{"id":6842,"date":"2017-01-31T16:38:27","date_gmt":"2017-01-31T16:38:27","guid":{"rendered":"https:\/\/multiacademstg.wpengine.com\/20000academy\/?p=6842"},"modified":"2024-12-12T16:56:42","modified_gmt":"2024-12-12T16:56:42","slug":"which-questions-will-the-iso-20000-certification-auditor-ask","status":"publish","type":"post","link":"https:\/\/staging.advisera.com\/20000academy\/blog\/2017\/01\/31\/which-questions-will-the-iso-20000-certification-auditor-ask\/","title":{"rendered":"Which questions will the ISO 20000 certification auditor ask?"},"content":{"rendered":"<p>Starting an <a href=\"https:\/\/staging.advisera.com\/20000academy\/what-is-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">ISO 20000<\/a>\u00a0implementation, and the implementation itself, usually require a lot of effort and resources inside the company. I would add \u2013 a lot of hassle and stress, too. And, once you are finished, a new issue is in front of you \u2013 the certification audit.<\/p>\n<p>Eyes wide open, questions coming from all sides: \u201cWhat does the certification audit look like? Who is coming? What will they ask?&#8230;\u201d Well, the certification audit process is pretty much the same for all (audited) companies, so there are no secrets; i.e., it\u2019s easy to find out what to expect. But, when we get to the auditor\u2026 well, that\u2019s a different story. The human factor plays a significant role here, but there are some common elements in auditors\u2019 questions that repeat at every audit.<\/p>\n<p>Read the article <a href=\"https:\/\/staging.advisera.com\/blog\/2015\/06\/22\/infographic-the-brain-of-an-iso-auditor-what-to-expect-at-a-certification-audit\/\" target=\"_blank\" rel=\"noopener noreferrer\">Infographic: The brain of an ISO auditor \u2013 What to expect at a certification audit<\/a> to understand how auditors think.<\/p>\n<h2>Documentation and records<\/h2>\n<p>This is the \u201ceasiest\u201d part of the certification audit. If you consider how much effort you needed to invest to prepare all required <a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/procedure-for-document-and-record-control\/\" target=\"_blank\" rel=\"noopener noreferrer\">documentation and records<\/a> (remember \u2013 ISO 20000-1, a set of requirements, has 256 \u201cshalls,\u201d with many of them requiring a record or a document), maybe it doesn\u2019t sound so easy. But, at least it is pretty much straightforward. The standard requires mandatory documents (e.g., process descriptions for all processes, plans, etc.) and records (generated as a result of certain processes, i.e., activities) and there are no \u201cpitfalls\u201d; i.e., you know what needs to be implemented. OK, if you are using an ITSM (IT Service Management) tool, then particular care should be taken not to forget some of the requirements or not to duplicate records (e.g., say you have the record inside the tool, but you have a template as well).<\/p>\n<p>So, the questions related to documents and records will tend to move toward checking that you fulfilled the standard\u2019s requirements and didn\u2019t exclude anything that is mandatory (these are the questions typically starting with \u201cDo you have \u2026 procedure,\u201d or \u201cMay I see the \u2026 process description?\u201d). Besides the mandatory documents, the auditor will also ask for any other document that you developed in order to support the SMS (e.g., Incident Catalogue, or Major Incident Report, etc.).<br \/>\n<div id=\"middle-banner\" class=\"banner-shortcode\"><\/div><script>loadMiddleBanner();<\/script><br \/>\n<div id=\"side-banner-trigger\" class=\"banner-shortcode\"><\/div><\/p>\n<h2>Evidences<\/h2>\n<p>At this point, you are done with the \u201ctheoretical part\u201d of your <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/?rel=sms-related-documents&#038;doc=service-management-system-scope\" target=\"_blank\" rel=\"noopener\">SMS<\/a> \u2013 which documents and which records you have in place. Now you have to show that everything you define in your documents (e.g., processes like Change Management, Incident and Service Request Management, etc.) works in real life. For example, the auditor will ask you about approval of changes in the scope of your Change Management process (in the documentation check phase, he already confirmed that your Change Management process description fulfills the standard\u2019s requirements); i.e., who is doing it, where is the change record for, e.g., the last change that was made, how was it approved, who did it\u2026 etc. Meaning, the auditor would like to confirm that the process description is not just a document for the sake of having a document, and in reality, the (<a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/request-for-change-and-change-record-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">Change Management<\/a>) process works completely differently in your SMS.<\/p>\n<h2>Interview<\/h2>\n<p>Who will be interviewed? You (if you are auditee), but your colleagues as well. The auditor will try to figure out whether all he has found out (by checking documentation and evidences) so far works in real life. And this is OK, because implementing the standard without having it \u201cwork\u201d in daily life is useless. I mean, you spend resources, time, money, management\u2019s time and effort\u2026 and at the end, all you have is a bunch of documents, maybe some tools, and no real value behind any of it.<\/p>\n<p>So, besides the person responsible for the SMS, process owners and people involved in process activities may be (usually will be) interviewed. Auditors will test their familiarity with process goals, activities, and details, in general. Questions that they could ask are:<\/p>\n<ul>\n<li>Do you know what to do if there is a <a href=\"https:\/\/staging.advisera.com\/20000academy\/documentation\/major-incident-report-iso-20000\/\" target=\"_blank\" rel=\"noopener noreferrer\">Major Incident<\/a>?<\/li>\n<li>How do you declare an incident to be a Major Incident?<\/li>\n<li>Do you know which service targets supplier X needs to fulfill for service ABC?<\/li>\n<li>Can you show me service reports for the last 30 days?<\/li>\n<\/ul>\n<p>In addition to those people who are part of the SMS (e.g., a technician who is working on incident resolution) being interviewed, your users (e.g., in the case of internal users of IT services) may also be interviewed. For example, the auditor might ask them whether they know how to open an incident, what to do when they need something to be changed, or which security policies are in place.<\/p>\n<h2>Use it as best you can<\/h2>\n<p>To be sure, when it comes to documentation and evidences, an internal audit can be of great help. Basically, you should conduct internal audits at regular intervals (one of the standard\u2019s requirement), and that will keep you on the \u201csafe side.\u201d Particularly if you have someone independent from the SMS (auditors should not audit their own work, anyway) \u2013 you will get a clear and objective picture. I would strongly recommend that you do that, even if you have to hire an external person to perform the internal audit.<\/p>\n<p>And, there is one more thing (which I quite often see happening opposite from how it should) \u2013 the certification audit should not be, necessarily, a bad or unpleasant experience. Namely, the certification audit will let you know how good you are, and what your weak points are (to correct them), but the auditor also brings his own experience gathered from many companies, and that\u2019s your excellent chance to learn and improve. It will benefit you, your company, and, most importantly \u2013 your customers. And they know how to appreciate that, believe me.<\/p>\n<p><em>To implement ISO 20000 easily and efficiently, use our<\/em> <a href=\"https:\/\/staging.advisera.com\/20000academy\/iso-20000-documentation-toolkit\/\" target=\"_blank\" rel=\"noopener\">ISO 20000 Documentation Toolkit<\/a> <em>that provides step-by-step guidance for full ISO 20000 compliance.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Starting an ISO 20000\u00a0implementation, and the implementation itself, usually require a lot of effort and resources inside the company. I would add \u2013 a lot of hassle and stress, too. And, once you are finished, a new issue is in front of you \u2013 the certification audit. Eyes wide open, questions coming from all sides: &#8230;<\/p>\n","protected":false},"author":32,"featured_media":6843,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[534,256,400,366],"class_list":["post-6842","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-auditor","tag-certification","tag-implementation","tag-iso-20000"],"acf":[],"_links":{"self":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6842","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/users\/32"}],"replies":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/comments?post=6842"}],"version-history":[{"count":2,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6842\/revisions"}],"predecessor-version":[{"id":17961,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/posts\/6842\/revisions\/17961"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media\/6843"}],"wp:attachment":[{"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/media?parent=6842"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/categories?post=6842"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/staging.advisera.com\/20000academy\/wp-json\/wp\/v2\/tags?post=6842"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}