ISO 28000 Lead Auditor: Supply Chain Security
Supply chain security depends on coordinated responsibilities and measures. Use ISO 28000 to structure audit investigations, assess evidence and substantiate conclusions. Make your findings useful to audited managers and improvement decisions.
- Duration
- 4.5 days 31 hours
- Code
- ISO28000LA Code
- Certification
- ISO 28000: Security management Certification
Accredited training for the ISO 28000: Security management certification.
Presentation
An organisation's supply chain can be highly complex from the point of manufacture to the point of sale, and the risk of criminal activity infiltrating it is significant.
This intensive 5-day course provides the knowledge needed to audit a supply chain security management system (SCSMS).
You will develop the expertise and skills to manage internal and external audits in accordance with ISO 19011 guidelines and ISO 17021 certification audit requirements.
Learning best practices will enable participants to master audit techniques, demonstrate their ability to complete an audit programme and ultimately lead an SCSMS audit effectively.
Download the ISO 28000LA guide (in French)
Objectives
- Master the auditing of an ISO 28000-compliant SCSMS.
- Gain a comprehensive understanding of the principles, processes, criteria, standards, methods and techniques needed to manage an SCSMS effectively.
- Understand how to assess SCSMS effectiveness, identify risks, determine whether customer and other interested-party requirements are met, and demonstrate conformity with management system standards.
- Understand how ISO 28000 operates within a supply chain security management system.
- Understand how to integrate an organisation's internal and external context, assess risks and make appropriate decisions within an SCSMS.
Program
Day 1: Introduction to SCSMS concepts
- The ISO 28000 family of standards and the legal and regulatory framework for supply chain security.
- Fundamental principles of supply chain security and physical security.
- The ISO 28000 certification process.
- The SCSMS.
- Detailed presentation of ISO 28000:2007 clauses 4.1 to 4.6.
Day 2: Planning and initiating an ISO 28000 audit
- Audit scope and principles.
- Identify audit objectives, scope and criteria.
- Develop an ISO 28000 certification audit programme and plan.
- Review audit and certification process documentation.
Day 3: Conducting an ISO 28000 audit
- Audit procedures: risk identification and assessment, information security, assurance of auditor competence, sampling methods, record retention, monitoring and review.
- Audit activities: conduct the opening meeting, communicate, review documents, and prepare audit findings and conclusions.
Day 4: Closing and following up an ISO 28000 audit
- Conduct the closing meeting.
- Prepare and distribute the audit report.
- Monitor the audit programme.
- Review and improve the audit programme.
- Corrective and preventive actions for the audit programme.
Day 5: Certification exam
Audience
- Internal auditors.
- Auditors wishing to manage and conduct SCSMS certification audits.
- Project managers and consultants seeking to master SCSMS audit processes.
- People responsible for supply chain security or compliance within an organisation.
- Technical experts preparing for supply chain security auditing roles.
Prerequisites
ISO 28000 Foundation certification or basic knowledge of ISO 28000 and ISO 28001 is recommended.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
Course highlights
The certification exam is included in the course price. If you do not pass, you can retake it within 12 months at no additional cost.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en