[2025年11月]更新のISO-IEC-42001-Lead-Auditor問題集で時間限定!無料アクセスせよ! [Q109-Q128]

Share

[2025年11月]更新のISO-IEC-42001-Lead-Auditor問題集で時間限定!無料アクセスせよ!

ISO-IEC-42001-Lead-Auditor問題集で2025年最新のPECB ISO-IEC-42001-Lead-Auditor試験問題


PECB ISO-IEC-42001-Lead-Auditor 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • ISO
  • IEC 42001監査の実施:この試験セクションでは、主任監査員のスキルを測定し、ISO
  • IEC 42001ガイドラインに従った監査の実施に重点を置きます。監査には、証拠の収集、関連スタッフへのインタビュー、AIマネジメントシステム規格への準拠状況の評価などが含まれます。
トピック 2
  • ISO
  • IEC 42001監査準備:この試験セクションでは、主任監査員のスキルを評価し、AIマネジメントシステム監査の計画と準備方法を網羅します。監査計画の作成、チームメンバーの選定、そして円滑な監査プロセスを実現するための明確な目標設定などが含まれます。
トピック 3
  • 監査の基本概念と原則:このセクションでは、主任監査人のスキルを評価し、証拠収集、公平性、客観性、倫理的行動といった監査の基本的な概念を概説します。信頼性と一貫性のある監査プロセスの基盤となる中核原則を紹介します。
トピック 4
  • ISO
  • IEC 42001監査の終了:このセクションでは、AIコンプライアンス担当者のスキルを評価し、監査プロセスを完了する方法を説明します。監査結果の報告、不適合の管理、継続的な改善とコンプライアンスを確保するためのフォローアップの実施などが含まれます。
トピック 5
  • ISO
  • IEC 42001監査プログラムの管理:この試験セクションでは、AIコンプライアンス担当者のスキルを評価し、監査プログラム全体の監督について扱います。複数の監査の管理、監査パフォーマンスの追跡、そして監査結果をAIガバナンスに関連するより広範な組織目標と整合させることが含まれます。

 

質問 # 109
Did the audit team leader thoroughly review all essential components before deciding to close the nonconformity? Refer to scenario 9.
Scenario 9: ImoAl, headquartered in California. USA, provides Al solutions for various industries such as finance, healthcare, retail, and manufacturing. Its clients include major financial institutions seeking Al powered fraud detection systems, healthcare providers leveraging Al for diagnostics and patient care, retailers optimizing supply chain management with Al forecasting, and manufacturers enhancing production efficiency through Al-driven automation.
ImoAl has recently undergone a certification audit to ensure that its artificial intelligence management system AIMS is in compliance with ISO/IEC 42001. During the audit, a major nonconformity related to data security protocols was identified, requiring urgent resolution.
ImoAl swiftly initiated corrective actions to address the
major nonconformity. The audit follow-up, in agreement with the auditee, was scheduled six weeks after the initial audit. As part of exploring alternatives to audit follow-up, the audit team leader chose to verify the effectiveness of the actions taken by the auditee by scheduling a specific visit to ImoAI's premises.
The follow-up audit involved a thorough evaluation of the effectiveness of these actions. The audit team leader thoroughly examined the corrections, corrective actions, and root cause analysis conducted by ImoAl to assess whether they adequately addressed the nonconformity identified during the initial audit.
In conjunction with the external audit follow-up, ImoAl engaged its internal auditing team to oversee the progress of corrective actions. The AIMS manager of ImoAl updated Ms. Rebecca Hayes, the internal auditor, on the status of corrections and corrective actions prompted by the nonconformity identified during the external audit. Subsequently, Ms. Hayes thoroughly reviewed these measures, analyzing the corrections, root causes, and effectiveness of the implemented actions.
Upon satisfactory validation of the action plans, ImoAl was recommended for certification.

  • A. No, the audit team leader overlooked potential impacts on related processes
  • B. Yes, the audit team leader reviewed all the necessary elements
  • C. No, the audit team leader focused solely on immediate corrective actions without considering long-term prevention strategies

正解:B

解説:
The scenario indicates that the audit team leader thoroughly evaluated ImoAI's corrective actions, root cause analysis, and effectiveness of those actions before closing the nonconformity. This aligns with ISO/IEC
17021-1:2015 Clause 9.4.8, which states that verification must include not only confirmation that the problem was fixed but also that the root cause has been addressed to prevent recurrence.
The use of internal audits (as carried out by Ms. Hayes) further supports the thoroughness of the review process.
Reference:
ISO/IEC 17021-1:2015 Clause 9.4.8 - Verification of effective corrective action ISO 19011:2018 Clause 6.6.4 - Audit follow-up and validation ISO/IEC 42001:2023 Clause 10.2 - Corrective actions and preventive mechanisms Certainly! Below are Questions 75 to 80 formatted in the required structure according to ISO/IEC 42001:2023 Artificial Intelligence Management System Lead Auditor standards, with correct answers and comprehensive explanations.
-


質問 # 110
Scenario 8:
Scenario 8: InnovateSoft, headquartered in Berlin, Germany, is a software development company known for its innovative solutions andcommitment to excellence. It specializes in custom software solutions, development, design, testing, maintenance, and consulting,covering both mobile apps and web development.
Recently, the company underwent an audit to evaluate the effectiveness and compliance of its artificial intelligence management system AIMS against ISO/IEC 42001.
The audit team engaged with the auditee to discuss their findings and observations during the audit's final phases. After evaluating theevidence, the audit team presented their audit findings to InnovateSoft, highlighting the identified nonconformities.
Upon receiving the audit findings, InnovateSoft accepted the conclusions but expressed concerns about some findings inaccuratelyreflecting the efficiency of their software development processes. In response, the company provided new evidence and additionalinformation to alter the audit conclusions for a couple of minor nonconformities identified. After thorough consideration, the audit teamleader clarified that the new evidence did not significantly alter the core conclusions drawn for the nonconformities. Therefore, thecertification body issued a certification recommendation conditional upon the filing of corrective action plans without a prior visit.
InnovateSoft accepted the decision of the certification body. The top management of the company also sought suggestions from theaudit team on resolving the identified nonconformities. The audit team leader offered solutions to address the issues, fostering acollaborative effort between the auditors and InnovateSoft.During the closing meeting, the audit team covered key topics to enhance transparency. They clarified to InnovateSoft that the auditevidence was based on a sample, acknowledging the inherent uncertainty. The method and time frame of reporting and grading findingswere discussed to provide a structured overview of nonconformities. The certification body's process for handling nonconformities,including potential consequences, guided InnovateSoft on corrective actions. The time frame for presenting a plan for correction was communicated, emphasizing urgency. Insights into the certification body's post-audit activities were provided, ensuring ongoing support.
Lastly, the audit team briefed InnovateSoft on complaint and appeal handling.
InnovateSoft submitted the action plans for each nonconformity separately, describing only the detected issues and the correctiveactions planned to address the detected nonconformities. However, the submission slightly exceeded the specified period of 45 days setby the certification body, arriving three days later.
InnovateSoft explained this by attributing the delay to unexpected challengesencountered during the compilation of the action plans.
Question:
Was the audit team leader's attitude appropriate regarding the new evidence provided by the company?

  • A. No, auditors should consult with the certification body before making any decisions regarding new evidence presented after the stage
  • B. No, auditors should not take into consideration new evidence or additional information after reaching audit conclusions
  • C. Yes, auditors should consider the new evidence provided and modify their audit conclusion, if necessary

正解:C

解説:
Auditorsmust remain open to considering additional evidence- even if submitted late - as long as it is relevant and within the audit timeframe.
* ISO/IEC 17021-1:2015 Clause 9.4.7states:"The audit team shall reconsider audit conclusions in light of any new, relevant information received before the audit report is finalized."
* TheLead Auditor Guidereinforces:"Evidence-based decision-making must include post-audit review of any additional submissions before certification decisions are made." Reference:ISO/IEC 17021-1:2015 Clause 9.4.7; ISO/IEC 42001 Lead Auditor Manual - Section 7 ("Handling New Evidence Post-Audit").


質問 # 111
Scenario 4 (continued):
BioNovaPharm, a German biopharmaceutical company, has implemented an artificial intelligence management system AIMSbased on ISO/IEC 42001 to optimize various aspects of drug discovery, including analyzing extensive biological data, identifying potentialdrug candidates, and streamlining clinical trial processes. After having the AIMS in place for over a year, the company contracted acertification body and is now undergoing an AIMS audit to obtain certification against ISO/IEC 42001.
Adopting a risk-based approach, the audit team focused on risk throughout their activities. The level of detail outlined in the audit plancorresponded to the scope and complexity of the audit. The team employed a ranking system for detailed audit procedures, prioritizingthose with the highest risk.
Once the stage 1 audit began, the audit team started reviewing the auditee's documented information. To assess whether BioNovaPharmcomplies with the legal and regulatory requirements related to incident communication, the audit team examined evidence provided bythe company's external legal office. The evidence confirmed that BioNovaPharm applies the requirements of the EU Al Act, whichmandates that providers of high-risk Al systems report serious incidents to relevant authorities.
Following the completion of the stage 1 audit, John, an audit team member, documented the stage 1 audit outputs, including theobservations of the audit team that could result in nonconformities during the on-site audit. However, the audit team leader, Emma, whowas overseeing the audit activities, observed that John failed to document significant observations related to the lack of transparency inthe Al decision-making processes of BioNovaPharm. Considering that Emma observed John's lack of competence in undertaking some audit activities, a disciplinary note was recorded for John.
Question:
Based on Scenario 4, is the decision of the top management representative not to provide theadditional evidence requested by the audit team justifiable?

  • A. No, because verbal evidence is less reliable than the other types of evidence and requires additional supporting evidence
  • B. No, because it is not recommended to conduct interviews with different employees to verify segregation of roles and responsibilities within the organization
  • C. Yes, because the top management representative determined that the answers from the interviews could be corroborated by interviewing different employees
  • D. Yes, because audits are based purely on interview evidence

正解:A

解説:
Verbal evidence alone is consideredless reliable.
* ISO/IEC 42001 Clause 9.2.2 states that"auditors shall corroborate interviews with documented information or other tangible evidence whenever possible."
* TheISO 19011:2018 Guidelines for Auditing Management Systems(adopted for auditing principles) Clause 6.5.6 also clearly specifies:"Interview results should be verified with other forms of evidence because interviews alone are insufficient." Reference:ISO/IEC 42001:2023 Clause 9.2.2; ISO 19011:2018 Clause 6.5.6.


質問 # 112
Question:
A software development company values collaborative decision-making. The CEO often gathers input from employees but retains final decision authority.
Which type of leadership does the CEO most closely embody?

  • A. Laissez-faire
  • B. Democratic
  • C. Autocratic

正解:B

解説:
This describes aDemocratic leadershipstyle - where input from employees is welcomed, and participation is encouraged, but final authority still lies with leadership.
* TheISO/IEC 42001 Lead Auditor Guide (Annex on Leadership Models)identifiesdemocratic leadershipas:"Involving teams in decision-making while the leader retains ultimate authority."
* Clause 5.1of ISO/IEC 42001 emphasizestop management leadership and commitment, including engagement and consultation with relevant roles across the organization.
Reference:ISO/IEC 42001:2023 Clause 5.1; ISO/IEC 42001 Lead Auditor Guide, Section 5 ("Leadership Styles").


質問 # 113
Question:
ReePharm, a pharmaceutical company, has decided to incorporate its AI risk management into the information security management system (ISMS) to identify and address risks related to the procurement, manufacturing, and distribution of pharmaceutical products. Is this decision appropriate?

  • A. No, integrating AI risk management into other management systems would not meet ISO/IEC 42001 requirements
  • B. Yes, integrating AI risk management into other management systems is acceptable
  • C. No, merging AI risk management directly into the ISMS system creates unnecessary complexity without substantial improvements
  • D. Yes, but only if performed after a surveillance audit

正解:B

解説:
ISO/IEC 42001 Clause 6.1 supportsintegration of AI-specific risk management into broader management systems, provided that AI-specific risks are addressed appropriately. Integration is allowed to improve efficiency without compromising the focus on AI risks.
Reference:ISO/IEC 42001:2023 Clause 6.1 (Risk Management in an Integrated Management System).


質問 # 114
Scenario 4 (continued):
BioNovaPharm, a German biopharmaceutical company, has implemented an artificial intelligence management system AIMS based on ISO/IEC 42001 to optimize various aspects of drug discovery, including analyzing extensive biological data, identifying potential drug candidates, and streamlining clinical trial processes. After having the AIMS in place for over a year, the company contracted a certification body and is now undergoing an AIMS audit to obtain certification against ISO/IEC 42001.
Adopting a risk-based approach, the audit team focused on risk throughout their activities. The level of detail outlined in the audit plan corresponded to the scope and complexity of the audit. The team employed a ranking system for detailed audit procedures, prioritizing those with the highest risk.
Once the stage 1 audit began, the audit team started reviewing the auditee's documented information. To assess whether BioNovaPharm complies with the legal and regulatory requirements related to incident communication, the audit team examined evidence provided by the company's external legal office. The evidence confirmed that BioNovaPharm applies the requirements of the EU Al Act, which mandates that providers of high-risk Al systems report serious incidents to relevant authorities.
Following the completion of the stage 1 audit, John, an audit team member, documented the stage 1 audit outputs, including the observations of the audit team that could result in nonconformities during the on-site audit. However, the audit team leader, Emma, who was overseeing the audit activities, observed that John failed to document significant observations related to the lack of transparency in the Al decision-making processes of BioNovaPharm. Considering that Emma observed John's lack of competence in undertaking some audit activities, a disciplinary note was recorded for John.
Question:
Which of the following AI applications for auditing did the audit team employ?

  • A. Augmented analysis
  • B. Automated data validation
  • C. Automated planning
  • D. Augmented audit interviews

正解:B

解説:
The audit team used Automated Data Validation by using AI to gather and validate external digital data (e.
g., drug development information).
* ISO/IEC 42001 Clause 9.2.2 allows the use of automated methods to collect and validate information, provided that the reliability and integrity of such systems are ensured.
* The Lead Auditor Course Guide explains: "Automated data validation tools help auditors improve evidence collection efficiency by cross-referencing multiple datasets with minimal manual intervention." Reference: ISO/IEC 42001:2023 Clause 9.2.2; Lead Auditor Guide Module 5 ("Use of Automated Tools in Audits").


質問 # 115
Was the audit team leader's decision regarding the handling of the technical expert's findings acceptable?
Refer to Scenario 7.
Scenario 7: TastyMade. headquartered in Hamburg, Germany, is an established company in the food manufacturing industry that applies Al technologies in its operations. It has implemented an artificial intelligence management system AIMS based on ISO/IEC 42001 to further strengthen its Al management and ensure compliance with international standards. As part of its commitment to excellence and continual improvement, TastyMade is undergoing an audit process to achieve certification against ISO/IEC 42001.
In preparation for the audit, TastyMade collaborated closely with the audit team leader to develop a detailed audit plan. This plan encompassed objectives, criteria, scope, and logistical arrangements for both on-site and remote audit activities. Recognizing the specialized nature of Al integration, a technical expert was brought in to support the audit team and ensure comprehensive coverage of relevant aspects. Upon discussion with the audit team leader, it was mutually decided that not every audit team member would need a guide throughout the audit process. At times, the TastyMade itself would assume the role of the guide, actively facilitating audit activities.
A formal opening meeting was held with TastyMade's management to provide an overview of the audit process and set expectations. During this meeting, key interested parties were briefed on the audit objectives and the methodologies that would be employed during the audit. Following the meeting, the audit team proceeded with their work, collecting information and conducting tests to evaluate the effectiveness of TastyMade's AIMS.
Daily evening meetings were held to review progress, discuss encountered issues, and facilitate collaboration among audit team members. The audit team leader adopted an open communication approach, encouraging all auditors to share their findings and challenges.
The communication regarding the progress of the audit
was informal, allowing for a fluid exchange of information and updates among team members.
To verify adherence to some requirements of clause 4.1 Understanding the organization and its context, the audit team arbitrarily selected for analysis a representative sample of Al management practices across different departments and functions within the company.
During the audit process, the technical expert uncovered certain technical and operational findings related to the integration and governance of Al systems.
Recognizing the significance of these findings, the expert promptly informed the audit team leader.
Understanding the need for further clarification and direct
communication, the audit team leader authorized the technical expert to address the findings directly with the auditee. However, to ensure proper oversight, the expert was supervised by one of the audit team members.
Throughout the audit, it became apparent that TastyMade promoted a culture of autonomy and decentralized decision-making in Al integration processes. Employees were empowered to set goals, allocate responsibilities, and devise methodologies independently, with management providing guidance and support as needed. This approach fostered innovation and agility within the company

  • A. Yes, technical experts fill knowledge or qualification gaps and must operate under the auditors' supervision
  • B. No, the technical expert should have worked under the direct supervision of the audit team leader
  • C. No, the technical expert should not have been advised to communicate directly with the auditee
  • D. Yes, but only if approved by TastyMade management in advance

正解:A

解説:
Per ISO/IEC 17021-1:2015 (Clause 9.1.6) and ISO 19011:2018, technical experts may be appointed to support the audit team with specific expertise. However, they are not auditors themselves and must work under the direction and supervision of the audit team.
In the scenario, the audit team leader authorized the expert to communicate directly with the auditee while ensuring proper oversight by assigning an auditor to supervise the interaction. This is acceptable and compliant with ISO requirements.
Reference:
ISO/IEC 17021-1:2015, Clause 9.1.6 - Role of technical experts
ISO 19011:2018, Clause 6.2.3 - Use of technical experts
PECB ISO/IEC 42001 Lead Auditor Study Guide - Section: Technical Expert Support


質問 # 116
Scenario 8 (continued):
Scenario 8:
Scenario 8: InnovateSoft, headquartered in Berlin, Germany, is a software development company known for its innovative solutions andcommitment to excellence. It specializes in custom software solutions, development, design, testing, maintenance, and consulting,covering both mobile apps and web development.
Recently, the company underwent an audit to evaluate the effectiveness and compliance of its artificial intelligence management system AIMS against ISO/IEC 42001.
The audit team engaged with the auditee to discuss their findings and observations during the audit's final phases. After evaluating theevidence, the audit team presented their audit findings to InnovateSoft, highlighting the identified nonconformities.
Upon receiving the audit findings, InnovateSoft accepted the conclusions but expressed concerns about some findings inaccuratelyreflecting the efficiency of their software development processes. In response, the company provided new evidence and additionalinformation to alter the audit conclusions for a couple of minor nonconformities identified. After thorough consideration, the audit teamleader clarified that the new evidence did not significantly alter the core conclusions drawn for the nonconformities. Therefore, thecertification body issued a certification recommendation conditional upon the filing of corrective action plans without a prior visit.
InnovateSoft accepted the decision of the certification body. The top management of the company also sought suggestions from theaudit team on resolving the identified nonconformities. The audit team leader offered solutions to address the issues, fostering acollaborative effort between the auditors and InnovateSoft.During the closing meeting, the audit team covered key topics to enhance transparency. They clarified to InnovateSoft that the auditevidence was based on a sample, acknowledging the inherent uncertainty. The method and time frame of reporting and grading findingswere discussed to provide a structured overview of nonconformities. The certification body's process for handling nonconformities,including potential consequences, guided InnovateSoft on corrective actions. The time frame for presenting a plan for correction was communicated, emphasizing urgency. Insights into the certification body's post-audit activities were provided, ensuring ongoing support.
Lastly, the audit team briefed InnovateSoft on complaint and appeal handling.
InnovateSoft submitted the action plans for each nonconformity separately, describing only the detected issues and the correctiveactions planned to address the detected nonconformities. However, the submission slightly exceeded the specified period of 45 days setby the certification body, arriving three days later.
InnovateSoft explained this by attributing the delay to unexpected challengesencountered during the compilation of the action plans.
InnovateSoft submitted corrective action plans for nonconformities three days past the certification body's deadline of 45 days.
Question:
Based on Scenario 8, is InnovateSoft eligible for certification?

  • A. Yes, it is up to the auditee to decide when to submit the action plans
  • B. Yes, the submission of the action plans can be delayed for up to 10 days
  • C. No, the action plans were not submitted within the specified period

正解:B

解説:
While ISO/IEC 17021-1 does not prescribe a strict number of days, certification bodiestypically allow minor grace periods, e.g., 5-10 days, based on internal policy.
* ISO/IEC 17021-1:2015 Clause 9.4.9requires that nonconformities must be addressedwithin a timeframe agreed by the certification body.
* If the delay is minor (e.g., 3 days), and the CB accepts it with justification, the certification process can still proceed.
* TheLead Auditor Manualnotes:"Minor extensions may be granted for corrective actions when justified and documented." Reference:ISO/IEC 17021-1:2015 Clause 9.4.9; ISO/IEC 42001 Lead Auditor Guide - Section 8 ("Certification Decision Timelines").


質問 # 117
A tech company has decided to apply ISO/IEC 42001 specifically to integrate the AIMS with existing management systems, such as the Information Security Management System and the Business Continuity Management System. Which part of ISO/IEC 42001 should the company use as guidance on aligning the AIMS with these systems to ensure cohesive objectives, streamlined processes, and unified documentation?

  • A. Annex B
  • B. Annex D
  • C. Annex C

正解:A

解説:
Annex B of ISO/IEC 42001:2023 provides detailed guidance on the integration of AIMS with other management systems. It supports harmonization with existing systems, such as:
ISO/IEC 27001 (Information Security Management System)
ISO 22301 (Business Continuity Management System)
ISO 9001 (Quality Management System)
Annex B promotes the use of a high-level structure (HLS), aligned terminology, and a risk-based approach to enable integrated planning, unified documentation, and cohesive objectives across systems.
Option B (Annex C) relates to additional implementation guidance for AI-specific controls.
Option C (Annex D) does not exist in ISO/IEC 42001.
Reference:
ISO/IEC 42001:2023, Annex B - Integration with other management system standards ISO/IEC Directives Part 1 - Harmonized Structure (Annex L) PECB Lead Auditor Study Guide, Chapter 3 - Integration of AIMS with existing management systems


質問 # 118
Which control in Annex A emphasizes the importance of security measures in AI system operations?

  • A. Performance Metrics
  • B. Financial Auditing
  • C. Customer Feedback
  • D. Access Control

正解:D

解説:
Annex A of ISO/IEC 42001:2023providesreference controlsto support operational and ethical AI governance. The control that emphasizessecurity in AI system operationsis:
A: 8.2.2 - Access Control: This control requires thatonly authorized individuals or systemscan access, modify, or influence the AI system, ensuringdata integrity and protectionof critical operations.
Access control is afoundational security controlused to prevent unauthorized interference or manipulation of AI behavior or data pipelines.


質問 # 119
Question:
Which of the following examples depicts frequent analysis?

  • A. The auditor selects a sample of employees to determine if they are aware of their roles and responsibilities relevant to AI
  • B. The auditor conducts a yearly review of the company's financial statements to assess long-term financial stability
  • C. The auditor observes the AI system's performance during its initial deployment to ensure it meets operational standards

正解:A

解説:
Frequent analysisinvolves ongoing or regularly performed assessments, such as interviews with employees regarding their role awareness.
* ISO 19011:2018 Clause 6.5.5discusses auditor sampling and analysis, andfrequent analysisrefers to repeated testing of a processover time.
* Periodic financial reviews (annual) or one-time deployment checks don't qualify as frequent - but ongoing interviews and awareness checksdo.
Reference:ISO 19011:2018 Clause 6.5.5; ISO/IEC 42001:2023 Clause 7.3 (Awareness).


質問 # 120
Scenario 5: Aizoia, located in Washington, DC, has revolutionized data analytics, software development, and consulting by using advanced Al algorithms. Central to its success is an Al platform adept at deciphering complex datasets for enhanced insights. To ensure that its Al systems operate effectively and responsibly, Aizoia has established an artificial intelligence management system AIMS based on ISO/IEC 42001 and is now undergoing a certification audit to verify the AIMS's effectiveness and compliance with ISO/IEC 42001.
Robert, one of the certification body's full-time employees with extensive experience in auditing, was appointed as the audit team leader despite not receiving an official offer for the role. Understanding the critical importance of assembling an audit team with diverse skills and knowledge, the certification body selected competent individuals to form the audit team. The certification body appointed a team of seven members to conduct the audit after considering the specific conditions of the audit mission and the required competencies.
Initially, the certification body, in cooperation with Aizoia, defined the extent and boundaries of the audit, specifying the sites (whether physical or virtual), organizational units, and the activities for review. Once the scope, processes, methods, and team composition had been defined, the certification body provided the audit team leader with extensive information, including the audit objectives and documented details on the scope, processes, methods, and team compositions.
Additionally, the certification body shared contact details of the auditee, including locations, time frames, and the duration of the audit activities to be conducted. The team leader also received information needed for evaluating and addressing identified risks and opportunities for the achievement of the audit objectives.
Before starting the audit, Robert wrote an engagement letter, introducing himself to Aizoia and outlining plans for scheduling initial contact. The initial contact aimed to confirm the communication channels, establish the audit team's authority to conduct the audit, and summarize the audit's key aspects, such as objectives, scope, criteria, methods, and team composition. During this first meeting, Robert emphasized the need for access to essential information that would help to conduct the audit.
Moreover, audit logistics, such as scheduling, access, health and safety arrangements, observer attendance, and the need for guides or interpreters, were thoroughly planned. The meeting also addressed areas of interest or concern, preemptively resolving potential issues and finalizing any matters related to the audit team composition.
As the audit progressed, Robert recognized the complexity of Aizoia's operations, leading him to conclude that a review of its Al-related data governance practices was essential for compliance with ISO/IEC 42001.
He discussed this need with Aizoia's management, proposing an expanded audit scope. After careful consideration, they agreed to conduct a thorough review of the Al data governance practices, but there was no mutual decision to officially change the audit scope. Consequently. Robert decided to proceed with the audit based on the original scope, adhering to the initial audit plan, and documented the conversation and decision accordingly.
Based on the scenario above, answer the following question:
Question:
Based on Scenario 5, did the certification body take the necessary steps to assure the overall competence of the audit team?

  • A. No, the certification body should have delegated the responsibility for team selection to the audit team leader
  • B. Yes, the certification body identified the required competencies and selected team members accordingly
  • C. No, the certification body should have based team selection solely on the audit objectives

正解:B

解説:
The certification body must ensure that audit team members possess the competencies necessary for the scope and complexity of the audit.
* ISO/IEC 17021-1:2015 Clause 7.2.1 states: "The certification body shall have a process for determining the competence required for personnel involved in the management and performance of audits."
* ISO/IEC 42001:2023 Clause 9.2 stresses that audit personnel must have appropriate knowledge of AI systems and the management system standards.
* The Lead Auditor Training Manual also explains: "The audit team must collectively possess all the necessary knowledge and skills determined through formal analysis by the certification body." Reference: ISO/IEC 17021-1:2015 Clause 7.2.1; ISO/IEC 42001:2023 Clause 9.2.


質問 # 121
What is the difference between reactive machines and limited-memory AI?

  • A. Reactive machines operate solely on present data, while limited memory AI can temporarily store and learn from past data to improve over time
  • B. Reactive machines can improve their functionality over time by learning from past data, while limited memory AI operates solely on present data
  • C. Reactive machines have conscious understanding of their existence and a sense of self, whereas limited memory AI does not

正解:A

解説:
Reactive machines: These are the simplest form of AI systems. They operate only on current inputs and do not store past data (e.g., IBM's Deep Blue chess computer).
Limited-memory AI: These systems can use past data to make better decisions and predictions - commonly seen in machine learning models like those used in autonomous vehicles.
Therefore, Option C correctly highlights that reactive machines lack memory and operate only on real-time inputs, whereas limited-memory AI can utilize recent past information for learning.
Reference:
ISO/IEC 22989:2022, Clause 3.7 - Types of AI systems
ISO/IEC TR 24028:2020 - Overview of Trustworthiness in AI, includes capability taxonomy PECB AI Lead Auditor Study Guide, Chapter 2.2 - AI System Classifications


質問 # 122
A retail company wants to implement a system that can predict customer buying behavior based on their browsing history and past purchases. Which AI concept would be most suitable for developing this predictive system?

  • A. Natural Language Processing (NLP)
  • B. Machine Learning (ML)
  • C. Deep Learning (DL)
  • D. Computer Vision

正解:B

解説:
Machine Learning (ML)is the most suitable AI concept in this scenario. ML focuses on developing algorithms that canlearn from structured or unstructured dataand make predictions based on historical patterns.
In this case, analyzing customerbrowsing history and purchase recordsfalls directly undersupervised learning, a subcategory of ML, which is typically used forpredictive modelingin retail (such as next-best- offer, product recommendation, or demand forecasting).
According to the PECB Lead Auditor Study Guide (Domain 1),ML is specifically referenced as the core techniquefor prediction systems, user behavior modeling, and data-driven decision-making systems.
Though Deep Learning (DL) is a subset of ML, it is often used for more complex pattern recognition tasks such as image or speech recognition, which is not explicitly required here.
Reference: PECB Lead Auditor Guide - Domain 1, Topic: "AI Concepts" - Table differentiating ML, DL, NLP, and Computer Vision ISO/IEC 42001:2023 Clause 8.2.3 (Operational Planning and Control) - Emphasizes selecting AI techniques appropriate to the context and purpose


質問 # 123
What should audit findings that are nonconformities NOT be recorded as?

  • A. Supporting evidence
  • B. Opportunities for improvement
  • C. Corrective actions needed
  • D. Nonfulfillment of a requirement

正解:B

解説:
Audit findings classified as nonconformities represent a failure to fulfill a requirement and must not be recorded as mere opportunities for improvement (OFIs). Doing so would downplay the seriousness of the issue and could result in miscommunication of risk or oversight during corrective actions.
ISO 19011:2018, Clause 6.5.8, clearly distinguishes nonconformities from observations and improvement opportunities.
Reference:
ISO 19011:2018, Clause 6.5.8 - Audit Findings
PECB ISO/IEC 42001 Lead Auditor Guide - Chapter: Classification of Findings
\===========


質問 # 124
Which statement best reflects the principle of professional skepticism?

  • A. Auditors use their expertise to assess AIMS, ensuring it meets organizational needs and maintains stakeholder trust
  • B. Auditors should always trust the auditee's representation unless contradictory evidence is obvious
  • C. Auditors ensure their reports clearly reflect the system's effectiveness, ethical concerns, and operational issues
  • D. Auditors critically evaluate AI systems, actively seeking evidence that may contradict claims of ethical compliance and accuracy

正解:D

解説:
Professional skepticism is an audit principle emphasizing the need for auditors to maintain a questioning mindset and critically assess evidence. It involves actively searching for inconsistencies or contradictions in the evidence provided.
ISO 19011:2018 emphasizes that auditors must "remain alert to indications of nonconformity and fraud" and
"consider contradictory information." This is especially relevant in AI audits where ethical compliance and data quality must be scrutinized.
Reference:
ISO 19011:2018, Clause 4(e) - Professional Skepticism
ISO/IEC 42001:2023, Clause 9.2.2 - Evaluating objective evidence
PECB ISO/IEC 42001 Lead Auditor Guide - Section: Auditor Attributes and Competence
\===========


質問 # 125
A retail company wants to implement a system that can predict customer buying behavior based on their browsing history and past purchases. Which AI concept would be most suitable for developing this predictive system?

  • A. Natural Language Processing (NLP)
  • B. Machine Learning (ML)
  • C. Deep Learning (DL)
  • D. Computer Vision

正解:B

解説:
Machine Learning (ML)is the most suitable AI concept in this scenario. ML focuses on developing algorithms that canlearn from structured or unstructured dataand make predictions based on historical patterns.
In this case, analyzing customerbrowsing history and purchase recordsfalls directly undersupervised learning, a subcategory of ML, which is typically used forpredictive modelingin retail (such as next-best- offer, product recommendation, or demand forecasting).
According to the PECB Lead Auditor Study Guide (Domain 1),ML is specifically referenced as the core techniquefor prediction systems, user behavior modeling, and data-driven decision-making systems.
Though Deep Learning (DL) is a subset of ML, it is often used for more complex pattern recognition tasks such as image or speech recognition, which is not explicitly required here.


質問 # 126
Based on Scenario 5, Alterhealth determined the audit time. Is this acceptable?
Scenario 5: Alterhealth is a mid-sized technology firm based in Toronto. Canada. It develops Al systems for healthcare providers, focusing on improving patient care, optimizing hospital workflows, and analyzing healthcare data for insights that can improve health outcomes.
To ensure responsible and effective use of Al in its
operations, Alterhealth has implemented an artificial intelligence management system AIMS based on ISO
/IEC 42001. After a year of having the AIMS in place, the
company decided to apply for a certification audit to obtain certification against ISO/IEC 42001.
The company contracted a certification body to conduct the audit, who assembled the audit team and appointed the audit team leader. The audit team leader had conducted a certification audit at Alterhealth in the past. The top management of Alterhealth decided to reject the appointment of this auditor because they believed that they would not receive added value from the audit. In response, the certification body appointed Jonathan, an independent auditor with no prior engagements with Alterhealth, as the new audit team leader. Jonathan's introduction marked the beginning of a collaborative process aimed at evaluating the conformity of the AIMS to ISO/IEC 42001 requirements.
The certification body determined the audit scope, which included only specific departments essential to the integration and application of Al, such as the Al Research, Machine Learning Applications, and Al Ethics and Compliance Departments, and did not cover all of the departments covered by the AIMS scope. Meanwhile, Alterhealth determined the audit time, setting the necessary time frame for planning and conducting a thorough and effective review to ensure all aspects of the AIMS within the selected departments were meticulously reviewed.
Afterward, Jonathan received a detailed offer from the certification body, outlining his role and including information related to the audit, such as the audit's duration, team members, their responsibilities, the limits to the audit engagement, and their salary compensation. With a clear mandate, Jonathan was tasked with a multitude of responsibilities: defining the audit objectives and criteria, planning the audit process, identifying and addressing audit risks, managing communication with Alterhealth, overseeing the audit team, and ensuring a smooth and conflict free execution.
With Jonathan's leadership and a well-defined audit framework in place, the certification audit proceeded with a structured and objective evaluation of Alterhealth's AIMS.

  • A. Yes, the audit time must be determined by the auditee
  • B. Yes, if agreed upon with the auditor in writing
  • C. No, the audit time must be determined by the certification body
  • D. No, the audit time must be determined by the audit team leader

正解:C

解説:
According to ISO/IEC 17021-1:2015 Clause 9.1.4, it is the responsibility of the certification body to determine the audit duration, based on factors such as the scope of the management system, number of personnel, complexity, and risk. While the auditee may provide input for logistical coordination, they do not have the authority to set the audit time unilaterally.
In Scenario 5, it is stated that "Alterhealth determined the audit time," which is not compliant with ISO/IEC
17021-1, as this responsibility lies with the certification body-not the auditee, and not the audit team leader alone.
Reference:
ISO/IEC 17021-1:2015, Clause 9.1.4 - Determination of audit time
ISO/IEC 42001:2023, Clause 9.2 - Internal and external audits
PECB ISO/IEC 42001 Lead Auditor Study Guide - Section: Certification Audit Management


質問 # 127
What among the below list of steps comes before the other ones in the management system audit process?

  • A. Preparing the audit report
  • B. Conducting the opening meeting
  • C. Initiating the audit
  • D. Performing document review

正解:C

解説:
The first step in the audit process isInitiating the audit.
As perISO 19011:2018 - Clause 6.3, initiating the audit involves activities such asappointing the audit team
, defining theaudit scope and objectives, andcommunicating with the auditeeto set expectations.
After initiation, the auditor proceeds withdocument review, followed by theopening meeting, and then moves into audit execution and reporting.


質問 # 128
......

PECB ISO-IEC-42001-Lead-Auditor試験実践テスト問題:https://www.passtest.jp/PECB/ISO-IEC-42001-Lead-Auditor-shiken.html

最新の無料ISO-IEC-42001-Lead-Auditor別格問題集をダウンロード:https://drive.google.com/open?id=18JS4bUzBGZrH-Ki64qWzsbYMdKmq7Xbm