The Opening Meeting
The opening meeting is the formal start of the on-site (or remote) audit activities. ISO 19011 (clause 6.4.3) and ISO/IEC 17021-1 (clause 9.4.2, for certification audits) both describe it. The audit team leader chairs it, and it is usually held with the auditee's top management and, where appropria… The opening meeting is the formal start of the on-site (or remote) audit activities. ISO 19011 (clause 6.4.3) and ISO/IEC 17021-1 (clause 9.4.2, for certification audits) both describe it. The audit team leader chairs it, and it is usually held with the auditee's top management and, where appropriate, the people responsible for the functions or processes to be audited. Attendance should be recorded. The meeting is normally short, often 15 to 30 minutes, but it sets the tone for the whole audit. Its main purposes are to: - confirm that all participants agree to the audit plan - introduce the audit team and explain their roles - ensure that all planned audit activities can be carried out A typical agenda includes: 1. Introductions of the audit team, guides, observers and auditee representatives. 2. Confirmation of the audit objectives, scope and criteria. For ISO/IEC 27001 this includes the ISMS scope, the Statement of Applicability and any exclusions. 3. Confirmation of the audit plan, timetable, interviews, sites and any changes. 4. Explanation of audit methods, including sampling. Because sampling is used, there is a risk that some nonconformities will not be detected. 5. Communication channels and the language of the audit. 6. Confidentiality and information security arrangements. These are especially important in an ISMS audit, for example access to sensitive records, systems and secure areas. 7. Health, safety, security and emergency arrangements for the audit team. 8. Availability of resources and facilities, and the role of guides. 9. How findings will be graded and reported, such as major or minor nonconformities and opportunities for improvement. 10. Conditions under which the audit may be terminated early. 11. Arrangements for the closing meeting, and information on complaints and appeals. The lead auditor should invite questions and clarify concerns. A well-run opening meeting builds trust, reduces anxiety and confirms logistics. It also demonstrates the auditor's professionalism, impartiality and evidence-based approach, which are key competencies assessed in the ISO/IEC 27001 Lead Auditor role.
The Opening Meeting in an ISO/IEC 27001 Audit: A Complete Guide for Lead Auditors
Introduction
The opening meeting is the formal start of the on-site (or remote) audit activities in an ISO/IEC 27001 certification or internal audit. It is defined in ISO 19011:2018 (clause 6.4.3, Conducting the opening meeting) and reflected in ISO/IEC 17021-1 (clause 9.4.2) for certification bodies. ISO/IEC 27006 adds specific requirements for bodies certifying information security management systems (ISMS). For the ISO 27001 Lead Auditor exam, the opening meeting is a frequently tested topic. Candidates must know its purpose, who attends, who leads it, what is covered and how to handle problems that arise during it.
What Is the Opening Meeting?
The opening meeting is a short, structured meeting held at the beginning of the audit. It brings the audit team together with the auditee's management and, where appropriate, the people responsible for the functions or processes being audited. Its main aim is to confirm that everyone agrees to the audit plan, to introduce the audit team and their roles, and to make sure all planned audit activities can be carried out.
Key characteristics:
- It is chaired by the audit team leader.
- It is formal, and an attendance record and minutes are kept.
- It is normally brief, often 15 to 30 minutes, and longer for complex, multi-site or first-time audits.
- Its level of detail depends on how familiar the auditee is with the audit process.
- It can be held face-to-face or remotely using information and communication technology (ICT).
Why Is the Opening Meeting Important?
1. Confirms agreement on the audit plan. The objectives, scope, criteria, schedule and logistics are confirmed with the auditee before evidence collection starts.
2. Builds trust and professionalism. It sets a cooperative, respectful tone. This reduces auditee anxiety and encourages openness, which supports the principle of fair presentation.
3. Clarifies roles and responsibilities. Everyone knows who the auditors, technical experts, observers and guides are, and what each is allowed to do.
4. Manages expectations. The auditee learns how findings will be graded and reported, how nonconformities are handled, and what conclusions are possible. Possible conclusions include a recommendation for certification, or a recommendation subject to corrective action.
5. Reduces risk to the audit. Constraints, safety rules, confidentiality issues and restricted areas are raised early. This avoids surprises that could invalidate the audit or breach security.
6. Provides an opportunity for questions. The auditee can raise concerns before the audit begins.
7. Is a mandatory step for certification audits. ISO/IEC 17021-1 requires a formal opening meeting with records of attendance.
Who Attends?
Audit team leader (chair): leads the meeting.
Audit team members: auditors, technical experts, auditors-in-training.
Auditee management: ideally top management and the ISMS manager or CISO.
Process owners: heads of functions or processes to be audited, where appropriate.
Guides: appointed by the auditee to escort auditors and facilitate access. Guides do not influence or interfere with the audit.
Observers: for example from accreditation bodies, regulators or the audit client. Observers do not take part in the audit.
Attendance should be recorded, for example on an attendance sheet.
How It Works: Typical Agenda
Based on ISO 19011 clause 6.4.3 and ISO/IEC 17021-1 clause 9.4.2, the team leader typically covers the following:
1. Introductions of participants, including observers and guides, with an outline of their roles.
2. Confirmation of the audit objectives, scope and criteria. The criteria are ISO/IEC 27001:2022, the Statement of Applicability (SoA), the organization's policies and legal requirements.
3. Confirmation of the audit plan and related arrangements: the schedule, the date and time of the closing meeting, interim meetings between the audit team and auditee management, and any last-minute changes.
4. Methods used to conduct the audit. These include interviews, observation and document review. The team leader explains that the audit is based on sampling, so the evidence available is limited.
5. Confirmation of formal communication channels between the audit team and the auditee.
6. Confirmation of the language to be used during the audit.
7. Confirmation that the auditee will be kept informed of audit progress.
8. Confirmation of resources and facilities needed by the auditors.
9. Confidentiality and information security matters. This is especially relevant in ISMS audits: handling of sensitive information, restrictions on access to records, and NDAs.
10. Health, safety, security and emergency procedures relevant to the audit team, including access badges and escort rules.
11. Method of reporting audit findings, including how findings are graded (for example major or minor nonconformity, or opportunity for improvement).
12. Conditions under which the audit may be terminated early.
13. Dealing with possible findings during the audit and the closing meeting arrangements.
14. Complaints and appeals process, for certification audits.
15. Feedback channels on the conduct of the audit.
16. Confirmation that the auditee's representative is aware of the audit's status and will be informed of any concerns.
17. Opportunity for the auditee to ask questions.
For certification bodies, ISO/IEC 17021-1 also requires the team leader to confirm three further points:
- The audit team represents the certification body.
- Any updates to the auditee's context since the last audit have been considered.
- Information gathered is treated as confidential.
ISMS-Specific Considerations
- Access to sensitive information. Some records may be too confidential to show auditors, for example security incident details or classified data. These should be identified in advance, ideally during audit preparation. ISO/IEC 27006 states that the certification body must be satisfied there is sufficient evidence. If evidence cannot be accessed, the audit may not be able to reach a conclusion on that area.
- Remote access and tools. The team confirms secure methods for screen sharing and evidence transfer.
- Statement of Applicability. The team confirms the version of the SoA being audited.
- Physical security rules. These cover escort requirements, clean desk rules and restrictions on photography.
Common Issues and How a Lead Auditor Handles Them
Top management absent: Proceed with the most senior available representative and record their absence. The team leader may note this as a concern relating to leadership commitment (clause 5.1). Absence alone is not a nonconformity.
Auditee requests a scope change: The team leader cannot unilaterally accept significant changes. They should consult the audit client or certification body and update the plan if agreed. Changes must be recorded.
Auditee disputes the plan or schedule: Resolve through discussion. Minor adjustments are acceptable if the audit objectives are still met.
Auditee denies access to an area or records: Discuss the reasons and look for alternatives, such as viewing records with sensitive parts redacted. If the objectives cannot be met, report this to the audit client.
Auditee becomes defensive: Reassure them that the audit is objective, evidence-based and sampling-based, and that its aim is to verify conformity, not to find fault.
Opening Meeting vs Closing Meeting
Timing: The opening meeting takes place at the start of the on-site or remote audit. The closing meeting takes place at the end, after the audit conclusions have been prepared.
Purpose: The opening meeting confirms the plan, introduces the team and sets expectations. The closing meeting presents findings and conclusions.
Content: The opening meeting covers what will happen and how. The closing meeting covers what was found and what happens next, such as corrective action timelines.
Chaired by: The audit team leader chairs both meetings.
Records: Attendance is recorded at both meetings.
Exam Tips: Answering Questions on The Opening Meeting
1. Know who chairs it. The answer is always the audit team leader, not the auditee's management representative, the CISO or a technical expert.
2. Remember the core purpose. The purpose is to confirm the agreement of all parties to the audit plan, introduce the audit team and their roles, and ensure all planned activities can be performed. If an option says the opening meeting is for presenting findings, it is wrong; that is the closing meeting.
3. Sampling and limitations. Exams often test whether you know that auditors explain that the audit is sampling-based. They should state that nonconformities may exist in areas not sampled.
4. Confidentiality is a key ISMS point. In scenario questions, confirming the confidentiality arrangements is often the best answer, especially when sensitive data is mentioned.
5. Attendance records. Remember that attendance must be recorded, which is a certification requirement under ISO/IEC 17021-1.
6. Guides and observers. Guides help but do not influence the audit. Observers do not participate. Expect questions testing these roles.
7. Scenario questions on scope changes. The correct approach is to not accept the change on the spot. The team leader should consult the audit client or certification body, assess the impact on the audit objectives and update the plan if needed.
8. Top management absence. Do not choose answers that cancel the audit or raise an immediate major nonconformity. Proceed, record the absence and consider leadership involvement during the audit.
9. Keep it proportionate. For surveillance audits of familiar auditees, the meeting can be shorter. However, it must still be held and its essential points covered.
10. Use the standard language. In essay or scenario answers, cite ISO 19011 clause 6.4.3 and ISO/IEC 17021-1 clause 9.4.2. Use terms such as audit objectives, scope, criteria, audit plan, communication channels, conditions for termination and grading of findings.
11. Structure your written answers. Use the sequence: purpose, then participants, then agenda items, then ISMS-specific points, then how issues are handled. This shows a full, logical understanding.
12. Watch for distractors. Wrong options often include starting to collect evidence, interviewing staff about controls, or negotiating findings during the opening meeting. Evidence collection begins after the opening meeting.
13. Remote audits. For remote audits, the meeting should also confirm the ICT tools, connection tests, secure evidence sharing and backup communication methods.
14. Think like a professional auditor. Choose answers reflecting the audit principles in ISO 19011: integrity, fair presentation, due professional care, confidentiality, independence and an evidence-based approach. Answers that are courteous, factual and plan-focused are usually correct.
Sample Exam Question
During the opening meeting, the IT manager states that server room logs cannot be shown to auditors due to confidentiality. What should the audit team leader do?
Best answer: Discuss alternative ways to verify the controls, such as viewing logs in the presence of the auditee, using redacted records, or observing the logging process. The team leader should also record the limitation. If sufficient evidence cannot be obtained, they should inform the audit client and note that this may affect the audit conclusions.
Summary
The opening meeting is a short, formal, team-leader-chaired session that starts audit activities. It confirms the plan and sets expectations, and it establishes communication, confidentiality and safety arrangements. In an ISMS audit, particular attention goes to access to sensitive information and security rules. In exams, focus on its purpose, participants, agenda items and correct handling of scenarios, and distinguish it clearly from the closing meeting.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!