What Clause 10.1 Actually Says
Clause 10.1 of ISO 27001:2022 is short. It reads, in essence, that the organisation shall continually improve the suitability, adequacy, and effectiveness of the information security management system. That is it. No prescriptive method, no required tools, no mandated frequency. Just a clear expectation that your ISMS must get better over time.
On this page
For some practitioners, that brevity is liberating. For others, it raises an immediate question: what does continual improvement actually look like in an information security context, and how do you demonstrate it to an auditor?
This article answers both questions. We will unpack what the clause requires, where the inputs to improvement come from, what auditors look for when they assess Clause 10.1, and what genuine improvement looks like versus the paper exercise that fools nobody.
Why Continual Improvement Sits at the End of the Standard
ISO 27001 follows the Harmonised Structure used across all modern ISO management system standards. Clause 10 sits at the close of that structure alongside nonconformity and corrective action. The placement is deliberate. By the time you reach Clause 10.1, you have already worked through planning, support, operation, and performance evaluation. You have run risk assessments, implemented controls, conducted internal audits, and reviewed performance data in management review.
Clause 10.1 is the point where all of that feeds forward. The outputs from performance monitoring, audit findings, management review decisions, corrective actions, and risk treatment reviews are not endpoints. They are inputs to a cycle of improvement that keeps the ISMS relevant and effective as threats evolve, the organisation changes, and the environment shifts.
This is the PDCA cycle in practice. Plan, Do, Check, Act. Clause 10.1 is the Act stage made explicit.
Exemplar Global Recognised Training ProviderRTP No. 310970The Three Words That Matter: Suitability, Adequacy, and Effectiveness
ISO 27001 uses three specific terms in Clause 10.1, and each one means something distinct. Auditors pay attention to all three.
Suitability
Suitability asks whether the ISMS is still the right fit for the organisation. As the business grows, acquires new systems, moves to cloud infrastructure, or enters new markets, the scope and design of the ISMS must keep pace. An ISMS designed for a fifty person firm operating from a single office may not be suitable for the same firm two years later operating across three states with remote workers and a SaaS product.
Improvement in suitability often shows up in scope reviews, updates to the context of the organisation, and changes to the interested party register. If none of those documents have changed in three years despite significant organisational change, suitability is a legitimate audit concern.
Adequacy
Adequacy asks whether the resources, controls, and processes are sufficient to address the risks the organisation faces. You might have the right structure in place, but if the controls are underfunded, understaffed, or outdated, the ISMS is not adequate. Adequacy gaps often surface through risk assessment reviews, incident analysis, and audit findings that keep recurring.
Effectiveness
Effectiveness asks whether the ISMS is actually achieving its intended outcomes. Are information security objectives being met? Are controls working as intended? Is the organisation more secure than it was last year? Effectiveness is the hardest of the three to demonstrate because it requires measurable outcomes, not just documented processes.
When an auditor sits down to assess Clause 10.1, they are looking for evidence that the organisation has genuinely considered all three dimensions, not just ticked a box labelled improvement.
Where the Inputs to Improvement Come From
Clause 10.1 does not exist in isolation. It draws on outputs from earlier clauses. Understanding those connections is essential for both implementing the clause and auditing it effectively.
Internal Audit Results
Clause 9.2 requires internal audits of the ISMS at planned intervals. Every finding from those audits, whether a nonconformity, an observation, or an opportunity for improvement, is a potential input to Clause 10.1. An organisation that runs internal audits but never uses the findings to drive improvement has broken the loop. The audit becomes a compliance exercise rather than a management tool.
Look at your internal audit reports from the past two years. Are the same issues appearing? If yes, that is not just a corrective action problem. It is a continual improvement failure. The system is not learning.
Management Review Outputs
Clause 9.3 requires management review at planned intervals, and the outputs of that review must include decisions related to continual improvement opportunities. This is where Clause 10.1 and Clause 9.3 connect explicitly. If management review minutes show no improvement decisions, no new initiatives, and no resource commitments, an auditor will question whether the review is genuinely driving the ISMS forward.
Strong management review outputs that feed Clause 10.1 might include decisions to expand the ISMS scope, invest in new technical controls, revise the security awareness programme, or address a recurring risk that has not been adequately treated.
Nonconformities and Corrective Actions
Clause 10.2 deals with nonconformity and corrective action. Every corrective action, once completed, should contribute to improving the system. But Clause 10.1 goes further than corrective action. Corrective action fixes what went wrong. Continual improvement asks whether the system can be made better even when nothing has gone wrong.
An organisation that only improves in response to problems is reactive. ISO 27001 expects a proactive element as well. That means looking for opportunities to strengthen the ISMS before an incident forces the issue.
Risk Assessment and Treatment Reviews
ISO 27001 requires that the information security risk assessment be conducted at planned intervals and when significant changes occur. The outputs of those reviews, including changes to the risk register, new risks identified, and risks that have materialised, all inform where improvement is needed. If a previously accepted risk has now been realised as an incident, the treatment decision needs revisiting. That revisiting is itself an act of continual improvement.
Performance Monitoring Data
Clause 9.1 requires monitoring, measurement, analysis, and evaluation of ISMS performance. The metrics you track, whether that is the number of phishing simulation failures, mean time to detect and respond to incidents, patch compliance rates, or access review completion rates, provide a data trail that shows whether the system is improving, staying static, or declining.
Improvement that cannot be measured is difficult to demonstrate. Auditors will ask to see the data and the trend. Flat metrics over multiple periods suggest the system is not actively being improved.
What Genuine Continual Improvement Looks Like
In practice, Clause 10.1 is satisfied when an organisation can show a credible, evidence based story of how its ISMS has evolved. That story does not need to be dramatic. Incremental, consistent improvement is exactly what the standard intends.
Here are some examples of what genuine improvement looks like in an information security context.
- A post incident review following a phishing attack leads to a redesigned security awareness programme with quarterly simulations and targeted training for high risk user groups. Completion rates and click rates are tracked. The next management review shows measurable improvement in both metrics.
- An internal audit finds that access reviews are being completed late and without proper documentation. A corrective action is raised, a new process is implemented, and the following audit cycle confirms the process is now operating consistently. The risk of unauthorised access has been reduced.
- The risk assessment review identifies a new threat related to AI generated phishing attacks. The threat is assessed, controls are updated, and staff awareness training is revised. The change is documented and the updated risk register reflects the current threat landscape.
- Management review identifies that the ISMS scope does not adequately cover a newly acquired subsidiary. A scope extension project is initiated, documented, and completed before the next surveillance audit.
None of these examples require a complete overhaul of the ISMS. They demonstrate a system that is paying attention, learning from experience, and making deliberate decisions to get better.
What Auditors Actually Check Under Clause 10.1
When an external auditor or internal auditor assesses Clause 10.1, they are not looking for a document titled Continual Improvement Plan. They are looking for evidence that improvement is actually happening. Here is what that evidence gathering typically looks like.
Tracing the Improvement Loop
A competent auditor will trace the loop from performance data through to action. They might start with the management review minutes and ask: what improvement decisions were made here? Then they will look for evidence that those decisions were acted on. If the minutes record a decision to improve patch management processes, the auditor will look for the updated procedure, the implementation evidence, and the performance data showing whether it worked.
If the loop is broken at any point, that is a finding. The decision was made but not implemented. Or it was implemented but never evaluated. Or it was evaluated but the results were never fed back into the next review cycle.
Reviewing Trends Over Time
Auditors will ask to see performance data across multiple periods. A single data point tells you nothing. Trends tell you whether the system is moving in the right direction. If your security incident count has increased year on year without a corresponding improvement in detection and response capability, that is a concern. If your access review completion rate has improved from 60 percent to 95 percent over two audit cycles, that is a concrete example of improvement.
Checking That Improvement Is Proactive, Not Just Reactive
Auditors will probe whether the organisation is only improving in response to failures or whether there is genuine proactive improvement activity. Questions like can you give me an example of an improvement you made before anything went wrong or how did you identify this as an area for improvement help reveal whether the organisation has a genuine improvement culture or just a corrective action process.
Looking at the Connection to Objectives
Information security objectives set under Clause 6.2 should be connected to improvement. If the objectives have not changed in three years and performance against them has been consistently met, an auditor might ask whether the objectives are challenging enough to drive meaningful improvement. Objectives that are always met without effort are not driving the system forward.
For a deeper look at how information security objectives feed into this cycle, see our article on setting measurable information security objectives under Clause 6.2.
Common Weaknesses Auditors Find in Clause 10.1
After conducting hundreds of ISO audits across multiple standards, certain patterns emerge in how organisations struggle with continual improvement. Here are the most common weaknesses.
Improvement Is Only Corrective Action in Disguise
Many organisations conflate Clause 10.2 corrective action with Clause 10.1 continual improvement. Corrective action is reactive. It addresses a specific nonconformity or failure. Continual improvement is broader. It includes proactive initiatives, enhancements to processes that are already working adequately, and strategic decisions to lift the capability of the ISMS. If your improvement register only contains corrective actions, you are missing part of the picture.
No Measurable Baseline
You cannot demonstrate improvement without a baseline. Organisations that have not established meaningful performance metrics under Clause 9.1 will struggle to show improvement under Clause 10.1. If you cannot show where you started, you cannot show how far you have come.
Management Review Outputs Are Too Vague
Minutes that record decisions like continue to monitor security performance or maintain current controls do not demonstrate continual improvement. They demonstrate inertia. Management review outputs need to include specific, actionable decisions with ownership and timeframes.
Improvement Is Not Linked to Risk
In an information security context, improvement should be risk driven. If the organisation is investing in improvements that do not address its most significant risks, the ISMS is not improving in the right places. Auditors will check whether the improvement priorities reflect the risk profile of the organisation.
To understand how the risk assessment process connects to these priorities, our article on information security risk assessment under Clause 6.1.2 provides a practical walkthrough.
Exemplar Global Recognised Training ProviderRTP No. 310970Documenting Continual Improvement Without Over Engineering It
ISO 27001 does not require a specific documented procedure for continual improvement. It does require that you retain documented information as evidence that the management system is being improved. What that looks like in practice will vary by organisation size and complexity.
For a small organisation, improvement evidence might be captured in management review minutes, internal audit close out records, and an updated risk register. For a larger organisation with a dedicated information security team, it might include a formal improvement register, a dashboard of security metrics, and a structured programme of ISMS enhancement projects.
The key is that the documentation tells a coherent story. An auditor should be able to pick up your records and trace improvement from identification through to implementation and evaluation. If that story is fragmented across disconnected documents with no clear thread, the evidence will not hold up.
For practical guidance on how the ISMS internal audit process feeds into this improvement cycle, see our article on ISMS internal audits under Clause 9.2.
Continual Improvement as a Culture, Not a Clause
The organisations that satisfy Clause 10.1 most convincingly are not the ones with the most elaborate improvement frameworks. They are the ones where improvement is a genuine part of how the ISMS is managed. Security teams that regularly discuss what is working and what is not, leadership that acts on management review outputs rather than filing the minutes away, and internal auditors who are empowered to raise opportunities for improvement without fear of pushback. These are the hallmarks of a system that is genuinely improving.
Clause 10.1 is ultimately a test of culture as much as compliance. An auditor can tell the difference between an organisation that has written an improvement plan to satisfy the standard and one that has actually embedded improvement into how it manages information security.
If you are preparing for an ISO 27001 certification or surveillance audit and want to build genuine competence in auditing and implementing the standard, Audit Workshop offers practical ISO 27001 internal auditor and lead auditor training delivered by experienced practitioners. The courses are built around real audit scenarios, not just clause recitation, so you leave with skills you can apply immediately.
For a broader view of how improvement connects to the nonconformity and corrective action process, our companion article on nonconformity and corrective action under Clause 10.2 covers the related requirements in detail.













