← All MSP Flashcard Decks

Mixed Deck — All MSP Topics Flashcards

100 cards from real MSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All MSP Topics flashcards as text
  1. A company uses an electronic document management system (EDMS) with automatic version control. Which additional control is STILL necessary to comply with ISO requirements?

    Answer: Ensuring appropriate access, protection, and legibility of the documented information

    Even with an EDMS, organizations must ensure documented information is accessible, protected from unauthorized changes, and remains legible and identifiable.

  2. Who is responsible for managing risk in an organization?

    Answer: Everyone in the organization

    While top management sets the risk appetite and establishes the risk management framework, and specific departments might have dedicated risk roles, effective risk management is a collective responsibility. Every employee, from the front line to leadership, contributes to identifying, reporting, and managing risks within their scope of work, making it an organization-wide effort.

  3. A company is developing its emergency preparedness and response plans under ISO 45001 Clause 8.2. Which of the following is a key requirement for these plans?

    Answer: The plans should be tested periodically, reviewed after testing or incidents, and communicated to all relevant workers and interested parties.

    Clause 8.2 of ISO 45001 requires an organization to establish, implement, and maintain processes to prepare for and respond to potential emergency situations. This includes identifying potential emergencies, providing training, and periodically testing the planned response. The standard also mandates that the organization review and revise its procedures where necessary, especially after tests or actual incidents, and communicate relevant information to workers, contractors, visitors, and emergency services.

  4. A software development firm is integrating its ISO 9001 (Quality) and ISO/IEC 27001 (Information Security) management systems. A core concept now central to both standards is 'risk-based thinking'. What does this concept primarily require the organization to do within its IMS?

    Answer: Proactively identify and address potential threats and opportunities that could affect objectives.

    Risk-based thinking is a proactive approach integrated throughout the IMS. It requires an organization to systematically identify risks and opportunities related to its objectives, analyze them, and plan actions to address them, thereby preventing or reducing undesired effects and promoting continual improvement.

  5. A manufacturing facility consistently finds that a specific machine tool loses its calibration, resulting in a recurring nonconformity. Each time, the maintenance team recalibrates the tool, which temporarily resolves the issue. According to the principles of continual improvement, what is the most critical next step?

    Answer: Initiate a root cause analysis to determine why the calibration is failing.

    Simply recalibrating the tool is a 'correction'—it fixes the immediate problem. True continual improvement requires a 'corrective action', which involves investigating the root cause (e.g., a worn part, software bug, environmental factor) and implementing a solution to prevent the problem from happening again.

  6. What does inclusive leadership promote?

    Answer: Diverse input and team collaboration

    Inclusive leadership actively seeks out and values contributions from all team members, regardless of background or position. This approach fosters an environment where diverse perspectives are heard and considered, leading to more innovative solutions, better decision-making, and stronger team collaboration as everyone feels valued and engaged.

  7. How does integration affect document control?

    Answer: It simplifies and harmonizes documentation

    Integrating management systems significantly simplifies and harmonizes document control. By identifying common processes and requirements across different standards, organizations can create unified documentation, reducing redundancy and the overall volume of paperwork. This streamlined approach makes documents easier to manage, update, and audit, improving efficiency and consistency throughout the organization.

  8. Which ISO standard clause most directly addresses the requirement for 'documented information' in a management system?

    Answer: Clause 7.5 – Documented information

    Clause 7.5 in the ISO High Level Structure (HLS) covers documented information requirements including creation, updating, and control.

  9. During an ISO 45001 audit, it is discovered that an employee was formally reprimanded after reporting a significant safety hazard. Which specific leadership and commitment requirement has top management most likely failed to establish effectively?

    Answer: A culture that protects workers from reprisals for reporting incidents and hazards.

    ISO 45001, Clause 5, places a strong emphasis on top management's role in developing, leading, and promoting a culture that supports the OH&S management system. This includes protecting workers from reprisals when reporting incidents, hazards, risks, and opportunities. A culture where workers are punished for reporting safety issues is a direct violation of this leadership commitment.

  10. What is the primary role of top management concerning the management system policy and objectives as described in the 'Leadership and Commitment' clause?

    Answer: To ensure they are established and are compatible with the strategic direction of the organization.

    Top management is responsible for ensuring that the policy and objectives are not only created but that they are strategically aligned with the organization's overall goals and its specific context. This ensures the management system supports the business's direction.

  11. How should audit findings be reported?

    Answer: Clearly, with evidence and communication

    Audit findings must be reported clearly and objectively to ensure they are understood by all relevant parties. Including supporting evidence validates the findings and prevents disputes, while effective communication ensures that management and affected departments are fully aware of the issues and their implications. This approach facilitates timely and appropriate corrective actions.

  12. Why is stakeholder engagement critical to success?

    Answer: To foster collaboration and gain support

    Stakeholder engagement is critical because it involves identifying, understanding, and involving all parties who are affected by or can affect an organization's activities. By engaging stakeholders, organizations can foster collaboration, build trust, gain valuable insights, and secure the necessary support and resources for successful project implementation and long-term sustainability.

  13. Which term describes the practice of systematically indexing, storing, and retrieving documented information to support management system performance and audits?

    Answer: Records management

    Records management involves the systematic creation, maintenance, use, and disposal of records as evidence of management system performance.

  14. What tool helps align management system elements with business strategy?

    Answer: Balanced Scorecard

    The Balanced Scorecard is a strategic performance management framework that helps align management system elements with broader business strategy. It translates an organization's vision and strategy into a comprehensive set of performance measures across four perspectives: financial, customer, internal business processes, and learning and growth. This tool ensures that all aspects of the management system contribute to achieving strategic objectives.

  15. During a surveillance audit, an auditor requests evidence of document review and approval for a recently updated environmental procedure. The organization presents an email chain with management approval. This would most likely be considered:

    Answer: Acceptable as evidence of approval if the email clearly identifies the approver and the approved document version

    ISO standards do not prescribe approval formats; an email trail that identifies the approver and document version can constitute acceptable evidence of the approval process.

  16. A chemical processing plant has identified that its air emissions (an environmental aspect) lead to a degradation in local air quality (an environmental impact). To manage this, they have established documented work instructions for operating their emission control equipment. In the context of the ISO 14001:2015 standard, these work instructions are an example of what?

    Answer: Operational control

    Documented work instructions for managing a significant environmental aspect fall under Clause 8.1, 'Operational Planning and Control'. This clause requires organizations to plan, implement, and control the processes needed to meet EMS requirements and to implement the actions identified in Clause 6 (Planning) by establishing operating criteria for the processes.

  17. Under ISO management system standards, which statement is TRUE regarding the level of documented information an organization must maintain?

    Answer: Organizations may determine the extent of documented information based on their size, complexity, and competence of personnel

    ISO standards explicitly allow organizations to tailor the extent of documented information based on their size, process complexity, and personnel competence.

  18. Which practice BEST supports the ongoing effectiveness of a document control system in an integrated management system?

    Answer: Conducting periodic reviews of documented information to ensure it remains current, accurate, and fit for purpose

    Periodic document reviews ensure documented information stays current and relevant as processes, regulations, and organizational needs evolve.

  19. Following a 'near miss' incident where a heavy load was dropped but no one was injured, what is the appropriate response according to ISO 45001 Clause 10.2?

    Answer: Investigate the incident to determine the root cause(s) and implement corrective actions to prevent recurrence.

    ISO 45001 Clause 10.2 covers 'Incident, nonconformity and corrective action'. It explicitly requires organizations to establish a process for reporting, investigating, and taking action on incidents, which are defined to include 'near misses'. The goal is to evaluate the need for corrective action to eliminate the root cause(s) so the incident does not happen again or elsewhere.

  20. A company is in the process of developing an Integrated Management System (IMS). According to the high-level structure (HLS) defined in Annex SL, which of the following clauses is fundamental and common across all modern ISO management system standards, facilitating their integration?

    Answer: Context of the Organization

    The 'Context of the Organization' (Clause 4 in the HLS) is a foundational requirement in all modern ISO management system standards. It requires the organization to determine internal and external issues relevant to its purpose and strategic direction, providing a common starting point for integrating systems like ISO 9001, ISO 14001, and ISO 45001.