Why Management Review Matters More in an ISMS Than Most Systems
If you have worked across multiple ISO standards, you will know that management review is one of those requirements that organisations often treat as a box to tick. A meeting happens once a year, someone reads through a slide deck, a few action items get recorded, and the minutes get filed. That approach might scrape through a surveillance audit for ISO 9001 or ISO 14001. It is far less likely to hold up when the standard in question is ISO 27001.
On this page
The management review of an Information Security Management System sits at Clause 9.3 of ISO 27001:2022. On the surface it follows the same structure as every other ISO standard built on the Harmonised Structure. But the inputs are more technical, the stakes are higher, and the expectation that top management genuinely understands what they are reviewing is far more visible when an auditor starts asking questions.
This article walks through exactly what Clause 9.3 requires, what auditors look for when they assess the management review, and the common failures that result in nonconformities. Whether you are a quality or security manager preparing for a certification audit or an auditor building your ISMS audit checklist, this is the practical guidance you need.
The Structure of Clause 9.3 in ISO 27001:2022
Clause 9.3 of ISO 27001:2022 is divided into three subclauses. Understanding how they connect is essential before you can assess whether the management review is genuinely effective.
Clause 9.3.1: General
The general requirement is straightforward. Top management must review the ISMS at planned intervals. The purpose of that review is to ensure the ISMS remains suitable, adequate, and effective. Those three words carry weight. Suitable means it still fits the organisation. Adequate means it covers what it needs to cover. Effective means it is actually working.
The standard does not specify how often the review must occur, only that it happens at planned intervals. For most organisations, this means at least annually. Organisations with higher risk profiles, significant change, or active security incidents may need more frequent reviews. The interval should be documented and justified, not just defaulted to once a year because that is what everyone else does.
Clause 9.3.2: Management Review Inputs
This is where ISO 27001 gets specific. The standard lists the information that must be considered during the management review. This is not a suggested agenda. These are mandatory inputs. If any of them are missing from the review record, that is a nonconformity.
The required inputs under Clause 9.3.2 are:
- The status of actions from previous management reviews
- Changes in external and internal issues relevant to the ISMS
- Changes in the needs and expectations of interested parties, including compliance requirements
- Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives
- Feedback from interested parties
- Results of risk assessment and the status of the risk treatment plan
- Opportunities for continual improvement
Each of these inputs requires actual data. Not a statement that things are going well. Not a verbal update. Documented evidence that the information was presented, considered, and discussed.
Clause 9.3.3: Management Review Results
The outputs of the management review must also be documented. The standard requires that the results include decisions and actions related to continual improvement opportunities and any need for changes to the ISMS. Those decisions need to be traceable. An auditor should be able to look at the management review output and identify specific decisions that were made, not just a general statement that the system is performing well.
Exemplar Global Recognised Training ProviderRTP No. 310970What Auditors Actually Check During an ISMS Management Review
When an auditor assesses Clause 9.3, they are doing more than confirming a meeting took place. They are looking for evidence that top management engaged with the substance of information security performance. Here is how that assessment typically unfolds.
Confirming the Review Happened at Planned Intervals
The first thing an auditor checks is whether the review occurred and whether it occurred within the planned timeframe. If the organisation says management review happens annually and the last one was 18 months ago, that is a finding. The auditor will also check whether the interval itself is documented somewhere, usually in a procedure or the ISMS scope documentation.
Verifying All Mandatory Inputs Were Addressed
The auditor will go through the management review minutes or report and map each mandatory input from Clause 9.3.2 against the documented record. This is a methodical check. If the risk assessment results are not mentioned, that is a gap. If there is no discussion of the status of the risk treatment plan, that is a gap. If audit results are referenced only as a single line saying
internal audit completed with no major findingswithout any detail, the auditor will probe further to determine whether that constitutes genuine consideration of the input.
One of the most commonly missed inputs is the status of actions from previous management reviews. Organisations often hold a review, generate action items, and then never formally close them out in the next review. The cycle breaks and there is no documented evidence of follow through. Auditors notice this quickly.
Assessing Whether Top Management Was Actually Involved
This is where ISMS management reviews differ from other standards. An auditor will check who attended the review. If the management review was conducted entirely by the IT manager and the quality team with no representation from the executive or board level, that raises a question about whether it genuinely constitutes a top management review.
ISO 27001 places significant emphasis on leadership. Clause 5.1 requires top management to demonstrate commitment to the ISMS. The management review is one of the most visible mechanisms through which that commitment is demonstrated. An auditor will ask questions of top management directly, and if a CEO or Operations Director cannot speak to the outcomes of the last management review, that signals a disconnect between the paper record and the reality of how the system is governed.
Checking That Outputs Are Actionable and Traceable
The auditor will look at the outputs of the review and assess whether decisions were actually made. Vague statements like
the ISMS continues to perform adequatelyare not decisions. Decisions look like: the risk treatment plan will be updated to address the newly identified cloud storage risk by a specific date, with a named owner. The auditor will then trace those decisions forward to see whether they were implemented.
If the management review happened six months ago and the actions have not progressed, that is a concern. It may not immediately be a nonconformity, but it raises questions about the effectiveness of the review process and the organisation's commitment to continual improvement.
Common Nonconformities Against Clause 9.3
Having conducted hundreds of external certification audits across information security and other management system standards, the same failures appear repeatedly. Here are the ones you need to watch for.
Missing Mandatory Inputs
The most common nonconformity is a management review that simply does not address all the required inputs. Risk assessment results and the status of the risk treatment plan are the most frequently absent. Organisations often discuss operational performance but forget that ISO 27001 requires specific attention to the risk register and treatment plan at every review.
No Evidence of Interested Party Feedback
Clause 9.3.2 requires feedback from interested parties to be considered. For many organisations, this means customers, regulators, and suppliers. If the management review has no reference to what interested parties have communicated about information security, and there is no documented process for gathering that feedback, the auditor has grounds for a nonconformity.
Management Review Conducted Without Genuine Top Management Involvement
The review is delegated entirely to the ISMS manager or IT team. Minutes are produced. But when the auditor interviews the CEO or CFO, they cannot explain what was discussed, what decisions were made, or what the current status of the risk treatment plan is. This points to a systemic failure in leadership commitment, which connects back to Clause 5.1 as well as Clause 9.3.
Actions Not Followed Through
The previous review generated five action items. The current review makes no reference to any of them. There is no evidence they were completed, no evidence they were discussed, and no evidence of why they may have been deferred. This breaks the improvement loop that management review is designed to create.
Outputs That Are Not Decisions
The management review results section of the minutes contains no actual decisions. It summarises what was presented but makes no commitments. This fails the output requirement of Clause 9.3.3, which explicitly requires decisions and actions related to improvement opportunities and ISMS changes.
How to Structure an Effective ISMS Management Review
If you are responsible for running the management review, the following structure will help you meet the requirements of Clause 9.3 and produce a record that holds up to audit scrutiny.
Prepare a Formal Agenda Tied to the Standard
Map your agenda directly to the inputs in Clause 9.3.2. Each agenda item should correspond to at least one mandatory input. Assign a presenter to each item and ensure the supporting data is prepared in advance. Do not rely on verbal updates. Have the numbers, the trends, the audit results, and the risk register status ready to present.
Ensure the Right People Are in the Room
Top management must be present. In most organisations, that means the CEO, Managing Director, or equivalent, along with relevant functional heads. The ISMS Manager or Information Security Officer typically facilitates and presents but should not be the only person in the room. If your organisation has a board that has oversight of information security, consider whether board level reporting is appropriate.
Document Inputs and Outputs Separately and Clearly
Your management review record should clearly distinguish between inputs considered and decisions made. A simple two column format works well: what was reviewed, and what was decided as a result. Each decision should have an owner and a target date. This makes follow up straightforward and gives the auditor a clear trail to follow.
Close Out Previous Actions Formally
Start every management review by reviewing the action register from the last review. Record the status of each action. If something was not completed, document why and whether it is being carried forward. This demonstrates that the review is a continuous process, not a standalone annual event.
Link the Review to Risk
The risk assessment and risk treatment plan should be a substantive agenda item, not a footnote. Present the current risk register, highlight any changes since the last review, and confirm the status of treatment actions. If new risks have emerged, document how they were identified and what decisions were made about treatment.
For a related look at how management review works across different standards, the article on how to conduct an effective management review under ISO 9001 provides useful context on the common structure and where ISMS reviews diverge.
How ISMS Management Review Connects to the Rest of Clause 9
Management review does not sit in isolation. It is the culmination of the performance evaluation section of ISO 27001. Clause 9.1 requires monitoring, measurement, analysis, and evaluation. Clause 9.2 requires internal audits. The results of both feed directly into the management review.
An auditor assessing Clause 9.3 will also look at whether the management review is genuinely informed by the outputs of Clause 9.1 and 9.2. If the internal audit programme has not been completed, the management review cannot properly address audit results. If monitoring and measurement processes are not functioning, the performance data presented at the review will be unreliable.
This interconnection is worth understanding if you are preparing for a certification audit. Weaknesses in Clause 9.1 or 9.2 will show up in the management review, and a capable auditor will trace that thread. The article on ISMS internal audits under Clause 9.2 covers the internal audit requirements in detail and explains how the audit programme feeds into performance evaluation.
Auditing Clause 9.3 as an Internal Auditor
If you are an internal auditor assigned to audit the management review process, your job is to assess conformity and effectiveness. Here is a practical approach.
Start by requesting the management review records for the past two or three cycles. Review the minutes or report against the mandatory input list in Clause 9.3.2. Check each input off systematically. Note any that are absent or addressed only superficially.
Then check the attendance record. Who was present? Does that constitute top management as defined in the organisation's own documentation?
Look at the outputs. Are there specific decisions recorded? Are owners and dates assigned? Pull the action register and check the status of items from the previous review.
Finally, if you have the opportunity, interview a member of top management. Ask them what the main outcomes of the last management review were. Ask what the current status of the risk treatment plan is. Their ability to answer those questions tells you a great deal about whether the management review is a genuine governance mechanism or a compliance exercise.
For practical guidance on conducting this kind of interview effectively, the article on how to audit management review provides a solid foundation that applies across standards including ISO 27001.
Exemplar Global Recognised Training ProviderRTP No. 310970What Changes When the Organisation Is Larger or More Complex
In larger organisations, the management review may be conducted at multiple levels. A divisional review might feed into a corporate level review. This is acceptable as long as the overall process ensures all mandatory inputs are addressed and top management at the appropriate level is involved in the final review.
In highly regulated industries, such as financial services, healthcare, or government, the management review may need to align with other governance cycles, such as board reporting or regulatory compliance reviews. This is worth documenting explicitly so that an auditor can see how the ISMS management review connects to broader organisational governance.
For organisations operating under frameworks like APRA CPS 234 or the Australian Government's Information Security Manual, the management review is also an opportunity to assess alignment with those external requirements. The inputs around compliance obligations and interested party needs are the natural place to address this.
Training That Builds Real Competence in ISMS Auditing
Understanding Clause 9.3 at a conceptual level is one thing. Knowing how to audit it, how to identify what is missing, and how to write a defensible nonconformity when the evidence falls short requires practical training grounded in real audit experience.
Audit Workshop offers ISO 27001 Internal Auditor and Lead Auditor training designed for practitioners who need to apply these skills in the field. The courses are built around real audit scenarios, not just clause summaries, and are delivered by a lead auditor with over 14 years of hands on certification audit experience across Australia and internationally. If you are preparing to audit an ISMS or building the competence to manage one through certification, the training at Audit Workshop is worth a close look.













