ISO 20000 Certification Auditor 3 — Questions and Answers
Question 1: Which of the following best describes a 'stage 1' audit in ISO 20000 certification?
- An on-site verification that all SMS processes are operating effectively
- A readiness review to assess the organization's documentation and preparedness for stage 2 (Correct answer)
- A follow-up audit to verify closure of previously identified nonconformities
- A surveillance audit conducted six months after initial certification
Correct answer: A readiness review to assess the organization's documentation and preparedness for stage 2
Stage 1 is a desk-based or on-site readiness review that evaluates documentation and confirms the organization is prepared for the full stage 2 audit.
Question 2: An auditor reviews an SLA and finds it lacks a defined review frequency. Under ISO 20000-1, what finding is appropriate?
- Major nonconformity — SLAs without review cycles are invalid
- Minor nonconformity — the standard requires service agreements to include review arrangements (Correct answer)
- Observation — review frequency is a best-practice element
- Conformity — organizations may set review cycles internally without documenting them
Correct answer: Minor nonconformity — the standard requires service agreements to include review arrangements
ISO 20000-1 requires service agreements to include review arrangements, so omitting a review frequency is a minor nonconformity against that specific requirement.
Question 3: What distinguishes a 'major nonconformity' from a 'minor nonconformity' in ISO 20000 auditing?
- A major nonconformity involves financial loss; a minor involves process deviation
- A major nonconformity represents failure of a key SMS element or systematic breakdown; a minor is an isolated lapse (Correct answer)
- A major nonconformity requires re-certification; a minor requires no action
- A major nonconformity is reported to the customer; a minor is kept internal
Correct answer: A major nonconformity represents failure of a key SMS element or systematic breakdown; a minor is an isolated lapse
A major nonconformity signals a systemic failure that threatens the integrity of the SMS, whereas a minor is a contained lapse against a specific requirement.
Question 4: When auditing supplier management under ISO 20000-1, which evidence is most relevant to verify that supplier performance is being managed?
- Supplier contract signature pages
- Supplier performance review records and KPI trend data (Correct answer)
- The organization's approved vendor list
- Supplier invoices and payment records
Correct answer: Supplier performance review records and KPI trend data
Performance review records and KPI trends provide objective evidence that the organization is actively monitoring and managing supplier performance as required.
Question 5: An auditor notices that problem records are being raised but root-cause analysis is never documented. Which ISO 20000-1 requirement is most likely breached?
- Clause 8.7 — Problem management (Correct answer)
- Clause 8.6 — Incident management
- Clause 9.2 — Internal audit
- Clause 6.2 — Service management objectives
Correct answer: Clause 8.7 — Problem management
ISO 20000-1 Clause 8.7 requires root-cause analysis to be conducted and documented as part of problem management.
Question 6: Why must an ISO 20000 auditor understand the organization's service management plan before conducting field interviews?
- To identify which employees to interview first
- To establish the intended objectives and approach against which actual practice will be compared (Correct answer)
- To calculate the audit fee accurately
- To determine which certification body issued the previous certificate
Correct answer: To establish the intended objectives and approach against which actual practice will be compared
The service management plan defines the organization's intended approach; auditors compare actual practice against this plan to identify gaps.
Question 7: An ISO 20000 auditor samples five change records and finds that three were not reviewed by the change advisory board as required by the procedure. What is the most appropriate action?
- Raise a major nonconformity covering all changes made during the period
- Raise a minor nonconformity and request corrective action within the agreed timeframe (Correct answer)
- Document an observation and recommend the CAB be trained
- Accept the evidence as conforming because two records were compliant
Correct answer: Raise a minor nonconformity and request corrective action within the agreed timeframe
Three of five failures indicates a pattern justifying a minor nonconformity, triggering a formal corrective action response from the organization.
Which of the following best describes a 'stage 1' audit in ISO 20000 certification?