Skip to main contentChat with us

ISO 27001:2022 Requirements  ·  Performance Evaluation

Clause 9.3
Management review

To put the health of the ISMS on top management's desk at defined intervals, so the decisions that keep it suitable, adequate, and effective are made by the people with the authority and budget to make them.

Last reviewed: June 12, 2026  ·  Authored by TÜV SÜD & BSI Certified Lead Auditors

What Clause 9.3 Requires

Clause 9.3 requires top management — the people who direct and control the organization at the highest level, not their delegates — to review the ISMS at planned intervals and confirm it remains suitable, adequate, and effective. The agenda is prescribed. The review must consider: the status of actions from previous reviews; changes in the external and internal issues that matter to the ISMS; changes in the needs and expectations of interested parties relevant to the ISMS (an input the 2022 revision added explicitly); feedback on information security performance, specifically including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and the fulfillment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.

The clause is equally specific about what must come out. The results of the review must include decisions on continual improvement opportunities and on any needed changes to the ISMS — resourcing, scope, objectives, policy, structure, whatever the inputs show requires action. Evidence of those results must be retained as documented information: in practice, minutes that show each input was considered and record the decisions and actions taken.

Why This Clause Exists

To put the health of the ISMS on top management's desk at defined intervals, so the decisions that keep it suitable, adequate, and effective are made by the people with the authority and budget to make them.

What This Really Means

Management review is the board meeting of the ISMS. Clause 5.1 makes top management promise commitment; Clause 9.3 is the standing appointment where that commitment is performed and evidenced — on a schedule, against a fixed agenda, with decisions recorded. It is not a status email, not a slide deck filed in a folder, and emphatically not the CISO presenting to themselves. It is a decision forum, and the standard tells you who must be in it and what must be on the table.

The required inputs read like a prescribed agenda, and the smartest implementation move is to treat them exactly that way: build the meeting template so each input is a numbered agenda item — prior action status, context changes, interested-party changes, the performance block (nonconformity trends, measurement results, audit results, objective progress), interested-party feedback, risk assessment results and treatment plan status, and improvement opportunities. With that structure, covering every input is a property of the template rather than a feat of memory, and your minutes map one-to-one against the clause when an auditor checks coverage — which is precisely what they do.

Attendance is where intent gets tested. "Top management" means the people who actually direct the organization and control its resources — CEO, MD, COO, CTO-level — because the required outputs are decisions about improvement and change that only they can authorize. A review where the security manager writes the pack, presents the pack, and approves the pack fails the point of the clause even if the minutes look immaculate. Folding the review into an existing leadership meeting is fine, and often the most realistic way to get executives in the room, provided the ISMS section has its own agenda and minuted outcomes.

On cadence: the standard says "planned intervals" and leaves the number to you. An annual full review is the floor in practice; the pattern that works well for growing organizations is quarterly-lite plus annual-deep — a short quarterly look at KPIs, incidents, risk movements, and objective progress, with one annual session covering the complete input list. What auditors treat as the heart of 9.3: every required input visibly considered, real decisions recorded with owners and dates, and the previous review's actions tracked to closure.

Why It Matters

Management review closes the governance loop. Everything else in Clause 9 generates information — metrics from 9.1, findings from 9.2 — and 9.3 is the only mechanism that forces the people with authority to read it and act. Without it, the ISMS drifts away from business reality: risks shift, customer security expectations change, objectives go stale, and resourcing requests die in middle management because no forum exists where leadership has to say yes or no. A security program whose leadership never reviews it is, functionally, unsponsored.

For certification, this clause is checked early and hard. Certification bodies expect at least one completed management review — with retained results — before Stage 2, alongside the internal audit. The most common findings are mechanical and avoidable: minutes silent on one or more required inputs (interested-party changes and objective fulfillment are the usual casualties), no recorded decisions, and prior actions with no follow-up trail.

Where weak management review bites:

  • Stage 2 prerequisite missed – no completed, evidenced management review before the certification audit is major-nonconformity territory and can stall the audit itself
  • Input-coverage findings – minutes that skip required inputs draw nonconformities; the 2022 addition on interested-party changes is now actively probed
  • Unresourced ISMS – without a forum where leadership decides, budget and headcount needs surface only after the incident that proves they were needed
  • Ceremonial reviews – a deck presented with no recorded decisions fails the results requirement and signals paper compliance to any experienced auditor
  • Evaporating actions – decisions without owners, dates, and follow-up resurface as repeat findings at the next review and the next audit

Documented Information Required

Management review results (minutes and decisions)

Mandatory

The retained record of each review: attendees, evidence that every required input was considered, the discussion in summary, and explicit decisions on improvement opportunities and ISMS changes with owners and due dates. Good minutes map visibly to the input list.

Management review agenda template

Recommended

A standing agenda with one item per required input, so coverage is structural rather than dependent on whoever prepares the meeting. The fastest fix for the most common 9.3 nonconformity.

Management review input pack

Recommended

The pre-read compiled by the ISMS manager: performance metrics, internal audit summary, nonconformity and corrective action trends, risk and treatment plan status, objective progress, and interested-party feedback. Circulated before the meeting so the session is spent deciding, not discovering.

Action tracker from previous reviews

Recommended

A live register of decisions and actions from prior reviews with owner, due date, and status — reviewed as the first agenda item of each session, since prior-action status is itself a required input.

See the full ISO 27001 mandatory documents checklist for every document and record the standard requires.

How to Implement Clause 9.3

1

Set the Cadence and Put It on the Leadership Calendar

Define the planned intervals — an annual full review at minimum, with a quarterly-lite check on metrics, incidents, and objectives if the organization is changing fast. Book the sessions a year ahead with named required attendees, and treat the dates like board meetings rather than something to schedule when convenient.

2

Build the Agenda Template from the Required Inputs

Create a standing agenda with one numbered item per required input: prior actions, context changes, interested-party changes, performance feedback (nonconformity trends, measurement results, audit results, objective fulfillment), interested-party feedback, risk assessment and treatment status, and improvement opportunities. Input coverage becomes a property of the template, not of memory.

3

Compile and Circulate the Input Pack

Have the ISMS manager assemble the pre-read: the 9.1 performance report, the 9.2 audit summary, the 10.2 nonconformity and corrective action trends, risk and treatment plan status, objective progress, and notable interested-party feedback such as new client security clauses or regulator activity. Send it days before the meeting so executives arrive ready to decide.

4

Hold the Review with Actual Top Management

Get the people who control budget and priorities in the room — CEO, MD, COO, CTO-level, not just the security function. The ISMS manager presents; management interrogates and decides. Folding the session into an existing executive meeting is acceptable and often the pragmatic route, provided the ISMS agenda and minutes stand on their own.

5

Record Decisions, Not Just Discussion

Minute the meeting so each required input is visibly covered, then capture explicit decisions: improvement opportunities to pursue, ISMS changes approved, resources committed, objectives adjusted. Every decision gets an owner and a due date. Minutes that read as a content summary with no decisions will not satisfy the results requirement.

6

Track Actions to Closure Between Reviews

Maintain the action tracker as a living register, chase owners between sessions, and open every review with it — the status of previous actions is the first required input. Aging actions escalate to the executives who made the decision, which is precisely the accountability the clause is engineered to create.

7

Feed Outputs Back into the ISMS

Route review decisions into the system they govern: objective changes into Clause 6.2, new risks into the assessment cycle, policy updates through document control, structural changes through Clause 6.3 planning. The next review then verifies these landed — closing the loop the clause exists to create.

Audit Evidence

During Stage 1 and Stage 2 of your ISO 27001 certification audit, auditors will expect the following evidence to demonstrate conformity with Clause 9.3:

Documentation

  • A defined review cadence (schedule, calendar entries, or procedure) showing planned intervals are set and met
  • The agenda template mapping one-to-one against the required inputs
  • Minutes of recent reviews showing input coverage, attendees, and explicit decisions with owners and due dates
  • The input pack presented — performance report, audit summary, risk and treatment status, objective progress
  • The action tracker showing prior review actions and their closure status over successive cycles

Interviews

  • A top-management attendee (CEO, MD, COO) on what the last review covered and what they decided — auditors test whether leadership can speak to it unprompted
  • The ISMS manager on how inputs are compiled and how decisions flow back into objectives, risks, and policies
  • An action owner on what they were assigned at the last review and where it stands

Observations

  • The auditor maps the minutes against the full required-input list, hunting for silently skipped items — interested-party changes and objective fulfillment are the usual gaps
  • Cross-checking recorded decisions against downstream evidence: budget approvals, revised objectives, updated policies, new risk entries
  • Verifying the attendee list against the org chart to confirm genuine top-management participation rather than a delegated security-team session

Practitioner Insights

Surendra Pal Singh

Certification auditors interview the CEO or MD about the management review, and that conversation is where ghost-written minutes collapse — if the leadership cannot recall what they reviewed or decided, the document stops being evidence and becomes a liability. My advice is to design the review for that interview: fewer slides, a decision-focused agenda, three to five explicit decisions recorded per session, and a short briefing to the executives that the certification body will ask them about it directly. A leadership team that can talk about its own decisions is the most convincing Clause 9.3 evidence there is.

Surendra Pal Singh · CISO, DPO, CISA, ISO 27001, 27701, 42001 Lead Auditor
Saundhi Chauhan

The small-company failure mode is a management review that exists only as a document — drafted by the consultant, signed by the director, attended by no one. Making it real is cheaper than faking it: sixty to ninety minutes twice a year inside an existing leadership meeting, an agenda template that mirrors the required inputs, and the founder making two or three actual calls about budget, tooling, or priorities. The input people miss most since the 2022 revision is changes in interested-party expectations — a one-line review of new client security clauses, contract requirements, and regulatory movement covers it and takes five minutes to prepare.

Saundhi Chauhan · ISO 27001, 27701 Lead Auditor

Common Challenges & Solutions

Challenge

Top management treats the review as the security team's meeting and sends apologies or a delegate.

Solution

Stop scheduling a separate ceremony and attach the review to a meeting executives already attend, framed as the risk-and-resource decisions it actually is. Keep it to 60–90 minutes with a pre-circulated pack. It also helps to be plain about the audit mechanics: the certification body will interview top management about this review, and absence is not a delegable problem.

Challenge

Minutes silently miss required inputs — interested-party changes and objective fulfillment are the perennial casualties.

Solution

Make the agenda template the control: one numbered item per required input, pre-filled by the ISMS manager before each session. Use the input names as minute headings so the mapping to the clause is explicit. Auditors check coverage by reading minutes against the input list — make that check trivially passable by construction.

Challenge

Reviews happen on schedule but produce no decisions — pure status theater with excellent attendance.

Solution

Engineer decisions into the format: end every agenda item with a stated question for management, and close the meeting by reading back the decisions captured. Even "no change required" is a legitimate recorded decision, but push for the real ones — resources, objective changes, improvement priorities. The clause requires results that include decisions; minutes without them are nonconforming, however polished.

Challenge

Actions agreed in the review evaporate — same topics, same promises, next year.

Solution

Run a single action tracker with owner, due date, and status, and make reviewing it the literal first agenda item, since prior-action status is a required input. Escalate aging actions to the executive who made the decision and link closure evidence to each item. When leadership sees its own unclosed decisions at the top of every meeting, closure rates change quickly.

Challenge

One annual mega-review means stale data, a three-hour meeting, and executives who dread it.

Solution

Split the load: quarterly-lite sessions of 30–45 minutes covering KPIs, incidents, risk movement, and objective progress, plus one annual deep review covering the complete input list. The quarterly rhythm keeps data fresh and decisions timely; the annual session satisfies the full agenda. Minute both — together they demonstrate planned intervals better than any single yearly marathon.

Frequently Asked Questions

How often must management review take place?
The standard requires "planned intervals" and lets you set them; annually is the accepted minimum in practice. Many organizations run a quarterly-lite pattern — short sessions on KPIs, incidents, and objective progress — with one annual deep review covering the complete input list. For initial certification, at least one full review must be completed, with retained results, before Stage 2.
Who has to attend the management review?
Top management — the people who direct and control the organization at the highest level, typically the CEO/MD and the executive team. The CISO or ISMS manager presents, but cannot substitute for leadership: the required outputs are decisions on resources and ISMS changes that only top management can make, and certification auditors routinely interview executives about the review to test genuine participation.
Can the management review be done by email or as an asynchronous document?
A purely asynchronous review is risky. The clause requires top management to review prescribed inputs and produce decisions, and a circulated PDF rarely evidences either engagement or decision-making. A hybrid can work — pre-read pack asynchronously, then a short minuted session for the decisions — but a meeting with recorded attendance, input coverage, and decisions is far easier to defend at audit.
Can we combine the management review with an existing board or leadership meeting?
Yes — this is common and often the best way to guarantee top-management attendance. The conditions: the ISMS review gets its own agenda section covering all required inputs, and the minutes for that section stand on their own as evidence. A standing quarterly slot in the executive meeting is usually more durable than a separate annual ceremony everyone forgets to schedule.
What is the difference between management review and internal audit?
Internal audit (9.2) tests conformity bottom-up: independent auditors check whether the ISMS meets the standard and your own requirements, producing findings. Management review (9.3) evaluates top-down: leadership judges whether the ISMS remains suitable, adequate, and effective — using audit results as one of several required inputs — and makes the improvement and change decisions. One produces evidence; the other produces direction.
What must management review minutes actually contain?
Enough to evidence three things: that every required input was considered (date, attendees, and input-by-input coverage), that the review reached results — decisions on improvement opportunities and any ISMS changes — and that actions carry owners and due dates. Minutes structured under headings matching the input list make the auditor's coverage check, and yours, mechanical.

Written By Expert Auditors

Surendra Pal Singh
Surendra Pal Singh
Chief Information Security Officer & Data Protection Officer
CISODPOCISAMCSEITILISO 27001 Lead AuditorISO 27701 Lead AuditorISO 42001 Lead Auditor
Saundhi Chauhan
Saundhi Chauhan
Lead Auditor
ISO 27001 Lead AuditorISO 27701 Lead Auditor
Last reviewed: June 2026Content verified by certified lead auditors

Get in touch

Book a free consultation or send us your requirements. We respond within 24 hours.

Quick Call

Pick a time slot

Send Requirements

Get a custom quote in 24 hours

We're Online

⚠️ Business inquiries only. Personal email addresses will be rejected.

24hr Response
Free Consultation
No Obligations