ISO 27001 Clause 9.3: Management Review

· 6 min read · Lyudmil Arkov

Clause 9.3 requires top management to review the ISMS at planned intervals to make sure it remains suitable, adequate and effective. This is where the “Check” of the PDCA cycle reaches the top of the organization. Monitoring and internal audit produce evidence; the management review is where leadership actually looks at that evidence and makes decisions about it. It is also one of the first records a certification auditor asks for, because it reveals in minutes whether leadership commitment is real or a signature on a policy. The clause has three parts: 9.3.1 sets the obligation, 9.3.2 lists the required inputs, and 9.3.3 defines the outputs.

What the clause requires

ISO 27001:2022 Clause 9.3 is structured in three sub-clauses.

9.3.1 General. Top management must review the organization’s ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness.

9.3.2 Management review inputs. The review must consider:

  1. The status of actions from previous management reviews
  2. Changes in external and internal issues relevant to the ISMS
  3. Changes in the needs and expectations of interested parties relevant to the ISMS
  4. Feedback on information security performance, including trends in: nonconformities and corrective actions; monitoring and measurement results; audit results; and fulfilment of information security objectives
  5. Feedback from interested parties
  6. Results of risk assessment and status of the risk treatment plan
  7. Opportunities for continual improvement

9.3.3 Management review results. The outputs must include decisions related to continual improvement opportunities and any need for changes to the ISMS. Documented information must be retained as evidence of the results.

Item 3 - changes in the needs and expectations of interested parties - was made an explicit input in the 2022 revision. It is a small addition that auditors now specifically look for, so make sure it appears on your agenda.

How to implement management review

Set a planned interval and hold to it

“Planned intervals” is not defined as a number, but for most organizations an annual full review is the minimum, and quarterly or half-yearly is stronger - especially in the first year of certification or after significant change. What matters is that the interval is defined, justified, and actually met. A review that slips by six months is itself evidence of weak commitment.

Build the agenda directly from 9.3.2

The fastest way to pass this clause is to make your agenda mirror the required inputs. If each 9.3.2 item is a standing agenda heading, the minutes automatically demonstrate coverage. A practical agenda:

  • Actions from the last review - status of each
  • Changes in internal and external issues (Clause 4 context)
  • Changes in interested parties’ needs and expectations
  • Performance: incidents, metrics and measurement results, internal audit results, nonconformity and corrective action trends, progress against objectives
  • Feedback from interested parties (customers, regulators, partners, staff)
  • Risk assessment results and risk treatment plan status
  • Opportunities for improvement
  • Decisions, actions, and resource commitments

Get the right people in the room

Clause 9.3.1 says top management reviews the ISMS. That means the review cannot be the ISMS manager talking to themselves. Directors or senior leaders with authority over resources and strategy must attend and engage. Their presence, questions, and decisions are what make the record credible.

Capture decisions and actions, not just attendance

The value of the review, and the evidence auditors want, sits in 9.3.3: decisions. Minutes should record what was decided, what changes to the ISMS were agreed, what actions were assigned to whom with due dates, and what resources were committed. A record that only lists topics “discussed” without any decision suggests a rubber-stamp meeting.

Close the loop

Every action from the review should be tracked to completion and reviewed at the next meeting under “status of actions from previous management reviews.” This is how 9.3 becomes a live improvement engine rather than an annual ritual, and it links directly to continual improvement under Clause 10.1.

Connecting 9.3 to the rest of your ISMS

Clause 5.1 connection. Management review is the most tangible evidence of leadership commitment. It is where top management demonstrates active engagement with the ISMS rather than delegating it entirely.

Clause 9.1 and 9.2 connection. Monitoring results and internal audit results are required inputs. The review is where their output is finally acted on by decision-makers.

Clause 4.1 and 4.2 connection. Changes in context and in interested parties are explicit inputs, keeping the ISMS aligned with a changing environment.

Clause 6.1 connection. Risk assessment results and risk treatment status are reviewed, so treatment decisions stay current with the risk picture.

Clause 10 connection. The outputs of 9.3 feed continual improvement and drive changes to the ISMS - the review is the formal decision point where improvement is authorized.

What auditors check

Records exist and are current. Auditors ask for management review minutes early. Missing reviews, or a review overdue against your own stated interval, is an immediate finding.

All required inputs are covered. They check the minutes against the 9.3.2 list. A frequent gap since 2022 is no evidence that changes in interested parties’ needs and expectations were considered.

Top management actually attended. Auditors look at who was present. A “management review” run without senior management undermines the whole clause and points back to a Clause 5.1 weakness.

Decisions and actions, not just discussion. They look for outputs under 9.3.3 - decisions on improvement and ISMS changes, actions with owners and dates, and resource commitments. Minutes with no decisions read as a formality.

The loop closes. Auditors trace actions from one review to the next to confirm follow-through. Actions that reappear year after year unresolved show the review is not driving change.

Common mistakes to avoid

The ISMS manager reviewing alone. A review without top management does not satisfy 9.3.1, no matter how thorough the deck. Get decision-makers in the room.

Missing inputs. Skipping required inputs - commonly interested parties’ needs, risk treatment status, or objective fulfilment - leaves gaps auditors will find by ticking the 9.3.2 list against your minutes.

Presenting without deciding. A meeting where information is shown but nothing is decided fails 9.3.3. The output is decisions, not a presentation.

Reviews that slip. Letting the planned interval lapse, especially after certification, signals fading commitment and is easy for surveillance auditors to spot from the dates alone.

No action tracking. Decisions that are never assigned, dated, or followed up turn the review into theatre. Track actions to closure and revisit them next time.

A generic template with no substance. Reusing last year’s minutes with the date changed is transparent to an experienced auditor. The review must reflect this period’s real performance, risks, and decisions.

How 27kay can help

We help leadership teams run management reviews that satisfy Clause 9.3 and genuinely steer the ISMS. As part of ISO 27001 implementation, we build the agenda and input pack from your monitoring and audit data, facilitate the session so decisions actually get made, and structure minutes that stand up to certification. For the full picture, see our ISO 27001 knowledge hub.

Want your management review to be auditor-ready? Get in touch - we will help you prepare the inputs and run a review that produces real decisions, not just minutes.