 reqirements for external providers interactions with the organization
8.4.2 ensuring that externally provided processes do not adversely affect
8.1 implementing control of the processes
Explanation:
1 = B: This issue aligns with clause 8.4.1, which talks about the controls to be applied to externally provided processes, products, and services.
2 = A: This relates to clause 8.4.2, which discusses the organization’s responsibility to ensure that externally provided processes do not adversely affect its ability to deliver conforming products.
3 = D: This matches clause 8.1, which focuses on planning, implementing, and controlling the processes needed to meet product and service requirements.
4 = C: This pertains to 8.4.3, which focuses on the requirements for interactions between the organization and its external providers.
An organization is in the technology sector, primarily focusing on software development. As part of its ongoing efforts to align its quality management system with ISO 9001, the leadership team is taking several actions. (3 Marks)
Select the words that best complete the sentences:
a) To gain a comprehensive view of its strategic direction, the organization needs to _____both external and internal issues.
b) The leadership team is focused on_____the needs and expectations of stakeholders like customers, suppliers, and regulators.
c) For effective operation and control of its quality management processes, the organization must _____criteria and methods, including performance indicators.
recognize/document/understand/evaluate/monitor/review/implement/maintain/identify/address/establish
Correct Answers:
a) To gain a comprehensive view of its strategic direction, the organization needs to understand both external and internal issues.
b) The leadership team is focused on establish the needs and expectations of stakeholders like customers, suppliers, and regulators.
c) For effective operation and control of its quality management processes, the organization must evaluate criteria and methods, including performance indicators.
Explanation:
a) Understand: According to Clause 4.1, the organization needs to “understand” both external and internal issues that are relevant to its strategic address direction and its ability to achieve the intended results of its quality management system.
b) Establish: Clause 4.2 stresses that the organization should “establish” the needs and expectations of interested parties like customers, suppliers, and regulators, as they have a potential effect on the organization’s ability to consistently provide quality products and services.
c) Evaluate: In line with Clause 4.4.1, it is vital for the organization to “evaluate” the criteria and methods needed for the effective operation and control of its quality management processes. This includes monitoring, measurements, and related performance indicators.
As a Lead Auditor, you’re examining an organization’s compliance with ISO 9001:2015. You observe the following: (3 Marks)
a) The organization has not clarified who is responsible for ensuring process effectiveness. The organization must_____responsibilities and authorities for these processes.
b) The company has no documented evidence to show that employees have the necessary training for their roles. The organization should______documented information as evidence of competence.
c) Infrastructure used in product creation, such as machinery, has no maintenance records. The organization needs to_____the infrastructure necessary for the operation of its processes.
assign/establish/determine/monitor/maintain/retain/review
Correct Answers:
a) The organization has not clarified who is responsible for ensuring process effectiveness. The organization mustassignresponsibilities and authorities for these processes.
b) The company has no documented evidence to show that employees have the necessary training for their roles. The organization shouldretaindocumented information as evidence of competence.
c) Infrastructure used in product creation, such as machinery, has no maintenance records. The organization needs tomaintainthe infrastructure necessary for the operation of its processes.
Explanation:
a) Assign: According to Clause 7.1.6, the organization must assign responsibilities and authorities for the processes related to the quality management system.
b) Retain: Clause 7.2 specifies that the organization should retain appropriate documented information as evidence of competence.
c) Maintain: As per Clause 7.1.3, the organization is required to determine, provide, and maintain the infrastructure necessary for the operation of its processes.
You are performing a Stage 2 audit for an automotive manufacturing company. During the audit, you meet with the Head of Human Resources to review the company’s training and competence records. You find that although the company has a training program, there is no documented evidence that employees working in the production line have received specific training in quality control techniques.
You:”Could you elaborate on the training provided to production line employees in terms of quality control?”
Head of HR:”We have general orientation and safety training, but specific quality control training is given on-the-job by supervisors.”
You:”Is this training documented or recorded in any way?”
Head of HR:”No, it’s more of an informal process.”
You:”Are you aware that competence in specific areas like quality control needs to be documented?”
Head of HR:”I wasn’t aware that it had to be documented. We assumed that on-the-job training would suffice.”
You decide to raise a nonconformity against section 7.2 of ISO 9001. Select the word(s) that best complete the sentence:(2 Marks)
“There is no_____evidence that employees involved in production have been______in quality control techniques, as required for the______of their work.”
Options:
skilled/documented/validated/trained/requirements/competence/nature/certified/regulatory/quality
Correct Answer:
“There is no documented evidence that employees involved in production have beentrained in quality control techniques, as required for the nature of their work.”
Explanation:
Documented: This term aligns with ISO 9001:2015 section 7.2, which requires organizations to maintain documented information as evidence of competence.
Trained: The term “trained” directly pertains to the need for employee training in specific areas, as per ISO 9001:2015 section 7.2.
Nature: This term aligns with the requirements of section 7.2, as it emphasizes that the type of work (in this case, quality control) necessitates specific training or competence.
You are conducting a third-party audit of a logistics company. During your review, you find an internal audit report indicating a nonconformity against section 9.1.3 of ISO 9001. The nonconformity states:
“The company has failed to analyze data relating to the performance of its third-party carriers, leading to frequent delays in shipments.”
What action would you take as an auditor following up on this audit? Chooseoneof the following options?(2 Marks)
A. You would ask for shipping delay records to validate the claim.
B. You would request to see if the issue was addressed in management review meetings.
C. You would inquire about any corrective actions taken to address the delays.
D. You would ask for customer feedback relating to shipping delays.
E. You would assess the effectiveness of any corrective actions implemented to resolve the issue.
F. You would verify if the company is monitoring and measuring the performance of its third-party carriers.
Correct Answer:E
Explanation:The correct option is E, “You would assess the effectiveness of any corrective actions implemented to resolve the issue.” ISO 9001:2015 section 9.1.3 emphasizes the need to analyze performance and effectiveness data. By evaluating the effectiveness of corrective actions, the auditor ensures that the organization has adequately addressed the root cause of the nonconformity, thus aligning with the requirements of the standard.
Audit concepts and auditor responsibilities
Considering the audit process for first-party, second-party, and third-party certification audits, select THREE of the following statements that correctly describe the audit objectives: (2 Marks).
A. First-party audits primarily focus on external supplier evaluations.
B. Third-party audits aim to provide an independent assessment for external stakeholders.
C. Second-party audits are conducted by external organizations to assess conformity.
D. First-party audits are internal audits conducted by the organization for self-assessment.
E. Third-party audits are internal audits conducted by the organization for self-assessment.
F. Second-party audits focus on evaluating a supplier’s performance against contractual obligations.
B. Third-party audits aim to provide an independent assessment for external stakeholders.
C. Second-party audits are conducted by external organizations to assess conformity.
D. First-party audits are internal audits conducted by the organization for self-assessment.
From the following list, identify the TWO audit methods or activities that may NOT require direct human interaction: (1 Mark)
A. On-site audits
B. Remote audits with live video conferencing
C. Automated system log reviews
D. Face-to-face interviews
E. Automated vulnerability scanning
F. Document reviews via shared platforms
Correct Answers:C, E
Explanation:
Automated system log reviews are conducted using tools that automatically scan and analyze system logs for anomalies. Therefore, option C doesn’t require direct human interaction.
Automated vulnerability scanning involves tools that identify vulnerabilities in systems without human intervention, making option E correct.
Regarding auditor responsibilities, select the TWO roles from the following list that are primarily responsible for ensuring effective communication with the auditee throughout the audit process: (2 Marks)
A. Audit client
B. Audit team leader
C. Auditors
D. Auditees
E. Guides
F. Observers
Correct Answers:B, C
Explanation:
The audit team leader manages the audit team and ensures effective communication with the auditee, making option B correct.
Auditors directly interact with auditees during the audit process, gathering evidence and verifying information. Hence, effective communication is essential for auditors, making option C correct.
Planning the audit
You are planning a Stage 2 audit for “FoodSafe,” a company that produces organic snacks. The audit’s objective is to assess conformity with ISO 9001. Given the complexity of the food safety regulations, you ponder on the audit’s duration.
What would be an appropriate consideration regarding the audit’s duration? (2 Marks)
A. Limit the audit to one day to reduce disruptions in FoodSafe’s operations.
B. Allocate sufficient time to thoroughly examine all relevant processes and regulations.
C. Extend the audit duration to also cover non-food safety related aspects.
D. Shorten the audit duration to focus only on the critical food safety processes.
E. Match the duration to the number of auditors available.
Correct Answer:B
Explanation:Duration should be sufficient to thoroughly cover all processes, objectives, and criteria set for the audit. Given that FoodSafe operates in a regulated industry (food production), sufficient time must be allocated to cover all necessary regulations and processes.
You’re the audit team leader for a third-party certification audit of a large agricultural firm, GreenField Inc., with multiple farms across the country. The audit was scheduled for the summer, but you learn that one of the farms has been severely affected by an unexpected drought, leading to crop failure.
What should be your course of action as the audit team leader?(1 Mark)
A. Proceed with the audit as planned, including the drought-affected farm.
B. Remove the affected farm from the scope of the audit and proceed with the audit as planned.
C. Postpone the audit to allow GreenField Inc. to recover from the drought’s impact.
D. Conduct a risk assessment and adjust the audit plan to focus on other equally important farms.
E. Cancel the audit, citing that GreenField Inc. is currently not suitable for auditing.
Correct Answer:D
Explanation: Option D is the most appropriate action because it allows the audit to proceed while taking into account the new risks introduced by the drought. By conducting a risk assessment and adjusting the audit plan, the audit can focus on other farms that are equally important, thereby maintaining the integrity of the audit.
You are the audit team leader for a third-party audit on a pharmaceutical company that has recently diversified into producing COVID-19 vaccines. The audit is primarily focused on quality management and compliance with pharmaceutical regulations. You discover that the company has hastily set up a new vaccine production line without fully integrating it into its existing quality management system. The audit is scheduled to last three days, but the audit team suspects it will take longer to thoroughly evaluate the new production line.
Which two would be the most suitable courses of action for you as the audit team leader? (1 Mark)
A. Proceed with the audit as planned, focusing only on the existing pharmaceutical lines.
B. Extend the duration of the audit to include a comprehensive evaluation of the new vaccine production line.
C. Exclude the new vaccine production line from the audit scope and proceed as planned.
D. Postpone the audit until the company fully integrates the new vaccine production line into its existing quality management system.
E. Proceed with the audit as planned but highlight in the report that the new vaccine production line was not audited.
Correct Answers:B, E
Explanation:
Option B: According toISO 19011:2018clause 6.3.2.2, audit planning should address the scope, criteria, and objectives, including the locations and duration of audit activities. Extending the duration to evaluate the new production line ensures that the audit objectives are met and covers the increased scope and complexity of the audit.
Option E: as perISO 19011:2018clause 6.3.2.1, audit planning should consider the risks of the audit activities on the auditee’s processes. Proceeding with the audit as planned but highlighting the limitation in the report aligns with risk-based planning. This option ensures that the audit objectives are met while acknowledging the limitations due to the new production line.
Conducting the audit
You are auditing a software development company seeking ISO 9001:2015 certification. During the audit, you discover that the Development Team often deploys updates to their software without going through a formal testing phase. They claim that their agile approach allows them to fix any issues ‘on the fly’ and that their customers are generally satisfied. The Quality Assurance Manager states that this approach has been approved because it speeds up deployment.
What three records would you seek to confirm whether management processes related to software quality are being effectively implemented? (3 Marks)
A. Code review logs from the Development Team.
B. Customer satisfaction surveys and feedback.
C. Internal audit reports of the software development process.
D. Minutes of Management Review Meetings discussing software quality.
E. Software version control and change logs.
F. Training records for the Development Team on secure coding practices.
G. Records of risk assessments related to software development.
Correct Answers:C, D, G
Correct Answers Explanation:
Internal audit reports of the software development process (C): These would provide evidence on how well the organization monitors and reviews its software development activities, aligning with the Plan-Do-Check-Act cycle mandated by ISO 9001:2015.
Minutes of Management Review Meetings discussing software quality (D): These records would offer insights into management’s commitment and approach to maintaining software quality, which is consistent with the leadership and planning clauses of ISO 9001:2015.
Records of risk assessments related to software development (G): Risk-based thinking is a key element of ISO 9001:2015, and these records would show how the organization identifies and manages risks related to software development.
Incorrect Answers Explanation:
Code review logs from the Development Team (A): While important for internal quality checks, these logs focus on technical aspects and may not provide a comprehensive view of the management processes, which is the focus of the question.
Customer satisfaction surveys and feedback (B): Customer feedback is valuable but may not directly reflect the effectiveness of internal management processes related to software quality.
Software version control and change logs (E): These logs may indicate how changes are managed but don’t necessarily reflect the effectiveness of overarching management processes.
Training records for the Development Team on secure coding practices
(F): While training is essential, these records are more aligned with competence and awareness but may not provide a full view of the effectiveness of management processes for software quality.
You are auditing a financial services company that specializes in wealth management. The company has recently undergone a significant organizational change, including the implementation of a new customer relationship management (CRM) system. During your audit, you meet the Chief Information Officer (CIO) who seems defensive and is reluctant to share information. She states that the organization has been through a lot of changes and feels that the audit is an additional burden at this time. Your objective is to ensure a thorough audit while being sensitive to the challenges the company is currently facing.
Given the defensive posture of the CIO and the ongoing organizational changes, whattwoapproaches would you employ to build rapport with the auditee and effectively assess the newly implemented CRM system? (2 Marks)
Question 20Answer
A.
Insist on immediate access to all CRM system records to ensure audit integrity.
B.
Acknowledge the organizational changes and offer to work around the CIO’s schedule for audit activities.
C.
Send an extensive list of questions about the CRM system in advance to prepare the CIO for the audit.
D.
Seek a brief initial meeting with the CIO to understand the objectives and concerns related to the new CRM system.
E.
Focus the audit exclusively on the CRM system, ignoring other organizational changes to save time.
F.
Engage in a multi-departmental assessment to see how the new CRM system is affecting different parts of the organization.
Correct Answers:B, D
Correct Answer Explanation:
Acknowledge the organizational changes and offer to work around the CIO’s schedule for audit activities: This approach is sensitive to the auditee’s current challenges and helps in building rapport. It also aligns with the objective of being sensitive to the needs and expectations of the auditee.
Seek a brief initial meeting with the CIO to understand the objectives and concerns related to the new CRM system: This allows for open communication and can help in establishing trust. It also gives insights into the auditee’s understanding and implementation of internal changes.
Incorrect Answer Explanation:
Insist on immediate access to all CRM system records to ensure audit integrity. This approach could strain the relationship further and is not sensitive to the auditee’s current challenges.
Send an extensive list of questions about the CRM system in advance to prepare the CIO for the audit: This could be seen as burdensome given the ongoing organizational changes.
Focus the audit exclusively on the CRM system, ignoring other organizational changes to save time: This approach would not be comprehensive and could miss out on evaluating how the CRM system fits into broader organizational changes.
Engage in a multi-departmental assessment to see how the new CRM system affects different parts of the organization: While comprehensive, this may be overwhelming for the auditee given their current challenges.
Scenario:You are conducting an audit at a software development company that specializes in cloud-based solutions. The organization is seeking ISO 9001 certification for the first time and operates from multiple global locations. You are auditing the organization’s quality assurance department where software testing is conducted. You are interviewing the Quality Assurance Manager (QAM).
Discussion with Quality Assurance Manager (QAM):
You:”Can you elaborate on how software testing cycles are planned and executed here?”
QAM:”We follow a sprint-based approach. Each testing cycle lasts two weeks, and we prioritize test cases based on risk assessments.”
You:”How do you ensure the test environments are controlled?”
QAM:”Each test environment is isolated and follows a version control system. Access is restricted to authorized personnel only.”
Question:
You need to assess the extent to which ISO 9001 requirements are met with respect to software testing controls.
Which of the following statements is false?(3 Marks)
A. You would verify the mechanisms for risk-based test case prioritization.
B. You would assess how access to test environments is restricted and controlled.
C. You would inquire about any third-party tools used for version control.
D. You would confirm that test cases are formally reviewed before execution.
E. You would check if software testing cycles are aligned with business objectives.
F. You would validate that a change management process is documented and in use.
G. You would confirm that only Quality Assurance personnel perform software testing.
Correct Answer:F. You would validate that a change management process is documented and in use.
Correct Answer Explanation:
F. This statement is false because it assumes that a change management process specifically needs to be documented and in use for software testing controls. While change management is important, ISO 9001:2015 does not explicitly require it to be documented for this specific context.
Incorrect Answer Explanation:
A. Verifying risk-based test case prioritization aligns with ISO’s focus on risk-based thinking.
B. Assessing access control mechanisms is consistent with ISO’s requirements for controlled environments.
C. Inquiring about third-party tools falls under the purview of understanding the resources used.
D. Confirming formal review processes aligns with ISO’s emphasis on planning and control.
E. Checking alignment with business objectives is a part of quality management principles.
G. Confirming the roles aligns with ISO’s requirements for competence and awareness.
You are an auditor at a pharmaceutical manufacturing company that specializes in the production of generic medications. The company is undergoing its ISO 9001 renewal audit. During the audit, you engage with the Production Manager (PM), the Quality Assurance Manager (QAM), and various team members.
Discussion:
You:”Can you walk me through the process of a batch production from start to finish?”
PM:”Certainly. We start by sourcing raw materials from verified suppliers, followed by quality checks. The production process is then initiated, adhering to specific SOPs. Post-production, another round of quality checks is conducted before the batch is approved for release.”
You:”How do you ensure that these processes are effective in meeting customer and regulatory requirements?”
QAM:”We do internal audits, and we also have KPIs like ‘Batch Rejection Rate’ and ‘Customer Complaints.’ These KPIs are reviewed monthly.”
You:”What sampling methods are used during quality checks?”
QAM:”We use both random and stratified sampling methods depending on the nature of the quality attribute being assessed.”
Question:
Based on the audit discussion and your responsibilities, which of the following activities would you undertake to collect and verify appropriate objective evidence and to evaluate the effectiveness of operational processes? (3 Marks)
A.
Validate that the sourced raw materials come from verified suppliers.
B.
Review the effectiveness of the internal audit process solely based on the ‘Batch Rejection Rate’ KPI.
C.
Examine the variety of sampling methods used in quality checks.
D.
Confirm that production adheres to generic industry practices rather than specific SOPs.
E.
Assess whether the KPIs for evaluating process effectiveness are reviewed and updated on a monthly basis.
Correct Answers:
A. Validate that the sourced raw materials come from verified suppliers.
C. Examine the variety of sampling methods used in quality checks.
Correct Answer Explanation:
A. Aligns with ISO 9001:2015 clause on external provision and ensures that the raw materials meet the necessary quality requirements.
C. Aligns with ISO 9001:2015 clause on monitoring, measurement, analysis, and evaluation. Sampling is an important aspect of this, and verifying the appropriateness of the sampling methods used is key in an audit.
Incorrect Answer Explanation:
B. Relying solely on one KPI would not give a comprehensive view of the effectiveness of the internal audit process, making this option incorrect.
D. The company adheres to specific SOPs for production, making this option incorrect.
E. While reviewing and updating KPIs is important, it is not directly related to the collection and verification of objective evidence during an audit, making this option incorrect.
You are conducting an ISO 9001 audit of a software development company that specializes in customized business solutions. While auditing the human resources department, you discover that they have an orientation program for new hires. However, the program does not include any training or awareness related to the company’s quality policy or quality objectives. You raised a nonconformity against clause 7.3 of ISO 9001.(2 Marks)
Select the words that best complete the sentence:
“The orientation program for new hires lacks training onproceduresand awareness ofqualityobjectives, which are essential elements forcompliance.”
Options:
awareness/ quality objectives/policy/standards/employeeonboarding/compliance/ guidelines/ Procedure
Correct Answer:
“The orientation program for new hires lacks training onpolicyand awareness ofquality objectives, which are essential elements foremployee onboarding.”
Explanation:
“Policy”: This is the correct choice as it refers to the company’s quality policy. According to ISO 9001:2015 Clause 7.3, the quality policy should be understood and applied within the organization.
“Quality Objectives”: This is the correct choice as it refers to the quality objectives of the organization. These objectives should be known and understood by relevant personnel as per ISO 9001:2015 Clause 7.1.6.
“Employee Onboarding”: This is the correct choice as the orientation program is part of the employee onboarding process, which should include training and awareness on essential elements like the company’s quality policy and objectives.
You are an audit team leader conducting a Stage 2 ISO 9001 audit for ABC Manufacturing, a company that specializes in automotive parts. During your audit, you discover that the organization has a robust system for monitoring product quality but lacks a formal process for addressing customer complaints. The Operations Manager is concerned about this gap and asks for your opinion on how they can improve their quality management system (QMS) to be more customer-centric. You raise a nonconformity against clause 9.1.2 related to customer satisfaction.(2 Marks)
Select thetwobest options of how the auditor should best respond to the Operations Manager’s question.
A. The auditor should recommend specific customer complaint software.
B. The auditor should evaluate the existing mechanisms for customer feedback.
C. The auditor should decline to give a personal opinion on the matter.
D. The auditor should advise the organization to prioritize product quality over customer complaints.
E. The organization should develop its own process for handling customer complaints.
F. The auditor should suggest organizing a workshop on customer complaint management.
G. The auditor should recommend an annual review of customer complaints.
Correct Answers:B, C
Correct Answer Explanation:
Option B: This is correct because the auditor’s role is to evaluate existing processes and mechanisms to identify any gaps or areas for improvement. This aligns with ISO 9001:2015 clause 9.1 related to monitoring, measurement, analysis, and evaluation.
Option C: Correct, as the auditor should remain impartial and not give personal opinions. This maintains the integrity of the audit process as specified in ISO 9001:2015 clause 5.1.2 on leadership and commitment.
Incorrect Answer Explanation:
Option A: Incorrect, as it is not the auditor’s role to recommend specific solutions like software. This could compromise the auditor’s impartiality, as indicated in ISO 9001:2015 clause 5.1.2.
Option D: Incorrect because prioritizing product quality over customer complaints would not align with a holistic approach to quality management as prescribed by ISO 9001:2015 clauses 9.1 and 10 on improvement.
Option E: While the organization should indeed develop its process, the auditor’s role is to evaluate existing systems rather than to prescribe specific actions, as guided by ISO 9001:2015 clause 9.1.
Option F: Recommending a workshop is beyond the scope of an auditor’s responsibilities and could compromise impartiality, as per ISO 9001:2015 clause 5.1.2.
Option G: Recommending an annual review might be a good practice, but it is not the auditor’s role to make such recommendations. The focus should be on evaluating existing processes, in line with ISO 9001:2015 clause 9.1.