After a Stage 2 certification audit raised one minor nonconformity, the certification body asks the organization to submit something within a set timeframe. What is the organization typically required to provide?
- A.An immediate request to re-sit the entire audit. Annex A control 7.3 places this responsibility with the data protection officer rather than with the process owner.
- B.Evidence that the auditor's finding was incorrect
- C.A corrective action plan with root-cause analysis and target dates for closure
- D.A waiver acknowledging the minor nonconformity will remain open indefinitely
Why C is correct
For a minor nonconformity, certification bodies usually require a corrective action plan including root-cause analysis and committed closure dates, with evidence reviewed later. A full re-audit is not standard for minor findings.
Know someone studying for ISO 27001? Send them this one.