ISO AUDITOR Audit Scheduling & Checklist Design 3 — Questions and Answers
Question 1: Which ISO standard provides the primary guidance for planning and conducting management system audits, including scheduling?
- ISO 9001:2015
- ISO 19011:2018 (Correct answer)
- ISO 17021-1:2015
- ISO 45001:2018
Correct answer: ISO 19011:2018
ISO 19011:2018 is the guidelines standard specifically for auditing management systems, covering audit program management, planning, and execution.
Question 2: An audit checklist should be treated as:
- A rigid script that auditors must follow without deviation
- A flexible tool that guides inquiry while allowing auditor judgment (Correct answer)
- A confidential document never shared with the auditee
- A substitute for the auditor's technical knowledge
Correct answer: A flexible tool that guides inquiry while allowing auditor judgment
Checklists guide the audit and ensure completeness but must not prevent auditors from pursuing objective evidence that emerges during the audit.
Question 3: When establishing audit frequency for a given process, which combination of inputs is MOST relevant?
- Customer complaints volume and management preference
- Process risk, previous audit results, and process importance to QMS objectives (Correct answer)
- Number of employees in the process and their tenure
- Cost of the process and its profit margin contribution
Correct answer: Process risk, previous audit results, and process importance to QMS objectives
ISO 19011 and ISO 9001 clause 9.2 direct audit frequency to be risk-based, informed by prior findings and the process's role in achieving quality objectives.
Question 4: A lead auditor discovers mid-audit that the scope needs to expand beyond the original plan. What is the correct course of action?
- Immediately expand the scope and inform the auditee afterward
- Abandon the audit and reschedule with the new scope
- Notify the audit client and obtain approval before expanding the scope (Correct answer)
- Proceed with the original scope only and note the gap in the report
Correct answer: Notify the audit client and obtain approval before expanding the scope
Scope changes require authorization from the audit client; expanding scope without approval undermines the integrity of the audit program and may violate agreed arrangements.
Question 5: When writing checklist questions for the management review process, the auditor should ensure coverage of:
- Board of directors meeting minutes from the past five years
- Inputs and outputs specified in ISO 9001 clause 9.3 (Correct answer)
- Employee satisfaction survey raw data
- Competitor benchmarking reports
Correct answer: Inputs and outputs specified in ISO 9001 clause 9.3
ISO 9001 clause 9.3 specifies mandatory inputs (e.g., audit results, customer feedback, KPIs) and required outputs (decisions and actions); checklists must verify all are present and documented.
Question 6: Which practice BEST ensures an audit schedule remains effective over a multi-year certification cycle?
- Rotating the same checklist questions to avoid auditor preparation fatigue
- Conducting all audits in the first year and using surveillance visits only thereafter
- Performing a periodic review of the program using audit results, risks, and organizational changes (Correct answer)
- Keeping the schedule identical each year for consistency and comparability
Correct answer: Performing a periodic review of the program using audit results, risks, and organizational changes
Continuous improvement of the audit program requires periodic reviews that incorporate findings, changing risks, and organizational developments to keep the program relevant.
Question 7: In a risk-based audit checklist, how should identified high-risk clauses be treated compared to low-risk clauses?
- High-risk clauses should be skipped to focus time on root cause analysis
- High-risk clauses warrant more detailed questions and greater sampling depth (Correct answer)
- All clauses receive equal checklist coverage regardless of risk
- Low-risk clauses should have more questions to compensate for less scrutiny elsewhere
Correct answer: High-risk clauses warrant more detailed questions and greater sampling depth
Risk-based thinking requires auditors to allocate greater checklist depth and sampling effort to clauses and processes that carry higher potential for nonconformity or quality impact.
Which ISO standard provides the primary guidance for planning and conducting management system audits, including scheduling?