Exam Mode

ISO 22301 Lead Auditor

Audit business continuity

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Domain 5 - Conducting an ISO 22301 Audit78%
Domain 2 - Business Continuity Management System Requirement64%
Domain 4 - Preparing an ISO 22301 Audit55%
Domain 3 - Fundamental Audit Concepts and Principles82%
Domain 6 - Closing an ISO 22301 Audit70%
Domain 7 - Managing an ISO 22301 Audit Programme61%
Domain 1 - Fundamental Principles and Concepts of a BCMS74%

The domains assessed

Actual distribution of this product questions.

Domain 5 - Conducting an ISO 22301 Audit70
Domain 2 - Business Continuity Management System Requirement55
Domain 4 - Preparing an ISO 22301 Audit55
Domain 3 - Fundamental Audit Concepts and Principles55
Domain 6 - Closing an ISO 22301 Audit45
Domain 7 - Managing an ISO 22301 Audit Programme45
Domain 1 - Fundamental Principles and Concepts of a BCMS35

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Domain 5 - Conducting an ISO 22301 Audit

    Evaluating Clause 7, the auditor finds that staff with BCMS roles have no evidence of competence and no records of training or experience. Which requirement is affected?

    1. ISO 22301 Clause 9.3, because the periodic management review of the BCMS was not performed as required by top management
    2. ISO 22301 Clause 8.5, because the required business continuity exercises and tests were never conducted at the organisation
    3. ISO 22301 Clause 4.2, because the organisation's relevant interested parties and their needs were not properly identified
    4. ISO 22301 Clause 7.2, because the organisation must determine and ensure the necessary competence of persons doing work affecting BCMS performance and retain evidence
  2. Domain 1 - Fundamental Principles and Concepts of a BCMS

    An auditor finds that an activity has an RTO of 48 hours and a maximum tolerable period of disruption (MTPD) of 24 hours. Why is this a concern?

    1. Because the RTO should be shorter than the MTPD/MAO, otherwise operations would be resumed only after impacts have already become unacceptable
    2. Because the MTPD should always be set longer than the maximum acceptable outage of any one of the organisation's own key suppliers and partners
    3. Because the RPO should always be equal to the MTPD, and no such recovery point objective is shown here at all
    4. Because the RTO and the MTPD must always be set to exactly the same value for every one of the prioritised activities
  3. Domain 2 - Business Continuity Management System Requirement

    While reviewing the context of the organisation, the auditor sees the organisation listed 'rising cyber-attack frequency in the sector' among its determined issues. Under which clause is this most appropriately captured as a determined issue?

    1. Clause 4.1 as an external issue relevant to the BCMS
    2. Clause 8.2.2 as a prioritised activity
    3. Clause 9.1 as a monitoring and measurement result reported to management
    4. Clause 10.2 as a continual improvement action
  4. Domain 4 - Preparing an ISO 22301 Audit

    For a third-party BCMS certification audit, who establishes the audit scope and criteria?

    1. The accreditation body that accredits the certification body
    2. The technical expert assigned to the audit team
    3. The certification body, which establishes the scope and criteria after consulting the client
    4. The auditee's business continuity manager, who defines the scope to suit internal preferences
  5. Domain 6 - Closing an ISO 22301 Audit

    Which statement about feeding audit results back into continual improvement is correct?

    1. After each audit an evaluation or satisfaction form is sent to the auditee together with the audit report.
    2. The auditee rates individual auditors so their salaries can be set.
    3. The auditee must pay an additional administrative fee before it is allowed to receive a copy of the completed audit report.
    4. The satisfaction form replaces the audit report entirely.
  6. Domain 3 - Fundamental Audit Concepts and Principles

    An auditor verifies the business continuity policy, the business impact analysis and the BC plan by reviewing the documents themselves. What type of evidence is gathered, and what affects its reliability?

    1. Mathematical evidence, whose reliability depends on the arithmetic used
    2. Documentary evidence, whose reliability depends on the nature, origin and management of the documents
    3. Physical evidence, whose reliability depends on the auditor's eyesight
    4. Verbal evidence, whose reliability depends chiefly on the seniority and perceived credibility of the interviewee who provides the statement
  7. Domain 7 - Managing an ISO 22301 Audit Programme

    A minor nonconformity was raised at last year's certification audit. At programme level, the responsibility to ensure the corrective action is tracked to completion and verified for effectiveness, then fed back into management review, rests with:

    1. The audit programme, through its follow-up process
    2. The auditee's marketing department
    3. No one, because minor nonconformities require no follow-up
    4. The accreditation body
  8. Domain 5 - Conducting an ISO 22301 Audit

    Which factor increases the reliability of a piece of audit evidence collected during a BCMS audit?

    1. The evidence is more objective and fact-based, for example inspecting the cameras rather than accepting photos or a statement
    2. The evidence comes to the auditor as a spoken verbal assurance rather than as an independently inspected physical record kept on file
    3. The evidence originates from within the audited activity itself rather than from an independent external source
    4. The evidence was collected a long time after the event took place, without any reliable timestamp attached to it
  9. Domain 1 - Fundamental Principles and Concepts of a BCMS

    The auditee explains that it implemented a BCMS before any disruption rather than improvising a response after an incident. Why is this proactive approach valued in the standard?

    1. Because it entirely removes the need for the organisation to carry out a business impact analysis
    2. Because implementing a BCMS before a disruption lets the organisation resume operations before unacceptable levels of impact arise
    3. Because it guarantees that the organisation will never again experience any form of operational disruption
    4. Because it transfers accountability for the BCMS from top management across to the incident response teams
  10. Domain 2 - Business Continuity Management System Requirement

    Which sequence correctly lists the main requirement clauses of ISO 22301:2019 in order?

    1. 4 Context of the organisation, 5 Planning, 6 Leadership, 7 Support, 8 Performance evaluation, 9 Operation, 10 Improvement
    2. 4 Context of the organisation, 5 Leadership, 6 Planning, 7 Support, 8 Operation, 9 Performance evaluation, 10 Improvement
    3. 4 Planning, 5 Context of the organisation, 6 Leadership, 7 Support, 8 Operation, 9 Performance evaluation, 10 Improvement
    4. 4 Leadership, 5 Context of the organisation, 6 Support, 7 Planning, 8 Operation, 9 Improvement, 10 Performance evaluation

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO 22301 Lead Auditor training.

See the training

All exams