S
The MR should be part of the senior management team for the MR role to be truly effective.
Designating one of the middle/line managers as MR may be fine from a pure compliance and certification perspective. However, this is not the best arrangement from the impact-on-business and perceived-value-to-business perspective.
In many ISO 9001/27001 organizations the quality/information security head/manager is allowed to wear the MR/CISO hat but if the quality/information security head/manager is not part of the operations and functional review meetings his/her contribution to business value-add from ISOs is generally a marginalized one.
Note: CISO (Chief Information Security Officer) is MR-equivalent in a typical ISO 27001 implementation.
Designating one of the middle/line managers as MR may be fine from a pure compliance and certification perspective. However, this is not the best arrangement from the impact-on-business and perceived-value-to-business perspective.
In many ISO 9001/27001 organizations the quality/information security head/manager is allowed to wear the MR/CISO hat but if the quality/information security head/manager is not part of the operations and functional review meetings his/her contribution to business value-add from ISOs is generally a marginalized one.
Note: CISO (Chief Information Security Officer) is MR-equivalent in a typical ISO 27001 implementation.
In short, MR isn't a position/role that can be assigned to anyone in the organization. It's not just about managing audits and meetings but to plan, organize and control the entire management system. It's one thing for someone to hold a managerial position (or being part of mgmt.) but the role of MR is more than just being a manager which in no way to say that the OP isn't capable to hold the position of an MR. It's to be decided by his/her top management who should be assigned the responsibility to steer the management system primarily to give a firm assurance to the customers, to the owners and all interested parties that the organization is capable to consistently meet it's business objectives or say satisfy their requirements and expectations.
