Noitol is an organisation specialising in the design and production of e-learning training materials for the insurance market. During an ISO 9001 audit of the development department, the auditor asks the Head of Development about the process used for validation of the final course design. She states that they usually ask customers to validate the product with volunteers. She says that the feedback received often leads to key improvements.
The auditor samples the design records for a recently completed course for the 247 Insurance organisation. Design verification was carried out but there was no validation report. The Head of Development advises that this customer required the product on an urgent basis, so the validation stage was omitted. When asked, the Head estimates that this occurs about 50% of the time. She confirms that they always ask for feedback and often make changes. There is no record of feedback in the design file for the course.
The auditor decides to review the training course design process in more depth.
Select three options that provide a meaningful audit trail for this process.
An audit team leader arrives at a printing company to carry out a Stage 2 audit for a certification body. At a meeting with the Quality Manager, she is told that they have won their biggest contract from a computer manufacturer to print and compile computer documentation packages. The Quality Manager wants the ISO 9001 certificate to cover the new contract.
During the audit, a team member found that some print jobs had been rejected by several clients over some months due to spelling errors in the print run. The Print Manager blames the new employees they had to take on because of a big contract.
The auditor finds that the responsibility for checking spelling errors is placed on the printer that sets up the print run.
In line with the policy of the certification body, the audit team raise improvement opportunities in the audit report. Which
three of the following options would represent acceptable opportunities for improvement in the report?
Knowledge and skills are requirements of the auditor's competence. Select two from the following topics of knowledge that apply to every member of an audit team auditing an ISO 9001 quality management system.
During an ISO 9001 audit of an electric cable manufacturer, you are reviewing the customer file for XYZ Construction in the Sales Department. This contract specifies that the installation configuration of the cable runs should meet national fire safety standards for Category A.
You discover that the customer later agreed to the approval of a less stringent Category B configuration instead.
The organization has the following quality policy document displayed in the reception area.
"This organization is committed to providing electric cables to customers' requirements, in accordance with statutory regulations for their use. Continual improvement is a permanent objective of the organization. This policy shall be communicated to all employees and, where required, to all interested parties."
Referring to the scenario, select the two options for which the organization is meeting its policy commitments.
Whistlekleen is a national dry cleaning and laundry company with 50 shops. You are conducting a surveillance audit of the Head Office and are sampling customer complaints. 80% of complaints originate from five shops in the same region. Most of these complaints relate to customer laundry not being cleaned as customers require. The Quality Manager tells you that these are the oldest shops in the company. The cleaning equipment needs replacing but the company cannot afford it now. You learn that the shop managers were told to dismiss most of the complaints because of the poor quality of the laundered materials.
On raising the matter with senior management, you are told that there are plans to replace the equipment in these shops over the next five years.
You raised a nonconformity against clause 8.5.1 of ISO 9001.
Based on the scenario, select the three options which best describe the evidence for raising such a nonconformity.
You are carrying out an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The organization manufactures cosmetics for major retailers and the name of the retailer supplied appears on the product packaging. Sales turnover has increased significantly over the past five years.
You are interviewing the new Product Development Manager. You note that a software application called SWIFT is used to help control the product development process.
You have gathered audit evidence as outlined in the table. Match the ISO 9001 clause 8.3 extracts to the audit evidence.

Which type of audit risk is the risk that a significant defect may occur in the QMS, although the organization has internal control mechanisms in place?
Scenario 4:
TD Advertising is a print management company based in Chicago. The company offers design services, digital printing, storage, and distribution. As TD expanded, its management recognized that success depended on adopting new technologies and improving quality.
To ensure customer satisfaction and quality improvement, the company decided to pursue ISO 9001 certification.
After implementing the QMS, TD hired a well-known certification body for an audit. Anne Key was appointed as the audit team leader. She received a document listing the audit team members, audit scope, criteria, duration, and audit engagement limits.
Anne reviewed the document and approved the audit mandate. The certification body and TD’s top management signed the certification agreement.
Before contacting TD, Anne reviewed the audit scope and noticed that TD made changes to it due to the adoption of new printing equipment. However, Anne disagreed with the changes, stating they would affect the audit timeline. She considered withdrawing from the audit.
The audit team members were selected based on their knowledge of the legal and other regulations that TD is subject to. Is this acceptable?
You are conducting a third-party audit to ISO 9001 and interviewing the Training Manager. She explains that training is more
important than ever because the organisation has had to reduce the number of staff employed. Many of the remaining staff
are now required to be 'multi-skilled'. You ask to see plans for the multi-skilling training and are shown plans that look
comprehensive, and include both 'on the job" training and internal and external training courses.
The records indicate that several staff required parts of their training to be repeated one month after the first training was
provided. You ask why this was needed and are told that an investigation of customer complaints identified that several staff
members did not complete certain tasks in the correct manner. The extra training was therefore recommended as a
corrective action.
Based on this interview, which two of the tollowing audit trails would be the most appropriate to follow?
Select the two most appropriate audit trails from the following.
"A set of interrelated or interlacing elements of an organization to establish policies and objectives, and processes to achieve those objectives" is the definition of a/an:
Scenario 7: POLKA is a car manufacturing company based in Stockholm, Sweden. The company has around 14,000 employees working in different sectors which help with the design, painting, assembling, and test drives of the final product. The company is widely known for its qualitative products and affordable prices. In order to retain their reputation, POLKA implemented a quality management system (QMS) based on ISO 9001.
Before applying for certification, the company decided to conduct an internal audit to check whether there are any nonconformities in their QMS and if the requirements of ISO 9001 are being fulfilled. The top management appointed Sean, the internal auditor, as the team leader of the internal audit team. Sean required from the top management to have unrestricted access to the employees and executives of POLKA and to the documented information. Furthermore, Sean required to establish a team with a large number of auditors, considering the size and the complexity of the organization. The top management of POLKA agreed with Sean's requirements.
The top management, in cooperation with Sean, assigned 10 more employees to the audit team. Following that. Sean planned the audit activities and assigned the roles and responsibilities to each auditor. They began by interviewing employees of different manufacturing departments to check whether they are aware of the process of the QMS implementation. While conducting these activities, one of the auditors asked Sean for permission to audit the department in which he worked on a daily basis, as he was very familiar with the processes of the department.
Along the way, the teams findings showed that the staff were trained, documented information was updated, and the QMS fulfilled the requirements of ISO 9001. The internal audit took three weeks to complete, and on the last week the audit team held a final meeting
The team shared their results and together drafted the audit report This report was submitted to the top management of the company. The report was maintained as documented information, and was available to the relevant interested parties.
Based on the scenario above, answer the following question:
Ten employees of POLKA were part of the audit team that conducted the internal audit. Is this acceptable?
Which of the following is a record related to the audit program that should be managed and maintained?
You are carrying out an annual surveillance audit at an organisation that has been certificated to ISO 9001 for two years. The organisation offers home cleaning services. The scope of the quality management system covers planning the weekly activities, providing cleaning materials, cleaning the whole property (including outdoor space) alarm installation, alarm servicing, alarm monitoring and response. The business operates from a single office and employs subcontract cleaners across the whole city.
You have just completed the opening meeting. You are interviewing the Managing Director (MD).
You: I would like to gain an understanding of how the quality management system has been supporting your business and its strategic direction.
MD: We are continuing to face difficult times. The market is extremely competitive, and customers typically look for the least expensive option when choosing home cleaning services. We have not yet seen any business benefit from our quality management system.
You: Tell me how you determine external and internal issues.
MD: We use PESTLE analysis (Political, economic, social, technological, legal, environmental).
You: Why did you not use the SWOT model (Strengths, Weaknesses, Opportunities, Threats)?
MD: I had used PESTLE in my previous job.
You: How have the outputs from your PESTLE been used?
Select two audit trails which would lead to a determination of how the PESTLE analysis would affect the planning of a QMS to ISO 9001.
You are a member of the audit team of a second-party audit of an organisation with 625 employees. The audit procedure recommends using sampling criteria which requires the review of the documented competence for 25 personnel. The audit team leader developed an audit plan allocating one hour to audit the Human Resources department (from 11:30 am to 12:30 pm). She told you that she could not allocate any additional time.
What would you do?
You are carrying out an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The organisation manufactures cosmetics for major retailers.
You are interviewing the Manufacturing Manager (MM).
You: "I would like to begin by looking at the cleaning controls."
MM: "We record the cleaning of the equipment at the end of every batch. This document details the minimum cleaning frequency and the procedures to follow for all areas and each item of equipment. The person who carries out the cleaning puts their initial on the document and records the time and date alongside."
Narrative: You sample production records over 3-days and note down evidence of nonconformity as per the table below.

You decide to raise a non-conformity.

You are carrying out an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The organization manufactures cosmetics for major retailers.
You are interviewing the Manufacturing Manager (MM).
You: "I would like to begin by looking at the cleaning controls."
MM: "We record the cleaning of the equipment at the end of every batch. This document details the minimum cleaning frequency and the procedures to follow for all areas and each item of equipment. The person who carries out the cleaning puts their initial on the document and records the time and date alongside."
Narrative: You sample production records over 3-days and note down evidence of nonconformity as per the table below.


What does the application of the process approach in a QMS enable?
You are conducting an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The organisation manufactures cosmetics for major retailers and the name of the retailer supplied appears on the product packaging. Sales turnover has increased significantly over the past five years
You are interviewing the new Product Development Manager. You note that a software application called SWIFT is used to help control the product development process.
You have gathered audit evidence as outlined in the table. Match the ISO 9001 clause 8.3 extracts to the audit evidence.

(As the audit team leader, you are planning an audit at an organisation that is seeking certification to ISO 9001. You have confirmed and agreed on the audit scope and audit date with the auditee. The audit team comprises of you and one other auditor. The auditee has two sites and one of these sites is the Head Office where the top management team are based.
The other site is referred to as Site 1, which is located in another country. Apart from that, each site is essentially similar in terms of customer service provision. The other auditor has been selected to audit Site 1 as she lives nearby.
Select four issues you need to finalise before documenting the audit plan.)
ABC is a worldwide fast-food organisation. One of the branches, in downtown Cape Town, decided to
implement an ISO 9001 quality management system and you are the audit team leader (with two other
auditors) that will carry out the certification audits, Stage 2.
ABC receive the orders by phone or internet; some of the employees deliver the ordered food to indicated
addresses. The normal menu includes 15 different types of hamburgers; however, in the last two weeks,
due to a shortage of a special type of meat, they can only prepare six of the 15 varieties.
During the internal meeting of the audit team, you ask one of the auditors to describe what she has
observed. She audited the reception of orders from customers (via phone or internet) and the
communication of the orders to the kitchen. She noticed that the menu offering food on the website is still
the normal one, with 15 different hamburgers, and during a 30-minute period, she observed many
customers reluctantly accepting something other than the hamburger they preferred.
You, as audit team leader, inform the Quality Manager of your concern about the major nonconformity,
since you consider this a serious breach of the basic principles of quality that lasted two weeks without
action being taken.
Right at the beginning of the Closing meeting, you discuss the nonconformity with the General Manager.
She got quite upset and said she was going to make a complaint to the certification body and left the
room; the Quality Manager was the only member of ABC left with the audit team. The Quality Manager said the General Manager would not come back to the meeting.
What would you do? Choose the best from the following options:
You work as an external quality consultant for an organisation, “ABC”, which provides packaged food to the public. You are asked to lead a team (you as the leader and two other auditors) to audit an external provider, “XYZ”, which provides packaging materials to “ABC”. It is 4 pm, and the closing meeting was scheduled for 5 pm.
You, as the audit team leader, audited Top Management. You explain to the audit team that you identified two non-conformities:
a. There is no documented information on the results of Top Management Reviews, as required in clause 9.3 of ISO 9001:2015.
b. There is no evidence of Top Management commitment as required in clause 5.1 of ISO 9001:2015 (e.g., not ensuring the availability of resources to operate the QMS, not ensuring the establishment of objectives).
All agreed to present these two non-conformities, graded as major.
As the audit team leader, select the best option on how to handle the closing meeting.
(From the following, select six tasks you would expect to be completed during the audit team meeting of a second-party audit in preparation for the closing meeting of a four-day audit being performed by organisation ABC to an external provider.)
During a second-party audit, the auditor examines the records that are available for the external provider, ABC Forgings, to whom manufacturing has recently been outsourced.
There are standard external provider checklists for three competitors for the contract and there are inspection records from the trial manufacturing batches produced by ABC Forgings. There is no documented evidence of the criteria used to confirm the appointment of ABC Forgings, and no contract or terms and conditions. Ongoing monitoring indicates that external provider performance is satisfactory, but no documented information has been retained.
Select two options for the evidence which demonstrates a nonconformity with clause 8.4 of ISO 9001.
In the context of a third-party certification audit, match the roles with the following responsibilities:

The following actions need to be carried out during a third-party audit planning stage. Which two actions correspond to the individual(s) managing the audit program before the involvement of the audit team leader’
In the context of a third-party certification audit, it is very important to have effective communication. Which is not the responsibility of the audit team leader?
You are carrying out an audit at a single-site organisation seeking certification to ISO 9001 for the first time. The
organisation manufactures cosmetics for major retailers and the name of the retailer supplied appears on the product
packaging. Sales turnover has increased significantly over the past five years. The organisation uses a software programme called SWIFT, which is used to record sales, plan production, purchase supplies, print despatch notes, track new product development, perform traceability exercises, carry out mass balance checks, raise invoices, create budgets, and support financial control.
You are nearing the end of the audit and you are reviewing your audit notes. You notice a recurring trend concerning the SWIFT database as shown below:

You ask the Quality Manager to explain how the SWIFT database is controlled. You learn that the Operations Director is
responsible for determining and progressing SWIFT software updates. You decide to meet the Operations Director (OD).
You: "Good afternoon."
OD: "Good afternoon."
You: "What responsibility do you have concerning the SWIFT database?"
OD: "I maintain it. If anyone wishes to propose an update to the database, they send me an email with
details of their proposal. I then either process the database update myself, or I send the request to the
consultant who designed the database 20 years ago. The necessary software changes are made, and the
amended software is immediately released to users."
You: "Would you explain how the software amendments are controlled?"
OD: "Of course. I personally update every computer myself."
You: "Do you inform the database users of the changes?"
OD: "No I don't. They find out for themselves by using the software, or they come to see me if they have
any questions."
You: "How do you ensure that the database users use the latest version?"
OD: "That's easy, I update every computer myself."
You: "During the audit, I noted there were several versions of SWIFT in use (you refer to your audit
notes)."
OD: "I know. That's because some versions work better than others, and depending on user needs and
experiences, we allow users to revert to using an earlier version if they find it works better for them."
Based on the scenario, which two of the following statements are true? There is evidence of
nonconformity with a requirement defined in ...
What are the objectives of the Stage 2 audit?
For each of the following scenarios, select four that are corrective actions.
Scenario 7: POLKA is a car manufacturing company based in Stockholm, Sweden. The company has around 14,000 employees working in different sectors which help with the design, painting, assembling, and test drives of the final product. The company is widely known for its qualitative products and affordable prices. In order to retain their reputation, POLKA implemented a quality management system (QMS) based on ISO 9001.
Before applying for certification, the company decided to conduct an internal audit to check whether there are any nonconformities in their QMS and if the requirements of ISO 9001 are being fulfilled. The top management appointed Sean, the internal auditor, as the team leader of the internal audit team. Sean required from the top management to have unrestricted access to the employees and executives of POLKA and to the documented information. Furthermore, Sean required to establish a team with a large number of auditors, considering the size and the complexity of the organization. The top management of POLKA agreed with Sean's requirements.
The top management, in cooperation with Sean, assigned 10 more employees to the audit team. Following that. Sean planned the audit activities and assigned the roles and responsibilities to each auditor. They began by interviewing employees of different manufacturing departments to check whether they are aware of the process of the QMS implementation. While conducting these activities, one of the auditors asked Sean for permission to audit the department in which he worked on a daily basis, as he was very familiar with the processes of the department.
Along the way, the teams findings showed that the staff were trained, documented information was updated, and the QMS fulfilled the requirements of ISO 9001. The internal audit took three weeks to complete, and on the last week the audit team held a final meeting
The team shared their results and together drafted the audit report This report was submitted to the top management of the company. The report was maintained as documented information, and was available to the relevant interested parties.
Based on the scenario above, answer the following question:
According to Scenario 7, one of the auditors requested permission from Sean to audit the department in which he worked on a daily basis. Should Sean grant the auditor permission?
An audit team of three people is conducting a Stage 2 audit to ISO 9001 of an engineering organisation that manufactures sacrificial anodes for the oil and gas industry in marine environments. These are aluminium products designed to prevent corrosion of submerged steel structures. You, as one of the auditors, find that the organisation has shipped anodes for Project DK in the Gulf of Mexico before the galvanic efficiency test results for the anodes have been fully analysed and reported as required by the customer. The Quality Manager explains that the Managing Director authorised the release of the anodes to avoid late delivery as penalties would be Imposed. The customer was not informed since the tests very rarely fall below the required efficiency. You raise a nonconformity against clause 8.6 of ISO 9001.
At the Closing meeting, the audit team leader presents the findings of the audit and comes to the above
nonconformity. The Quality Manager produces the test report for Project DK, which shows an acceptable galvanic efficiency, and presents an email from the customer confirming acceptance of the anodes. He asks that the nonconformity be withdrawn.
Which two of the following responses by the audit team leader would be acceptable?
ISO 9001 requires that the organisation shall continually improve the quality management system.
Select the two options for how this can best be achieved.
Which one of the following documents addresses audit time calculation for third-party certification audits?
At the end of a second-party audit, the audit team enters the meeting room to hold the closing meeting; only
two people are present and waiting for them: the Health and Safety supervisor and the Administrative Officer.
Neither has participated in the audit. However, the team had previously agreed with the auditee Quality
Manager on two nonconformities identified during the audit (NC1 and NC2).
They said:
Health and Safety Supervisor: "Good evening. We are sorry to inform you that the general manager was
involved in a serious car accident, and the other two managers have had to leave urgently to attend to the
emergency."
The Administration Officer: "Concerning 'nonconformity 2', the General Manager left a message asking us
to tell you that he does not accept it and requests you not to include it in the audit report. Here is a note in
which he explains why."
Which one of the following would be your preferred answer (as team leader) to the General
Manager's request?
Match the following potential audit client options to the type of audit.

Which statement regarding the drafting of the audit conclusions is correct?
The procedures of an organisation require that all purchase orders have to be signed by the Purchasing Manager, or, in her absence, by the Production Manager. During an audit carried out in November 2020, an auditor determined that during three weeks in February 2020, the purchase orders were not signed. You raise a nonconformance under Clause 8.4.3 of ISO 9001:2015.
Which one of the following answers would you accept as a 'correction' from the Purchasing Manager?
What is a list of actions that should be performed during the audit with their respective timeline?
Which of the following is correct with regard to the internal audit?
You are conducting a third-party audit to ISO 9001 and the next item on your audit plan is 'internal auditing'.
When reviewing a sample of audit records up to 5 years previously, you find that many contain non-conformance reports and no actions have been taken. You interview the Quality Manager.
You: "I have noted that many of the older files contain non-conformances that have not had any corrective action taken."
Quality Manager: "Because the business is always changing, the departmental managers tell me that the non-conformances are no longer applicable. I made a decision that any non-conformance over 3 years old is automatically closed"
You: "Do you obtain any confirmation beforehand from the appropriate departments that the non-conformances are no longer applicable."
Quality Manager: " No, because they are so old I consider that they are no longer appropriate. Please remember that we take a risk-based approach which means we audit where and when it is considered important to do so.
Select one course of action you would now take from the options.
According to ISO 9000, what is quality?
Which two of the following should be included in an audit plan?
ISO 9001 is based on quality management principles. Match each of the following quality management principles to the related activity.

Noitol is an organisation specialising in the design and production of e-learning training materials for the insurance market. During an ISO 9001 audit
of the development department, the auditor asks the Head of Development about the process used for validation of the final course design. She states that they usually ask customers to validate the product with volunteers. She says that the feedback received often leads to key improvements.
The auditor samples the design records for a recently completed course for the 247 Insurance organisation. Design verification was carried out but there was no validation report. The Head of Development advises that this customer required the product on an urgent basis, so the validation stage
was omitted. When asked, the Head estimates that this occurs about 50% of the time. She confirms that they always ask for feedback and often make changes. There is no record of feedback in the design file for the course.
The auditor raises a nonconformity against ISO 9001. Which one of the following options is the basis for the nonconformity?
You, as auditor, are in dialogue with the quality lead and managing director of a small business that supplies specialist
laboratory equipment and furniture.
You: "I'd like to look at how you manage change in the organisation. What changes have you made as a business, say,
over the last 12 months?"
Auditee: "We have made some strategic changes, the main one being that we no longer manufacture our own products
in house."
You: "That sounds like quite a significant change. What has been the impact of that?"
Auditee: "We now mainly sell other manufacturers' products, under their brand names, and have outsourced
manufacture of our own brand products to one of our suppliers. Unfortunately, we had to make six members of our staff
redundant. This represents about 20% of our workforce, so this has been quite a challenging time."
This scenario presents a number of audit trails to different ISO 9001 requirements.
Which three of the following requirements would be relevant audit trails for this scenario?
Scenario 3:
Fin-Pro is a financial institution in Austria offering commercial banking, wealth management, and investment services. The company faced a significant loss of customers due to failing to improve service quality as they expanded.
To regain customer confidence, top management implemented a QMS based on ISO 9001. After a year, they contacted ACB, a local certification body, to pursue ISO 9001 certification.
The audit team was led by Emilia, an experienced lead auditor, and included three auditors. After an agreement was reached, ACB sent the audit objectives to the audit team.
The audit team began by gathering information about Fin-Pro’s understanding of ISO 9001 requirements. While reviewing documented information, they noticed missing records of training and awareness sessions. They conducted employee interviews to verify attendance.
The team also reviewed the organizational chart and job descriptions to confirm employee competence. They observed the company’s working environment (social, psychological, and physical conditions).
The audit team analyzed the evidence and prepared an audit report with findings and conclusions.
ACB sent the audit objectives to the audit team after an agreement was reached. Is this acceptable?
Scenario 6: Davis Clinic (DC) is an American medical center focused on integrated health care. Since its establishment DC was committed to providing qualitative services for its clients, which is the reason why the company decided to implement a quality management system (QMS) based on ISO 9001. After a year of having an active QMS in place, DC applied for a certification audit.
A team of five auditors, from a well-known certification body, was selected to conduct the audit. Eva was appointed as the audit team leader. After three days of auditing, the team gathered to review and examine their findings. They also discussed the audit findings with DC's top management and then drafted the audit conclusions.
In the closing meeting, which was held between the audit team and the top management of DC. Eva presented two nonconformities that were detected during the audit. Eva stated that the company did not retain documented information regarding its outsourced services for an analysis laboratory and regarding the conducted management reviews. During the closing meeting, the audit team required from DCs top management to come up with corrective action plans within two weeks. Although the top management did not agree with the audit findings, the audit team insisted that the auditee must submit corrective actions within the given time frame in order for the audit activities to continue.
Once the action plans were evaluated, the audit team began preparing the audit report. Eva required from the team to provide accurate descriptions of the audit findings and the audit conclusions. The report was then distributed to all the interested parties involved in the audit, including the certification body Based on the report, the certification body together with Eva, as the audit team leader, made the certification decision.
Based on the scenario above, answer the following question:
Why is it important to discuss the audit findings with DC’s top management prior to the closing meeting and the submission of the final audit report?
You, as auditor, are in dialogue with the quality lead and managing director of a small business that supplies specialist laboratory equipment and furniture.
You: "I'd like to look at how you manage change in the organisation. What changes have you made as a
business, say, over the last 12 months?"
Auditee: "We have made some strategic changes, the main one being that we no longer manufacture our
own products in house."
You: "That sounds like quite a significant change. What has been the impact of that?"
Auditee: "We now mainly sell other manufacturers' products, under their brand names, and have outsourced
manufacture of our own brand products to one of our suppliers. Unfortunately, we had to make six members
of our staff redundant. This represents about 20% of our workforce, so this has been quite a challenging
time."
You: "I'm sure. What were the reasons for making the change?"
Auditee: "Our manufacturing section was a small operation, and we struggled to cope with fluctuations in
demand. During busy periods, we found it hard to meet lead times, and in quiet periods we had staff with
little to do. This was having an impact on customer satisfaction and meant we had to charge premium prices
that made our product uncompetitive."
You: "How did you go about the change?"
The auditor asks to speak to the purchasing manager about the selection of the subcontractor to
manufacture the company's own brand products.
You: "How did you choose a supplier to manufacture your products?"
Auditee: "We have had a long-term relationship with a supplier ABC Ltd - we gave them our design
drawings, got them to complete a supplier questionnaire and run a couple of trial batches for us. We were
happy with the result and we have used them ever since."
ISO 9001:2015, clause 8.4.1 outlines situations when controls need to be applied to externally provided processes, products and services. Which one of the following situations is applicable to this scenario?
An audit team leader arrives at a printing organisation to carry out a Stage 2 audit for a certification body. At a meeting with the Quality Manager, she is told that they have won their biggest contract from a computer manufacturer to print and compile computer documentation packages. They have leased the unit next door for space reasons but have never worked in this sector before. The Quality Manager wants the ISO 9001 certificate to cover the new contract.
During the audit, a team member finds that a number of print jobs have been rejected by several clients over a number of months due to spelling errors in the print run. The Print Manager blames the new employees they had to take on because of a big contract. The auditor raises a nonconformance against clause 10.2.1.b of ISO 9001.
Which one of the evidence statements would support this finding?
During a third-party surveillance audit, the auditor finds that the management review meeting minutes record that the improvement actions set by the previous review have not been completed for a second year running. It states that a new Quality Manager has been brought in at the middle management level to rectify the situation. You learn that top management is not involved in the QMS other than being copied into the minutes of the management review meeting.
The audit reveals that the new Quality Manager was given responsibility by top management to:
a) take accountability for the effectiveness of the QMS,
b) select, approve, and monitor improvement actions without involving and reporting to top management,
c) promote the improvement of the QMS, and
d) make efficient use of the limited financial and personnel resources allocated for the QMS by top management.
The auditor considers whether there is a nonconformity against clause 5.1.1 of ISO 9001:2015.
Select two options of the evidence required for such a nonconformity:
An organization has decided to implement a QMS based on ISO 9001. What should they consider when determining internal issues?
You are conducting a third-party Stage 1 audit at ABC Ltd, a single-site organisation that manufactures wooden furniture. You interview the Technical Director to learn more about the organisation. The Technical Director explains that they have had a successful year and that obtaining ISO 9001 certification will support the further growth of the business. You ask for an overview of the organisation's structure and its interrelationships with external interested parties.
The Technical Director shows you a document detailing all business processes and interrelationships. You notice in this document that another organisation called Teak Ltd manufactures wooden furniture on behalf of ABC Ltd. The Technical Director confirms this capability has been accounted for in the scope of the quality management system. You learn that the furniture manufactured by Teak Ltd has accounted for 40% of the sales revenue over the previous 12 months.
Which two of the following options best describe how you would plan the audit of the interrelationship with Teak Ltd during the Stage 2 audit at ABC Ltd?
Audit criteria are a set of requirements used as a reference against which objective evidence is compared.
Which two of the following are not potential audit criteria?
A person who provides specific knowledge or expertise to the audit team during the audit is known as a/an:
Scenario 6: Davis Clinic (DC) is an American medical center focused on integrated health care. Since its establishment DC was committed to providing qualitative services for its clients, which is the reason why the company decided to implement a quality management system (QMS) based on ISO 9001. After a year of having an active QMS in place, DC applied for a certification audit.
A team of five auditors, from a well-known certification body, was selected to conduct the audit. Eva was appointed as the audit team leader. After three days of auditing, the team gathered to review and examine their findings. They also discussed the audit findings with DC's top management and then drafted the audit conclusions.
In the closing meeting, which was held between the audit team and the top management of DC. Eva presented two nonconformities that were detected during the audit. Eva stated that the company did not retain documented information regarding its outsourced services for an analysis laboratory and regarding the conducted management reviews. During the closing meeting, the audit team required from DCs top management to come up with corrective action plans within two weeks. Although the top management did not agree with the audit findings, the audit team insisted that the auditee must submit corrective actions within the given time frame in order for the audit activities to continue.
Once the action plans were evaluated, the audit team began preparing the audit report. Eva required from the team to provide accurate descriptions of the audit findings and the audit conclusions. The report was then distributed to all the interested parties involved in the audit, including the certification body Based on the report, the certification body together with Eva, as the audit team leader, made the certification decision.
Based on the scenario above, answer the following question:
The audit team delayed audit activities until DC’s top management submitted their action plans. Is this acceptable?
XYZ Corporation is an organisation that employs 100 people. As audit team leader, you are conducting a
certification audit at Stage 1. When reviewing the quality management system (QMS) documentation, you
find that quality objectives have been set for every employee in the organisation except top management.
The Quality Manager complains that this has created a lot of resistance to the QMS, and the Chief Executive
is asking questions about how much it will cost. He asks for your opinion on whether this is the correct
method of setting objectives.
Three months after Stage 1, you return to XYZ Corporation to conduct a Stage 2 certification audit as Audit
Team Leader with one other auditor. You find that the Quality Manager has cancelled the previous quality
objectives for all employees and replaced them with a single objective for himself. This states that "The
Quality Manager will drive multiple improvements in the QMS in the next year". The Quality Manager indicates
that this gives him the authority to issue instructions to department managers when quality improvement is
needed. He says that this approach has the full backing of senior management. He shows you the latest
Quality Improvement Request that was included in the last management review.

After further auditing, the issues below were found. Select two statements that apply to the term
`nonconformity'.
One of the conflict resolution techniques is toning down. How is the conflict managed in that case?
Select the phrase that best describes the purpose of a quality management system to ISO 9001 in relation to the performance of an organization.
Takitup is a small fabrication organisation that manufactures steel fencing, stairs and platforms for the construction sector. It has been certified to ISO 9001 for some time and has appointed a new Quality Manager. The audit plan during a surveillance audit covers the organisation's improvement actions and the auditor asks to see the most recent management review meeting minutes.
The auditor finds that the management review report records that none of the improvement actions set by the previous review has been realised for a second time. A new Quality Manager has been brought in at the middle management level to rectify the situation as the organisation is concerned that it might lose its certification.
Select three options that would provide evidence of conformance with clause 10.3 of ISO 9001.
How can an organization ensure the objectivity and impartiality of the internal audit function?
Match each of the following statements into the table below to show whether they apply to first-party audits, second-party audits or third-party audits:

Scenario 1: AL-TAX is a company located in California which provides financial and accounting services. The company manages the finances of 17 companies and now is seeking to expand their business even more The CEO of AL-TAX, Liam Durham, claims that the company seeks to provide top-notch services to their clients Recently, there were a number of new companies interested in the services provided by AL-TAX.
In order to fulfill the requirements of new clients and further improve quality, Liam discussed with other top management members the idea of implementing a quality management system (QMS) based on ISO 9001. During the discussion, one of the members of the top management claimed that the size of the company was not large enough to implement a QMS. In addition, another member claimed that a QMS is not applicable for the industry in which AL TAX operates. However, as the majority of the members voted for implementing the QMS. Liam initiated the project.
Initially, Liam hired an experienced consultant to help AL-TAX with the implementation of the QMS. They started by planning and developing processes and methods for the establishment of a QMS based on ISO 9001. Furthermore, they ensured that the quality policy is appropriate to the purpose and context of AL TAX and communicated to all employees. In addition, they also tried to follow a process that enables the company to ensure that its processes are adequately resourced and managed, and that improvement opportunities are determined.
During the implementation process, Liam and the consultant focused on determining the factors that could hinder their processes from achieving the planned results and implemented some preventive actions in order to avoid potential nonconformities Six months after the implementation of the QMS. AL-TAX conducted an internal audit. The results of the internal audit revealed that the QMS was not fulfilling all requirements of ISO 9001. A serious issue was that the QMS was not fulfilling the requirements of clause 5.1.2 Customer focus and had also not ensured clear and open communication channels with suppliers.
Throughout the next three years, the company worked on improving its QMS through the PDCA cycle in the respective areas. To assess the effectiveness of the intended actions while causing minimal disruptions, they tested changes that need to be made on a smaller scale. After taking necessary actions, AL-TAX decided to apply for certification against ISO 9001.
Based on the scenario above, answer the following question:
As stated in scenario 1, AL-TAX tested the effectiveness of the intended actions as part of the QMS improvement through the PDCA cycle. Which stage did it perform in this case?
Below are four of the seven principles on which ISO 9000 series are based. Match a potential benefit to each of the quality management principles (QMP).

In the context of a second-party audit, match the activity with the party responsible for conducting it.
Which of the following is a responsibility of a guide in an audit?
What is a combined audit?
An internal auditor of a manufacturer of polystyrene packaging products for the electronics industry raised a nonconformity against section 10.3 of ISO 9001 in Report IA202. The nonconformity (NC 3) stated:
"The reject rate of the finished product of 9.7% needs improvement as it doesn't meet the stated objective of top management of 5%."
As the third-party auditor reviewing the internal audit process, you come across the nonconformity. For corrective action, the Quality Manager conducted an investigation into the reject rates. He reported that the collection baskets for products ejecting from the moulding machines were not large enough. About 6% of products fell onto the wet and dirty factory floor. Management stated that replacing the baskets was too costly and ordered the Maintenance Manager to ensure that the floor was kept clean and dry to prevent rejects. The auditor later checked the factory floor, which was wet and dirty in places.
From the following nonconformities, select three that the auditor could raise to ISO 9001.
You are carrying out an audit to ISO 9001 at an organisation which offers regulatory consultancy services to manufacturers of cosmetics.
You are interviewing the Technical Director (TD), who manages a team of regulatory experts responsible for providing regulatory services to customers.
You: "How do you ensure your regulatory team's competence concerning regulatory requirements is maintained?"
TD: "The two Regulatory Experts we employ full-time have years of experience of working in the cosmetics industry."
You: "How is their regulatory competence maintained?"
TD: "They are dedicated individuals with lots of contacts in the sector."
You: "How does the business enable them to maintain their understanding of current regulatory requirements?"
TD: "We leave that up to them."

XYZ Corporation employs 100 people, and during a Stage 1 certification audit, certain issues are identified with the Quality Management System (QMS). Which two options describe the circumstances in which you could raise a nonconformity against Clause 6.2 of ISO 9001:2015?
Scenario 1: AL-TAX is a company located in California which provides financial and accounting services. The company manages the finances of 17 companies and now is seeking to expand their business even more The CEO of AL-TAX, Liam Durham, claims that the company seeks to provide top-notch services to their clients Recently, there were a number of new companies interested in the services provided by AL-TAX.
In order to fulfill the requirements of new clients and further improve quality, Liam discussed with other top management members the idea of implementing a quality management system (QMS) based on ISO 9001. During the discussion, one of the members of the top management claimed that the size of the company was not large enough to implement a QMS. In addition, another member claimed that a QMS is not applicable for the industry in which AL TAX operates. However, as the majority of the members voted for implementing the QMS. Liam initiated the project.
Initially, Liam hired an experienced consultant to help AL-TAX with the implementation of the QMS. They started by planning and developing processes and methods for the establishment of a QMS based on ISO 9001. Furthermore, they ensured that the quality policy is appropriate to the purpose and context of AL TAX and communicated to all employees. In addition, they also tried to follow a process that enables the company to ensure that its processes are adequately resourced and managed, and that improvement opportunities are determined.
During the implementation process, Liam and the consultant focused on determining the factors that could hinder their processes from achieving the planned results and implemented some preventive actions in order to avoid potential nonconformities Six months after the implementation of the QMS. AL-TAX conducted an internal audit. The results of the internal audit revealed that the QMS was not fulfilling all requirements of ISO 9001. A serious issue was that the QMS was not fulfilling the requirements of clause 5.1.2 Customer focus and had also not ensured clear and open communication channels with suppliers.
Throughout the next three years, the company worked on improving its QMS through the PDCA cycle in the respective areas. To assess the effectiveness of the intended actions while causing minimal disruptions, they tested changes that need to be made on a smaller scale. After taking necessary actions, AL-TAX decided to apply for certification against ISO 9001.
Based on the scenario above, answer the following question:
Scenario 1 indicates that AL-TAX did not ensure clear and open communication channels with interested parties. Which quality management principle did the organization not follow in this case?
A small cleaning services organisation is about to start work on a hospital cleaning contract for the local Health Trust. You,
as auditor, are conducting a Stage 2 audit to ISO 9001 and review the contract with the Service Manager. The contract
requires that a cleaning plan is produced.
You: "How was the cleaning plan for the contract developed?"
Service Manager: "We have a basic template that covers the materials, labour requirements and cleaning methods to be
employed. Some of that is specified by the customer."
You: "How does the plan deal with locations like the intensive care wards and the operating theatres, which are included
in the contract?"
Service Manager: "The basic plan covers general wards, but we will do more frequent cleaning in those areas if the
hospital requests it."
You: "Are you aware of the regulatory requirements for cleaning standards in hospitals?"
Service Manager: "No. We depend on the hospital to look after that side of things in the contract."
You decide to raise a non-conformity against section 8.2.2.a.1 of ISO 9001.
You decide to raise another non-conformity against section 8.2.4 of ISO 9001 when finding that the
cleaning plan was amended without the agreement of the Health Trust. A different cleaning chemical was
substituted to that specified in the contract. At the follow-up audit, the corrective action proposed was to
"obtain a concession from the Health Trust for use of the new chemical."
Which one of the following options is the reason why you did not accept this action taken?
Select the term which best describes the quality management system process of modifying a non-conforming product to bring it within acceptance criteria.