5.3 Conducting the Opening Meeting

Key Takeaways

  • The opening meeting formally starts on-site or remote audit activity: confirm objectives, scope, criteria, and plan, and establish communication channels.
  • The Lead Auditor introduces the team, explains methods and sampling uncertainty, and defines how findings will be graded and reported.
  • Logistics, health and safety, information security rules for the visit, and confidentiality commitments must be addressed explicitly.
  • A clear, professional tone reduces defensiveness and supports timely access to people and evidence throughout the audit.
Last updated: July 2026

Exam relevance

Opening-meeting items appear within the Conducting the audit domain (14/40 online exam questions). Expect scenarios about what must be confirmed (scope, criteria, plan), what must be explained (sampling, finding categories, communication), and which administrative topics are mandatory (safety, security of the visit, confidentiality). ISO 19011 describes opening meetings as the point where audit arrangements are confirmed and questions are addressed. For certification audits, ISO/IEC 17021-1 expects audits to be conducted according to plan with clear communication—professional opening meetings are how that starts in practice.

Core rules: purpose and tone

The Lead Auditor chairs the opening meeting with management, the ISMS owner/representative, and key process owners. Goals:

  • Confirm audit objectives, scope, and criteria
  • Confirm or adjust the audit plan and logistics
  • Introduce the audit team and roles (auditors, technical experts, observers, guides)
  • Explain methods, sampling, and reporting of findings
  • Establish communication channels and meeting cadence
  • Address health, safety, security, and confidentiality
  • Invite questions and confirm closing-meeting arrangements

Tone should be authoritative and calm—neither aggressive interrogation nor casual chat. Audits are stressful; defensiveness blocks access to evidence. Clarity and respect keep the process objective.

Recommended opening-meeting agenda

Agenda itemLead Auditor actionsWhy it matters
IntroductionsName audit team roles; invite client introductionsMaps contacts to processes
Objectives, scope, criteriaRestate boundaries, standards, and exclusionsPrevents mid-audit scope disputes
Audit plan walk-throughConfirm interviews, locations, remote links, timesSurfaces availability conflicts early
Methods and samplingExplain interviews, observation, document review; sampling uncertaintyManages expectations on "no findings"
Finding categoriesDefine major/minor nonconformity and OFI (as used by the CB)Reduces closing-meeting arguments
Logistics and H&SEscorts, rooms, badges, evacuation, PPEProtects people and schedule
Security & confidentialityDevice rules, photo bans, secure evidence transferProtects sensitive ISMS data
CommunicationsDaily wrap-ups; named contactsKeeps management informed
Questions & closing timeConfirm Q&A and closing meeting slotFormalizes next steps

Explaining methodology without over-promising

Evidence will be collected through:

  • Interviews with process owners and practitioners
  • Observation of activities and the work environment
  • Review of documented information and records

Because audits sample available information, absence of reported nonconformities does not prove absolute conformity everywhere. State this plainly. Also explain how findings will be classified and when they will be communicated (for example, as they arise and/or in daily briefings), so surprises at the closing meeting are minimized.

Logistics, safety, security, and confidentiality checklist

  • Confirm guides/escorts and access to agreed areas and systems
  • Confirm emergency procedures and any site-specific hazards
  • Confirm rules on cameras, phones, removable media, and printing
  • Confirm secure channels for sharing screenshots, logs, and tickets (especially for remote audits)
  • Reaffirm NDA/confidentiality: audit information used only for audit purposes and protected against unauthorized disclosure
  • Confirm language, interpreters, and any observers' status

Remote openings add identity checks for participants, stable screen-share for the plan, and explicit agreement on evidence transfer tools that meet confidentiality expectations.

Scenario: scope creep attempt in the opening meeting

At opening, a CIO asks the team to "also quickly look at the newly acquired subsidiary" that was excluded from the certified ISMS scope and the agreed Stage 2 plan. The Lead Auditor thanks them for the request, restates the confirmed scope and criteria, and explains that expanding boundaries mid-audit would invalidate timeboxing and sampling design. Options offered: keep the agreed scope now, or pause to renegotiate contract/scope with the certification body before continuing. The CIO accepts the planned scope. By handling this in the opening meeting—not after two days of informal "extra" sampling—the Lead Auditor protects audit integrity and avoids unplanned conclusions about entities outside criteria.

Confirming plan logistics without losing control of the audit

The opening meeting is also where last-minute availability problems surface: a key process owner is on leave, a data center escort is delayed, or VPN tokens for remote evidence review fail. The Lead Auditor should adjust sequence and timeboxes while protecting audit objectives. Acceptable flexibility includes swapping interview slots or shifting a low-risk process to later. Unacceptable "flexibility" includes casually adding out-of-scope entities, skipping high-risk processes because the owner is busy, or accepting client-chosen samples that avoid known weak areas. Guides and observers should be identified; guides facilitate access but must not answer for interviewees or filter evidence.

Remote/hybrid specifics to confirm aloud:

  • Participant identity and role for each dial-in attendee
  • Breakout rooms or separate calls for parallel audit streams
  • Screen-share and recording rules (usually no recording unless contractually agreed)
  • How offline sites or paper records will be covered if the audit is partly remote

Managing resistance and closing the meeting

If participants appear anxious or hostile, restate that the audit evaluates the management system against agreed criteria—it is not a personal performance review. Emphasize continual improvement and the need for timely access to people and records. If someone challenges auditor competence or confidentiality, respond factually: outline roles, accreditation/certification-body framework at a high level, and the binding confidentiality arrangements—without becoming defensive or argumentative.

Second scenario: safety and device rules ignored

An opening meeting rushes past H&S. Mid-morning, an auditor enters a restricted operations hall with an unmarked tripping hazard and begins photographing rack labels on a personal phone, violating the client's no-camera policy. The audit stops for an incident discussion; trust drops; IT restricts further access. A proper opening meeting would have covered evacuation routes, escorts, camera bans, and approved evidence-capture methods (for example, client-assisted screenshots via a secure share). Administrative topics are not bureaucracy—they protect people, the client's security posture, and the audit schedule.

Record attendance, confirm the closing-meeting time and place (or link), answer remaining questions, and then begin evidence gathering promptly. A disciplined opening meeting is short relative to Stage 2, but it prevents the costliest failures: wrong scope, missing interviewees, unclear finding language, unsafe or insecure site conduct, and confidentiality misunderstandings. Master it as a Lead Auditor skill, not a formality.

Test Your Knowledge

Why should the Lead Auditor explain during the opening meeting that the audit is based on sampling?

A
B
C
D
Test Your Knowledge

What is the main benefit of explaining finding categories (for example major nonconformity, minor nonconformity, opportunity for improvement) in the opening meeting?

A
B
C
D
Test Your Knowledge

Which administrative topic must the Lead Auditor explicitly address in the opening meeting before on-site work proceeds?

A
B
C
D