ISO AUDITOR Supplier & External Provider Auditing 2 — Questions and Answers
Question 1: Which factor should PRIMARILY determine whether to conduct an on-site supplier audit versus a questionnaire-based evaluation?
- The auditor's available travel budget
- The risk level and criticality of the supplier's output to the organization's products and services (Correct answer)
- The supplier's stated preference for evaluation method
- The number of years the supplier has been in business
Correct answer: The risk level and criticality of the supplier's output to the organization's products and services
Higher-risk and critical suppliers warrant on-site audits, while lower-risk suppliers may be adequately assessed through questionnaires, reflecting ISO 9001's risk-based approach.
Question 2: What does 'outsourcing' mean in the context of ISO 9001:2015 clause 8.4?
- Transferring ownership of a process to an external provider with no further organizational accountability
- Having an external provider perform a function or process that is within the scope of the organization's QMS (Correct answer)
- Purchasing off-the-shelf standard products from external vendors
- Hiring temporary employees through a third-party staffing agency
Correct answer: Having an external provider perform a function or process that is within the scope of the organization's QMS
In ISO 9001:2015, outsourcing means an external provider performs a process that the organization is responsible for, and the organization retains accountability for its conformance.
Question 3: When a nonconformity is identified during a supplier audit, what should the auditor do FIRST?
- Immediately remove the supplier from the approved supplier list
- Document the finding with objective evidence and report it to the supplier (Correct answer)
- Issue a financial penalty to the supplier for the nonconformity
- Stop the audit and return to the organization without further documentation
Correct answer: Document the finding with objective evidence and report it to the supplier
Audit protocol requires findings to be documented with objective evidence and communicated to the auditee; further actions such as disqualification follow based on severity and supplier response.
Question 4: Which metrics are MOST commonly used to monitor ongoing external provider performance?
- Number of employees at the supplier's facility
- Supplier's annual revenue and market share
- On-time delivery rate and defect rate (PPM — parts per million) (Correct answer)
- Number of years the supplier has held ISO 9001 certification
Correct answer: On-time delivery rate and defect rate (PPM — parts per million)
On-time delivery rate and defect rate (PPM) directly reflect supplier reliability and quality, making them the standard KPIs for supplier performance monitoring.
Question 5: What documented information must an organization retain as evidence of external provider evaluations per ISO 9001:2015?
- Only the final approval or rejection decision
- Results of evaluations, monitoring of performance, and re-evaluations of external providers (Correct answer)
- Copies of the external provider's employee training records
- The external provider's own internal audit reports
Correct answer: Results of evaluations, monitoring of performance, and re-evaluations of external providers
ISO 9001:2015 clause 8.4.1 explicitly requires retaining documented information of evaluation results, ongoing monitoring data, and re-evaluation outcomes for external providers.
Question 6: What distinguishes a 'second-party' audit from a 'first-party' audit in the supplier auditing context?
- A second-party audit is conducted by an independent accredited certification body
- A second-party audit is conducted by the customer (or on behalf of the customer) at the supplier's site (Correct answer)
- A second-party audit is an internal audit performed by the supplier's own quality team
- A second-party audit uses only remote desktop assessment techniques
Correct answer: A second-party audit is conducted by the customer (or on behalf of the customer) at the supplier's site
A second-party audit is performed by the customer on their supplier, while a first-party audit is an organization auditing itself internally.
Question 7: Which risk-based approach BEST helps an organization prioritize which suppliers require more stringent controls and audit frequency?
- Alphabetical ordering of suppliers by company name
- A supplier risk matrix based on output criticality and supplier performance history (Correct answer)
- Random selection of suppliers for enhanced monitoring each quarter
- Prioritizing suppliers who offer the lowest unit prices
Correct answer: A supplier risk matrix based on output criticality and supplier performance history
A risk matrix combining criticality of supplier outputs and historical performance data enables a risk-based allocation of audit and monitoring resources as required by ISO 9001:2015.
Which factor should PRIMARILY determine whether to conduct an on-site supplier audit versus a questionnaire-based evaluation?