Free CQI IRCA QMS LA Exam Flashcards
Memorize 50 essential terms and definitions for the CQI and IRCA Certified ISO 9001:2015 QMS Auditor / Lead Auditor Course Exam. See the term, recall the definition, then flip to check yourself.
The Seven Quality Management Principles (ISO 9000)
Customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management. They explain the intent behind ISO 9001's requirement clauses but are never themselves cited as audit criteria.
Filter by Topic
Jump to Card
About These CQI IRCA QMS LA Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the CQI and IRCA Certified ISO 9001:2015 QMS Auditor / Lead Auditor Course Exam. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Complete Flashcard Reference
Review every term in this set. Open any term to reveal its definition.
The Seven Quality Management Principles (ISO 9000)
Customer focus, leadership, engagement of people, process approach, improvement, evidence-based decision making, and relationship management. They explain the intent behind ISO 9001's requirement clauses but are never themselves cited as audit criteria.
PDCA Cycle Mapped to ISO 9001:2015 Clauses
Plan = Clauses 4-6 (context, leadership, planning); Do = Clauses 7-8 (support, operation); Check = Clause 9 (performance evaluation); Act = Clause 10 (improvement). The clause sequence was deliberately built around PDCA.
Risk-Based Thinking (ISO 9001:2015)
Replaced the standalone 'preventive action' clause from the 2008 edition. Requires proportionate action on risks and opportunities — NOT a mandatory formal risk-management methodology, risk register, or quantified scoring. Surfaces in clauses 4.4, 5.1.2, 6.1, and 9.3.
Annex SL High-Level Structure (HLS)
The common ten-clause skeleton (1 Scope, 2 Normative references, 3 Terms/definitions, 4 Context, 5 Leadership, 6 Planning, 7 Support, 8 Operation, 9 Performance evaluation, 10 Improvement) shared by ISO 9001, 14001, 45001 and other modern ISO management system standards. Clauses 1-3 are not substantive audit criteria.
Clause 4.4 Process Approach — What Must Be Determined for Each Process
Inputs/outputs, sequence and interaction, criteria/methods (including monitoring and KPIs), resources needed, assigned responsibilities/authorities, risks and opportunities, and how the process will be evaluated and improved. SIPOC and the turtle diagram are practical tools for this.
Clause 4.1 — Understanding the Organization and Its Context
Requires determining external and internal issues relevant to the organization's purpose and strategic direction that affect its ability to achieve intended QMS results, and monitoring/reviewing that information over time.
Clause 4.2 — Interested Parties
Requires determining interested parties relevant to the QMS and their relevant requirements. Analysis is limited to parties and requirements relevant to the QMS — not an exhaustive stakeholder census.
Clause 4.3 — QMS Scope and Valid Exclusions
The QMS scope must be maintained as documented information, including written justification for any requirement determined not applicable. An exclusion is valid only if it does not affect the organization's ability to ensure conformity of products/services or enhance customer satisfaction.
What Changed in Clause 5 vs. the 2008 Edition
ISO 9001:2015 removed the mandatory 'management representative' role. Clause 5.1.1(a) places direct, non-delegable accountability for QMS effectiveness on top management — auditors must gather evidence of leadership commitment directly from top management, not just the quality department.
Clause 5.2 — Quality Policy Requirements
Must be appropriate to the organization's context, provide a framework for quality objectives, and commit to satisfying requirements and continual improvement. It must be documented, communicated, understood within the organization, and available to relevant interested parties.
Clause 6.1 — Actions to Address Risks and Opportunities
Requires determining risks/opportunities arising from the Clause 4.1/4.2 context and planning proportionate actions to address them. ISO 9001:2015 does NOT require a documented risk-management process or a formal risk register.
Clause 6.2 — What a Complete Quality Objective Plan Must Define
What will be done, what resources are required, who is responsible, when it will be completed, and how results will be evaluated. Objectives must also be consistent with policy, measurable where practicable, monitored, communicated, and updated. Missing any element is a common audit finding.
Clause 7.1.5.2 — Out-of-Tolerance (OOT) Equipment
When measuring equipment is found unfit for purpose, the organization must assess the impact of the finding on the validity of previous measurement results — not simply recalibrate the equipment and move on. This is a high-yield exam detail.
Clause 7.1.6 — Organizational Knowledge
Addresses institutional-memory risk: what happens to critical process knowledge when an experienced person leaves. Draws on internal sources (experience, lessons learned) and external sources (standards, customers, conferences).
Clause 7.5 — 'Maintained' vs. 'Retained' Documented Information
'Maintained' documented information (e.g., procedures, policy) is kept current. 'Retained' documented information (records) is fixed evidence of a result. Both must be identified, formatted, and reviewed/approved before use.
Clause 8.2.3 — Review of Requirements Before Supply
Requirements must be reviewed BEFORE the organization commits to supply a product or service. Verbal orders must be confirmed before acceptance, and the results of the review must be documented — auditors check the review is dated before production, not retrofitted afterward.
Clause 8.3.4 — Review, Verification & Validation (Design)
Three distinct controls: review evaluates design progress against requirements; verification checks design outputs against design inputs; validation checks the resulting product/service against its intended or specified use, and must be completed before delivery unless the customer stipulates otherwise.
Clause 8.4 — Three Types of External Provision
(1) Products/services incorporated into the organization's own products/services, (2) products/services delivered directly to the customer on the organization's behalf, and (3) a process, or part of a process, outsourced to an external provider.
Clause 8.7 — The Four Permitted Dispositions for Nonconforming Outputs
Correction; segregation/containment/return/suspension; informing the customer; and obtaining concession authorization. Required documented information must record the nonconformity, actions taken, any concessions obtained, and who authorized the disposition.
Clause 9.2.2(c) — Internal Audit Objectivity Rule
Auditors must be selected, and audits conducted, to ensure the objectivity and impartiality of the audit process — nobody may audit their own work.
Clause 9.3.2 — Most Commonly Omitted Management Review Inputs
Required inputs include status of previous actions, changes in issues, performance trends (customer satisfaction, objectives, conformity, nonconformities, monitoring results, audit results), resource adequacy, and risk/opportunity effectiveness. External provider performance and resource adequacy are the two most commonly missing inputs.
Correction vs. Corrective Action (Clause 10.2)
Correction eliminates a DETECTED nonconformity's symptom (e.g., re-calibrating one out-of-tolerance gauge). Corrective action eliminates the ROOT CAUSE to prevent recurrence (e.g., revising the calibration schedule so gauges never drift again).
Clause 10.2.1(b) — Evaluating the Need for Corrective Action
Requires root-cause analysis, including checking whether similar nonconformities exist elsewhere or could potentially occur. Corrective action taken must then be reviewed for effectiveness.
The Seven Audit Principles (ISO 19011:2018)
Integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Risk-based approach is the newest, added in the 2018 revision.
Audit Evidence → Finding → Conclusion Chain
Audit evidence is compared against audit criteria to produce an audit finding (conformity, nonconformity, or opportunity for improvement — ISO 19011:2018 clause 3.6). Findings are then synthesized by the audit team into an overall audit conclusion.
Fair Presentation (Audit Principle)
Requires truthfully and accurately reporting audit findings, conclusions, and reports — including significant obstacles encountered during the audit and unresolved diverging opinions between the audit team and the auditee. These must never be omitted.
First-, Second-, and Third-Party Audits
First-party = the organization audits its own QMS (internal audit, Clause 9.2). Second-party = an organization audits an external party with a direct interest, e.g., a customer auditing a supplier. Third-party = an independent certification body with no direct commercial relationship, governed by ISO/IEC 17021-1.
Combined Audit vs. Joint Audit
A combined audit covers two or more management-system disciplines (e.g., QMS + EMS) at one site by one audit team. A joint audit means two or more auditing organizations cooperate to audit a single auditee together.
Establishing an Audit Programme (ISO 19011:2018 Clause 5 Sequence)
Set programme objectives → determine and evaluate programme risks and opportunities → establish the programme's extent and resources → establish supporting procedures.
What an Audit Plan Must State (ISO 19011:2018)
Audit objectives, scope, and criteria; locations, dates, and duration; methods including the extent of sampling; roles and responsibilities of the team; and allocation of resources to critical areas. Must be reviewed and accepted by the audit client and presented to the auditee before the opening meeting.
Risk-Based Audit Planning
Directs more time and larger or more targeted samples toward higher-risk processes, consistent with the risk-based approach — the seventh ISO 19011:2018 audit principle.
Sources of Audit Evidence
Interviews, observation of activities, review of documented information/records, and data or performance indicators. Evidence is strongest when multiple independent sources corroborate the same finding; only verified information counts as audit evidence.
Effective Interview Technique During an Audit
Start with open questions, avoid leading the interviewee, and corroborate the interviewee's statements with other evidence rather than accepting them at face value.
Following an Audit Trail
Tracing a single process forward and backward across every function it touches (e.g., order-to-delivery) rather than visiting departments in isolation. This exposes the handoffs where nonconformities most often hide.
Why Audits Provide 'Reasonable' Rather Than 'Absolute' Assurance
Because audits rely on sampling rather than a 100% review of evidence. This inherent audit risk is managed through risk-based, representative sampling — it is never fully eliminated.
Technical Expert vs. Observer vs. Auditor-in-Training
A technical expert provides specific subject-matter knowledge to the audit team but does not act as an auditor. Observers and auditors-in-training may accompany the team, with agreement of the team leader, auditee, and audit client, but do not audit.
MAJOR Nonconformity — Definition
The total breakdown or absence of a required process; a nonconformity likely to result in product or service failure; or an accumulation of minor nonconformities against one requirement showing a systemic failure.
MINOR Nonconformity — Definition
A single lapse or isolated slip that does NOT represent a systemic failure of the process or requirement.
Who Defines 'Major' and 'Minor' Nonconformity?
Neither ISO 9001 nor ISO 19011 defines these grades. The certification body sets its own grading scheme under its ISO/IEC 17021-1 obligations, though the major/minor definitions taught on IRCA courses are the industry-standard convention.
How Nonconformity Grading Affects the Certification Decision
An unresolved major nonconformity blocks certification or recertification. Minor nonconformities typically allow certification to proceed against an accepted correction and corrective-action plan.
The Three Parts of a Nonconformity Statement
(1) The requirement — the specific clause or documented procedure not met; (2) the objective evidence — specific, factual, traceable data; (3) the statement of nonconformity that links the two together.
Citing the Requirement in a Nonconformity Statement
Must cite a specific ISO 9001:2015 clause number (or documented procedure) that was not met — never a general area of the standard, and never a quality management principle by name.
Objective Evidence Standard for Nonconformity Writing
Must be specific, factual, and traceable: exact document or record references, dates, sample sizes, and roles. Vague words like 'some,' 'often,' or 'poorly' are not acceptable.
What a Nonconformity Statement Must NEVER Include
The names of individuals or opinions about a person's competence or attitude — reference roles and facts only, so the statement is defensible and someone who wasn't on the audit can trace it back to the record, interview, or observation that generated it.
The Closing Meeting (ISO 19011:2018 Clause 6.4.10)
Presents findings, confirms nonconformity grading, and agrees timeframes for the auditee's response. It should surface no findings the auditee hasn't already seen the supporting evidence for during the audit.
Closing a Nonconformity During Follow-Up (Clause 6.7)
Requires objective evidence that the corrective action was BOTH implemented AND effective — a completed action plan alone is not sufficient to close the nonconformity.
ISO/IEC 17021-1 — Purpose
Governs certification bodies (CBs) themselves — their competence, consistency, impartiality, and confidentiality when auditing and certifying management systems. It does not set QMS requirements; that is ISO 9001.
Certification Body Accreditation
National accreditation bodies (e.g., UKAS, ANAB) accredit certification bodies against ISO/IEC 17021-1. The IAF's multilateral recognition arrangement keeps accreditation consistent worldwide.
Stage 1 vs. Stage 2 Certification Audits
Stage 1 is a readiness review that evaluates documented information and readiness for Stage 2. Stage 2 is the on-site audit of implementation and effectiveness of the QMS, leading to the certification decision, which is made by CB personnel independent of the audit team.
The Three-Year Certification Cycle
Certified organizations receive surveillance audits at least annually and undergo a full recertification audit before the three-year certification cycle expires. A CB or auditor that consulted on the QMS design cannot later audit that same QMS.
Frequently Asked Questions
How many questions are on the CQI/IRCA ISO 9001 Lead Auditor exam?
The current SARAS-platform exam has 40 questions across 5 weighted sections, taken in 1 hour 45 minutes as an open-book, remotely proctored test.
What is the passing mark for the CQI/IRCA Lead Auditor exam?
Candidates must score at least 50% overall (40 of 80 marks) and meet a minimum threshold in each individual section to pass.
Is the CQI/IRCA Lead Auditor exam open-book?
Yes. Candidates may use their course materials and the ISO standards, but no internet access is permitted during the exam.
What standards does the exam cover?
It covers ISO 9001:2015 (clauses 4-10), the seven quality-management principles and PDCA, ISO 19011:2018 auditing guidelines, and ISO/IEC 17021-1 certification requirements.
Are these CQI/IRCA flashcards free?
Yes. These 50 ISO 9001 QMS Lead Auditor flashcards are free and cover the QMS clauses, the audit lifecycle, nonconformity grading, and writing NC statements.
Explore More CQI and IRCA Auditor Training Exams
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.