Document & Record Control Flashcards
7 cards from real ISO AUDITOR practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Document & Record Control flashcards as text
Which of the following scenarios demonstrates effective 'access control' for documented information as required by ISO 9001:2015?
Answer: Role-based permissions allow read access to relevant procedures and edit access only to document owners
Role-based permissions aligning read/edit rights to job function satisfy the access control requirement of clause 7.5.3(a).
An auditor reviews a corrective action report and notices no completion date or verification signature. What requirement has not been met?
Answer: Completeness and evidence of effectiveness verification
Records must capture evidence of results and verification of actions taken; missing completion data and sign-off means the record is incomplete.
ISO 9001:2015 clause 7.5.2 requires that documented information be 'suitable and adequate.' Which pair of attributes best defines this?
Answer: Fit for its intended purpose and of the right scope
Suitability means it achieves its purpose; adequacy means it covers the necessary scope for effective process control.
When auditing a service organization that uses only electronic records, an auditor must verify that the system provides:
Answer: Protection, version control, and retrievability of electronic documented information
Electronic systems must provide protection from loss/corruption, version control, and easy retrieval to satisfy clause 7.5.3 requirements.
A supplier's quality certificate is kept in a shared folder but has no indication of when it was received or whether it has been verified. Which control element is missing?
Answer: Identification of the documented information
External documented information must be identified (date, source, verification status) per clause 7.5.3 to enable its controlled use.
What is the auditor's primary concern when an organization states, 'We don't need a documented procedure for that because our staff are experienced'?
Answer: Whether the organization has determined and justified that documented information is not necessary for that process
ISO 9001:2015 allows organizations to determine the extent of documentation needed; the auditor must verify that determination is justified and risks are managed.
An organization destroys training records after each calendar year to save storage space. No retention requirement is documented. Which action should an auditor take?
Answer: Raise a finding for undefined and potentially non-compliant retention periods
Retention periods must be defined and meet applicable requirements; destroying records without a documented policy risks noncompliance with clause 7.5.3.