← All ISO 20000 Certification Flashcard Decks

Auditor Flashcards

7 cards from real ISO 20000 Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Auditor flashcards as text
  1. An ISO 20000 auditor reviews corrective action records and finds that root causes were identified but the effectiveness of corrective actions was never verified. Which requirement is not being met?

    Answer: Clause 10.1 — Nonconformity and corrective action

    Clause 10.1 requires the organization to review the effectiveness of corrective actions taken, not merely implement them.

  2. Which of the following is a valid reason for an ISO 20000 certification body to suspend an organization's certificate?

    Answer: Surveillance audits reveal persistent major nonconformities that are not addressed

    Persistent unresolved major nonconformities demonstrate that the SMS is no longer maintaining conformity, justifying suspension of the certificate.

  3. When auditing continual improvement under ISO 20000-1, which evidence demonstrates that the organization is systematically identifying improvement opportunities?

    Answer: A register of improvement activities linked to service management objectives and measurement results

    A register that links improvement activities to measured performance data demonstrates a systematic, evidence-based approach to continual improvement.

  4. An auditor is reviewing the organization's management review records. Which of the following topics is explicitly required by ISO 20000-1 to be included?

    Answer: Status of actions from previous management reviews

    ISO 20000-1 Clause 9.3 requires management reviews to consider the status of actions from previous reviews as a mandatory input.

  5. An ISO 20000 auditor asks to see evidence that top management has communicated the importance of the SMS to staff. Which of the following is the strongest evidence?

    Answer: Training records showing all staff completed SMS awareness training tied to a leadership-sponsored programme

    Training records linked to a leadership-sponsored awareness program provide objective, documented evidence of top management communication.

  6. What is the auditor's responsibility regarding confidentiality of information obtained during an ISO 20000 audit?

    Answer: Information must be kept confidential and not disclosed without authorization from the auditee

    Auditors are ethically and contractually obligated to protect the confidentiality of all information gathered during the audit unless the auditee authorizes disclosure.

  7. An organization's ISO 20000 scope statement refers to 'IT services provided to internal customers.' During audit, the auditor finds that some services are also provided to external customers under the same processes. What should the auditor do?

    Answer: Note a minor nonconformity because the scope statement is inaccurate and misleading

    An inaccurate or incomplete scope statement is a nonconformity because the scope must accurately reflect the boundaries of the SMS as required by Clause 4.3.