Part4 A8 Flashcards

1
Q

2 definitions of risk

ISO 31000:2018
ISO 9000:2015

A

Effective on uncertainty on objectives

Effective of uncertainty

If something is certain there is not risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk can be _____ or ——-

A

Positive or negative

Positive 9001 is called opportunity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Risk is also

A

Probability and consequences (severity)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

7 principles of audits which is the last principle

A

Risk based auditing

5H aid another section going into section body of knowledge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When it comes to audit program management where does risk come into play?

A

How the audit program affects the organization risk level?

How the risk level affects the audit program (number and frequency of audits)?

Risk associated with the audit program

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How the audit program affects the organizations risk level?

A

Monitors the KCP to check if they are being performed as planned

IDs gaps from customer/contract requirements statutory regulatory requirements

Create the culture of conformance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How the risk level affects the audit program?

A

The extent of an audit program should be based on the size and nature of the auditee as all as the functionality complexity the type of risks and opportunities and the level of maturity or the management system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk to audit program management

A

During planning - failure to set objective

Resources - time of training

Communication. Ineffective channels

Security and confidentiality rules

Ineffective program monitoring

Lack of cooperation from auditee

Not controlling audits costs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly