4 ms·
More Internal (or external) audits in this case would have no impact. The organisation performing the tests was most likely performing their own internal audits
by triggercut 4y ago
More Internal (or external) audits in this case would have no impact. The organisation performing the tests was most likely performing their own internal audits, had that process certified and demonstrated that satisfactorily to certifiers and customers. The only way to counter the risk of a rogue operator trying to cover their tracks is to have a second run from another operator (the risk is then the organisation not the individual), or ideally, and more expensively, have another organisation perform the same tests and a third party confirm an absence of discrepancies.
I would prefer the latter as standard but audit is always a trade off between peace of mind and cost. You can demonstrate that a process is superior and mitigates known risks (however unlikely they are) but there will be those that despite operating under in "no failure" environment will ignore the low likelihood, high impact risks because their risk process puts it in the "green" and there are far more pressing things to spend attention and money on.