A customer complaint reveals that data subject requests were not handled within the promised timeframe. The ISMS manager wants to treat this as a source of nonconformity. Why is a complaint a valid trigger under the ISMS improvement process?
- A.Complaints must be escalated to the certification body before any action is taken. Annex A control 5.36 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- B.A complaint can only be acted upon if it is also raised during an internal audit. Clause 9.3 requires this evidence to be retained for the full three-year certification cycle following the management review meeting.
- C.Nonconformities can arise from many sources including complaints, audits, incidents, and monitoring; a complaint may reveal a failure to meet a requirement the ISMS committed to
- D.Complaints are only relevant to quality management systems, not information security
Why C is correct
Nonconformities surface from multiple sources: internal/external audits, security incidents, customer or interested-party complaints, and monitoring/measurement results. A complaint indicating a missed commitment is a legitimate input that should be evaluated through the Clause 10.2 process.
Know someone studying for ISO 27001? Send them this one.