ISO 20000 Certification Auditor 5 — Questions and Answers
Question 1: An ISO 20000 auditor reviews corrective action records and finds that root causes were identified but the effectiveness of corrective actions was never verified. Which requirement is not being met?
- Clause 7.4 — Communication
- Clause 10.1 — Nonconformity and corrective action (Correct answer)
- Clause 8.7 — Problem management
- Clause 9.3 — Management review
Correct answer: Clause 10.1 — Nonconformity and corrective action
Clause 10.1 requires the organization to review the effectiveness of corrective actions taken, not merely implement them.
Question 2: Which of the following is a valid reason for an ISO 20000 certification body to suspend an organization's certificate?
- The organization changes its service management software
- Surveillance audits reveal persistent major nonconformities that are not addressed (Correct answer)
- The organization adds new services to its scope
- An auditor is unable to attend the scheduled surveillance visit
Correct answer: Surveillance audits reveal persistent major nonconformities that are not addressed
Persistent unresolved major nonconformities demonstrate that the SMS is no longer maintaining conformity, justifying suspension of the certificate.
Question 3: When auditing continual improvement under ISO 20000-1, which evidence demonstrates that the organization is systematically identifying improvement opportunities?
- A list of complaints received from customers over the past year
- A register of improvement activities linked to service management objectives and measurement results (Correct answer)
- Meeting minutes from the IT steering committee
- The organization's five-year IT roadmap
Correct answer: A register of improvement activities linked to service management objectives and measurement results
A register that links improvement activities to measured performance data demonstrates a systematic, evidence-based approach to continual improvement.
Question 4: An auditor is reviewing the organization's management review records. Which of the following topics is explicitly required by ISO 20000-1 to be included?
- Individual staff performance ratings
- Status of actions from previous management reviews (Correct answer)
- Annual IT capital expenditure plans
- Customer payment histories
Correct answer: Status of actions from previous management reviews
ISO 20000-1 Clause 9.3 requires management reviews to consider the status of actions from previous reviews as a mandatory input.
Question 5: An ISO 20000 auditor asks to see evidence that top management has communicated the importance of the SMS to staff. Which of the following is the strongest evidence?
- A memo from the CEO stating the organization is pursuing ISO 20000 certification
- Training records showing all staff completed SMS awareness training tied to a leadership-sponsored programme (Correct answer)
- The organization's website mentioning the certification goal
- A verbal assurance from the IT director that communication occurred
Correct answer: Training records showing all staff completed SMS awareness training tied to a leadership-sponsored programme
Training records linked to a leadership-sponsored awareness program provide objective, documented evidence of top management communication.
Question 6: What is the auditor's responsibility regarding confidentiality of information obtained during an ISO 20000 audit?
- Audit information may be shared freely between certification bodies
- Information must be kept confidential and not disclosed without authorization from the auditee (Correct answer)
- Audit findings are public record once the certificate is issued
- Confidentiality applies only to financial data, not process information
Correct answer: Information must be kept confidential and not disclosed without authorization from the auditee
Auditors are ethically and contractually obligated to protect the confidentiality of all information gathered during the audit unless the auditee authorizes disclosure.
Question 7: An organization's ISO 20000 scope statement refers to 'IT services provided to internal customers.' During audit, the auditor finds that some services are also provided to external customers under the same processes. What should the auditor do?
- Ignore external services since they are outside the declared scope
- Note a minor nonconformity because the scope statement is inaccurate and misleading (Correct answer)
- Immediately recommend scope expansion to include external customers
- Treat the external services as a separate, unrelated matter
Correct answer: Note a minor nonconformity because the scope statement is inaccurate and misleading
An inaccurate or incomplete scope statement is a nonconformity because the scope must accurately reflect the boundaries of the SMS as required by Clause 4.3.
An ISO 20000 auditor reviews corrective action records and finds that root causes were identified but the effectiveness of corrective actions was never verified.
Which requirement is not being met?