ABC is a worldwide fast-food organisation. One of the branches, in downtown Cape Town, decided to
implement an ISO 9001 quality management system and you are the audit team leader (with two other
auditors) that will carry out the certification audits, Stage 2.
ABC receive the orders by phone or internet; some of the employees deliver the ordered food to indicated
addresses. The normal menu includes 15 different types of hamburgers; however, in the last two weeks,
due to a shortage of a special type of meat, they can only prepare six of the 15 varieties.
During the internal meeting of the audit team, you ask one of the auditors to describe what she has
observed. She audited the reception of orders from customers (via phone or internet) and the
communication of the orders to the kitchen. She noticed that the menu offering food on the website is still
the normal one, with 15 different hamburgers, and during a 30-minute period, she observed many
customers reluctantly accepting something other than the hamburger they preferred.
You, as audit team leader, inform the Quality Manager of your concern about the major nonconformity,
since you consider this a serious breach of the basic principles of quality that lasted two weeks without
action being taken.
Right at the beginning of the Closing meeting, you discuss the nonconformity with the General Manager.
She got quite upset and said she was going to make a complaint to the certification body and left the
room; the Quality Manager was the only member of ABC left with the audit team. The Quality Manager said the General Manager would not come back to the meeting.
What would you do? Choose the best from the following options:
For a third-party, match the Activity with the Responsibility for conducting it.
A small cleaning services organisation is about to start work on a hospital cleaning contract for the local Health Trust. You,
as auditor, are conducting a Stage 2 audit to ISO 9001 and review the contract with the Service Manager. The contract
requires that a cleaning plan is produced.
You: "How was the cleaning plan for the contract developed?"
Service Manager: "We have a basic template that covers the materials, labour requirements and cleaning methods to be
employed. Some of that is specified by the customer."
You: "How does the plan deal with locations like the intensive care wards and the operating theatres, which are included
in the contract?"
Service Manager: "The basic plan covers general wards, but we will do more frequent cleaning in those areas if the
hospital requests it."
You: "Are you aware of the regulatory requirements for cleaning standards in hospitals?"
Service Manager: "No. We depend on the hospital to look after that side of things in the contract."
You decide to raise a non-conformity against section 8.2.2.a.1 of ISO 9001.
You decide to raise another non-conformity against section 8.2.4 of ISO 9001 when finding that the
cleaning plan was amended without the agreement of the Health Trust. A different cleaning chemical was
substituted to that specified in the contract. At the follow-up audit, the corrective action proposed was to
"obtain a concession from the Health Trust for use of the new chemical."
Which one of the following options is the reason why you did not accept this action taken?
In the context of a third-party audit, select the issue which is not expected to be included in the audit plan.
An audit team leader arrives at a printing company to carry out a Stage 2 audit for a certification body. At a meeting with the Quality Manager, she is told that they have won their biggest contract from a computer manufacturer to print and compile computer documentation packages. The Quality Manager wants the ISO 9001 certificate to cover the new contract.
During the audit, a team member found that some print jobs had been rejected by several clients over some months due to spelling errors in the print run. The Print Manager blames the new employees they had to take on because of a big contract.
The auditor finds that the responsibility for checking spelling errors is placed on the printer that sets up the print run.
In line with the policy of the certification body, the audit team raise improvement opportunities in the audit report. Which
three of the following options would represent acceptable opportunities for improvement in the report?
During an internal audit, it was discovered that the calibration of a spectrometer used daily for production had expired, causing a nonconformance under Clause 7.1.5.2 of ISO 9001:2015. The root cause was the organization not considering the risk of the calibration provider leaving the country.
Which corrective action is the best one?
Select one of the options that best describes the purpose of conducting a document review:
The Closing meeting of a second-party audit was planned for 6 pm with the general manager and the quality manager.
At 6 pm, when the audit team enters the meeting room, only the Quality Manager is present and walting for them.
The dialogue among them is as follows:
Auditor team leader: "Good evening, could you please inform the general manager that we are ready to start with the closing meeting?"
Quality manager: "Good evening. I am sorry to inform you that the general manager will not be able to attend the meeting. He will try to
participate virtually to make some closing remarks."
Auditor team leader: "OK. We identified seven nonconformities - these are the reports. Could you please review them and sign them?"
Quality manager: "OK. As you know, I reviewed them after yesterday's meeting and accept of all them, where shall I sign?"
General manager (from speakers in the room and addressing the quality manager): "Hold on! Do not sign the two nonconformities related to ABC
Bank! I have just checked, and we did not provide any services to ABC Bank during September! You can sign the remaining five nonconformities."
How would you proceed with the audit? Select one.
Read the following role descriptions. Select two roles that are not directly involved in the audit process.
You are the supervisor in Production of a medium size manufacturing organisation. You are qualified as an internal auditor. The Quality Manager asks you to lead the next internal audit of Production and Logistics Dispatch. The audit team includes two other internal auditors.
You will lead a third-party audit next Monday on ABC, an organisation that provides services for cleaning windows from the outside of tall buildings. They work on demand, and usually have 4-5 orders per week. All documented information on these activities is kept at the central office.
On Friday evening, before the audit, you are informed by mail that customers cancelled all orders for the next week; therefore, the auditors will not have the chance to see them working at the customer's premises, but the field supervisors will be available at the ABC offices.
You have prepared the audit plan and the checklist. Choose the best action you would take:
In the context of a third-party certification audit, how can the auditor demonstrate confidentiality? Select two.
You are carrying out an audit at an organisation seeking certification to ISO 9001 for the first time. The organisation offers health and safety training to customers. Training courses are offered either as open courses, delivered at a public venue, or online, or as courses that are tailored to meet specific requirements. The business operates from a single office and those who deliver the training are either full-time employees or subcontractors.
You are interviewing the Training Manager (TM).
You: "What quality objectives apply to the training process?"
TM: "One of the quality objectives we aim for is a 90% minimum exam pass rate for all open training courses."
You: "How do you measure this objective?"
The Training Manager shows you a record on her computer and you see the following:
Which two of the following statements are true?
An audit team of three people is conducting a Stage 2 audit to ISO 9001 of an engineering organisation that manufactures sacrificial anodes for the oll and gas industry in marine environments. These are aluminium products designed to prevent corrosion of submerged
steel structures. You, as one of the auditors, find that the organisation has shipped anodes for Project DK in the Gulf of Mexico before the galvanic efficiency test results for the anodes have been fully analysed and reported as required by the customer. The Quality
Manager explains that the Managing Director authorised release of the anodes to avoid late delivery as penalties would be imposed. The customer was not informed since the tests very rarely fall below the required efficiency. You raise a nonconformity against clause 8.6 of ISO 9001.
Which of the following options for the best description of the nonconformity?
ABC is a fast food shop that receives orders by phone or the internet. The normal menu includes 15 different types of hamburgers; however, in the
last two days, due to a shortage of a special type of meat, they can only prepare six of the 15 varieties.
You are performing a third-party audit of ABC; you observed that the menu offering food on the website is still the normal one, with 15 different
hamburgers. During a 30-minute period, you observed several customers reluctantly accepting other than the hamburger they preferred. You decided
to raise the following nonconformity as follows:
"There is evidence that ABC has not reviewed the ability to provide customers the offered products".
The restaurant manager does not accept the nonconformity. She says that ABC had an extensive training programme for all personnel, which you have already seen when auditing Human Resources. This shortage of some hamburgers cannot be considered a management system failure.
Which one would be your answer from the following options?
During a third-party audit of a pharmaceutical organisation (CD9000) site of seven COVID-19 testing laboratories in various terminals at
a major international airport, you interview the CD 9000's General Manager (GM), who was accompanied by Jack, the legal compliance
expert. Jack is acting as the guide in the absence of the Technical Manager due to him contracting COVID-19.
You: "What external and internal issues have been identified that could affect CD9000 and its quality management system?"
GM: "Jack guided us on this. We identified issues like probable competition of another laboratory organisation in the airport, legal
requirements on COVID-19 continuously changing, the shortage of competent laboratory analysists, the epidemic declining soon,
shortage of chemicals for the analysis. It was quite a good experience."
You: "Did you document these issues?"
GM: "No. Jack said that ISO 9001 does not require us to document these issues."
You: "How did you determine the risks associated with the issues and did you plan actions to address them?"
GM: "I am not sure. The Technical Manager is responsible for this process. Jack may be able to answer this question in his absence."
Select two options for how you would respond to the General Manager's suggestion:
Which two of the following work documents are not required for audit planning by an auditor conducting a certification audit?
Which two of the following are included in the objectives of the 'Stage 1 initial certification audit'?
You are conducting an audit at an organisation seeking certification to ISO 9001 for the first time. The organisation offers health and safety training to customers. Training courses are offered either as open courses, delivered at a public venue, or online, or as courses that are tailored to meet specific requirements. The business operates from a single office and those who deliver the training are either full-time employees or subcontractors.
You have gathered audit evidence as outlined below. Match the ISO 9001 Clause 8 extract to the audit evidence.
An audit team leader arrives at a printing organisation to carry out a Stage 2 audit for a certification body. At a meeting with the Quality Manager, she is told that they have won their biggest contract from a computer manufacturer to print and compile computer documentation packages. They have leased the unit next door for space reasons but have never worked in this sector before. The Quality Manager wants the ISO 9001 certificate to cover the new contract.
During the audit, a team member finds that a number of print jobs have been rejected by several clients over a number of months due to spelling errors in the print run. The Print Manager blames the new employees they had to take on because of a big contract. The auditor raises a nonconformance against clause 10.2.1.b of ISO 9001.
Which one of the evidence statements would support this finding?
At the end of a second-party audit, the audit team enters the meeting room to hold the closing meeting; only
two people are present and waiting for them: the Health and Safety supervisor and the Administrative Officer.
Neither has participated in the audit. However, the team had previously agreed with the auditee Quality
Manager on two nonconformities identified during the audit (NC1 and NC2).
They said:
Health and Safety Supervisor: "Good evening. We are sorry to inform you that the general manager was
involved in a serious car accident, and the other two managers have had to leave urgently to attend to the
emergency."
The Administration Officer: "Concerning 'nonconformity 2', the General Manager left a message asking us
to tell you that he does not accept it and requests you not to include it in the audit report. Here is a note in
which he explains why."
Which one of the following would be your preferred answer (as team leader) to the General
Manager's request?
An audit team of three people is conducting a Stage 2 audit to ISO 9001 of an engineering organisation that manufactures sacrificial anodes for the oil and gas industry in marine environments. These are aluminium products designed to prevent corrosion of submerged steel structures. You, as one of the auditors, find that the organisation has shipped anodes for Project DK in the Gulf of Mexico before the galvanic efficiency test results for the anodes have been fully analysed and reported as required by the customer. The Quality Manager explains that the Managing Director authorised the release of the anodes to avoid late delivery as penalties would be Imposed. The customer was not informed since the tests very rarely fall below the required efficiency. You raise a nonconformity against clause 8.6 of ISO 9001.
At the Closing meeting, the audit team leader presents the findings of the audit and comes to the above
nonconformity. The Quality Manager produces the test report for Project DK, which shows an acceptable galvanic efficiency, and presents an email from the customer confirming acceptance of the anodes. He asks that the nonconformity be withdrawn.
Which two of the following responses by the audit team leader would be acceptable?
During a third-party audit of a pharmaceutical organisation (CD9000) site of seven COVID-19 testing
laboratories in various terminals at a major international airport, you interview the CD 9000's General Manager (GM), who was accompanied by Jack, the legal compliance expert. Jack is acting as the guide in the absence of the Technical Manager due to him contracting COVID-19.
You: "What external and internal issues have been identified that could affect CD9000 and its quality
management system?"
GM: "Jack guided us on this. We identified issues like probable competition of another laboratory
organisation in the airport, legal requirements on COVID-19 continuously changing, the shortage of
competent laboratory analysists, the epidemic declining soon, shortage of chemicals for the analysis. It was
quite a good experience."
You: "Did you document these issues?"
GM: "No. Jack said that ISO 9001 does not require us to document these issues."
You: "How did you determine the risks associated with the issues and did you plan actions to address
them?"
GM: "I am not sure. The Technical Manager is responsible for this process. Jack may be able to answer this question in his absence."
Select two options for how you would respond to the General Manager's suggestion:
Below are four of the seven principles on which ISO 9000 series are based. Match a potential benefit to each of the quality management principles (QMP).
In the context of a third-party certification audit, it is very important to have effective communication. Which is not the responsibility of the audit team leader?
Which one of the following documents addresses audit time calculation for third-party certification audits?
Takitup is a small fabrication organisation that manufactures steel fencing, stairs and platforms for the construction sector. It has been certified to ISO 9001 for some time and has appointed a new Quality Manager. The audit plan during a surveillance audit covers the organisation's improvement actions and the auditor asks to see the most recent management review meeting minutes.
The auditor finds that the management review report records that none of the improvement actions set by the previous review has been realised for a second time. A new Quality Manager has been brought in at the middle management level to rectify the situation as the organisation is concerned that it might lose its certification.
Select three options that would provide evidence of conformance with clause 10.3 of ISO 9001.
Which one of the following options best describes the purpose of a Stage 1 third-party audit?
You are conducting a third-party audit to ISO 9001 and the next item on your audit plan is 'internal auditing'.
When reviewing a sample of audit records up to 5 years previously, you find that many contain non-conformance reports and no actions have been taken. You interview the Quality Manager.
You: "I have noted that many of the older files contain non-conformances that have not had any corrective action taken."
Quality Manager: "Because the business is always changing, the departmental managers tell me that the non-conformances are no longer applicable. I made a decision that any non-conformance over 3 years old is automatically closed"
You: "Do you obtain any confirmation beforehand from the appropriate departments that the non-conformances are no longer applicable."
Quality Manager: " No, because they are so old I consider that they are no longer appropriate. Please remember that we take a risk-based approach which means we audit where and when it is considered important to do so.
Select one course of action you would now take from the options.
Put the following steps of a third-party audit into the correct sequence in which they happen.
Which two of the following aspects of a quality management system must the organisation continually improve?
Select the term which best describes the quality management system process of modifying a non-conforming product to bring it within acceptance criteria.
You have been nominated audit team leader of a third-party audit. Which of the following could be the two most relevant objectives of this audit?
You are carrying out an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The
organisation manufactures cosmetics for major retailers and the name of the retailer supplied appears on the product
packaging. Sales turnover has increased significantly over the past five years. The organisation uses a software programme called SWIFT, which is used to record sales, plan production, purchase supplies, print despatch notes, track new product development, perform traceability exercises, carry out mass balance checks, raise invoices, create budgets, and support financial control.
You are nearing the end of the audit and you are reviewing your audit notes. You notice a recurring trend concerning the SWIFT database as shown below:
You ask the Quality Manager to explain how the SWIFT database is controlled. You learn that the Operations Director is
responsible for determining and progressing SWIFT software updates. You decide to meet the Operations Director (OD).
You: "Good afternoon."
OD: "Good afternoon."
You: "What responsibility do you have concerning the SWIFT database?"
OD: "I maintain it. If anyone wishes to propose an update to the database, they send me an email with
details of their proposal. I then either process the database update myself, or I send the request to the
consultant who designed the database 20 years ago. The necessary software changes are made, and the
amended software is immediately released to users."
You: "Would you explain how the software amendments are controlled?"
OD: "Of course. I personally update every computer myself."
You: "Do you inform the database users of the changes?"
OD: "No I don't. They find out for themselves by using the software, or they come to see me if they have
any questions."
You: "How do you ensure that the database users use the latest version?"
OD: "That's easy, I update every computer myself."
You: "During the audit, I noted there were several versions of SWIFT in use (you refer to your audit
notes)."
OD: "I know. That's because some versions work better than others, and depending on user needs and
experiences, we allow users to revert to using an earlier version if they find it works better for them."
Based on the scenario, which two of the following statements are true? There is evidence of
nonconformity with a requirement defined in ...
XYZ Corporation is an organisation that employs 100 people. As the audit team leader, you are conducting a certification audit at Stage 1. When reviewing the quality management system (QMS)
documentation, you find that quality objectives have been set for every employee in the organisation except top management. The Quality Manager complains that this has created a lot of resistance
to the QMS, and the Chief Executive is asking questions about how much it will cost. He asks for your opinion on whether this is the correct method of setting objectives.
How would you respond with the following options? Select three.
ABC is a service organisation that cleans and irons bed and table linen for four large hospitals in the city centre. It claims to meet ISO 9001:2015 requirements. During an internal audit, an auditor observes that
machine No. 4 is being operated with the three variables outside the limits established in the applicable documented procedure SP-701. The auditor has decided to raise a nonconformity.
Which six elements should be included in the nonconformity report?