ISO 27001 Clause 10.1: Continual Improvement
Clause 10.1 requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. It is the shortest requirement in the standard - a single sentence - and one of the most important, because it captures the whole point of a management system: security is not a project you finish but a capability you keep sharpening. This is the “Act” in the PDCA cycle, the phase that takes everything learned from monitoring, audit, and review and turns it into a better ISMS next cycle. In the 2022 revision, continual improvement was moved ahead of corrective action to lead Clause 10, a deliberate signal that improvement is the goal and correction is one route to it.
What the clause requires
ISO 27001:2022 Clause 10.1 states, in full:
The organization shall continually improve the suitability, adequacy and effectiveness of the information security management system.
Three words define what you are improving:
- Suitability - does the ISMS still fit the organization, its context, and its risks?
- Adequacy - is it sufficient to meet requirements and objectives?
- Effectiveness - does it actually achieve its intended outcomes?
The clause names no method. That is intentional. Improvement can come from corrective actions, from acting on audit findings, from management review decisions, from new objectives, from threat intelligence, or from a good idea raised by staff. What the standard expects is evidence that improvement is happening on purpose and over time, not by accident.
A note on the 2022 reordering. In ISO 27001:2013, Clause 10.1 was “Nonconformity and corrective action” and 10.2 was “Continual improvement.” The 2022 version swaps them: 10.1 is now continual improvement, 10.2 is nonconformity and corrective action. The requirements did not fundamentally change, but the order now reads as improvement-led. If you are migrating from the 2013 version, update any documents that reference the old numbering.
How to demonstrate continual improvement
Treat improvement as an output, not a vague aspiration
“We are committed to continual improvement” in a policy proves nothing. Auditors look for a stream of concrete changes to the ISMS over time, each traceable to a trigger. The practical answer is to capture improvement the same way you capture risk: in a register.
Keep a continual improvement register
A simple log turns an abstract requirement into hard evidence. For each improvement, record:
- Source - where it came from (audit finding, management review decision, incident, metric trend, staff suggestion, risk reassessment)
- Description - what is being improved
- Owner - who is accountable
- Target date and status
- Outcome - what actually changed and, where relevant, evidence it worked
This register becomes the single artefact that answers “show me your continual improvement” in seconds.
Feed improvement from the checks you already run
You do not need a separate improvement machine. The ISMS already generates improvement inputs:
- Monitoring and measurement trends that show a control underperforming
- Internal audit findings and opportunities for improvement
- Management review decisions, whose outputs explicitly include improvement opportunities
- Lessons learned from incidents and near misses
- Changes in context and interested-party expectations
Continual improvement is largely the discipline of routing these signals into deliberate action rather than letting them evaporate.
Distinguish improvement from correction
Not every improvement is a corrective action. Correcting a nonconformity is reactive - fixing something that failed a requirement, handled under Clause 10.2. Continual improvement is broader and often proactive: raising a control’s maturity that was never non-conformant, streamlining a process, adopting a better tool, tightening an objective. A healthy ISMS shows both reactive correction and proactive improvement.
Show a trend, not a one-off
Auditors want evidence over time. A single improvement last month is weak; a register showing a steady flow of improvements across the year, sourced from varied triggers, demonstrates a living management system. Quality matters more than volume - a few meaningful changes beat a long list of trivial edits.
Connecting 10.1 to the rest of your ISMS
Clause 9.3 connection. Management review outputs explicitly include continual improvement opportunities. The review is a primary, auditable source of improvements.
Clause 9.1 and 9.2 connection. Monitoring and internal audit surface where the ISMS is falling short - the raw material for improvement.
Clause 10.2 connection. Corrective action is one mechanism of improvement: eliminating the causes of nonconformities so they do not recur. Improvement is the wider goal that corrective action serves.
Clause 6.2 connection. Raising or tightening information security objectives over time is a direct form of continual improvement.
Clause 5.1 connection. Top management is required to promote continual improvement, so leadership commitment and this clause reinforce each other.
What auditors check
Evidence of actual improvements. Auditors ask you to demonstrate continual improvement and expect concrete examples with records - not a policy statement. A continual improvement register answers this directly.
A trend over time. They look for a flow of improvements across the period, from varied sources, rather than a single change made just before the audit.
Traceability to triggers. Auditors check that improvements connect to real inputs - audit findings, review decisions, incidents, metrics - showing the ISMS learns from itself.
Follow-through. Improvements that were logged but never implemented, or that stall indefinitely, undermine the evidence. Auditors confirm items reach completion.
Consistency with 10.2. They check that corrective actions feed improvement and that the two processes are joined up rather than parallel silos.
Common mistakes to avoid
Treating 10.1 as a slogan. A policy line about being “committed to continual improvement” with no evidence behind it is the most common failure. The clause wants outputs, not intent.
No record of improvements. If improvements happen but are never captured, you cannot prove the clause is met. An unrecorded improvement is, for audit purposes, no improvement at all.
Confusing improvement with corrective action only. Organizations that only ever “improve” by fixing nonconformities miss the proactive half. Show deliberate enhancements that were not triggered by a failure.
A burst before the audit. Ten improvements logged the week before certification, and none before, signals a box-ticking exercise. Build the habit continuously.
Trivial changes to pad the list. Padding the register with cosmetic edits invites scrutiny. A smaller number of substantive improvements is more convincing.
Losing management review outputs. Improvement opportunities raised in the review that never make it into the register are a missed, and visible, link auditors will trace.
How 27kay can help
We help organizations make continual improvement real and evidenced rather than aspirational. As part of ISO 27001 implementation, we set up a lightweight improvement register, wire it to your audit, monitoring, and management review outputs, and help you build the habit that keeps the ISMS sharp between audits. For the full picture, see our ISO 27001 knowledge hub.
Struggling to show auditors a genuine improvement trend? Get in touch - we will help you turn the signals your ISMS already produces into evidence of a management system that keeps getting better.