Exemplar Global Certified Courses from USD 119. Ending Soon!

Management Review of an ISMS: What Clause 9.3 Expects

AW

Team @ Audit Workshop

13 min read
Management Review of an ISMS: What Clause 9.3 Expects

Why Management Review Matters More in an ISMS Than Most Systems

If you have worked across multiple ISO standards, you will know that management review is one of those requirements that organisations often treat as a box to tick. A meeting happens once a year, someone reads through a slide deck, a few action items get recorded, and the minutes get filed. That approach might scrape through a surveillance audit for ISO 9001 or ISO 14001. It is far less likely to hold up when the standard in question is ISO 27001.

The management review of an Information Security Management System sits at Clause 9.3 of ISO 27001:2022. On the surface it follows the same structure as every other ISO standard built on the Harmonised Structure. But the inputs are more technical, the stakes are higher, and the expectation that top management genuinely understands what they are reviewing is far more visible when an auditor starts asking questions.

This article walks through exactly what Clause 9.3 requires, what auditors look for when they assess the management review, and the common failures that result in nonconformities. Whether you are a quality or security manager preparing for a certification audit or an auditor building your ISMS audit checklist, this is the practical guidance you need.

The Structure of Clause 9.3 in ISO 27001:2022

Clause 9.3 of ISO 27001:2022 is divided into three subclauses. Understanding how they connect is essential before you can assess whether the management review is genuinely effective.

Clause 9.3.1: General

The general requirement is straightforward. Top management must review the ISMS at planned intervals. The purpose of that review is to ensure the ISMS remains suitable, adequate, and effective. Those three words carry weight. Suitable means it still fits the organisation. Adequate means it covers what it needs to cover. Effective means it is actually working.

The standard does not specify how often the review must occur, only that it happens at planned intervals. For most organisations, this means at least annually. Organisations with higher risk profiles, significant change, or active security incidents may need more frequent reviews. The interval should be documented and justified, not just defaulted to once a year because that is what everyone else does.

Clause 9.3.2: Management Review Inputs

This is where ISO 27001 gets specific. The standard lists the information that must be considered during the management review. This is not a suggested agenda. These are mandatory inputs. If any of them are missing from the review record, that is a nonconformity.

The required inputs under Clause 9.3.2 are:

  • The status of actions from previous management reviews
  • Changes in external and internal issues relevant to the ISMS
  • Changes in the needs and expectations of interested parties, including compliance requirements
  • Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives
  • Feedback from interested parties
  • Results of risk assessment and the status of the risk treatment plan
  • Opportunities for continual improvement

Each of these inputs requires actual data. Not a statement that things are going well. Not a verbal update. Documented evidence that the information was presented, considered, and discussed.

Clause 9.3.3: Management Review Results

The outputs of the management review must also be documented. The standard requires that the results include decisions and actions related to continual improvement opportunities and any need for changes to the ISMS. Those decisions need to be traceable. An auditor should be able to look at the management review output and identify specific decisions that were made, not just a general statement that the system is performing well.

What Auditors Actually Check During an ISMS Management Review

When an auditor assesses Clause 9.3, they are doing more than confirming a meeting took place. They are looking for evidence that top management engaged with the substance of information security performance. Here is how that assessment typically unfolds.

Confirming the Review Happened at Planned Intervals

The first thing an auditor checks is whether the review occurred and whether it occurred within the planned timeframe. If the organisation says management review happens annually and the last one was 18 months ago, that is a finding. The auditor will also check whether the interval itself is documented somewhere, usually in a procedure or the ISMS scope documentation.

Verifying All Mandatory Inputs Were Addressed

The auditor will go through the management review minutes or report and map each mandatory input from Clause 9.3.2 against the documented record. This is a methodical check. If the risk assessment results are not mentioned, that is a gap. If there is no discussion of the status of the risk treatment plan, that is a gap. If audit results are referenced only as a single line saying

internal audit completed with no major findings
without any detail, the auditor will probe further to determine whether that constitutes genuine consideration of the input.

One of the most commonly missed inputs is the status of actions from previous management reviews. Organisations often hold a review, generate action items, and then never formally close them out in the next review. The cycle breaks and there is no documented evidence of follow through. Auditors notice this quickly.

Assessing Whether Top Management Was Actually Involved

This is where ISMS management reviews differ from other standards. An auditor will check who attended the review. If the management review was conducted entirely by the IT manager and the quality team with no representation from the executive or board level, that raises a question about whether it genuinely constitutes a top management review.

ISO 27001 places significant emphasis on leadership. Clause 5.1 requires top management to demonstrate commitment to the ISMS. The management review is one of the most visible mechanisms through which that commitment is demonstrated. An auditor will ask questions of top management directly, and if a CEO or Operations Director cannot speak to the outcomes of the last management review, that signals a disconnect between the paper record and the reality of how the system is governed.

Checking That Outputs Are Actionable and Traceable

The auditor will look at the outputs of the review and assess whether decisions were actually made. Vague statements like

the ISMS continues to perform adequately
are not decisions. Decisions look like: the risk treatment plan will be updated to address the newly identified cloud storage risk by a specific date, with a named owner. The auditor will then trace those decisions forward to see whether they were implemented.

If the management review happened six months ago and the actions have not progressed, that is a concern. It may not immediately be a nonconformity, but it raises questions about the effectiveness of the review process and the organisation's commitment to continual improvement.

Common Nonconformities Against Clause 9.3

Having conducted hundreds of external certification audits across information security and other management system standards, the same failures appear repeatedly. Here are the ones you need to watch for.

Missing Mandatory Inputs

The most common nonconformity is a management review that simply does not address all the required inputs. Risk assessment results and the status of the risk treatment plan are the most frequently absent. Organisations often discuss operational performance but forget that ISO 27001 requires specific attention to the risk register and treatment plan at every review.

No Evidence of Interested Party Feedback

Clause 9.3.2 requires feedback from interested parties to be considered. For many organisations, this means customers, regulators, and suppliers. If the management review has no reference to what interested parties have communicated about information security, and there is no documented process for gathering that feedback, the auditor has grounds for a nonconformity.

Management Review Conducted Without Genuine Top Management Involvement

The review is delegated entirely to the ISMS manager or IT team. Minutes are produced. But when the auditor interviews the CEO or CFO, they cannot explain what was discussed, what decisions were made, or what the current status of the risk treatment plan is. This points to a systemic failure in leadership commitment, which connects back to Clause 5.1 as well as Clause 9.3.

Actions Not Followed Through

The previous review generated five action items. The current review makes no reference to any of them. There is no evidence they were completed, no evidence they were discussed, and no evidence of why they may have been deferred. This breaks the improvement loop that management review is designed to create.

Outputs That Are Not Decisions

The management review results section of the minutes contains no actual decisions. It summarises what was presented but makes no commitments. This fails the output requirement of Clause 9.3.3, which explicitly requires decisions and actions related to improvement opportunities and ISMS changes.

How to Structure an Effective ISMS Management Review

If you are responsible for running the management review, the following structure will help you meet the requirements of Clause 9.3 and produce a record that holds up to audit scrutiny.

Prepare a Formal Agenda Tied to the Standard

Map your agenda directly to the inputs in Clause 9.3.2. Each agenda item should correspond to at least one mandatory input. Assign a presenter to each item and ensure the supporting data is prepared in advance. Do not rely on verbal updates. Have the numbers, the trends, the audit results, and the risk register status ready to present.

Ensure the Right People Are in the Room

Top management must be present. In most organisations, that means the CEO, Managing Director, or equivalent, along with relevant functional heads. The ISMS Manager or Information Security Officer typically facilitates and presents but should not be the only person in the room. If your organisation has a board that has oversight of information security, consider whether board level reporting is appropriate.

Document Inputs and Outputs Separately and Clearly

Your management review record should clearly distinguish between inputs considered and decisions made. A simple two column format works well: what was reviewed, and what was decided as a result. Each decision should have an owner and a target date. This makes follow up straightforward and gives the auditor a clear trail to follow.

Close Out Previous Actions Formally

Start every management review by reviewing the action register from the last review. Record the status of each action. If something was not completed, document why and whether it is being carried forward. This demonstrates that the review is a continuous process, not a standalone annual event.

Link the Review to Risk

The risk assessment and risk treatment plan should be a substantive agenda item, not a footnote. Present the current risk register, highlight any changes since the last review, and confirm the status of treatment actions. If new risks have emerged, document how they were identified and what decisions were made about treatment.

For a related look at how management review works across different standards, the article on how to conduct an effective management review under ISO 9001 provides useful context on the common structure and where ISMS reviews diverge.

How ISMS Management Review Connects to the Rest of Clause 9

Management review does not sit in isolation. It is the culmination of the performance evaluation section of ISO 27001. Clause 9.1 requires monitoring, measurement, analysis, and evaluation. Clause 9.2 requires internal audits. The results of both feed directly into the management review.

An auditor assessing Clause 9.3 will also look at whether the management review is genuinely informed by the outputs of Clause 9.1 and 9.2. If the internal audit programme has not been completed, the management review cannot properly address audit results. If monitoring and measurement processes are not functioning, the performance data presented at the review will be unreliable.

This interconnection is worth understanding if you are preparing for a certification audit. Weaknesses in Clause 9.1 or 9.2 will show up in the management review, and a capable auditor will trace that thread. The article on ISMS internal audits under Clause 9.2 covers the internal audit requirements in detail and explains how the audit programme feeds into performance evaluation.

Auditing Clause 9.3 as an Internal Auditor

If you are an internal auditor assigned to audit the management review process, your job is to assess conformity and effectiveness. Here is a practical approach.

Start by requesting the management review records for the past two or three cycles. Review the minutes or report against the mandatory input list in Clause 9.3.2. Check each input off systematically. Note any that are absent or addressed only superficially.

Then check the attendance record. Who was present? Does that constitute top management as defined in the organisation's own documentation?

Look at the outputs. Are there specific decisions recorded? Are owners and dates assigned? Pull the action register and check the status of items from the previous review.

Finally, if you have the opportunity, interview a member of top management. Ask them what the main outcomes of the last management review were. Ask what the current status of the risk treatment plan is. Their ability to answer those questions tells you a great deal about whether the management review is a genuine governance mechanism or a compliance exercise.

For practical guidance on conducting this kind of interview effectively, the article on how to audit management review provides a solid foundation that applies across standards including ISO 27001.

What Changes When the Organisation Is Larger or More Complex

In larger organisations, the management review may be conducted at multiple levels. A divisional review might feed into a corporate level review. This is acceptable as long as the overall process ensures all mandatory inputs are addressed and top management at the appropriate level is involved in the final review.

In highly regulated industries, such as financial services, healthcare, or government, the management review may need to align with other governance cycles, such as board reporting or regulatory compliance reviews. This is worth documenting explicitly so that an auditor can see how the ISMS management review connects to broader organisational governance.

For organisations operating under frameworks like APRA CPS 234 or the Australian Government's Information Security Manual, the management review is also an opportunity to assess alignment with those external requirements. The inputs around compliance obligations and interested party needs are the natural place to address this.

Training That Builds Real Competence in ISMS Auditing

Understanding Clause 9.3 at a conceptual level is one thing. Knowing how to audit it, how to identify what is missing, and how to write a defensible nonconformity when the evidence falls short requires practical training grounded in real audit experience.

Audit Workshop offers ISO 27001 Internal Auditor and Lead Auditor training designed for practitioners who need to apply these skills in the field. The courses are built around real audit scenarios, not just clause summaries, and are delivered by a lead auditor with over 14 years of hands on certification audit experience across Australia and internationally. If you are preparing to audit an ISMS or building the competence to manage one through certification, the training at Audit Workshop is worth a close look.

Frequently Asked Questions

ISO 27001 Clause 9.3 requires the management review to occur at planned intervals. The standard does not specify a minimum frequency, but annual reviews are the most common approach. Organisations with significant change, active incidents, or high risk profiles may need to review more frequently. Whatever interval is chosen should be documented and consistently followed, as deviating from the planned schedule without justification can result in a nonconformity.
Start Learning

Ready to Build Real Audit Skills?

Join practitioners training with ISO auditors who've conducted 500+ external certification audits.

ISO 9001:2015 Lead Auditor Training Course
20+ enrolled
View Details
Exemplar Global certified
ISO 9001:2015 Lead Auditor Training Course badge
ISO 9001:2015 Lead Auditor

Quality Management Systems (QMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 45001:2018 Lead Auditor Training Course
15+ enrolled
View Details
Exemplar Global certified
ISO 45001:2018 Lead Auditor Training Course badge
ISO 45001:2018 Lead Auditor

Occupational Health and Safety Management Systems (OHSMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
ISO 14001:2026 Lead Auditor Training Course
10+ enrolled
View Details
Exemplar Global certified
ISO 14001:2026 Lead Auditor Training Course badge
ISO 14001:2026 Lead Auditor

Environmental Management Systems (EMS)

Lead AuditorSelf-Paced OnlineDigital BadgeVideo Lessons
USD 249USD 789
Exemplar Global Recognised Training Provider digital badge

Audit Workshop is an Exemplar Global Recognised Training Provider

Globally Recognised, Certified Training

Pass an Exemplar Global Certified course and you earn a Certificate of Attainment and an Exemplar Global digital badge. Audit Workshop graduates can apply for third-party Personnel Certification through Exemplar Global.

  • 12 months of Graduate certification
  • Access to Exemplar Global Community
  • Access to self-coaching assessment
  • Access to webinars, events, and online resources
Learn Anytime

No fixed schedule. Start, pause, and pick up exactly where you left off.

Instant Certificate

Download your digital certificate the moment you complete the course.

Practical Content

Every lesson is built from real-world ISO auditing experience.

Lifetime Access

Course materials are yours to keep and revisit long after you complete.