Part4 A8 Flashcards
2 definitions of risk
ISO 31000:2018
ISO 9000:2015
Effective on uncertainty on objectives
Effective of uncertainty
If something is certain there is not risk
Risk can be _____ or ——-
Positive or negative
Positive 9001 is called opportunity
Risk is also
Probability and consequences (severity)
7 principles of audits which is the last principle
Risk based auditing
5H aid another section going into section body of knowledge
When it comes to audit program management where does risk come into play?
How the audit program affects the organization risk level?
How the risk level affects the audit program (number and frequency of audits)?
Risk associated with the audit program
How the audit program affects the organizations risk level?
Monitors the KCP to check if they are being performed as planned
IDs gaps from customer/contract requirements statutory regulatory requirements
Create the culture of conformance
How the risk level affects the audit program?
The extent of an audit program should be based on the size and nature of the auditee as all as the functionality complexity the type of risks and opportunities and the level of maturity or the management system.
Risk to audit program management
During planning - failure to set objective
Resources - time of training
Communication. Ineffective channels
Security and confidentiality rules
Ineffective program monitoring
Lack of cooperation from auditee
Not controlling audits costs