7.2 Conducting the Closing Meeting and Presenting Results
Key Takeaways
- The closing meeting formally ends on-site (or remote execution) audit activities and presents findings and conclusions to auditee management.
- The Lead Auditor chairs a structured agenda covering attendance, scope, sampling limitations, findings, conclusions, and next steps.
- Findings presented at closeout should already have been discussed during the audit; the meeting is not for gathering new evidence.
- Disputes are handled with professionalism, objective evidence, and formal appeal routes—not by negotiating away valid nonconformities.
Purpose of the Closing Meeting
The closing meeting is the formal conclusion of the audit execution phase—whether the audit was on-site, remote, or hybrid. Its purpose is to present audit findings and conclusions so that auditee management, including those accountable for the ISMS, understand the results and the implications for corrective action and, where applicable, certification. In third-party audits, the Lead Auditor also communicates the audit team's recommendation regarding certification status, subject to the certification body's independent decision process.
ISO 19011 expects the closing meeting to be chaired by the Lead Auditor. The tone should be professional, constructive, and factual. Critically, the closing meeting is not the place to introduce surprise findings. Potential nonconformities should already have been discussed with process owners during fieldwork. Surprises damage trust and usually indicate weak daily communication.
Who Should Attend
Attendance should include auditee management with authority over the ISMS, process owners for areas audited, guides, and the audit team. For certification audits, the management representative and, where possible, top management should attend so that Major NCs and certification implications are understood at the right level. Circulate and retain an attendance record; certification bodies commonly require this evidence.
Closing Meeting Agenda
A structured agenda keeps the meeting complete and auditable. The Lead Auditor typically covers the following sequence:
1. Opening, Thanks, and Attendance
Thank the auditee for cooperation and logistics support. Confirm attendance and any absences that affect understanding of results.
2. Reconfirmation of Objectives, Scope, and Criteria
Restate audit objectives, scope boundaries (organizational units, locations, technologies, and exclusions), and criteria such as ISO/IEC 27001:2022 and the SoA version audited. This frames every finding that follows.
3. Confidentiality and Sampling Limitation
Reaffirm confidentiality commitments. Emphasize that the audit was a sampling exercise. Auditors do not examine 100% of records or activities; therefore, undetected nonconformities may still exist. Conformity in the sample does not prove absolute conformity across the entire ISMS. This statement protects both parties from misunderstanding the assurance level provided.
4. Positive Observations and Strengths
Begin with strengths and improvements since the previous audit where evidence supports them. Balanced reporting increases receptiveness without softening genuine NCs.
5. Presentation of Findings
Present Major NCs, Minor NCs, and OFIs. For each NC, walk through the three-part statement: requirement, objective evidence, and failure. Keep presentation crisp; offer detail on request. Use consistent grading language so management sees why one issue is Major and another is Minor.
| Agenda item | Lead Auditor focus | Auditee takeaway |
|---|---|---|
| Scope and criteria | Boundaries and standards used | Context for all results |
| Sampling caveat | Assurance limits | No false certainty from a clean sample |
| Strengths | Evidence-based positives | Recognition of effective controls |
| Nonconformities | Requirement + evidence + failure | Clear basis for CAP work |
| Conclusion / recommendation | Overall ISMS effectiveness view | Certification or programme next steps |
| Follow-up | CAP timelines and verification method | What happens after the meeting |
6. Audit Conclusion and Recommendation
State the overall conclusion on conformity and ISMS effectiveness based on the sample. In certification audits, present the team's recommendation (for example, recommend certification subject to acceptable corrective action on identified Minor NCs, or indicate that Major NCs require verified closure before positive recommendation). The certification body—not the individual auditor—makes the final certification decision.
7. Questions, Disputed Facts, and Next Steps
Allow clarifying questions. Explain CAP submission expectations, verification approach, and the timeline for the written audit report. Do not reopen the entire audit or conduct new interviews during the meeting.
Presenting Results Effectively
Effective presentation is evidence-led:
- Read or paraphrase the requirement citation first so the "against what" is clear.
- Present objective evidence with identifiers (records, dates, system outputs).
- State the nonconformity conclusion and grade.
- Separate OFIs clearly so they are not mistaken for NCs.
- Avoid designing the corrective action in the meeting; that would shift the auditor into a consulting role.
If multiple related Minors were elevated to a Major, explain the systemic rationale so management understands the grading logic.
Handling Disputes and Disagreements
Disputes commonly concern grading, interpretation of ISO/IEC 27001 text, or factual accuracy. Professional responses include:
- Stay calm and objective. Do not personalize disagreement.
- Return to evidence and the cited requirement. Re-state facts and the clause or control wording.
- Listen for new factual evidence. Rarely, the auditee may produce records that change the finding. If facts change, amend accordingly; if not, the finding stands.
- Do not negotiate grades. Do not downgrade a Major to a Minor—or convert an NC to an OFI—to preserve goodwill when evidence supports the original grade.
- Use formal routes. If unresolved, record the disagreement, explain the certification body's (or internal programme's) complaint and appeal process, and continue the agenda.
Practical dispute script
- Acknowledge the concern.
- Re-read the objective evidence and requirement.
- Ask whether any additional factual evidence exists that was not available during fieldwork.
- Confirm whether the disagreement is about facts, interpretation, or grade.
- Either amend based on new facts, maintain the finding, or note an unresolved dispute for appeal.
Closing the Meeting
End by summarizing the count of Major NCs, Minor NCs, and OFIs; restating CAP and report timelines; and thanking participants. Ensure management understands that report content will align with what was presented—no new NCs should appear later without a justified, communicated reason under programme rules.
A well-run closing meeting converts fieldwork into shared understanding. The auditee leaves knowing what failed, why it matters to the ISMS, and what post-audit actions are expected. The audit team leaves with acknowledged facts, a clear conclusion, and a defensible basis for the written report.
Why must the Lead Auditor emphasize sampling during the closing meeting?
Which activity does not belong in a standard ISMS audit closing meeting?
When auditee management strongly disputes a graded nonconformity at closeout, what is the most appropriate Lead Auditor response?