The correct answers are D, F, H.
ISO 19011 guidance on generating audit findings says that nonconformities can be graded depending on the context of the organization and its risks. That directly supports D, because any grading should reflect the risk the nonconformity presents to the organization. The same guidance also says this grading can be quantitative (for example 1 to 5) or qualitative (for example minor/major), which makes F correct. Because the wording is “can be graded”, grading is optional rather than mandatory, so H is also true. (Synersia Foundation)
Why the other options are not true:
A is not a requirement in ISO 19011. An organization may define grading rules in its audit programme or procedure, but there is no rule that grading must be agreed with the individual(s) managing the audit programme. (ISO)
B is false. ISO 19011 does not recommend that top management grade nonconformities. Audit findings are generated by auditors based on objective evidence and audit criteria. (ISO)
C is false. A second-party audit team does not have to adopt the auditee’s grading system. The grading approach can follow the auditing organization’s own rules and purpose for the audit. (ISO)
E is false. Additional documented information at the closing meeting does not mean the grading must be changed. The evidence should be reviewed, but unresolved issues may simply remain recorded in the audit report. (Synersia Foundation)
G is false. There is no requirement that extra grading categories must be agreed with the auditee before the closing meeting. The auditee should understand the findings, but the grading framework is not something ISO 19011 requires to be negotiated at that point. (ISO)
Submit