Why Clause 9.1 Is More Than a Tick Box Exercise
Clause 9.1 of ISO 27001 sits in the performance evaluation section of the standard, and it is one of those clauses that organisations often underestimate. On paper it looks simple: monitor things, measure things, analyse the results, evaluate them. In practice, many organisations either over-engineer it into a reporting nightmare or reduce it to a spreadsheet that nobody reads.
On this page
This walkthrough is aimed at quality and information security managers, internal auditors, and anyone preparing for a certification audit who wants to understand what the clause actually demands, what auditors look for, and where organisations commonly go wrong.
The clause applies across ISO 27001:2022, but the principles are consistent with the High Level Structure shared by ISO 9001, ISO 14001, and ISO 45001. If you understand how to work with Clause 9.1 in one standard, you can apply that thinking across all of them.
What Clause 9.1 Actually Says
ISO 27001 Clause 9.1 requires the organisation to determine what needs to be monitored and measured, including information security processes and controls. It then requires the organisation to determine the methods for monitoring, measurement, analysis, and evaluation, as well as when the monitoring and measuring shall be performed and when the results shall be analysed and evaluated.
Crucially, the clause also requires that the results be retained as documented information. This is not optional. If you cannot show an auditor evidence that monitoring and measurement is happening, and that results are being reviewed, you have a gap.
Breaking it down into its component parts makes the clause easier to work with in practice.
What to Monitor and Measure
The first decision is scope. What are you actually going to track? For an ISMS, this typically includes:
- The performance of information security controls from Annex A
- Progress against information security objectives set under Clause 6.2
- Indicators of security incidents, near misses, and vulnerabilities
- Results from risk assessments and risk treatment activities
- Compliance with legal, regulatory, and contractual requirements
- The effectiveness of training and awareness programmes
The key word in the clause is effectiveness. You are not just counting activities. You are evaluating whether those activities are actually working. An organisation that runs monthly phishing simulations but never reviews the click rates or adjusts its training programme accordingly is monitoring without evaluating. That distinction matters enormously to auditors.
Methods for Monitoring and Measurement
The standard does not prescribe specific methods, which is intentional. Your methods need to be appropriate to your organisation, your risk profile, and the controls you have in place. Common approaches include:
- Key performance indicators tracked in a dashboard or register
- Periodic reviews of access control logs and privileged account activity
- Patch compliance reporting from your IT team
- Supplier performance reviews tied to information security requirements
- Physical security inspection records
- Results from internal audits and management reviews
Whatever methods you choose, they need to produce comparable and reproducible results. That phrase comes directly from the standard and it is important. If two people running the same measurement get wildly different results, the method is not fit for purpose. Auditors will probe this when they review your monitoring framework.
When to Monitor and When to Analyse
The clause requires you to define the timing of both the monitoring activity and the analysis of results. These are not always the same thing. You might collect access logs continuously but only analyse them monthly. You might run a phishing simulation quarterly but review the results at the next management review meeting.
The important thing is that the timing is defined, documented, and followed. If your procedure says you review security metrics monthly but the last review was six months ago, that is a nonconformity waiting to happen. Auditors will check the dates on your records.
Exemplar Global Recognised Training ProviderRTP No. 310970Documented Information: What You Need to Keep
Clause 9.1 explicitly requires documented information as evidence of the results of monitoring and measurement. This is a mandatory requirement, not a recommendation. The form that documentation takes is up to you. It might be a dashboard report, a spreadsheet, meeting minutes, or a formal monitoring report. What matters is that the evidence exists and that it demonstrates the results were actually reviewed and acted upon.
A common mistake is to have a monitoring process that generates data but no evidence that anyone looked at it. The logs exist, the reports are generated automatically, but there is no record of a human reviewing the results and making a decision based on them. That gap will attract a nonconformity from most auditors.
Think of it this way: the documentation needs to tell the story of what was measured, what the result was, what it was compared against, and what decision was made. If your records can answer those four questions, you are in reasonable shape.
Connecting Clause 9.1 to Objectives and Risk
Clause 9.1 does not operate in isolation. It connects directly to the information security objectives you set under Clause 6.2, and to the risk treatment activities you planned under Clause 6.1. If you set an objective to reduce phishing susceptibility by 30 percent over 12 months, your monitoring programme needs to be measuring progress against that objective. If you implemented a control to address a specific risk, your monitoring needs to tell you whether that control is working.
This linkage is where many organisations fall short. They have objectives in one document, monitoring data in another, and risk treatment records in a third, with no visible connection between them. When an auditor asks how you know your controls are effective, the answer needs to flow naturally from your monitoring data back to your risk register and your objectives. If it does not, the system is fragmented.
For a practical look at how information security objectives should be structured, the article on setting measurable information security objectives under Clause 6.2 walks through the requirements in detail.
What Auditors Actually Check in Clause 9.1
Having conducted hundreds of external audits across multiple standards, the approach to Clause 9.1 is fairly consistent. Auditors are looking for evidence of a functioning system, not just a documented one. Here is what typically gets examined:
The Monitoring Framework Itself
Auditors will ask to see your documented approach to monitoring and measurement. This might be a procedure, a policy, or a section of your ISMS manual. They want to see that you have defined what is being measured, how, by whom, and how often. If this exists only in someone's head, it does not satisfy the requirement.
Actual Monitoring Records
This is where auditors spend most of their time. They will ask for the records that demonstrate monitoring has occurred. They will check dates to confirm the frequency matches what is documented. They will look for evidence of analysis, not just raw data. A spreadsheet full of numbers with no commentary or conclusions does not demonstrate evaluation.
Evidence of Action
Auditors will look for evidence that the results of monitoring led to something. If a metric shows deteriorating performance, what happened next? If a control is not working as intended, how was that identified and what was done about it? The link between monitoring results and management decisions is critical. This is also where Clause 9.1 connects to Clause 10.1 on continual improvement.
Coverage of Controls
For ISO 27001 specifically, auditors will check whether your monitoring covers the controls you have implemented from Annex A. If you have implemented a control but have no way of knowing whether it is effective, that is a significant gap. You do not need to monitor every control with the same intensity, but you need to demonstrate that you have thought about how effectiveness is assessed for each applicable control.
Common Nonconformities Under Clause 9.1
These are the patterns that appear most frequently in certification and surveillance audits:
- Monitoring without evaluation. Data is collected but there is no documented analysis of what it means or whether performance is acceptable.
- Objectives not connected to measurement. Information security objectives exist but there is no monitoring data that tracks progress against them.
- Outdated records. The monitoring process is defined but the last set of records is months or years old, indicating the process has lapsed.
- No defined frequency. The organisation monitors things but cannot demonstrate when monitoring is supposed to happen or when it did happen.
- Methods not validated. Measurement methods produce results that are inconsistent or cannot be reproduced, raising questions about reliability.
- No evidence of management involvement. Monitoring data exists but there is no evidence it was reviewed by anyone with authority to act on it.
If you are preparing for an internal audit of Clause 9.1, the article on how to audit performance evaluation in an ISMS provides a practical checklist approach you can adapt for your programme.
Practical Tips for Building a Clause 9.1 Framework That Works
Getting Clause 9.1 right does not require sophisticated technology or a dedicated team. It requires clear thinking about what matters and a discipline for following through. Here are some practical approaches that work well in real organisations:
Start With Your Objectives and Risks
Rather than trying to measure everything, start with your information security objectives and your highest-rated risks. What are you trying to achieve? What controls are in place to manage your most significant risks? Build your monitoring framework around those first. You can add breadth over time.
Assign Ownership
Every metric or monitoring activity needs an owner. Someone who is responsible for collecting the data, reviewing it, and escalating issues. Without ownership, monitoring becomes inconsistent and records become unreliable. This is also a requirement under Clause 5.3 on roles and responsibilities.
Create a Simple Monitoring Calendar
Define a schedule for when each monitoring activity occurs and when results are reviewed. This does not need to be complex. A simple table with the activity, frequency, responsible person, and last completed date is sufficient. Review this calendar at your management review meetings.
Make the Link to Decisions Visible
When you review monitoring results, document the outcome. Even if the conclusion is that performance is acceptable and no action is required, record that conclusion. It demonstrates that a human reviewed the data and made a judgement. That is what evaluation means in the context of this clause.
Feed Results Into Management Review
Clause 9.3 requires management review to consider the results of monitoring and measurement. Make sure your monitoring outputs flow naturally into the management review agenda. If your management review minutes do not reference specific monitoring results, that linkage is missing and an auditor will notice.
Exemplar Global Recognised Training ProviderRTP No. 310970Clause 9.1 Across ISO 9001, ISO 14001, and ISO 45001
Because ISO 27001 uses the same High Level Structure as the other major management system standards, Clause 9.1 appears in all of them with very similar requirements. The specific content of what gets monitored differs by standard, but the framework is the same.
For ISO 9001, monitoring focuses on product and service conformity, customer satisfaction, and process performance. For ISO 14001, it includes environmental performance indicators, compliance obligations, and progress against environmental objectives. For ISO 45001, it covers OH&S performance, incident rates, and the effectiveness of controls for significant hazards.
If your organisation operates an integrated management system, you can often consolidate your monitoring framework across all three standards, which reduces duplication and makes the system easier to manage. The approach to auditing an IMS covering ISO 9001, ISO 14001, and ISO 45001 together covers how this works in practice.
For those working specifically with ISO 9001, the detailed requirements of ISO 9001 Clause 9.1.1 on monitoring, measurement, analysis and evaluation provides a useful companion reference.
Preparing for a Certification Audit on Clause 9.1
If you are preparing for a Stage 2 certification audit or a surveillance audit, here is what to have ready for Clause 9.1:
- Your documented monitoring and measurement procedure or equivalent documented information.
- A list of what is being monitored, with defined methods, frequency, and owners.
- Records of monitoring activities from the past 12 months, showing dates and results.
- Evidence of analysis, including documented conclusions and any decisions made.
- Traceability from monitoring results back to your objectives and risk treatment plan.
- Evidence that monitoring results were presented at management review.
If you can walk an auditor through those six items with confidence, you are well positioned for Clause 9.1. The gaps that cause nonconformities are almost always in the evidence, not in the intent. Organisations usually have some form of monitoring happening. The problem is that it is not documented, not consistent, or not connected to anything that drives improvement.













