ISO 27001 Clause 10.1: Continual Improvement

· 6 min read · Lyudmil Arkov

Clause 10.1 requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. It is the shortest requirement in the standard - a single sentence - and one of the most important, because it captures the whole point of a management system: security is not a project you finish but a capability you keep sharpening. This is the “Act” in the PDCA cycle, the phase that takes everything learned from monitoring, audit, and review and turns it into a better ISMS next cycle. In the 2022 revision, continual improvement was moved ahead of corrective action to lead Clause 10, a deliberate signal that improvement is the goal and correction is one route to it.

What the clause requires

ISO 27001:2022 Clause 10.1 states, in full:

The organization shall continually improve the suitability, adequacy and effectiveness of the information security management system.

Three words define what you are improving:

  • Suitability - does the ISMS still fit the organization, its context, and its risks?
  • Adequacy - is it sufficient to meet requirements and objectives?
  • Effectiveness - does it actually achieve its intended outcomes?

The clause names no method. That is intentional. Improvement can come from corrective actions, from acting on audit findings, from management review decisions, from new objectives, from threat intelligence, or from a good idea raised by staff. What the standard expects is evidence that improvement is happening on purpose and over time, not by accident.

A note on the 2022 reordering. In ISO 27001:2013, Clause 10.1 was “Nonconformity and corrective action” and 10.2 was “Continual improvement.” The 2022 version swaps them: 10.1 is now continual improvement, 10.2 is nonconformity and corrective action. The requirements did not fundamentally change, but the order now reads as improvement-led. If you are migrating from the 2013 version, update any documents that reference the old numbering.

How to demonstrate continual improvement

Treat improvement as an output, not a vague aspiration

“We are committed to continual improvement” in a policy proves nothing. Auditors look for a stream of concrete changes to the ISMS over time, each traceable to a trigger. The practical answer is to capture improvement the same way you capture risk: in a register.

Keep a continual improvement register

A simple log turns an abstract requirement into hard evidence. For each improvement, record:

  • Source - where it came from (audit finding, management review decision, incident, metric trend, staff suggestion, risk reassessment)
  • Description - what is being improved
  • Owner - who is accountable
  • Target date and status
  • Outcome - what actually changed and, where relevant, evidence it worked

This register becomes the single artefact that answers “show me your continual improvement” in seconds.

Feed improvement from the checks you already run

You do not need a separate improvement machine. The ISMS already generates improvement inputs:

Continual improvement is largely the discipline of routing these signals into deliberate action rather than letting them evaporate.

Distinguish improvement from correction

Not every improvement is a corrective action. Correcting a nonconformity is reactive - fixing something that failed a requirement, handled under Clause 10.2. Continual improvement is broader and often proactive: raising a control’s maturity that was never non-conformant, streamlining a process, adopting a better tool, tightening an objective. A healthy ISMS shows both reactive correction and proactive improvement.

Show a trend, not a one-off

Auditors want evidence over time. A single improvement last month is weak; a register showing a steady flow of improvements across the year, sourced from varied triggers, demonstrates a living management system. Quality matters more than volume - a few meaningful changes beat a long list of trivial edits.

Connecting 10.1 to the rest of your ISMS

Clause 9.3 connection. Management review outputs explicitly include continual improvement opportunities. The review is a primary, auditable source of improvements.

Clause 9.1 and 9.2 connection. Monitoring and internal audit surface where the ISMS is falling short - the raw material for improvement.

Clause 10.2 connection. Corrective action is one mechanism of improvement: eliminating the causes of nonconformities so they do not recur. Improvement is the wider goal that corrective action serves.

Clause 6.2 connection. Raising or tightening information security objectives over time is a direct form of continual improvement.

Clause 5.1 connection. Top management is required to promote continual improvement, so leadership commitment and this clause reinforce each other.

What auditors check

Evidence of actual improvements. Auditors ask you to demonstrate continual improvement and expect concrete examples with records - not a policy statement. A continual improvement register answers this directly.

A trend over time. They look for a flow of improvements across the period, from varied sources, rather than a single change made just before the audit.

Traceability to triggers. Auditors check that improvements connect to real inputs - audit findings, review decisions, incidents, metrics - showing the ISMS learns from itself.

Follow-through. Improvements that were logged but never implemented, or that stall indefinitely, undermine the evidence. Auditors confirm items reach completion.

Consistency with 10.2. They check that corrective actions feed improvement and that the two processes are joined up rather than parallel silos.

Common mistakes to avoid

Treating 10.1 as a slogan. A policy line about being “committed to continual improvement” with no evidence behind it is the most common failure. The clause wants outputs, not intent.

No record of improvements. If improvements happen but are never captured, you cannot prove the clause is met. An unrecorded improvement is, for audit purposes, no improvement at all.

Confusing improvement with corrective action only. Organizations that only ever “improve” by fixing nonconformities miss the proactive half. Show deliberate enhancements that were not triggered by a failure.

A burst before the audit. Ten improvements logged the week before certification, and none before, signals a box-ticking exercise. Build the habit continuously.

Trivial changes to pad the list. Padding the register with cosmetic edits invites scrutiny. A smaller number of substantive improvements is more convincing.

Losing management review outputs. Improvement opportunities raised in the review that never make it into the register are a missed, and visible, link auditors will trace.

How 27kay can help

We help organizations make continual improvement real and evidenced rather than aspirational. As part of ISO 27001 implementation, we set up a lightweight improvement register, wire it to your audit, monitoring, and management review outputs, and help you build the habit that keeps the ISMS sharp between audits. For the full picture, see our ISO 27001 knowledge hub.

Struggling to show auditors a genuine improvement trend? Get in touch - we will help you turn the signals your ISMS already produces into evidence of a management system that keeps getting better.