A management review that changes nothing isn’t a review!
When I’m brought in to help an operator strengthen its compliance monitoring system, the management review is usually the part nobody flags as a problem. It’s the one element almost every operator gets right on paper: scheduled annually, senior attendees, agenda circulated, minutes filed. From a documentation standpoint, it’s the easiest item to clear off a gap-analysis checklist.
ORO.GEN.200 doesn’t leave much room here. The management review exists to assess the continuing suitability and effectiveness of the compliance monitoring system itself — not to review the findings list, not to confirm audit completion rates. The real question is whether the system, as resourced today, is actually capable of catching the compliance issues present in the operation. That’s a harder question than most management review meetings are built to answer.
I’ve seen this scenario more than once in client engagements. A medium-sized operator runs its annual audit programme and comes out with eight minor findings, nothing systemic. That could mean the operation is well-controlled. It could also mean the audit scope is missing where the real risk sits, the auditors lack the understanding to recognise what they’re looking at, or certain non-conformances have been around so long they’ve stopped being written up at all. They’ve just become “how we do it here.” A review that looks at eight closed minors and signs off that the system works hasn’t tested any of that. It has confirmed eight findings were raised and closed.
The questions that should drive the conversation are operational, not administrative. Is the audit programme targeting where the compliance risk actually sits, or where it’s easiest to schedule? Do the auditors still have the technical currency for what they’re reviewing? Are corrective actions changing behaviour on the line, or just generating paperwork? Does the trend data suggest the operation is drifting? If the record doesn’t show those questions asked and answered, what’s been produced is minutes, not assurance. It’s usually visible within the first ten minutes of reviewing the file.
Take-away: If the only output of your management review is a signed record confirming audits were completed, that meeting served an administrative function only. The regulation calls for a substantive assessment of system capability. Those are two different meetings, and running the first does not satisfy the second.
That gap — between a meeting that confirms activity and one that actually tests capability — is where I spend most of my time with operators who bring me in.