ISO 20000 Certification Auditor 2 — Questions and Answers
Question 1: During an ISO 20000-1 audit, an auditor discovers that the organization's service catalog is maintained but has not been reviewed in 18 months. What is the most appropriate audit finding?
- Conformity — catalogs do not require scheduled reviews
- Minor nonconformity — the organization has not fulfilled a specific requirement (Correct answer)
- Major nonconformity — the entire SMS is invalid without a current catalog
- Observation — this is a best-practice gap, not a requirement
Correct answer: Minor nonconformity — the organization has not fulfilled a specific requirement
ISO 20000-1 requires the service catalog to be maintained and kept up to date, so failure to review it within a reasonable period constitutes a minor nonconformity.
Question 2: Which audit technique is most effective for verifying that change management records are complete and accurate in an ISO 20000 context?
- Interviewing the change manager
- Observing a change advisory board meeting
- Sampling and reviewing actual change records against defined criteria (Correct answer)
- Reviewing the change management policy document
Correct answer: Sampling and reviewing actual change records against defined criteria
Record sampling provides objective evidence that change records meet defined content and approval criteria, satisfying the auditor's need for factual evidence.
Question 3: An ISO 20000 auditor finds that the organization's continual improvement register lists twelve items but none have been implemented in the past year. What should the auditor conclude?
- Conformity, because maintaining a register is all that is required
- Minor nonconformity, because the standard requires improvements to be actioned, not just recorded (Correct answer)
- Major nonconformity, because all twelve items must be completed annually
- Observation only, because timelines are at organizational discretion
Correct answer: Minor nonconformity, because the standard requires improvements to be actioned, not just recorded
ISO 20000-1 requires the organization to implement and evaluate improvement activities, not merely document them, making inaction a minor nonconformity.
Question 4: What is the primary purpose of an audit trail in ISO 20000 internal audits?
- To document auditor qualifications
- To provide a record linking audit evidence to findings and conclusions (Correct answer)
- To track financial costs of the SMS
- To list all services in scope
Correct answer: To provide a record linking audit evidence to findings and conclusions
An audit trail ensures that each finding can be traced back to the specific evidence on which it is based, supporting transparency and reproducibility.
Question 5: When an ISO 20000 auditor identifies a potential conflict of interest, what is the required course of action?
- Proceed but note the conflict in the audit report
- Disclose the conflict and withdraw from auditing that area (Correct answer)
- Obtain written permission from the auditee to continue
- Assign the finding a lower severity to compensate
Correct answer: Disclose the conflict and withdraw from auditing that area
Auditor independence is a foundational principle; disclosing and recusing oneself from the conflicted area preserves audit integrity.
Question 6: An ISO 20000 surveillance audit reveals that an organization has changed its incident classification scheme without updating the incident management procedure. Which clause is most directly relevant?
- Clause 6.1 — Actions to address risks and opportunities
- Clause 8.6 — Incident management
- Clause 7.5 — Documented information (Correct answer)
- Clause 9.1 — Monitoring, measurement, analysis and evaluation
Correct answer: Clause 7.5 — Documented information
Documented information (Clause 7.5) must be controlled and kept up to date; a procedure that no longer reflects the actual process is a documented-information nonconformity.
Question 7: During an audit opening meeting, the lead auditor should do which of the following?
- Present preliminary findings and corrective actions
- Confirm the audit scope, objectives, and methodology with the auditee (Correct answer)
- Conduct the first set of interviews immediately
- Review the organization's previous certification audit report
Correct answer: Confirm the audit scope, objectives, and methodology with the auditee
The opening meeting establishes shared understanding of scope, objectives, criteria, and approach before evidence collection begins.
During an ISO 20000-1 audit, an auditor discovers that the organization's service catalog is maintained but has not been reviewed in 18 months.
What is the most appropriate audit finding?