← All ISO AUDITOR Flashcard Decks

Supplier & External Provider Auditing Flashcards

7 cards from real ISO AUDITOR practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Supplier & External Provider Auditing flashcards as text
  1. Which factor should PRIMARILY determine whether to conduct an on-site supplier audit versus a questionnaire-based evaluation?

    Answer: The risk level and criticality of the supplier's output to the organization's products and services

    Higher-risk and critical suppliers warrant on-site audits, while lower-risk suppliers may be adequately assessed through questionnaires, reflecting ISO 9001's risk-based approach.

  2. What does 'outsourcing' mean in the context of ISO 9001:2015 clause 8.4?

    Answer: Having an external provider perform a function or process that is within the scope of the organization's QMS

    In ISO 9001:2015, outsourcing means an external provider performs a process that the organization is responsible for, and the organization retains accountability for its conformance.

  3. When a nonconformity is identified during a supplier audit, what should the auditor do FIRST?

    Answer: Document the finding with objective evidence and report it to the supplier

    Audit protocol requires findings to be documented with objective evidence and communicated to the auditee; further actions such as disqualification follow based on severity and supplier response.

  4. Which metrics are MOST commonly used to monitor ongoing external provider performance?

    Answer: On-time delivery rate and defect rate (PPM — parts per million)

    On-time delivery rate and defect rate (PPM) directly reflect supplier reliability and quality, making them the standard KPIs for supplier performance monitoring.

  5. What documented information must an organization retain as evidence of external provider evaluations per ISO 9001:2015?

    Answer: Results of evaluations, monitoring of performance, and re-evaluations of external providers

    ISO 9001:2015 clause 8.4.1 explicitly requires retaining documented information of evaluation results, ongoing monitoring data, and re-evaluation outcomes for external providers.

  6. What distinguishes a 'second-party' audit from a 'first-party' audit in the supplier auditing context?

    Answer: A second-party audit is conducted by the customer (or on behalf of the customer) at the supplier's site

    A second-party audit is performed by the customer on their supplier, while a first-party audit is an organization auditing itself internally.

  7. Which risk-based approach BEST helps an organization prioritize which suppliers require more stringent controls and audit frequency?

    Answer: A supplier risk matrix based on output criticality and supplier performance history

    A risk matrix combining criticality of supplier outputs and historical performance data enables a risk-based allocation of audit and monitoring resources as required by ISO 9001:2015.