Aegentra Labs
Menu
Login

Free · no account required

ISO/IEC 42001 Lead Auditor practice questions

Five original questions follow an AI referral-prioritisation service across two clinics, examining impact assessment, human oversight, monitoring, supplier responsibilities and evaluation evidence. Reveal each answer to see the reasoning and why the other options fail.

Independent subject review and learner calibration are pending. Explanations use an explicit ISO 19011:2018 audit-guidance baseline. ISO 19011:2026 has replaced it; alignment with the current PECB course materials has not yet been verified. The questions are original practice material, and scores are not a validated prediction of your PECB result.

What this exact sample covers

Clinical referral priorities and AI audit evidence

  • AI risks and impacts
  • Human oversight and monitoring
  • Deployment context and supplier responsibilities

Scenario for Questions 1–5

Referral priorities across two clinics

Morrow Health uses a purchased AI service to rank referrals for clinician review. The intended use is queue prioritisation, and clinicians retain the final triage decision. Its pilot measured overall agreement with senior clinicians, but referrals requiring an interpreter were uncommon in that sample. The service now operates at two clinics with substantially different referral populations.

The operations team reports shorter average waiting times and no confirmed patient injury. At the second clinic, interpreter referrals are repeatedly placed near the bottom of the queue. The clinical lead cannot tell whether this reflects clinical urgency, missing referral information or the model. Her concern is delayed access for a particular group, even if the hospital's throughput target is achieved.

A review screen lets clinicians change the suggested priority after opening a referral. Under the actual workflow, low-ranked referrals may remain unopened for several days, and that period is absent from the override statistics. The supplier provides a current model card but does not set local queue rules. Morrow's AIMS assigns responsibility for intended use and local monitoring to its clinical operations director.

  1. Question 01Domain 1 · analysis

    Which distinction should guide Morrow's assessment of the interpreter-referral issue?

    1. AAssess the interpreter group's confirmed clinical outcomes against the hospital's risk criteria, then determine the need for delayed-access impact analysis.
    2. BAssess delayed referrals within the hospital's queue-performance risk, using average waiting-time improvement to judge the residual service-quality impact.
    3. CAssess the interpreter group's potential delayed access through impact assessment, using those results to inform the hospital's risk decisions.
    the answer and reasoning

    Correct answerC. Assess the interpreter group's potential delayed access through impact assessment, using those results to inform the hospital's risk decisions.

    An impact assessment considers potential effects on individuals and groups; it need not wait for confirmed injury. Morrow's operational gain and the group's possible disadvantage can coexist. The impact information should inform risk assessment and treatment, rather than being collapsed into the hospital's throughput measure or postponed until harm is proved. Reference: ISO/IEC 42001:2023 6.1.2 and 6.1.4.

    Why the other options fail

    • A. The suspected group effect is already relevant to impact analysis. Waiting for confirmed clinical outcomes would exclude a potential effect that the process should consider.
    • B. Throughput describes the hospital's aggregate result. It does not resolve a potentially adverse distribution of effects among people using the service.

    Published exam-scope sources: PECB ISO/IEC 42001 Lead Auditor course · ISO/IEC 42001:2023 — Artificial intelligence management system

  2. Question 02Domain 1 · analysis

    What most directly challenges Morrow's claim that human review adequately controls the prioritisation risk?

    1. AThe supplier describes periodic clinical review, while the local agreement measure evaluates completed triage decisions against senior clinicians' recorded priorities.
    2. BThe intervention rate combines two clinics with different populations, while the clinical team needs to understand each clinic's pattern of overrides.
    3. CThe reviewer can intervene after opening a referral, while the suspected disadvantage accumulates before that referral reaches the review screen.
    the answer and reasoning

    Correct answerC. The reviewer can intervene after opening a referral, while the suspected disadvantage accumulates before that referral reaches the review screen.

    The human intervention is available only after opening, while the suspected disadvantage occurs earlier. Clinic-level override analysis and agreement with senior clinicians are relevant monitoring activities, but neither includes unopened referrals. The decisive issue is whether oversight reaches the failure pathway, not simply whether clinicians can correct a recommendation. Reference: ISO/IEC 42001:2023 Annex A.9.2 and A.9.4.

    Why the other options fail

    • A. Completed decisions can inform monitoring quality, but they miss the pre-opening period that most directly challenges this particular human-review control.
    • B. Clinic-specific rates could improve analysis, but even disaggregated override rates exclude referrals that remain unopened during the suspected delay.

    Published exam-scope sources: PECB ISO/IEC 42001 Lead Auditor course · ISO/IEC 42001:2023 — Artificial intelligence management system

  3. Question 03Domain 1 · analysis

    Which additional measure would best test the specific concern at the second clinic?

    1. ACompare model-clinician agreement by interpreter need and urgency, using referrals with completed clinical review in the same weekly reporting periods.
    2. BCompare time to first review by interpreter need and urgency, retaining referrals still unopened at the end of each weekly period.
    3. CCompare override frequency by interpreter need and urgency, using referrals with completed clinical review in the same weekly reporting periods.
    the answer and reasoning

    Correct answerB. Compare time to first review by interpreter need and urgency, retaining referrals still unopened at the end of each weekly period.

    The concern is unequal delay before first review. That interval needs comparison by interpreter need and urgency without dropping referrals still unopened at period end. Agreement and override measures concern reviewed referrals; even when disaggregated identically, they can omit the people waiting in the queue. Reference: ISO/IEC 42001:2023 9.1 and Annex A.5.4.

    Why the other options fail

    • A. Agreement among reviewed referrals excludes the still-unopened cases where the suspected effect is occurring. It may conceal rather than test queue delay.
    • C. Override frequency concerns referrals already opened for clinical review. Even disaggregation by interpreter need and urgency does not measure the unobserved waiting interval before opening.

    Published exam-scope sources: PECB ISO/IEC 42001 Lead Auditor course · ISO/IEC 42001:2023 — Artificial intelligence management system

  4. Question 04Domain 1 · analysis

    The supplier says the model card transfers safe-use responsibility to Morrow. Which interpretation is most defensible?

    1. AAllocate local queue assurance to Morrow's operating responsibilities, testing supplier duties separately against their agreement and the activities each party performs.
    2. BAllocate safe-use assurance from the model card, testing Morrow's queue practices against the local duties that the supplier assigns in that document.
    3. CAllocate safe-use assurance around final clinical approval, testing disputed recommendations through Morrow's review decisions and supplier explanations of those individual outputs.
    the answer and reasoning

    Correct answerA. Allocate local queue assurance to Morrow's operating responsibilities, testing supplier duties separately against their agreement and the activities each party performs.

    AI responsibilities depend on the organisation's role and the agreed distribution of activities. Morrow controls queue rules, intended use and local monitoring, so it cannot outsource those decisions merely by purchasing a model. Equally, assigning those duties locally does not erase the supplier's agreed information, performance or notification obligations. Reference: ISO/IEC 42001:2023 4.1 and Annex A.10.2.

    Why the other options fail

    • B. The model card is relevant information, but it does not displace agreed responsibilities or Morrow's control of the local queue and monitoring activities.
    • C. Local accountability does not make supplier information relevant only after a complaint. Preventive evaluation and monitoring may depend on that information before disputed decisions occur.

    Published exam-scope sources: PECB ISO/IEC 42001 Lead Auditor course · ISO/IEC 42001:2023 — Artificial intelligence management system

  5. Question 05Domain 1 · analysis

    Which conclusion about the pilot evidence is justified before further investigation?

    1. AThe pilot establishes ranking suitability across the two clinics, with follow-up needed to monitor injury and confirm the persistence of agreement.
    2. BThe sparse pilot coverage limits inference for the second clinic's interpreter group, with follow-up needed to distinguish the possible delay mechanisms.
    3. CThe disparity establishes a model-ranking cause in the second clinic, with follow-up needed to determine the clinical consequences of that ranking.
    the answer and reasoning

    Correct answerB. The sparse pilot coverage limits inference for the second clinic's interpreter group, with follow-up needed to distinguish the possible delay mechanisms.

    Sparse representation limits the inference that can be drawn about the relevant group in a different operational population. It does not itself establish the mechanism or prove model bias. The sound conclusion identifies that evidence limit while recognising that changed use conditions and potential group impacts warrant a targeted assessment. Reference: ISO/IEC 42001:2023 6.1.4 and Annex A.7.4.

    Why the other options fail

    • A. An unchanged model can operate in a changed population and workflow. Overall agreement and absence of confirmed injury do not resolve subgroup suitability.
    • C. The observed disparity establishes a concern, but several mechanisms remain possible. Neither the group difference nor sparse pilot coverage establishes the model as its cause.

    Published exam-scope sources: PECB ISO/IEC 42001 Lead Auditor course · ISO/IEC 42001:2023 — Artificial intelligence management system

Continue preparing

Move from examples to a saved practice session.

Casual mode shows feedback as you answer. Full access adds the complete weighted bank, exam mode, saved results and domain-level analysis for this exact qualification.

Start free practice Read the Lead Auditor study guideRead the complete exam guideBuy the official PECB course