CRP Continuous Improvement & Auditing 2 — Questions and Answers
Question 1: Which audit methodology is most appropriate when an organization wants to assess compliance against the ISO 22301 standard for business continuity?
- Gap analysis
- Third-party certification audit (Correct answer)
- Internal control review
- Risk register walkthrough
Correct answer: Third-party certification audit
A third-party certification audit conducted by an accredited certification body is required to formally assess and certify compliance against ISO 22301.
Question 2: In the PDCA (Plan-Do-Check-Act) cycle applied to resilience programs, what is the primary purpose of the 'Check' phase?
- Develop new resilience strategies
- Implement corrective actions from prior audits
- Monitor and measure program performance against objectives (Correct answer)
- Assign roles and responsibilities for resilience activities
Correct answer: Monitor and measure program performance against objectives
The Check phase involves monitoring, measuring, analyzing, and evaluating results against the planned objectives to determine if goals are being met.
Question 3: What does a 'lessons learned' process in resilience management primarily help an organization achieve?
- Meet regulatory filing deadlines
- Identify gaps and embed improvements after incidents or exercises (Correct answer)
- Reduce insurance premiums through documentation
- Satisfy board-level reporting requirements
Correct answer: Identify gaps and embed improvements after incidents or exercises
Lessons learned processes capture what worked, what failed, and what should change, directly feeding continuous improvement into resilience programs.
Question 4: An auditor discovers that a business continuity plan has not been updated in 36 months despite two significant organizational changes. This finding would MOST likely be classified as:
- Observation
- Minor nonconformity
- Major nonconformity (Correct answer)
- Opportunity for improvement
Correct answer: Major nonconformity
A plan that fails to reflect significant organizational changes over an extended period represents a systemic failure of the maintenance process, qualifying as a major nonconformity.
Question 5: Which metric BEST measures the effectiveness of a business continuity training program over time?
- Number of training sessions delivered per quarter
- Employee attendance rate at training events
- Reduction in plan errors identified during exercises following training (Correct answer)
- Cost per trainee per year
Correct answer: Reduction in plan errors identified during exercises following training
Reduction in errors identified during exercises directly measures whether training is translating into improved competency and plan execution.
Question 6: Root cause analysis (RCA) in a resilience context is BEST described as:
- A technique to rank risks by likelihood and impact
- A structured method to identify underlying causes of failures or incidents (Correct answer)
- A compliance checklist for auditing plan documentation
- A process for calculating recovery time objectives
Correct answer: A structured method to identify underlying causes of failures or incidents
RCA identifies the fundamental cause of a problem — not just symptoms — so that corrective actions address the source and prevent recurrence.
Question 7: Which of the following BEST represents a leading indicator for resilience program health?
- Number of incidents that activated the BCP in the past year
- Percentage of recovery time objective (RTO) breaches during actual events
- Percentage of plans tested and updated within the required cycle (Correct answer)
- Average downtime duration per disruption event
Correct answer: Percentage of plans tested and updated within the required cycle
Leading indicators predict future performance; plan testing and update completion rates signal program maintenance health before an incident occurs.
Which audit methodology is most appropriate when an organization wants to assess compliance against the ISO 22301 standard for business continuity?