Resolution Register as an Output of Management Review

Introduction

Clause 9.3 of ISO 18788 requires that management reviews produce documented outputs in the form of decisions and actions. To ensure governance accountability, these outputs should be formalized into a Resolution Register, which records resolutions passed during management review meetings. This approach elevates the management review process from being an internal “minutes and action log” exercise to a governance-compliant mechanism that aligns with international governance models.

Why a Resolution Register is Important

  1. Governance Compliance
    • Most national Companies Acts require decisions of Boards and Committees to be recorded as formal resolutions.
    • Ensures ISO 18788 implementation is aligned with wider governance frameworks.
  2. Accountability
    • Provides traceability of who decided what, when, and why.
    • Holds decision-makers accountable for outcomes.
  3. Audit Trail
    • Creates reliable evidence for internal and external auditors.
    • Aligns with the Audit Evidence Reliability Model (AERM).
  4. Integration with Risk & Performance
    • Each resolution can be linked to risk registers, incident data, or performance objectives, ensuring decisions support the SOMS ecosystem.
  5. Stakeholder Assurance
    • Demonstrates professionalism and transparency to clients, regulators, and communities.

Required Structure of a Resolution Register

Each resolution should contain:

  • Reference Number (Ref No.) - Unique ID for tracking.
  • Date of Resolution - When the resolution was passed.
  • Description of Decision - Clear wording of the resolution.
  • Linked Clause/Objective - ISO 18788 clause, risk register entry, or objective it addresses.
  • Signed Off By - Name(s) and designation(s) of approving authority.
  • Responsible Person/Owner - Person tasked with implementation.
  • Due Date/Timeline - Deadline for implementation.
  • Status - Open, In Progress, Completed, Overdue.
  • Evidence of Closure - Links to supporting documents, reports, or CAPA records.

Integration with International Governance Models

  • ISO 37000 (Governance of Organizations): Requires transparency, accountability, and recording of governance decisions.
  • King IV Code (South Africa): Emphasizes formalized Board resolutions and disclosure of decisions to stakeholders.
  • OECD Governance Principles: Stress the importance of documentation, decision accountability, and stakeholder trust.
  • Companies Acts (various countries): Require corporate boards and management bodies to maintain resolution registers or decision logs.

By integrating a Resolution Register into ISO 18788 management reviews, organizations align SOMS governance with corporate governance standards, creating a unified governance ecosystem.

Example: Resolution Register Template (Excel)

I've created a workable Excel template that can be used as a Resolution Register.

Columns included:

Ref No. | Date | Description of Decision | Linked Clause/Objective | Signed Off By | Responsible Person | Due Date | Status | Evidence of Closure

Conclusion

A Resolution Register transforms management review outputs into governance-compliant resolutions, bridging ISO 18788 with international governance best practices.

This structured approach ensures that decisions are:

  • Properly documented.
  • Linked to SOMS objectives and risks.
  • Assigned, tracked, and auditable.
  • Aligned with corporate governance obligations.

By embedding a Resolution Register into the SOMS, security organizations create a golden thread from operational data → strategic review → governance resolution → accountability and improvement.