Which type of audit risk is the risk that a significant defect may occur in the QMS, although the organization has internal control mechanisms in place?
At the end of an initial third-party certification audit, the audit team enters the closing meeting room to hold the closing meeting. Only two people are present and waiting for them, the Health and Safety Supervisor and the Administrative Officer. Neither has participated in the audit. However, the team had previously agreed with the auditee Quality Manager on a major non-conformity.
They said:
Health and Safety Supervisor says: "Good evening. We are sorry to inform you that the General Manager was convened by the CEO of the organization to analyze an unexpected, very serious situation with the personnel.
The Administration Officer: "Concerning the major non-conformity, the General Manager called us on the phone asking us to tell you that he agrees with the non-conformity and that the correction will be taken this week, and the corrective action is to be implemented before the end of this month. He also asked us to tell you that it would be a pity to postpone the recommendation for certification due to this ongoing issue that can be solved so easily. Do you want me to describe to you what he told me he would do?"
Which one of the following would be the correct response (as team leader) to the General Manager's request?
Scenario 4:
TD Advertising is a print management company based in Chicago. The company offers design services, digital printing, storage, and distribution. As TD expanded, its management recognized that success depended on adopting new technologies and improving quality.
To ensure customer satisfaction and quality improvement, the company decided to pursue ISO 9001 certification.
After implementing the QMS, TD hired a well-known certification body for an audit. Anne Key was appointed as the audit team leader. She received a document listing the audit team members, audit scope, criteria, duration, and audit engagement limits.
Anne reviewed the document and approved the audit mandate. The certification body and TD’s top management signed the certification agreement.
Before contacting TD, Anne reviewed the audit scope and noticed that TD made changes to it due to the adoption of new printing equipment. However, Anne disagreed with the changes, stating they would affect the audit timeline. She considered withdrawing from the audit.
Based on scenario 4, conducting which of the activities below is NOT the responsibility of Anne?
Which two of the following auditors would not participate in a first-party audit?
You will lead a third-party audit next Monday on ABC, an organisation that provides services for cleaning windows from the outside of tall buildings. They work on demand, and usually have 4-5 orders per week. All documented information on these activities is kept at the central office.
On Friday evening, before the audit, you are informed by mail that customers cancelled all orders for the next week; therefore, the auditors will not have the chance to see them working at the customer's premises, but the field supervisors will be available at the ABC offices.
You have prepared the audit plan and the checklist. Choose the best action you would take:
Select six of the activities that are specifically required by ISO 17021-1 as part third-party (Certification Body) surveillance audit processes.
Scenario 6: Davis Clinic (DC) is an American medical center focused on integrated health care. Since its establishment DC was committed to providing qualitative services for its clients, which is the reason why the company decided to implement a quality management system (QMS) based on ISO 9001. After a year of having an active QMS in place, DC applied for a certification audit.
A team of five auditors, from a well-known certification body, was selected to conduct the audit. Eva was appointed as the audit team leader. After three days of auditing, the team gathered to review and examine their findings. They also discussed the audit findings with DC's top management and then drafted the audit conclusions.
In the closing meeting, which was held between the audit team and the top management of DC. Eva presented two nonconformities that were detected during the audit. Eva stated that the company did not retain documented information regarding its outsourced services for an analysis laboratory and regarding the conducted management reviews. During the closing meeting, the audit team required from DCs top management to come up with corrective action plans within two weeks. Although the top management did not agree with the audit findings, the audit team insisted that the auditee must submit corrective actions within the given time frame in order for the audit activities to continue.
Once the action plans were evaluated, the audit team began preparing the audit report. Eva required from the team to provide accurate descriptions of the audit findings and the audit conclusions. The report was then distributed to all the interested parties involved in the audit, including the certification body Based on the report, the certification body together with Eva, as the audit team leader, made the certification decision.
Based on the scenario above, answer the following question:
The audit team delayed audit activities until DC’s top management submitted their action plans. Is this acceptable?
During a Stage 1 audit, the Quality Manager asks that the audit includes coverage of a new work area they have expanded into since the application was made.
Which of the following two actions should the auditor take?
Which two of the following statements related to Stage 1 of an initial certification audit against ISO 9001:2015 are true?
Scenario 3:
Fin-Pro is a financial institution in Austria offering commercial banking, wealth management, and investment services. The company faced a significant loss of customers due to failing to improve service quality as they expanded.
To regain customer confidence, top management implemented a QMS based on ISO 9001. After a year, they contacted ACB, a local certification body, to pursue ISO 9001 certification.
The audit team was led by Emilia, an experienced lead auditor, and included three auditors. After an agreement was reached, ACB sent the audit objectives to the audit team.
The audit team began by gathering information about Fin-Pro’s understanding of ISO 9001 requirements. While reviewing documented information, they noticed missing records of training and awareness sessions. They conducted employee interviews to verify attendance.
The team also reviewed the organizational chart and job descriptions to confirm employee competence. They observed the company’s working environment (social, psychological, and physical conditions).
The audit team analyzed the evidence and prepared an audit report with findings and conclusions.
ACB sent the audit objectives to the audit team after an agreement was reached. Is this acceptable?