FreeQAs
 Request Exam  Contact
  • Home
  • View All Exams
  • New QA's
  • Upload
PRACTICE EXAMS:
  • Oracle
  • Fortinet
  • Juniper
  • Microsoft
  • Cisco
  • Citrix
  • CompTIA
  • VMware
  • ISC
  • SAP
  • EMC
  • PMI
  • HP
  • Salesforce
  • Other
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • ISC
    ISC
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. PECB Certification
  3. ISO-IEC-42001-Lead-Auditor Exam
  4. PECB.ISO-IEC-42001-Lead-Auditor.v2025-06-28.q54 Dumps
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • …
  • »
  • »»
Download Now

Question 6

Question:
During a combined audit, if an auditor identifies a finding linked to one criterion, should they consider its potential impact on corresponding or related criteria of other management systems?

Correct Answer: B
In acombined audit, auditors are required toconsider the implications of a finding across different but related management systems.
* ISO/IEC 17021-1:2015 Clause 9.2.2.2states:"Findings should be evaluated not only against the specific audit criteria but also their relevance to other applicable requirements in combined audits."
* TheLead Auditor Training Manualclarifies:"In combined audits, findings must be reviewed for their potential cross-system impacts to ensure full system-wide conformity." Reference:ISO/IEC 17021-1:2015 Clause 9.2.2.2; ISO/IEC 42001 Lead Auditor Guide, Combined Audit Considerations.
insert code

Question 7

Question:
During the annual ISO/IEC 42001 audit at a financial company, the auditor selected and analyzed a sample of
5 out of 25 follow-up nonconformity reports to assess whether the company adheres to its follow-up process.
What type of evidence did the auditor gather?

Correct Answer: D
The auditor gatheredQuantitative evidence.
* Quantitative evidenceis defined as evidence that is measurable and based on numbers or statistical sampling.
* ISO 19011:2018 Clause 6.5.5states:"Quantitative audit evidence is numerical or measurable and collected through sampling, measurements, or observations."
* Sampling nonconformity reports to check process adherence clearly falls underquantitative evidence.
Reference:ISO 19011:2018 Clause 6.5.5; ISO/IEC 42001:2023 Clause 9.2.2.
insert code

Question 8

Scenario 4 (continued):
BioNovaPharm, a German biopharmaceutical company, has implemented an artificial intelligence management system AIMSbased on ISO/IEC 42001 to optimize various aspects of drug discovery, including analyzing extensive biological data, identifying potentialdrug candidates, and streamlining clinical trial processes. After having the AIMS in place for over a year, the company contracted acertification body and is now undergoing an AIMS audit to obtain certification against ISO/IEC 42001.
Adopting a risk-based approach, the audit team focused on risk throughout their activities. The level of detail outlined in the audit plancorresponded to the scope and complexity of the audit. The team employed a ranking system for detailed audit procedures, prioritizingthose with the highest risk.
Once the stage 1 audit began, the audit team started reviewing the auditee's documented information. To assess whether BioNovaPharmcomplies with the legal and regulatory requirements related to incident communication, the audit team examined evidence provided bythe company's external legal office. The evidence confirmed that BioNovaPharm applies the requirements of the EU Al Act, whichmandates that providers of high-risk Al systems report serious incidents to relevant authorities.
Following the completion of the stage 1 audit, John, an audit team member, documented the stage 1 audit outputs, including theobservations of the audit team that could result in nonconformities during the on-site audit. However, the audit team leader, Emma, whowas overseeing the audit activities, observed that John failed to document significant observations related to the lack of transparency inthe Al decision-making processes of BioNovaPharm. Considering that Emma observed John's lack of competence in undertaking some audit activities, a disciplinary note was recorded for John.
Question:
What level of negligence did Emma observe regarding John's audit documentation failures?

Correct Answer: A
Ordinary negligencerefers to a failure to apply the level of care that a reasonable auditor would exercise, without intentional misconduct.
* ISO/IEC 17021-1:2015 Clause 7.2.5 requires auditors todocument audit findings properly and completely.
* TheLead Auditor Study Guidedefines ordinary negligence as:"An auditor's unintentional oversight or failure to perform duties to expected professional standards, without evidence of deliberate wrongdoing." Reference:ISO/IEC 17021-1:2015 Clause 7.2.5; Lead Auditor Manual Chapter 6 ("Audit Team Behavior and Ethics").
insert code

Question 9

How does ISO 19011 recommend auditors select audit criteria?

Correct Answer: C
Audit criteria should be selectedaccording to the requirements of the management system standard (e.g., ISO/IEC 42001:2023)and theorganization's objectives.
PerISO 19011:2018 - Clause 5.4.2, audit criteria must be defined based onstandards, statutory requirements, internal policies, procedures, and contractual obligationsrelevant to the audit.
Random selection or convenience-based criteria are not acceptable in professional audit practice.
insert code

Question 10

Scenario 9 (continued):
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company aimed to manage its Al-driven systems' capabilities to detect and mitigate cyber threats more efficiently andethically. As part of its commitment to upholding the highest standards of Al use and management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC 42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on reviewing Securisai's documentation, policies, andprocedures related to its AIMS. This review laid the groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify nonconformities identified during thecertification audit. He developed a long term strategy, highlighting key AIMS processes for triennial audits. Roger's internal audits play a key role in advancing Securisai's goals by employing a systematic and disciplined method to assess and boost the efficiency of risk management, governance processes, and strategic decision-making. Roger reported his findings directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against ISO/IEC
42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from onecertification body to another despitebeing initially bound by a long-term agreement with the current certification body.
This decision was motivated by the desire to partnerwith a certification body that offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the required documentation forsubmission to the new certification body. This includes a formal request, the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action plan that highlights its continuous efforts toward improvement, and a copy of its current validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the certification body on its AIMS. The purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing improvement of the AIMS. The audit team concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
Question:
What type of audit is described in the last paragraph of Scenario 9?

Correct Answer: C
The follow-up auditone year after initial certificationto assess ongoing conformity is classified as a Surveillance Audit.
* ISO/IEC 17021-1:2015 Clause 9.6.2.1states:"Surveillance audits are conducted at least once a year to ensure that the certified management system continues to meet requirements."
* ISO/IEC 42001:2023 Clause 9.2.2also references surveillance as part of maintaining AI management system certification.
Reference:ISO/IEC 17021-1:2015 Clause 9.6.2.1; ISO/IEC 42001:2023 Clause 9.2.2.
insert code
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • …
  • »
  • »»
[×]

Download PDF File

Enter your email address to download PECB.ISO-IEC-42001-Lead-Auditor.v2025-06-28.q54 Dumps

Email:

FreeQAs

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2026 FreeQAs

www.freeqas.com materials do not contain actual questions and answers from Cisco's certification exams.