Auditor Flashcards
7 cards from real ISO 20000 Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Auditor flashcards as text
During an ISO 20000-1 audit, an auditor discovers that the organization's service catalog is maintained but has not been reviewed in 18 months. What is the most appropriate audit finding?
Answer: Minor nonconformity — the organization has not fulfilled a specific requirement
ISO 20000-1 requires the service catalog to be maintained and kept up to date, so failure to review it within a reasonable period constitutes a minor nonconformity.
Which audit technique is most effective for verifying that change management records are complete and accurate in an ISO 20000 context?
Answer: Sampling and reviewing actual change records against defined criteria
Record sampling provides objective evidence that change records meet defined content and approval criteria, satisfying the auditor's need for factual evidence.
An ISO 20000 auditor finds that the organization's continual improvement register lists twelve items but none have been implemented in the past year. What should the auditor conclude?
Answer: Minor nonconformity, because the standard requires improvements to be actioned, not just recorded
ISO 20000-1 requires the organization to implement and evaluate improvement activities, not merely document them, making inaction a minor nonconformity.
What is the primary purpose of an audit trail in ISO 20000 internal audits?
Answer: To provide a record linking audit evidence to findings and conclusions
An audit trail ensures that each finding can be traced back to the specific evidence on which it is based, supporting transparency and reproducibility.
When an ISO 20000 auditor identifies a potential conflict of interest, what is the required course of action?
Answer: Disclose the conflict and withdraw from auditing that area
Auditor independence is a foundational principle; disclosing and recusing oneself from the conflicted area preserves audit integrity.
An ISO 20000 surveillance audit reveals that an organization has changed its incident classification scheme without updating the incident management procedure. Which clause is most directly relevant?
Answer: Clause 7.5 — Documented information
Documented information (Clause 7.5) must be controlled and kept up to date; a procedure that no longer reflects the actual process is a documented-information nonconformity.
During an audit opening meeting, the lead auditor should do which of the following?
Answer: Confirm the audit scope, objectives, and methodology with the auditee
The opening meeting establishes shared understanding of scope, objectives, criteria, and approach before evidence collection begins.