CRP Continuous Improvement & Auditing 3 — Questions and Answers
Question 1: When conducting an internal audit of a resilience program, which sampling approach is MOST effective for identifying systemic issues across a large organization?
- Convenience sampling from the most accessible departments
- Judgmental sampling based on prior audit findings and risk profile (Correct answer)
- Simple random sampling with no weighting
- Auditing only the most recent plan updates
Correct answer: Judgmental sampling based on prior audit findings and risk profile
Judgmental sampling uses auditor expertise and historical risk data to focus on higher-risk areas, increasing the likelihood of uncovering systemic issues.
Question 2: A corrective action plan (CAP) developed after an audit should PRIMARILY include which of the following elements?
- Identified root cause, action steps, owner, and target completion date (Correct answer)
- A summary of all findings from the previous five audits
- Approval signatures from all department heads
- A risk score reassessment for every identified finding
Correct answer: Identified root cause, action steps, owner, and target completion date
An effective CAP specifies what went wrong (root cause), what will be done (action steps), who is responsible (owner), and by when (target date).
Question 3: How does benchmarking contribute to continuous improvement in resilience management?
- It replaces the need for internal audits by comparing to external standards
- It provides an objective external reference point to identify gaps and best practices (Correct answer)
- It automates corrective action tracking across departments
- It determines the recovery time objective for critical processes
Correct answer: It provides an objective external reference point to identify gaps and best practices
Benchmarking compares an organization's resilience practices against industry peers or standards, revealing gaps and improvement opportunities that internal review alone might miss.
Question 4: Which standard provides specific guidance on management system auditing and is commonly applied when auditing ISO 22301 programs?
- ISO 31000
- ISO 22313
- ISO 19011 (Correct answer)
- NFPA 1600
Correct answer: ISO 19011
ISO 19011 provides guidelines for auditing management systems, including audit principles, managing an audit program, and conducting audits — applicable across all ISO management system standards.
Question 5: An organization's post-exercise review reveals that 40% of staff were unaware of their roles during activation. Which continuous improvement action is MOST directly indicated?
- Revise the risk assessment methodology
- Enhance training and awareness programs targeting role clarity (Correct answer)
- Shorten recovery time objectives across all critical processes
- Commission a third-party audit of the BCP documentation
Correct answer: Enhance training and awareness programs targeting role clarity
Staff unawareness of roles is a training and communication gap, making enhanced training and awareness the most direct corrective action.
Question 6: In continuous improvement frameworks, what is the purpose of a 'management review' in an ISO 22301-aligned program?
- To conduct a full internal audit of all business continuity plans
- To ensure top management evaluates program performance and drives strategic improvements (Correct answer)
- To approve the budget for all resilience-related expenditures
- To validate recovery time objectives with operational teams
Correct answer: To ensure top management evaluates program performance and drives strategic improvements
Management reviews require top leadership to evaluate the BCMS performance against strategic objectives and make decisions to drive improvement at the organizational level.
Question 7: What is the MOST significant risk of relying solely on tabletop exercises for continuous improvement without conducting full-scale tests?
- Tabletop exercises are too expensive to run regularly
- Procedural gaps may go undetected because physical execution and logistics are not tested (Correct answer)
- Staff tend to disengage from discussion-based exercises faster than drills
- Tabletop exercises cannot assess recovery time objectives at all
Correct answer: Procedural gaps may go undetected because physical execution and logistics are not tested
Tabletop exercises test knowledge and decision-making but cannot reveal logistical failures, physical resource gaps, or execution problems that only emerge during full-scale testing.
When conducting an internal audit of a resilience program, which sampling approach is MOST effective for identifying systemic issues across a large organization?