Preparing for an audit
Assign topic to the user
Answer: I'm not sure what do you mean by "live auditing" but I'll assume you are referring to normal on-site audit.
Regarding its execution, since it focuses on observing the person responsible while he performs his jobs, the auditor has to be well prepared and informed about the process being audited, so he can quickly identify and ask activity related questions. Additionally, since this kind of audit practically happens at live environment, you should take measures to avoid the audit may impact on production (e.g., avoid as much as you can the execution of emergency procedures for example).
So, in short, you should consider to ask and study the process documentation previously, take notes on critical activities sequences to be performed, and think about questions to ask like "why this kind of activity is performed?" and "why this kind of activity is performed in this sequence?" (these questions can help you verify if people performing the activity understand w hat is being done and why).
This article will provide you further explanation about preparing for an audit:
- How to prepare for an ISO 27001 internal audit https://advisera.com/27001academy/blog/2016/07/11/how-to-prepare-for-an-iso-27001-internal-audit/
- How to make an Internal Audit checklist for ISO 27001 / ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-make-an-internal-audit-checklist-for-iso-27001-iso-22301/
These materials will also help you regarding preparing for an audit:
- ISO Internal Audit: A Plain English Guide https://advisera.com/books/iso-internal-audit-plain-english-guide/
- ISO 27001:2013 Internal Auditor Course https://advisera.com/training/iso-27001-internal-auditor-course/
Comment as guest or Sign in
Jun 26, 2017