3.4 KiB
3.4 KiB
BRN WMS (200-WMS-26-001-00) — ISO/IEC 29110 audit preparation
1. Questions auditors usually ask
Project Management (PM)
| Usual question | Where to point |
|---|---|
| What was agreed with the customer: scope, deliverables, acceptance criteria? | Statement of Work, Software Project Plan §3 |
| How did you plan: tasks, people, effort, schedule? | Work Schedule, Software Project Plan §5–8 |
| How did you track progress, and what did you do when something slipped? | Progress Status Records (15 periods), Minutes of Meeting |
| What risks did you identify, and were they reviewed? | Software Project Plan §9 (R1–R8); expect "show me a risk that changed during the project" |
| How were changes requested, assessed and approved? | Change Report |
| How were defects recorded and closed? | Correction Register ISS-001–028, each linked to a commit and a test case |
| How is the repository controlled and backed up? | Project Repository, Project Repository (Backup), Software Configuration (main, baseline 6c39700) |
| Did the customer formally accept the product? | Acceptance Report, Validation Results |
Software Implementation (SI)
| Usual question | Where to point |
|---|---|
| Were requirements reviewed and baselined before development? | Customer Requirements (CR01–CR14), SRS (SR01–SR09), requirements baseline 18 Feb 2569 |
| Pick one requirement and show its design, code, test and result | Traceability Record — most common test; rehearse 2–3 requirements end to end |
| Show the design and how it maps to the code | Software Design (units UN01–UN13 with file paths) |
| Who reviewed which documents, what was found, and how was it fixed? | Verification Results V0.1–V1.0 (4 rounds) |
| Show the test cases and test results, including a failure and its retest | Test Case and Test Procedures (45), Test Report, Correction Register |
| What exactly was delivered, and can you rebuild it? | Software, Software Components, Product Operation Guide |
| Are user, operation and maintenance documents available? | Software User Document, Product Operation Guide, Maintenance Document |
Weak points likely to be probed
| Point | What to show | What to say |
|---|---|---|
| No change requests in 8 months | Change Report parts 1–3; Minutes of Meeting 23 May (Rack → Bin), 3 Aug and 14 Aug (Task 4.7) | "Change control was used: 3 items were judged against the criteria and none qualified." Rehearse the advisor's test: "if we removed it, could we still deliver?" |
| All 45 test cases passed in one run | Correction Register: 28 issues found and fixed during development, each linked to a commit and a test case; Test Case and Test Procedures pass rule: defects logged and retested until they pass | "The formal run came after the defects were fixed, so a clean run is the result of that work." If git history has real failing test runs, have one ready |
| Risks never re-rated | Software Project Plan R1–R8; risk table in every Progress Status Record | Pick 1–2 risks that actually occurred (R1 → Rack/Bin decision; R7 → evidence prepared before UAT) and show where they were handled. Do not change ratings in the records now |
| Interviews must match the documents | One rehearsal session with the three people | Developer: how a defect is logged (ISS-002 → commit 92d116f → TC-UN08.002). QA: run TC-UN08.002 (rollback test). PM: trace CR13:001 → SR09:003 → UN08.002 → TC-UN08.002 → Passed in Test Report and Validation Results |