Audit Evidence for ISO 18788 Management Review

1. Evidence of Planning and Structure

  • Management Review Procedure (governing document): Defines frequency, scope, responsibilities, inputs, and outputs.
  • Annual Management Review Schedule: Calendar of planned reviews (annual, semi-annual, quarterly, tactical reviews).
  • Management Review Agendas: Agendas issued before meetings to ensure all required inputs are addressed.
  • Attendance Records: Signed registers showing participation from Board, CEO, EXCO, tactical managers, and operational supervisors.

2. Evidence of Inputs (as required by ISO 18788)

Auditors will expect to see documented evidence that the following items were reviewed:

  • Monitoring and Measurement Results (Clause 9.1.1): Control monitoring reports, KPIs, KRIs, ICE assessments.
  • Performance Measurement Reports: Trends against strategic, tactical, and operational objectives.
  • Analysis and Evaluation Reports: Gap analysis, lessons learned from incidents.
  • Internal Audit Results (Clause 9.2): Audit reports, findings registers, CAPA status.
  • Incident Management Data (Clause 8.8): Incident registers, investigation reports, root cause analysis.
  • Complaints and Grievances Records: Internal/external complaints, resolutions, whistleblower reports.
  • Human Rights Performance Reports: VPSHR compliance reviews, stakeholder engagement outcomes.
  • Risk and Opportunity Assessments (Clause 6.1): Updated risk registers, risk appetite/tolerance reviews.
  • Legal and Compliance Updates: Changes in laws, regulations, ISO standards, VPSHR commitments.
  • Resource Adequacy Reviews (Clause 7.1): Evidence of budgeting, staffing, equipment, training funds.
  • Competence, Training, and Awareness Records (Clause 7.2-7.4): Skills audits, training effectiveness evaluations, awareness campaign results.
  • Supplier/Subcontractor Performance Evaluations (Clause 8.6): Vetting reports, compliance audits.
  • Corrective and Preventive Actions (CAPA) Logs: Status reports of actions taken from previous audits, incidents, or reviews.
  • Opportunities for Improvement (OFIs): Documented inputs from audits, employees, or clients.

3. Evidence of the Review Process

  • Meeting Minutes: Detailed minutes documenting discussions, evaluations, and decisions on each required input.
  • Presentation Packs/Briefing Reports: Materials submitted for review (trend charts, dashboards, audit summaries).
  • Stakeholder Feedback Integration: Evidence that complaints, grievances, and external stakeholder feedback were considered.
  • Risk-Based Discussions: Records showing how review linked performance back to risk registers and objectives.

4. Evidence of Outputs (as required by ISO 18788)

The outputs of management reviews must be documented, communicated, and implemented. Evidence includes:

  • Decisions and Action Items: Documented outputs of reviews with responsible persons and deadlines.
  • Updated Objectives: Evidence of adjusted strategic, tactical, and operational objectives.
  • Policy Updates: Records showing when governance documents (Security Policy, Use of Force Policy, Whistleblower Policy, etc.) were updated following reviews.
  • Resource Allocation Decisions: Budget approvals, hiring decisions, procurement actions linked to review findings.
  • Corrective Action Plans: CAPAs created or updated during management review.
  • Continual Improvement Records: Logs showing how performance trends are improving across reviews.
  • Communication Records: Evidence that review outputs were cascaded to tactical managers, operational supervisors, and, where necessary, clients and stakeholders.

5. Evidence of Follow-Up

  • Action Logs/Registers: Tracking system for all actions raised in management reviews with closure status.
  • Review of Previous Outputs: Minutes showing how previous review actions were tracked and verified.
  • Effectiveness Verification: Reports showing whether corrective actions and resource allocations had the intended effect.
  • Trend Analysis Reports: Multi-review comparisons showing improvement or recurring issues.

6. Evidence of Strategic, Tactical, and Operational Integration

  • Strategic Reviews: Board/EXCO minutes, VPSHR performance reports, governance dashboards.
  • Tactical Reviews: Divisional/regional review minutes, risk registers updated with review outcomes.
  • Operational Reviews: Supervisor-level reports, site review minutes, weekly/monthly checklists feeding into higher-level reviews.

Summary

To fulfil Clause 9.3 requirements, an organization must maintain a full ecosystem of audit evidence covering:

  • Planning Evidence: Procedures, schedules, agendas, attendance.
  • Input Evidence: Performance data, audits, incidents, risks, resources, complaints, compliance updates.
  • Process Evidence: Minutes, reports, stakeholder feedback integration.
  • Output Evidence: Decisions, corrective actions, updated objectives, resource allocations.
  • Follow-Up Evidence: Action logs, effectiveness reviews, trend analyses.
  • Integration Evidence: Proof that reviews occur at strategic, tactical, and operational levels.

Together, these create a closed-loop assurance process, demonstrating to auditors, clients, and regulators that the SOMS is being systematically reviewed, governed, and improved.