The Closing Meeting
The closing meeting is the formal conclusion of the on-site (or remote) phase of an ISO/IEC 27001 audit. It is chaired by the audit team leader and follows the guidance of ISO 19011 and ISO/IEC 27006. Its purpose is to present the audit findings and conclusions so that the auditee's top management … The closing meeting is the formal conclusion of the on-site (or remote) phase of an ISO/IEC 27001 audit. It is chaired by the audit team leader and follows the guidance of ISO 19011 and ISO/IEC 27006. Its purpose is to present the audit findings and conclusions so that the auditee's top management and other attendees clearly understand them. Attendance is recorded, and participants usually include top management, the ISMS manager, process owners, the audit team, and, where relevant, observers or technical experts. The audit team leader typically begins by thanking the auditee for its cooperation and restating the audit objectives, scope, and criteria. They also remind attendees that an audit is based on sampling, so undetected nonconformities may still exist. Next, the findings are presented. These include strengths, opportunities for improvement, and nonconformities graded as major or minor, each supported by objective evidence and linked to specific clauses of ISO/IEC 27001 or Annex A controls. Because nonconformities have already been communicated during the audit, there should be no surprises. The leader then states the audit conclusion, such as a recommendation for certification, a recommendation conditional on resolving major nonconformities, or no recommendation. They explain that the final decision rests with the certification body and not with the audit team. Post-audit activities are also explained. These include the timeline for the auditee to submit corrective action plans, how the auditor will verify those actions, when the final audit report will be distributed, and the confidentiality of information collected. Attendees are invited to ask questions. Any diverging opinions about findings should be discussed and, if possible, resolved. Unresolved disagreements must be documented. The meeting should remain professional, factual, and constructive, avoiding blame and focusing on continual improvement. A well-conducted closing meeting builds trust, confirms mutual understanding, and gives the auditee a clear path toward conformity with ISO/IEC 27001.
The Closing Meeting in an ISO/IEC 27001 Audit: A Complete Guide for Lead Auditors
Introduction
The closing meeting is the formal end of the on-site (or remote) part of an ISO/IEC 27001 audit. The audit team presents its findings and conclusions to the auditee's management. It is a key step in the audit process described in ISO 19011:2018, clause 6.4.9 (Conducting the closing meeting). For third-party certification audits it is also governed by ISO/IEC 17021-1:2015, clause 9.4.7 and supplemented by ISO/IEC 27006. A Lead Auditor must know what the meeting must cover, who leads it, how to handle disagreement and what happens next.
1. What Is the Closing Meeting?
The closing meeting is chaired by the audit team leader. It is held with the auditee's management and, where appropriate, with those responsible for the audited functions or processes. Its purpose is to present the audit findings and audit conclusions so that the auditee understands and acknowledges them.
It mirrors the opening meeting. The opening meeting confirms the plan and sets expectations. The closing meeting reports results and agrees the way forward.
Key characteristics:
- It takes place after the audit team has held its private team meeting. In that meeting the team reviews findings, grades nonconformities, agrees conclusions and, for certification audits, agrees a recommendation.
- The level of formality depends on the audit. Certification audits are formal, with an attendance record. Internal audits of small organizations may be a short communication of results.
- It is a presentation and clarification session. It is not a negotiation, and it is not a place to introduce new evidence-gathering.
2. Why Is the Closing Meeting Important?
- Transparency and fairness: The auditee hears all findings directly. They get a chance to ask questions before the written report is issued.
- No surprises: Findings should already have been raised during the audit and at daily briefings. The closing meeting confirms them so the final report contains nothing unexpected.
- Shared understanding: Management confirms it understands each nonconformity, the requirement involved and the objective evidence behind it.
- Starts corrective action: It sets out timeframes and expectations for correction and corrective action. This drives continual improvement of the ISMS (ISO/IEC 27001 clause 10).
- Certification decision path: In third-party audits, the auditee learns the team's recommendation. They also learn that the final certification decision rests with the certification body, not the audit team.
- Protects the integrity of the audit: Disagreements are discussed and recorded. Limitations of sampling are disclosed, and complaints and appeals routes are explained. This supports impartiality and credibility.
3. Who Attends?
- Chair: the audit team leader.
- Audit team: all auditors, plus technical experts, observers and guides as appropriate.
- Auditee: top management or their representatives, the ISMS manager or management representative, and process owners of audited areas.
- Attendance record: ISO/IEC 17021-1 requires attendance to be recorded for certification audits. Good practice is to record it in all formal audits.
4. How the Closing Meeting Works: Typical Agenda
ISO 19011:2018 clause 6.4.9 and ISO/IEC 17021-1 clause 9.4.7 together give the following content.
a) Opening and thanks
- Thank the auditee for cooperation and record attendance.
- Restate the audit objectives, scope and criteria, such as ISO/IEC 27001:2022, the Statement of Applicability and the organization's policies.
b) Sampling disclaimer
- Explain that the audit evidence was based on a sample of available information.
- Explain that it is therefore not necessarily fully representative of the overall effectiveness of the ISMS. There is an element of uncertainty.
c) Presentation of findings
- Present positive findings, strengths and good practices. Many auditors present these first.
- Present nonconformities, each stating:
- the requirement (for example, clause 6.1.3 or Annex A control 5.15),
- the objective evidence,
- the statement of nonconformity,
- the grading (major or minor).
- Present opportunities for improvement, where permitted by the audit programme. These must not become consultancy or specific recommended solutions.
d) Audit conclusions
- Give the overall conclusion on the extent of conformity and the effectiveness of the ISMS.
- For certification audits, give the recommendation: for example, recommended for certification, recommended subject to acceptance of corrective action plans, or not recommended. Make clear that the certification body makes the final decision.
e) Method and timeframe of reporting
- Explain how and when the written audit report will be issued, and who will receive it.
f) Process for handling nonconformities
- Explain the process, including the possible consequences for certification status. Examples are delayed certification, suspension or withdrawal.
- Give the timeframe for the auditee to submit a plan for correction and corrective action, including root cause analysis.
- Explain how closure will be verified: by document review or by a follow-up visit, typically required for major nonconformities.
g) Post-audit activities
- Describe follow-up audits, surveillance audits, recertification cycles and corrective action verification.
h) Complaints and appeals
- Explain the certification body's complaint and appeal handling processes, as required by ISO/IEC 17021-1.
i) Questions and divergent opinions
- Invite questions and clarify findings.
- Discuss and, where possible, resolve diverging opinions about findings or conclusions.
- If they cannot be resolved, record them. In certification audits, refer them to the certification body (ISO 19011 6.4.9 and ISO/IEC 17021-1 9.4.7).
j) Close
- Confirm confidentiality of the information obtained, thank attendees and formally close the audit.
5. Handling Disagreement
- A finding should only change if the auditee provides new, verifiable objective evidence showing the requirement was met at the time of the audit. Pressure, seniority or promises of future fixes are not grounds for change.
- A promise to fix the issue does not remove a nonconformity. It becomes part of the correction and corrective action response.
- The audit team leader keeps professional composure, explains the evidence, and records any unresolved disagreement rather than suppressing it.
- If the auditee shows evidence was overlooked, the team leader may verify it. If it is valid, the finding should be withdrawn or regraded. This reflects the principle of an evidence-based approach.
6. Common Pitfalls
- Introducing new nonconformities for the first time at the closing meeting. This is poor practice, so communicate issues during the audit.
- Giving consultancy advice on how to fix nonconformities. This threatens impartiality, especially for certification bodies.
- Implying the audit team grants certification.
- Omitting the sampling statement or the complaints and appeals information.
- Allowing the meeting to become a debate or re-audit.
- Failing to record attendance or unresolved divergent opinions.
- Using vague findings without clear requirement and evidence references.
7. Closing Meeting vs. Related Activities
- Audit team meeting (private): held before the closing meeting to agree findings, grading and conclusions. The auditee is not present.
- Daily briefings: communicate progress and potential findings during the audit.
- Audit report: the formal written record issued after the closing meeting. Its content should be consistent with what was presented.
- Audit follow-up: verification of corrective actions after the audit (ISO 19011 6.7).
Exam Tips: Answering Questions on The Closing Meeting
Tip 1 - Know who leads it. The audit team leader chairs the closing meeting. Answers naming the auditee's management representative or a junior auditor as chair are usually wrong.
Tip 2 - Memorize the mandatory content. Use this mnemonic: S-F-C-R-N-P-A-D.
- Sampling disclaimer
- Findings
- Conclusions and recommendation
- Reporting method and timeframe
- Nonconformity handling and consequences
- Post-audit activities
- Appeals and complaints
- Divergent opinions resolved or recorded
If asked 'which of the following is NOT normally covered', look for items such as detailed solutions or consultancy, or re-auditing.
Tip 3 - Evidence decides, not authority. In scenario questions where a CEO disputes a nonconformity, the best answer is usually this sequence:
- listen,
- review any new objective evidence,
- change the finding only if the evidence demonstrates conformity,
- otherwise record the divergent opinion and refer it to the certification body.
Never choose 'withdraw the finding to maintain goodwill'.
Tip 4 - Certification decision. The audit team recommends, and the certification body decides. Any option stating the lead auditor awards or confirms certification at the closing meeting is incorrect.
Tip 5 - No surprises principle. Expect questions about raising a new major nonconformity only at the closing meeting. The best practice answer is that findings should be communicated during the audit. If something is discovered late, it must still be reported, never hidden, but the auditee should be told as early as possible.
Tip 6 - Avoid consultancy. If asked how to respond when the auditee asks 'How should we fix this?', the correct approach is this:
- explain the requirement and the gap,
- do not prescribe a specific solution, especially in third-party audits, to preserve impartiality.
Tip 7 - Corrective action timing. Know that the auditee must submit correction and corrective action plans within a defined timeframe. Major nonconformities typically require verification, often on-site, before certification can be granted.
Tip 8 - Essay or written answers. Structure your answer using a clear sequence:
- purpose,
- attendees,
- agenda items,
- handling disagreement,
- outputs (attendance record, agreed or recorded findings, next steps).
Cite ISO 19011 clause 6.4.9 and ISO/IEC 17021-1 clause 9.4.7 to show depth. Use correct terminology: audit findings, audit conclusions, objective evidence, correction, corrective action, divergent opinions.
Tip 9 - Watch the keywords. Words like 'always', 'must negotiate' or 'guarantee' often signal wrong options. An auditor cannot guarantee the ISMS is fully effective, because of sampling. Prefer options reflecting professionalism, impartiality and an evidence-based approach.
Tip 10 - Formality depends on context. If a question involves an internal audit of a small team, a less formal closing meeting may be acceptable. Certification audits require a formal meeting with recorded attendance.
Summary
The closing meeting turns audit work into agreed, understood outcomes. Led by the audit team leader, it covers:
- the sampling limitation,
- the findings and conclusions,
- reporting, nonconformity handling and post-audit activities,
- complaints and appeals,
- resolution or recording of disagreements.
In the exam, anchor every answer in objective evidence, impartiality, the 'recommend, not decide' principle, and the requirements of ISO 19011 and ISO/IEC 17021-1.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!