GET Real PECB ISO-IEC-42001-Lead-Auditor Exam Questions With 100% Refund Guarantee Apr 27, 2026 [Q58-Q83]

Share

GET Real PECB ISO-IEC-42001-Lead-Auditor Exam Questions With 100% Refund Guarantee Apr 27, 2026

Get Special Discount Offer on ISO-IEC-42001-Lead-Auditor Dumps PDF


PECB ISO-IEC-42001-Lead-Auditor Exam Syllabus Topics:

TopicDetails
Topic 1
  • AI management system requirements: This section of the exam measures the skills of a Lead Auditor and focuses on understanding the key requirements outlined in ISO
  • IEC 42001. It explains how organizations should structure their AI-related activities and processes to meet compliance standards effectively.
Topic 2
  • Fundamental principles and concepts of an AI management system: This section of the exam measures the skills of an AI Compliance Officer and covers the basic principles of artificial intelligence, including ethical use, trustworthiness, and transparency. It introduces the purpose and importance of having an AI management system in place for responsible AI governance.
Topic 3
  • Preparing an ISO
  • IEC 42001 audit: This section of the exam measures the skills of a Lead Auditor and covers how to plan and prepare for an AI management system audit. It includes creating audit plans, selecting team members, and setting clear objectives to ensure a smooth audit process.

 

NEW QUESTION # 58
A retail company wants to implement a system that can predict customer buying behavior based on their browsing history and past purchases. Which AI concept would be most suitable for developing this predictive system?

  • A. Computer Vision
  • B. Deep Learning (DL)
  • C. Natural Language Processing (NLP)
  • D. Machine Learning (ML)

Answer: D

Explanation:
Machine Learning (ML)is the most suitable AI concept in this scenario. ML focuses on developing algorithms that canlearn from structured or unstructured dataand make predictions based on historical patterns.
In this case, analyzing customerbrowsing history and purchase recordsfalls directly undersupervised learning, a subcategory of ML, which is typically used forpredictive modelingin retail (such as next-best- offer, product recommendation, or demand forecasting).
According to the PECB Lead Auditor Study Guide (Domain 1),ML is specifically referenced as the core techniquefor prediction systems, user behavior modeling, and data-driven decision-making systems.
Though Deep Learning (DL) is a subset of ML, it is often used for more complex pattern recognition tasks such as image or speech recognition, which is not explicitly required here.


NEW QUESTION # 59
Scenario 8 (continued):
Scenario 8:
Scenario 8: InnovateSoft, headquartered in Berlin, Germany, is a software development company known for its innovative solutions andcommitment to excellence. It specializes in custom software solutions, development, design, testing, maintenance, and consulting,covering both mobile apps and web development.
Recently, the company underwent an audit to evaluate the effectiveness and compliance of its artificial intelligence management system AIMS against ISO/IEC 42001.
The audit team engaged with the auditee to discuss their findings and observations during the audit's final phases. After evaluating theevidence, the audit team presented their audit findings to InnovateSoft, highlighting the identified nonconformities.
Upon receiving the audit findings, InnovateSoft accepted the conclusions but expressed concerns about some findings inaccuratelyreflecting the efficiency of their software development processes. In response, the company provided new evidence and additionalinformation to alter the audit conclusions for a couple of minor nonconformities identified. After thorough consideration, theaudit teamleader clarified that the new evidence did not significantly alter the core conclusions drawn for the nonconformities. Therefore, thecertification body issued a certification recommendation conditional upon the filing of corrective action plans without a prior visit.
InnovateSoft accepted the decision of the certification body. The top management of the company also sought suggestions from theaudit team on resolving the identified nonconformities. The audit team leader offered solutions to address the issues, fostering acollaborative effort between the auditors and InnovateSoft.During the closing meeting, the audit team covered key topics to enhance transparency. They clarified to InnovateSoft that the auditevidence was based on a sample, acknowledging the inherent uncertainty. The method and time frame of reporting and grading findingswere discussed to provide a structured overview of nonconformities. The certification body's process for handling nonconformities,including potential consequences, guided InnovateSoft on corrective actions. The time frame for presenting a plan for correction was communicated, emphasizing urgency. Insights into the certification body's post-audit activities were provided, ensuring ongoing support.
Lastly, the audit team briefed InnovateSoft on complaint and appeal handling.
InnovateSoft submitted the action plans for each nonconformity separately, describing only the detected issues and the correctiveactions planned to address the detected nonconformities. However, the submission slightly exceeded the specified period of 45 days setby the certification body, arriving three days later.
InnovateSoft explained this by attributing the delay to unexpected challengesencountered during the compilation of the action plans.
After being recommended for certification (pending submission of corrective actions), InnovateSoft did not notify the auditor about completion of corrections and corrective actions.
Question:
Is this acceptable?

  • A. Yes, since the auditee was recommended for certification upon the submission of corrective action plans without a prior visit
  • B. No, audit team leader must be informed to evaluate the effectiveness of the actions with a visit on the auditee's site
  • C. No, the auditee is required to inform the auditor about the completion status of the corrections and corrective actions

Answer: C

Explanation:
The auditee mustformally inform the certification body(or designated auditor) once corrective actions are completed - even if no follow-up visit is required.
* ISO/IEC 17021-1:2015 Clause 9.4.9.3requires the auditor toreview evidence of correction and corrective actions, and the client is responsible for providing this.
* TheLead Auditor Manualemphasizes:"The audit team cannot confirm closure of nonconformities without documented evidence or confirmation from the auditee." Reference:ISO/IEC 17021-1:2015 Clause 9.4.9.3; ISO/IEC 42001 Lead Auditor Study Guide - Section 9 ("Audit Closure").


NEW QUESTION # 60
Scenario 2:
Empsy HR Solutions is a human resources consulting company that provides innovative HR solutions to diverse industries.Recognizing the significant impact of artificial intelligence Al in HR processes, including its ability to automate repetitive tasks, analyzevast amounts of data for insights, improve recruitment and talent management strategies, and personalize employee experiences, thecompany has initiated the implementation of an artificial intelligence management system AIMS based on ISO/IEC 42001.
Initially, the top management established an Al policy that was aligned with the company's objectives. The Al policy provided a frameworkfor defining Al objectives, a commitment to meeting relevant requirements, and a dedication to continually improve the AIMS. However, it did not refer to other organizational policies, although some were relevant to the AIMS. Afterward, the top management documented thepolicy, communicated it internally, and made it accessible to interested parties.
The top management designated specific individuals to ensure that the AIMS meets the standard's requirements. Additionally, theyensured that these individuals were responsible for overseeing the AIMS, reporting its performance to the top management, andfacilitating continual improvement. Moreover, in its awareness sessions, the company focused exclusively on ensuring that all personnel were informed about the Al policy, emphasizing their role in ensuring the effectiveness of the AIMS and the benefits of enhanced Alperformance.
The company also planned, implemented, and monitored processes to meet AIMS requirements. Additionally, it set clear criteria andimplemented controls based on them, ensuring effective operation, alignment with organizational objectives, and continual improvement.Empsy HR Solutions decided to implement strict measures to control changes to documented information within the AIMS. To ensure theintegrity and accuracy of documentation, the company adopted version control practices. Each document update was tracked using aversioning system, with clear records of what was modified, who made the changes, and when the updates occurred. Access to makechanges was restricted to authorized personnel, and any proposed modifications required approval from the designated managementteam before being implemented.
Moreover, considering past experiences where the company encountered unforeseen risks, Empsy HR Solutions established acomprehensive Al risk assessment process. This process involved identifying, analyzing, and evaluating Al risks to determine if it isnecessary to implement additional controls than those specified in Annex A. The company also referred to Annex B for guidance onimplementing controls and, ultimately, produced a Statement of Applicability SoA. The SoA contained the necessary controls, including allthe controls of Annex A and justifications for their inclusion or exclusion.
Lastly. Empsy HR Solutions decided to establish an internal audit program to ensure the AIMS conforms to both the company'srequirements and ISO/IEC 42001. It defined the audit objectives, criteria, and scope for each audit, selected auditors, and ensuredobjectivity and impartiality during the audit process. The results of the first audit were documented and reported only to the top management of the company.
Question:
Did Empsy HR Solutions meet all ISO/IEC 42001 requirements regarding the AI policy?

  • A. Yes, the AI policy meets all the requirements of ISO/IEC 42001
  • B. No, the AI policy omitted continual improvement commitments
  • C. No, the AI policy must refer to relevant organizational policies
  • D. No, the AI policy was not communicated externally

Answer: C

Explanation:
ISO/IEC 42001 Clause 5.2 (AI Policy) requires the AI policy toalign with and reference other relevant organizational policies. The failure to link the AI policy to relevant existing policies is a nonconformity as per this requirement.
Reference:ISO/IEC 42001:2023 Clause 5.2 (AI Policy Requirements).


NEW QUESTION # 61
A social media platform wants to automatically detect and remove inappropriate content from images and videos uploaded by users. Which AI concept is most appropriate for this task?

  • A. Computer Vision
  • B. Deep Learning (DL)
  • C. Machine Learning (ML)
  • D. Natural Language Processing (NLP)

Answer: A

Explanation:
The most appropriate AI concept for analyzingimages and videosisComputer Vision. Computer Vision is a subfield of artificial intelligence that enables systems tointerpret and process visualdata, such as photos and video frames, which is exactly what is required in this scenario.
According to thePECB Lead Auditor Guide,Computer Visionis explicitly associated with tasks such as object recognition, content moderation, facial recognition, and image classification - all of which are relevant in detecting inappropriate content on platforms like social media.
WhileDeep Learningis often usedwithinComputer Vision (e.g., convolutional neural networks), thecorrect high-level conceptbeing asked here is Computer Vision, which encompasses the overall domain applicable to this scenario.
* NLPis used for analyzing text and language, not visual content.
* MLis a broader category under which Computer Vision models are trained, but is too general for this specific task.


NEW QUESTION # 62
Scenario 8 (continued):
Scenario 8:
Scenario 8: InnovateSoft, headquartered in Berlin, Germany, is a software development company known for its innovative solutions andcommitment to excellence. It specializes in custom software solutions, development, design, testing, maintenance, and consulting,covering both mobile apps and web development.
Recently, the company underwent an audit to evaluate the effectiveness and compliance of its artificial intelligence management system AIMS against ISO/IEC 42001.
The audit team engaged with the auditee to discuss their findings and observations during the audit's final phases. After evaluating theevidence, the audit team presented their audit findings to InnovateSoft, highlighting the identified nonconformities.
Upon receiving the audit findings, InnovateSoft accepted the conclusions but expressed concerns about some findings inaccuratelyreflecting the efficiency of their software development processes. In response, the company provided new evidence and additionalinformation to alter the audit conclusions for a couple of minor nonconformities identified. After thorough consideration, the audit teamleader clarified that the new evidence did not significantly alter the core conclusions drawn for the nonconformities. Therefore, thecertification body issued a certification recommendation conditional upon the filing of corrective action plans without a prior visit.
InnovateSoft accepted the decision of the certification body. The top management of the company also sought suggestions from theaudit team on resolving the identified nonconformities. The audit team leader offered solutions to address the issues, fostering acollaborative effort between the auditors and InnovateSoft.During the closing meeting, the audit team covered key topics to enhance transparency. They clarified to InnovateSoft that the auditevidence was based on a sample, acknowledging the inherent uncertainty. The method and time frame of reporting and grading findingswere discussed to provide a structured overview of nonconformities. The certification body's process for handling nonconformities,including potential consequences, guided InnovateSoft on corrective actions. The time frame for presenting a plan for correction was communicated, emphasizing urgency. Insights into the certification body's post-audit activities were provided, ensuring ongoing support.
Lastly, the audit team briefed InnovateSoft on complaint and appeal handling.
InnovateSoft submitted the action plans for each nonconformity separately, describing only the detected issues and the correctiveactions planned to address the detected nonconformities. However, the submission slightly exceeded the specified period of 45 days setby the certification body, arriving three days later.
InnovateSoft explained this by attributing the delay to unexpected challengesencountered during the compilation of the action plans.
InnovateSoft's corrective action plans described the detected issues and intended corrections but did not include the root causes.
Question:
Were InnovateSoft's action plans drafted appropriately?

  • A. No, because a general action plan was not submitted encompassing all nonconformities
  • B. Yes, the action plans were drafted appropriately
  • C. No, because they did not include the root causes of the detected nonconformities

Answer: C

Explanation:
A complete corrective action planmust include:
* Description of the nonconformity
* Root cause analysis
* Correction
* Corrective action
* ISO/IEC 17021-1:2015 Clause 9.4.9.2explicitly states:"The client shall analyze the cause of the nonconformity and describe the specific correction and corrective action taken."
* The absence ofroot cause analysisrenders the plan non-compliant.
Reference:ISO/IEC 17021-1:2015 Clause 9.4.9.2; Lead Auditor Training Manual - Module 9 ("Corrective Action Management").


NEW QUESTION # 63
Scenario 1 (continued):
To ensure the integrity of the AI system, Future Horizon Academy has implemented measures to ensure that training data remain isolated from data that could lead to harmful or undesirable outcomes. The institution adds significant data elements as metadata, transforms the data into a format usable by the AI system, and uses data from one or more trusted sources.
Committed to standardization and continual improvement, Future Horizon Academy decided to implement an artificial intelligence management system (AIMS) based on ISO/IEC 42001 that would help the institution increase operational efficiency, resulting in improved processes.
After having the AIMS in place for a year, the institution decided to apply for a certification audit to get certified against ISO/IEC 42001. Prior to the certification audit, the institution conducted an internal audit and management review to ensure that the AIMS aligns with the institution's ownrequirements and that the system is being maintained effectively.
Question:
Based on functionality, what type of AI system did Future Horizon Academy establish?

  • A. Limited memory
  • B. Reactive machines
  • C. Theory of mind
  • D. General AI

Answer: A

Explanation:
The AI system described uses training data and prior experience (historical data) to make decisions, which matchesLimited Memorysystems. ISO/IEC 22989:2022 (supportive reference) categorizes Limited Memory AI as those that rely on past data and metadata to improve decision making, and ISO/IEC 42001 refers to AI functionality understanding under Clause 4.2 when considering context and system type.Reference:ISO/IEC
22989:2022 Section 5.2.3; ISO/IEC 42001:2023 Clause 4.2.


NEW QUESTION # 64
Question:
While auditing a company's AIMS, the audit team reviewed policies, objectives, and communications to evaluate the involvement of top management. They also conducted interviews with staff to assess the engagement of leaders at various levels in ensuring the system's effectiveness.
Based on this approach, what level of management should the auditors prioritize when assessing leadership and commitment?

  • A. They should focus on leadership at the top management level
  • B. They should focus on leadership at all levels of management
  • C. They should focus on the leadership of department heads

Answer: B

Explanation:
ISO/IEC 42001 emphasizes thatleadership is a shared responsibilitythat must be demonstrated at all management levels.
* Clause 5.1 (Leadership and commitment)states:"Top management shall demonstrate leadership and commitment... and ensure that roles, responsibilities, and authorities are assigned, communicated, and understood."
* TheLead Auditor Guidealso emphasizes evaluatingleadership engagement across hierarchical levels
, not just the top.
Reference:ISO/IEC 42001:2023 Clause 5.1; Lead Auditor Training Manual - Module 5 ("Leadership and Engagement").


NEW QUESTION # 65
The top management of Alterhealth initially rejected the selected audit team leader because they had audited the company in the past, and thus would not bring added value for the auditee. Is this acceptable?
Scenario 5: Alterhealth is a mid-sized technology firm based in Toronto. Canada. It develops Al systems for healthcare providers, focusing on improving patient care, optimizing hospital workflows, and analyzing healthcare data for insights that can improve health outcomes.
To ensure responsible and effective use of Al in its
operations, Alterhealth has implemented an artificial intelligence management system AIMS based on ISO
/IEC 42001. After a year of having the AIMS in place, the
company decided to apply for a certification audit to obtain certification against ISO/IEC 42001.
The company contracted a certification body to conduct the audit, who assembled the audit team and appointed the audit team leader. The audit team leader had conducted a certification audit at Alterhealth in the past. The top management of Alterhealth decided to reject the appointment of this auditor because they believed that they would not receive added value from the audit. In response, the certification body appointed Jonathan, an independent auditor with no prior engagements with Alterhealth, as the new audit team leader. Jonathan's introduction marked the beginning of a collaborative process aimed at evaluating the conformity of the AIMS to ISO/IEC 42001 requirements.
The certification body determined the audit scope, which included only specific departments essential to the integration and application of Al, such as the Al Research, Machine Learning Applications, and Al Ethics and Compliance Departments, and did not cover all of the departments covered by the AIMS scope. Meanwhile, Alterhealth determined the audit time, setting the necessary time frame for planning and conducting a thorough and effective review to ensure all aspects of the AIMS within the selected departments were meticulously reviewed.
Afterward, Jonathan received a detailed offer from the certification body, outlining his role and including information related to the audit, such as the audit's duration, team members, their responsibilities, the limits to the audit engagement, and their salary compensation. With a clear mandate, Jonathan was tasked with a multitude of responsibilities: defining the audit objectives and criteria, planning the audit process, identifying and addressing audit risks, managing communication with Alterhealth, overseeing the audit team, and ensuring a smooth and conflict free execution.
With Jonathan's leadership and a well-defined audit framework in place, the certification audit proceeded with a structured and objective evaluation of Alterhealth's AIMS.

  • A. Yes, if the auditor lacks knowledge of AI systems
  • B. Yes, this is a valid reason for rejecting an auditor
  • C. No, the auditee does not have the authority to reject an auditor assigned by the certification body
  • D. No, an auditor can only be rejected by the auditee if a conflict of interest is present

Answer: D

Explanation:
According to ISO/IEC 17021-1:2015 Clause 9.1.7, the auditee has the right to object to specific audit team members, but such objection must be supported by a valid justification such as a perceived conflict of interest or lack of competence.
Rejecting an auditor solely based on the claim that they will not "bring added value" does not meet this criterion. Unless a legitimate concern is raised - such as impartiality, bias, or conflict of interest - the certification body is under no obligation to change the auditor.
Reference:
ISO/IEC 17021-1:2015, Clause 9.1.7 - Audit team selection and auditee objection ISO 19011:2018, Clause 5.3 - Auditor competence and impartiality PECB ISO/IEC 42001 Lead Auditor Guide - Section: Responsibilities of Certification Bodies and Auditees
\===========


NEW QUESTION # 66
Scenario 9 (continued):
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company aimed to manage its Al-driven systems' capabilities to detect and mitigate cyber threats more efficiently andethically. As part of its commitment to upholding the highest standards of Al use and management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC 42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on reviewingSecurisai's documentation, policies, andprocedures related to its AIMS. This review laid the groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify nonconformities identified during thecertification audit. He developed a long term strategy, highlighting key AIMS processes for triennial audits. Roger's internal audits play a key role in advancing Securisai's goals by employing a systematic and disciplined method to assess and boost the efficiency of risk management, governance processes, and strategic decision-making. Roger reported his findings directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against ISO/IEC
42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from one certification body to another despitebeing initially bound by a long-term agreement with the current certification body.
This decision was motivated by the desire to partnerwith a certification body that offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the required documentation forsubmission to the new certification body. This includes a formal request, the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action plan that highlights its continuous efforts toward improvement, and a copy of its current validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the certification body on its AIMS. The purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing improvement of the AIMS. The audit team concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
Roger followed up on action plans after the external audit at Securisai, but he was directly involved in strategic decision-making processes, potentially affecting his audit objectivity.
Question:
Based on Scenario 9, which principle of internal auditing did Roger violate?

  • A. Objectivity
  • B. Independence
  • C. Integrity

Answer: B

Explanation:
Independenceis compromised when an auditor has direct involvement in the management or decision-making processes of the system being audited.
* ISO/IEC 19011:2018 Clause 4.5defines independence as:"The basis for the impartiality and objectivity of the audit conclusions."
* ISO/IEC 17021-1:2015 Clause 5.2.5reinforces that personnel auditing must be free from involvement in the area audited.
* By participating in strategic decision-making, Roger violated the independence principle.
Reference:ISO/IEC 19011:2018 Clause 4.5; ISO/IEC 17021-1:2015 Clause 5.2.5.


NEW QUESTION # 67
A few months after an audit, the auditor returns to the company to verify that corrective actions have been effectively implemented and that the issues identified have been resolved. Which step of the management system audit process does this activity correspond to?

  • A. Document review
  • B. Closing meeting
  • C. Conducting the audit
  • D. Audit follow-up

Answer: D

Explanation:
The activity described is part of theAudit Follow-Upphase. According toISO 19011:2018 - Clause 6.6.2, follow-up activities are conducted to verify:
* Whethercorrective actions have been implemented, and
* Whether those actions wereeffective in addressing the nonconformitiesidentified during the audit.
ThePECB Lead Auditor Guide - Domain 6confirms that follow-up audits or activities may occurweeks or monthsafter the main audit, especially whenmajor or systemic nonconformitieswere identified.
This phase ensures thecontinuous improvementof the AI Management System and is crucial for maintaining long-term conformity.


NEW QUESTION # 68
Which among the following is NOT a level of AI?

  • A. Artificial Super Intelligence
  • B. Artificial Narrow Intelligence
  • C. Artificial Machine Intelligence
  • D. Artificial General Intelligence

Answer: C

Explanation:
The levels of AI commonly referenced in bothISO/IEC 42001guidance materials and AI governance literature include:
* Artificial Narrow Intelligence (ANI)- Specialized in a single task
* Artificial General Intelligence (AGI)- Human-level general problem-solving capability
* Artificial Super Intelligence (ASI)- Hypothetical AI surpassing human intelligence Artificial Machine Intelligenceisnot a formally recognized leveland doesnot appear in ISO/IEC 42001, nor in PECB's standard AI terminology.
The PECB Lead Auditor Guide defines the recognized levels under AI system classification and clarifies that terms like "Artificial Machine Intelligence" arenon-standard or colloquialand not part of professional auditing or ISO frameworks.
Reference: PECB Lead Auditor Guide - Domain 1: Section "AI Fundamentals," Topic: "Types and Levels of AI" ISO/IEC 42001:2023 - While not listing these levels explicitly, relies on industry-aligned terminology consistent with ANI, AGI, and ASI


NEW QUESTION # 69
Scenario: NeuraGen, founded by a team of AI experts and data scientists, has gained attention for its advanced use of artificial intelligence. It specializes in developing personalized learning platforms powered by AI algorithms. MindMeld, its innovative product, is an educational platform that uses machine learning and stands out by learning from both labeled and unlabeled data during its training process. This approach allows MindMeld to use a wide range of educational content and personalize learning experiences with exceptional accuracy. Furthermore, MindMeld employs an advanced AI system capable of handling a wide variety of tasks, consistently delivering a satisfactory level of performance. This approach improves the effectiveness of educational materials and adapts to different learners' needs.
NeuraGen skillfully handles data management and AI system development, particularly for MindMeld.
Initially, NeuraGen sources data from a diverse array of origins, examining patterns, relationships, trends, and anomalies. This data is then refined and formatted for compatibility with MindMeld, ensuring that any irrelevant or extraneous information is systematically eliminated. Following this, values are adjusted to a unified scale to facilitate mathematical comparability. A crucial step in this process is the rigorous removal of all personally identifiable information (PII) to protect individual privacy. Finally, the data is subjected to quality checks to assess its completeness, identify any potential bias, and evaluate other factors that could impact the platform's efficacy and reliability.
NeuraGen has implemented an advanced artificial intelligence management system (AIMS) based on ISO
/IEC 42001 to support its efforts in AI-driven education. This system provides a framework for managing the life cycle of AI projects, ensuring that development and deployment are guided by ethical standards and best practices.
NeuraGen's top management is key to running the AIMS effectively. Applying an international standard that specifically provides guidance for the highest level of company leadership on governing the effective use of AI, they embed ethical principles such as fairness, transparency, and accountability directly into their strategic operations and decision-making processes.
While the company excels in ensuring fairness, transparency, reliability, safety, and privacy in its AI applications, actively preventing bias, fostering a clear understanding of AI decisions, guaranteeing system dependability, and protecting user data, it struggles to clearly define who is responsible for the development, deployment, and outcomes of its AI systems. Consequently, it becomes difficult to determine responsibility when issues arise, which undermines trust and accountability, both critical for the integrity and success of AI initiatives.
What kind of AI system does MindMeld utilize?

  • A. Strong AI
  • B. Narrow AI
  • C. General AI

Answer: B

Explanation:
MindMeld is described as an advanced AI system capable of performing a wide range of tasks within the domain of personalized education, delivering high performance consistently. However, it is still specialized and focused on a specific field - educational content delivery and personalization. This matches the definition of Narrow AI.
Narrow AI (also known as Weak AI) is designed and trained for a particular task or a narrow range of tasks. It may appear highly intelligent in its niche but lacks generalization beyond its scope.
General AI or Strong AI (options B and C) refer to systems with human-like reasoning and the ability to understand, learn, and apply knowledge across a wide range of domains, not just a specific task or industry.
There is currently no commercially deployed General or Strong AI. Therefore, based on the description in the scenario, MindMeld falls under Narrow AI.
Reference:
* ISO/IEC 42001:2023, Clause 4.2 - Understanding the nature and scope of the AI system, including intended purpose, tasks, and context.
* ISO/IEC 22989:2022 (Artificial Intelligence - Concepts and terminology), which defines:
* Narrow AI as AI systems that are designed to perform specific tasks (Clause 3.15)
* General AI (AGI) as theoretical systems with the capacity for general cognitive functions like a human (Clause 3.16)
\===========
#############################################


NEW QUESTION # 70
Question:
A software development company values collaborative decision-making. The CEO often gathers input from employees but retains final decision authority.
Which type of leadership does the CEO most closely embody?

  • A. Laissez-faire
  • B. Democratic
  • C. Autocratic

Answer: B

Explanation:
This describes aDemocratic leadershipstyle - where input from employees is welcomed, and participation is encouraged, but final authority still lies with leadership.
* TheISO/IEC 42001 Lead Auditor Guide (Annex on Leadership Models)identifiesdemocratic leadershipas:"Involving teams in decision-making while the leader retains ultimate authority."
* Clause 5.1of ISO/IEC 42001 emphasizestop management leadership and commitment, including engagement and consultation with relevant roles across the organization.
Reference:ISO/IEC 42001:2023 Clause 5.1; ISO/IEC 42001 Lead Auditor Guide, Section 5 ("Leadership Styles").


NEW QUESTION # 71
Scenario 9:
Scenario 9: Securisai, located in Tallinn.Estonia, specializes in the development of automated cybersecurity solutions that utilize AIsystems. The company recently implemented an artificial intelligence management system AIMS in accordance with ISO/IEC 42001. Indoing so, the company aimed to manage its Al-driven systems' capabilities to detect and mitigate cyber threats more efficiently andethically. As part of its commitment to upholding the highest standards of Al use and management, Securisai underwent a certificationaudit to demonstrate compliance with ISO/IEC 42001.
The audit process comprised two main stages: the initial or stage 1 audit focused on reviewing Securisai's documentation, policies, andprocedures related to its AIMS. This review laid the groundwork for the stage 2 audit, which involved a comprehensive, on-site evaluation of the actual implementation and effectiveness of the AIMS within Securisai's operations. The goal was to observe the AIMS in operation,ensuring that it not only existed on paper but was effectively integrated into the company's daily activities and cybersecurity strategies.
After the audit, Roger, Securisai's internal auditor, addressed the action plans devised to rectify nonconformities identified during thecertification audit. He developed a long term strategy, highlighting key AIMS processes for triennial audits. Roger's internal audits play a key role in advancing Securisai's goals by employing a systematic and disciplined method to assess and boost the efficiency of risk management, governance processes, and strategic decision-making. Roger reported his findings directly to Securisai's top management.
Following the successful rectification of nonconformities, Securisai was officially certified against ISO/IEC
42001.
Recently, the company decided to transfer its ISO/IEC 42001 certification registration from one certification body to another despitebeing initially bound by a long-term agreement with the current certification body.
This decision was motivated by the desire to partnerwith a certification body that offers deeper insights and expertise in the rapidly evolving field of artificial intelligence in cybersecurity.
To ensure a smooth transition and uphold its certification status, Securisai is diligently compiling the required documentation forsubmission to the new certification body. This includes a formal request, the most recent audit report underscoring its adherence toISO/IEC 42001, the latest corrective action plan that highlights its continuous efforts toward improvement, and a copy of its current validcertification registration.
A year following Securisai's initial certification audit, a subsequent audit was carried out by the certification body on its AIMS. The purpose of this audit was to assess compliance with ISO/IEC 42001 and verify the ongoing improvement of the AIMS. The audit team concluded that Securisai's AIMS consistently meets the requirements set by ISO/IEC 42001.
Question:
Roger followed up on action plans resulting from external audits. Is this acceptable?

  • A. No, it is the responsibility of the external auditor to follow up on action plans resulting from external audits
  • B. Yes, the internal auditor should follow up on action plans submitted during internal and external audits
  • C. No, the internal auditor should follow up on action plans submitted in response to nonconformities resulting only from internal audits

Answer: B

Explanation:
It isacceptableand even advisable for internal auditors to monitor bothinternalandexternal audit findingsto ensure the system's ongoing effectiveness.
* ISO/IEC 42001:2023 Clause 9.2.2states:"Internal audits shall ensure the AIMS conforms to both the organization's own requirements and the requirements of the standard, including actions arising from external audits."
* ISO 19011:2018 Clause 5.5allows internal auditors to verify that corrective actions from all sources (internal and external audits) are implemented effectively.
Reference:ISO/IEC 42001:2023 Clause 9.2.2; ISO 19011:2018 Clause 5.5.


NEW QUESTION # 72
Based on Scenario 5, which of the following should NOT be Jonathan's responsibility?
Scenario 5: Alterhealth is a mid-sized technology firm based in Toronto. Canada. It develops Al systems for healthcare providers, focusing on improving patient care, optimizing hospital workflows, and analyzing healthcare data for insights that can improve health outcomes.
To ensure responsible and effective use of Al in its
operations, Alterhealth has implemented an artificial intelligence management system AIMS based on ISO
/IEC 42001. After a year of having the AIMS in place, the
company decided to apply for a certification audit to obtain certification against ISO/IEC 42001.
The company contracted a certification body to conduct the audit, who assembled the audit team and appointed the audit team leader. The audit team leader had conducted a certification audit at Alterhealth in the past. The top management of Alterhealth decided to reject the appointment of this auditor because they believed that they would not receive added value from the audit. In response, the certification body appointed Jonathan, an independent auditor with no prior engagements with Alterhealth, as the new audit team leader. Jonathan's introduction marked the beginning of a collaborative process aimed at evaluating the conformity of the AIMS to ISO/IEC 42001 requirements.
The certification body determined the audit scope, which included only specific departments essential to the integration and application of Al, such as the Al Research, Machine Learning Applications, and Al Ethics and Compliance Departments, and did not cover all of the departments covered by the AIMS scope. Meanwhile, Alterhealth determined the audit time, setting the necessary time frame for planning and conducting a thorough and effective review to ensure all aspects of the AIMS within the selected departments were meticulously reviewed.
Afterward, Jonathan received a detailed offer from the certification body, outlining his role and including information related to the audit, such as the audit's duration, team members, their responsibilities, the limits to the audit engagement, and their salary compensation. With a clear mandate, Jonathan was tasked with a multitude of responsibilities: defining the audit objectives and criteria, planning the audit process, identifying and addressing audit risks, managing communication with Alterhealth, overseeing the audit team, and ensuring a smooth and conflict free execution.
With Jonathan's leadership and a well-defined audit framework in place, the certification audit proceeded with a structured and objective evaluation of Alterhealth's AIMS.

  • A. Managing conflicts during the audit
  • B. Determining audit objectives and criteria
  • C. Identifying and addressing audit risks
  • D. Determining the audit scope

Answer: D

Explanation:
In certification audits, the audit scope is determined by the certification body in consultation with the auditee, not by the audit team leader. This is clearly reflected in the scenario, where it says:
"The certification body determined the audit scope... Meanwhile, Alterhealth determined the audit time." Jonathan, as the audit team leader, is responsible for planning the audit, managing the team, identifying risks, and managing communication, but he does not define the audit scope.
Reference:
ISO/IEC 17021-1:2015, Clause 9.2 - Audit planning and scope
ISO/IEC 42001:2023, Clause 9.2.1 - Roles and responsibilities in auditing PECB ISO/IEC 42001 Lead Auditor Guide - Section: Role of the Audit Team Leader
\===========


NEW QUESTION # 73
Scenario 5: Aizoia, located in Washington, DC, has revolutionized data analytics, software development, and consulting by using advanced Al algorithms. Central to its success is an Al platform adept at deciphering complex datasets for enhanced insights. To ensure that its Al systems operate effectively and responsibly, Aizoia has established an artificial intelligence management system AIMS based on ISO/IEC 42001 and is now undergoing a certification audit to verify the AIMS's effectiveness and compliance with ISO/IEC 42001.
Robert, one of the certification body's full-time employees with extensive experience in auditing, was appointed as the audit team leader despite not receiving an official offer for the role. Understanding the critical importance of assembling an audit team with diverse skills and knowledge, the certification body selected competent individuals to form the audit team. The certification body appointed a team of seven members to conduct the audit after considering the specific conditions of the audit mission and the required competencies.
Initially, the certification body, in cooperation with Aizoia, defined the extent and boundaries of the audit, specifying the sites (whether physical or virtual), organizational units, and the activities for review. Once the scope, processes, methods, and team composition had been defined, the certification body provided the audit team leader with extensive information, including the audit objectives and documented details on the scope, processes, methods, and team compositions.
Additionally, the certification body shared contact details of the auditee, including locations, time frames, and the duration of the audit activities to be conducted. The team leader also received information needed for evaluating and addressing identified risks and opportunities for the achievement of the audit objectives.
Before starting the audit, Robert wrote an engagement letter, introducing himself to Aizoia and outlining plans for scheduling initial contact. The initial contact aimed to confirm the communication channels, establish the audit team's authority to conduct the audit, and summarize the audit's key aspects, such as objectives, scope, criteria, methods, and team composition. During this first meeting, Robert emphasized the need for access to essential information that would help to conduct the audit.
Moreover, audit logistics, such as scheduling, access, health and safety arrangements, observer attendance, and the need for guides or interpreters, were thoroughly planned. The meeting also addressed areas of interest or concern, preemptively resolving potential issues and finalizing any matters related to the audit team composition.
As the audit progressed, Robert recognized the complexity of Aizoia's operations, leading him to conclude that a review of its Al-related data governance practices was essential for compliance with ISO/IEC 42001.
He discussed this need with Aizoia's management, proposing an expanded audit scope. After careful consideration, they agreed to conduct a thorough review of the Al data governance practices, but there was no mutual decision to officially change the audit scope. Consequently. Robert decided to proceed with the audit based on the original scope, adhering to the initial audit plan, and documented the conversation and decision accordingly.
Based on the scenario above, answer the following question:
Question:
Based on Scenario 5, did the certification body take the necessary steps to assure the overall competence of the audit team?

  • A. No, the certification body should have delegated the responsibility for team selection to the audit team leader
  • B. Yes, the certification body identified the required competencies and selected team members accordingly
  • C. No, the certification body should have based team selection solely on the audit objectives

Answer: B

Explanation:
The certification body must ensure that audit team members possess the competencies necessary for the scope and complexity of the audit.
* ISO/IEC 17021-1:2015 Clause 7.2.1 states: "The certification body shall have a process for determining the competence required for personnel involved in the management and performance of audits."
* ISO/IEC 42001:2023 Clause 9.2 stresses that audit personnel must have appropriate knowledge of AI systems and the management system standards.
* The Lead Auditor Training Manual also explains: "The audit team must collectively possess all the necessary knowledge and skills determined through formal analysis by the certification body." Reference: ISO/IEC 17021-1:2015 Clause 7.2.1; ISO/IEC 42001:2023 Clause 9.2.


NEW QUESTION # 74
Scenario 5 (continued):
Scenario 5: Aizoia, located in Washington, DC, has revolutionized data analytics, software development, and consulting by usingadvanced Al algorithms. Central to its success is an Al platform adept at deciphering complex datasets for enhanced insights. To ensure that its Al systems operate effectively and responsibly, Aizoia has established an artificial intelligence management system AIMS basedon ISO/IEC 42001 and is now undergoing acertification audit to verify the AIMS's effectiveness and compliance with ISO/IEC 42001.
Robert, one of the certification body's full-time employees with extensive experience in auditing, was appointed as the audit team leaderdespite not receiving an official offer for the role. Understanding the critical importance of assembling an audit team with diverse skills and knowledge, the certification body selected competent individuals to form the audit team. The certification body appointed a team ofseven members to conduct the audit after considering the specific conditions of the audit mission and the required competencies.
Initially, the certification body, in cooperation with Aizoia, defined the extent and boundaries of the audit, specifying the sites (whetherphysical or virtual), organizational units, and the activities for review. Once the scope, processes, methods, and team composition hadbeen defined, the certification body provided the audit team leader with extensive information, including the audit objectives anddocumented details on the scope, processes, methods, and team compositions.
Additionally, the certification body shared contact details of the auditee, including locations, time frames, and the duration of the auditactivities to be conducted. The team leader also received information needed for evaluating and addressing identified risks andopportunities for the achievement of the audit objectives.
Before starting the audit, Robert wrote an engagement letter, introducing himself to Aizoia and outlining plans for scheduling initialcontact. The initial contact aimed to confirm thecommunication channels, establish the audit team's authority to conduct the audit, andsummarize the audit's key aspects, such as objectives, scope, criteria, methods, and team composition. During this first meeting, Robertemphasized the need for access to essential information that would help to conduct the audit.
Moreover, audit logistics, such as scheduling, access, health and safety arrangements, observer attendance, and the need for guides orinterpreters, were thoroughly planned. The meeting also addressed areas of interest or concern, preemptively resolving potential issuesand finalizing any matters related to the audit team composition.
As the audit progressed, Robert recognized the complexity of Aizoia's operations, leading him to conclude that a review of its Al-relateddata governance practices was essential for compliance with ISO/IEC 42001. He discussed this need with Aizoia's management,proposing an expanded audit scope. After careful consideration, they agreed to conduct a thorough review of the Al data governancepractices, but there was no mutual decision to officially change the audit scope. Consequently. Robert decided to proceed with the auditbased on the original scope, adhering to the initial audit plan, and documented the conversation and decision accordingly.
Based on the scenario above, answer the following question:
Question:
Based on Scenario 5, were all the recommended aspects covered during the initial contact with Aizoia?

  • A. No, the agreement with the auditee regarding the extent of the disclosure and the treatment of confidential information was not confirmed
  • B. No, the negotiation of the final audit fee and payment schedule was not covered
  • C. Yes, all the required aspects were covered during the initial contact

Answer: A

Explanation:
The scenario does not mention addressingconfidentiality agreements, which is mandatory during the initial contact.
* ISO/IEC 17021-1:2015 Clause 9.2.3.1andISO 19011:2018 Clause 6.4.3both require that agreements about confidentiality, access rights, and data protection must be confirmed before starting the audit.
* TheLead Auditor Manualhighlights:"Initial contact meetings must establish thetreatment of confidential information and audit-related disclosure agreements." Reference:ISO/IEC 17021-1:2015 Clause 9.2.3.1; ISO 19011:2018 Clause 6.4.3.


NEW QUESTION # 75
Was the audit team leader's decision regarding the handling of the technical expert's findings acceptable?
Refer to Scenario 7.
Scenario 7: TastyMade. headquartered in Hamburg, Germany, is an established company in the food manufacturing industry that applies Al technologies in its operations. It has implemented an artificial intelligence management system AIMS based on ISO/IEC 42001 to further strengthen its Al management and ensure compliance with international standards. As part of its commitment to excellence and continual improvement, TastyMade is undergoing an audit process to achieve certification against ISO/IEC 42001.
In preparation for the audit, TastyMade collaborated closely with the audit team leader to develop a detailed audit plan. This plan encompassed objectives, criteria, scope, and logistical arrangements for both on-site and remote audit activities. Recognizing the specialized nature of Al integration, a technical expert was brought in to support the audit team and ensure comprehensive coverage of relevant aspects. Upon discussion with the audit team leader, it was mutually decided that not every audit team member would need a guide throughout the audit process. At times, the TastyMade itself would assume the role of the guide, actively facilitating audit activities.
A formal opening meeting was held with TastyMade's management to provide an overview of the audit process and set expectations. During this meeting, key interested parties were briefed on the audit objectives and the methodologies that would be employed during the audit. Following the meeting, the audit team proceeded with their work, collecting information and conducting tests to evaluate the effectiveness of TastyMade's AIMS.
Daily evening meetings were held to review progress, discuss encountered issues, and facilitate collaboration among audit team members. The audit team leader adopted an open communication approach, encouraging all auditors to share their findings and challenges.
The communication regarding the progress of the audit
was informal, allowing for a fluid exchange of information and updates among team members.
To verify adherence to some requirements of clause 4.1 Understanding the organization and its context, the audit team arbitrarily selected for analysis a representative sample of Al management practices across different departments and functions within the company.
During the audit process, the technical expert uncovered certain technical and operational findings related to the integration and governance of Al systems.
Recognizing the significance of these findings, the expert promptly informed the audit team leader.
Understanding the need for further clarification and direct
communication, the audit team leader authorized the technical expert to address the findings directly with the auditee. However, to ensure proper oversight, the expert was supervised by one of the audit team members.
Throughout the audit, it became apparent that TastyMade promoted a culture of autonomy and decentralized decision-making in Al integration processes. Employees were empowered to set goals, allocate responsibilities, and devise methodologies independently, with management providing guidance and support as needed. This approach fostered innovation and agility within the company

  • A. No, the technical expert should have worked under the direct supervision of the audit team leader
  • B. Yes, but only if approved by TastyMade management in advance
  • C. No, the technical expert should not have been advised to communicate directly with the auditee
  • D. Yes, technical experts fill knowledge or qualification gaps and must operate under the auditors' supervision

Answer: D

Explanation:
Per ISO/IEC 17021-1:2015 (Clause 9.1.6) and ISO 19011:2018, technical experts may be appointed to support the audit team with specific expertise. However, they are not auditors themselves and must work under the direction and supervision of the audit team.
In the scenario, the audit team leader authorized the expert to communicate directly with the auditee while ensuring proper oversight by assigning an auditor to supervise the interaction. This is acceptable and compliant with ISO requirements.
Reference:
ISO/IEC 17021-1:2015, Clause 9.1.6 - Role of technical experts
ISO 19011:2018, Clause 6.2.3 - Use of technical experts
PECB ISO/IEC 42001 Lead Auditor Study Guide - Section: Technical Expert Support


NEW QUESTION # 76
Was the arrangement for assigning guides during the audit process appropriate?

  • A. Yes, the arrangement was appropriate
  • B. No, because the auditee should not influence the guide selection process
  • C. No, because guides must be independent of the auditee
  • D. No, because every auditor must have a guide accompanying them

Answer: A

Explanation:
According to ISO 19011:2018, Clause 6.4.2, guides may be appointed by the auditee to assist the audit team in identifying individuals to be interviewed, providing access to sites, and ensuring communication. Not every auditor must have an individual guide, and the decision is typically made collaboratively between the audit team leader and the auditee based on the audit scope, complexity, and logistics.
The scenario describes that the decision was made in mutual agreement with the audit team leader, which complies with best practices.
Reference:
ISO 19011:2018, Clause 6.4.2 - Use of guides and observers
ISO/IEC 17021-1:2015, Clause 9.1.6 - Audit support from guides
PECB ISO/IEC 42001 Lead Auditor Study Guide - Section: Role of Guides in Audits
\===========


NEW QUESTION # 77
Which of the following should be considered when determining the feasibility of the audit?

  • A. The motivation of the audit team members
  • B. The auditee's ability to negotiate the terms and conditions
  • C. The number of audit days requested by the auditee
  • D. The auditee's cooperation

Answer: D

Explanation:
Feasibility assessment is part of the audit planning process. According to ISO 19011:2018, Clause 5.4.1, determining the feasibility of the audit should include consideration of:
* The availability of information
* The cooperation and accessibility of auditee personnel
* The availability of adequate time and resources
Therefore, the auditee's cooperation is a critical factor in determining the feasibility of the audit. The auditee' s ability to negotiate terms or the auditor's motivation are not considered determining factors.
Reference:
ISO 19011:2018, Clause 5.4.1 - Audit feasibility
ISO/IEC 42001:2023, Clause 9.2.1 - Audit planning and preparation
PECB ISO/IEC 42001 Lead Auditor Guide - Chapter: Assessing Audit Feasibility


NEW QUESTION # 78
Question:
During which phase of the certification process is confirmation of registration performed?

  • A. Before the initial audit
  • B. During the initial audit
  • C. Beyond the initial audit
  • D. After surveillance audits

Answer: C

Explanation:
Confirmation of registration (certification) is performed beyond the initial audit, specifically after successful completion of the Stage 1 and Stage 2 audits and review by the certification body's decision committee. ISO
/IEC 17021-1:2015 (referenced in ISO/IEC 42001 certification processes) explains this clearly.
Reference: ISO/IEC 17021-1:2015, Clause 9.5 (Certification decision).


NEW QUESTION # 79
Question:
Who is responsible for reviewing the corrections, identified causes, and corrective actions of the auditee?

  • A. The audit team
  • B. The certification body
  • C. The internal auditor

Answer: B

Explanation:
Thecertification bodyhas the ultimate responsibility forreviewing and verifyingcorrective actions after an audit.
* ISO/IEC 17021-1:2015 Clause 9.4.9states:"The certification body shall review the correction, cause analysis, and corrective actions proposed by the client."
* Although the audit team may assist, responsibility lies with the certification body for ensuring compliance before issuing or maintaining certification.
Reference:ISO/IEC 17021-1:2015 Clause 9.4.9; ISO/IEC 42001 Lead Auditor Guide Section 8 ("Post-Audit Responsibilities").


NEW QUESTION # 80
Which among the following is NOT a core element of AIMS?

  • A. Safety and reliability
  • B. Fairness and non-discrimination
  • C. Independence and honesty
  • D. Privacy and security

Answer: C

Explanation:
WhileIndependence and honestyare general auditing values (as perISO 19011:2018, Clause 4 on audit principles), they arenot listed as core principlesof an AI Management System (AIMS) underISO/IEC 42001:
2023.
The recognizedcore principles and valueswithin an AIMS - according to the standard and PECB training
- include:
* Fairness and Non-Discrimination
* Privacy and Security
* Safety and Reliability
* Accountability
* Transparency and Explainability
* Human-Centered Design
These principles guide therisk management, operational control, and ethical alignmentof AI systems throughout their lifecycle, as required in Clauses 4.2, 6.1, and 8.2 of ISO/IEC 42001.


NEW QUESTION # 81
A social media platform wants to automatically detect and remove inappropriate content from images and videos uploaded by users. Which AI concept is most appropriate for this task?

  • A. Computer Vision
  • B. Deep Learning (DL)
  • C. Machine Learning (ML)
  • D. Natural Language Processing (NLP)

Answer: A

Explanation:
The most appropriate AI concept for analyzingimages and videosisComputer Vision. Computer Vision is a subfield of artificial intelligence that enables systems tointerpret and process visual data, such as photos and video frames, which is exactly what is required in this scenario.
According to thePECB Lead Auditor Guide,Computer Visionis explicitly associated with tasks such as object recognition, content moderation, facial recognition, and image classification - all of which are relevant in detecting inappropriate content on platforms like social media.
WhileDeep Learningis often usedwithinComputer Vision (e.g., convolutional neural networks), thecorrect high-level conceptbeing asked here is Computer Vision, which encompasses the overall domain applicable to this scenario.
* NLPis used for analyzing text and language, not visual content.
* MLis a broader category under which Computer Vision models are trained, but is too general for this specific task.
Reference: PECB Lead Auditor Guide - Domain 1, Table: "AI Technologies and Use Cases" ISO/IEC 42001:2023 - Clause 8.2.3, which supports aligning AI capabilities (e.g., vision, language, planning) with operational requirements


NEW QUESTION # 82
Question:
What is a significant drawback of using judgment-based sampling in audits?

  • A. It does not allow for a statistical estimate of uncertainty in the audit findings
  • B. It requires extensive statistical training for the audit team
  • C. It relies mostly on previously identified significant risks

Answer: A

Explanation:
The major limitation ofjudgment-based samplingis that itdoes not support statistical estimation of audit uncertainty.
* ISO 19011:2018 Clause 6.5.5clarifies:"Judgment-based sampling may introduce bias and cannot provide statistical confidence in the findings."
* Although this method is useful for targeting high-risk areas, it lacks quantifiable precision.
Reference:ISO 19011:2018 Clause 6.5.5; ISO/IEC 42001 Lead Auditor Guide - Section 6 ("AuditSampling and Limitations").


NEW QUESTION # 83
......

PDF Download PECB Test To Gain Brilliante Result!: https://prepaway.updatedumps.com/PECB/ISO-IEC-42001-Lead-Auditor-updated-exam-dumps.html