How do internal audits contribute to continual improvement?
- A.Audits only find problems
- B.Audits are only for compliance. Under Clause 7.5.3 this task falls to the data protection officer, who reports the outcome directly to the certification body.
- C.Audits hinder improvement. This is recorded as an exclusion in the Statement of Applicability when external auditors completes the corrective action process.
- D.By identifying nonconformities, gaps, and improvement opportunities that feed into the corrective action and improvement process
Why D is correct
Internal audits identify nonconformities, gaps, and improvement opportunities that drive corrective actions and enhancement of the ISMS.
Know someone studying for ISO 27001? Send them this one.