Last updated: 8 October 2026
Quick answer: The ISO 27001 management review (clause 9.3) is a planned, recorded meeting in which top management checks that the ISMS is still suitable, adequate and effective. It must consider seven defined inputs, from audit results to risk treatment status, and produce documented decisions on improvements and any changes needed to the ISMS.
The ISO 27001 management review is one of the few clauses in the standard that belongs squarely to leadership rather than the security team. Auditors read the minutes closely because they show whether the board actually steers the information security management system (ISMS) or just signs what it is given.
For a CISO, that makes the review both a compliance obligation and an opportunity. Done well, it is the one meeting a year (or more) where you can put risk, resources and priorities in front of the people who decide them, and leave with recorded decisions.
This guide explains what clause 9.3 of ISO/IEC 27001:2022 requires, who should attend, how often to hold it, and gives you a ready-to-use agenda and minutes template.
What is the ISO 27001 management review?
It is a formal review, led by top management, of the whole ISMS at planned intervals. Clause 9.3.1 requires top management to review the ISMS “to ensure its continuing suitability, adequacy and effectiveness”.
Those three words each ask a different question:
- Suitability: does the ISMS still fit the organisation’s context, strategy and risks?
- Adequacy: is it sufficient, with enough scope, controls and resources, to meet its requirements?
- Effectiveness: is it achieving its intended outcomes, such as the information security objectives?
The current edition is ISO/IEC 27001:2022, published in October 2022. Compared with the 2013 edition, clause 9.3 is now split into three sub-clauses: 9.3.1 General, 9.3.2 Management review inputs and 9.3.3 Management review results. Our ISO 27001 overview covers the rest of the standard, and our guide to the statement of applicability explains a closely related document.
What inputs must the management review consider?
Clause 9.3.2 lists the topics the review must consider. Every one should be visibly covered in your agenda and minutes, because auditors often check them line by line.
| Clause 9.3.2 input | What to bring to the meeting |
|---|---|
| a) Status of actions from previous management reviews | Action log with owner, due date and status; explanation for anything overdue |
| b) Changes in external and internal issues relevant to the ISMS | Updated context analysis: new regulations, reorganisations, new products, threat trends |
| c) Changes in needs and expectations of interested parties relevant to the ISMS | New customer, regulator, insurer or contractual security requirements |
| d) Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results and fulfilment of information security objectives | KPI dashboard, internal and external audit findings, corrective action status, progress against objectives |
| e) Feedback from interested parties | Customer security questionnaires, complaints, regulator correspondence, staff feedback |
| f) Results of risk assessment and status of the risk treatment plan | Top risks, changes since last review, overdue treatments, risks awaiting acceptance |
| g) Opportunities for continual improvement | Proposals with estimated effort and benefit, ready for a decision |
Input c) is new in the 2022 edition. It asks leadership to look actively at how stakeholder requirements have moved, not just at internal performance. In addition, Amendment 1:2024 added climate action text to clauses 4.1 and 4.2, so your context and interested party updates should record whether climate change is a relevant issue.
In practice: send the input pack at least a week in advance and keep it short. A two-page summary with a KPI table and a top-ten risk list gets read. A 60-slide deck does not, and the discussion then happens without the facts.
How often should the ISO 27001 management review take place?
The standard only says “at planned intervals”. It does not set a frequency, so you decide and document it, usually in your ISMS manual or governance procedure.
Most organisations hold a full review at least once a year. Many CISOs prefer quarterly or half-yearly sessions, with some inputs covered at each and all inputs covered over the year. What matters is that the interval matches the pace of change in your risks and that the plan is followed.
Timing also matters around certification. An organisation going for initial certification should expect its certification body to want evidence that the ISMS has operated through a full cycle, including internal audit and management review, before the stage 2 audit. Confirm the expectations with your certification body early.
Common mistake: scheduling the management review before the internal audit has finished. Audit results are a mandatory input, so the review then either misses them or has to be repeated.
Who should attend?
Top management must own the review. ISO/IEC 27000 defines top management as the person or group who directs and controls the organisation at the highest level, so that means the chief executive or executive committee for the scope of the ISMS, not only the CISO.
A typical attendee list:
- CEO or managing director (or the executive sponsor for the ISMS scope)
- CISO or ISMS manager, who usually prepares and presents the inputs
- Heads of IT, operations, HR and legal or compliance
- The data protection officer, where personal data is in scope
- Risk owners for the highest-rated risks
- Internal audit, to present findings
What outputs must the review produce?
Clause 9.3.3 requires the results to include decisions related to continual improvement opportunities and any needs for changes to the ISMS. Documented information must be available as evidence of the results.
Good minutes turn those two lines into a clear decision record:
- Decisions on improvement proposals: approved, rejected or deferred, with reasons
- Changes to the ISMS scope, policy, objectives or risk appetite
- Resource decisions: budget, headcount, tools or external support (linked to clause 7.1)
- Risk acceptance decisions by the appropriate risk owners
- New or updated information security objectives (clause 6.2)
- An action log with owners and due dates, carried into the next review as input a)
Mapping every action to a ticket or task keeps the loop closed. A connected enterprise risk management module can then show the board how treatment plans have moved since the last meeting, instead of a static spreadsheet.
ISO 27001 management review agenda and minutes template
Use this agenda as a starting point. The timings assume a 90-minute annual review; shorten sections for quarterly sessions.
- Opening and attendance (5 minutes). Confirm quorum and that top management for the ISMS scope is present.
- Previous actions (10 minutes). Status of each action from the last review (input a).
- Context and interested parties (15 minutes). Internal and external changes, new legal, regulatory and contractual requirements, climate change relevance (inputs b and c).
- Security performance (20 minutes). KPIs and trends, incidents, nonconformities and corrective actions, internal and external audit results, objectives (input d).
- Interested party feedback (5 minutes). Customers, regulators, suppliers, staff (input e).
- Risk (20 minutes). Risk assessment results, risk treatment plan status, risks for acceptance (input f).
- Improvement and resources (10 minutes). Proposals for decision, resource needs (input g).
- Decisions and close (5 minutes). Read back decisions and actions; confirm the date of the next review.
For the minutes, record at least: date, attendees and roles, the input documents reviewed (with version numbers), the discussion summary for each agenda item, each decision, each action with an owner and due date, and approval of the minutes. Store them with your other ISMS records so they are easy to produce at audit.
If you already track controls, risks and audit findings in one place, much of this pack can be generated rather than compiled by hand. Teams that want to try that can start your 14-day free trial and build the input pack from live data.
How does the management review support NIS2, DORA and board oversight rules?
A well-run ISO 27001 management review produces exactly the kind of evidence that newer laws expect from management bodies. It will not satisfy those laws on its own, but it gives you a governance record you can reuse.
| Jurisdiction | Leadership expectation | How the management review helps |
|---|---|---|
| EU (NIS2) | Article 20 of the NIS2 Directive requires management bodies to approve cybersecurity risk-management measures, oversee their implementation, and follow training | Minutes record approval of measures and oversight of their status |
| EU financial sector (DORA) | Article 5 of DORA makes the management body responsible for the ICT risk management framework | Structured review of ICT risk, incidents and audit results feeds the DORA governance record |
| UK | The NCSC Cyber Security Toolkit for Boards sets out what boards should do to govern cyber risk | Gives the board a recurring, evidenced forum for that governance |
| US (listed companies) | SEC rules adopted in July 2023 require annual disclosure of board oversight of cybersecurity risk and management’s role | Minutes support what the company says about its oversight process |
If you run several frameworks, align the inputs once. For example, the NIS2 risk-management measures and your Annex A controls overlap heavily, and a cross-framework control map lets one review cover both. Our article on the overlap between DORA, NIS2 and the EU AI Act goes into that in more detail.
What do auditors look for in the management review?
Auditors want evidence that top management, not only the security team, reviewed every required input and made real decisions. They usually sample the latest minutes and follow a few actions through to completion.
Common nonconformities include:
- Minutes that do not show one or more of the clause 9.3.2 inputs, most often input c) or e)
- No evidence that top management attended, or a review held only by the ISMS team
- Decisions recorded as “noted” with no clear outcome
- Actions from the previous review with no owner, no due date or no follow-up
- Reviews not held at the planned interval, with no documented reason
In practice: before the audit, trace three actions from last year’s minutes to their closure evidence. If you cannot do it in five minutes, neither can the auditor.
Key takeaways
- Clause 9.3 requires top management to review the ISMS at planned intervals for suitability, adequacy and effectiveness.
- Seven inputs in clause 9.3.2 must be considered, including the 2022 addition on interested parties’ changing needs.
- Outputs must include documented decisions on improvements and changes to the ISMS.
- Hold the review after internal audit, keep the pack short, and track every action to closure.
- The same minutes can support NIS2, DORA and board oversight expectations in the UK and US.
Frequently asked questions
Is the ISO 27001 management review mandatory?
Yes. Clause 9.3 is a mandatory requirement of ISO/IEC 27001:2022, and certification bodies check it at every audit. You must hold the review at planned intervals, consider all the inputs listed in clause 9.3.2, and keep documented information as evidence of its results. Missing inputs or missing records are a common source of nonconformities.
How often should the management review be held?
The standard does not set a frequency; it only requires planned intervals. Most organisations hold at least one full review a year, and many split the inputs across quarterly or half-yearly meetings. Choose an interval that matches how quickly your risks and context change, document it, and make sure the plan is actually followed.
Can the CISO run the management review alone?
No. The review must be carried out by top management, meaning the person or group that directs and controls the organisation for the ISMS scope. The CISO usually prepares the inputs, presents them and records the decisions, but auditors expect to see senior leaders attending and making the decisions themselves.
What changed in clause 9.3 in the 2022 version?
The clause was split into three sub-clauses covering general requirements, inputs and results. A new input was added requiring consideration of changes in the needs and expectations of interested parties relevant to the ISMS. Amendment 1:2024 later added climate change considerations to clauses 4.1 and 4.2, which feed into the context inputs.
Can we combine the ISO 27001 management review with other reviews?
Yes. Many organisations run a single integrated review for ISO 27001, ISO 9001, ISO 22301 or privacy frameworks, or use an existing risk committee. This works well as long as the minutes clearly show that every clause 9.3.2 input was considered for the ISMS and that decisions specific to information security were recorded.
Turning the management review into a real steering tool
The ISO 27001 management review is easy to treat as a once-a-year formality, but it is the clause that links security work to leadership decisions. Plan it after internal audit, cover every input, record clear decisions and follow the actions through. You will pass the audit and, more importantly, get the resources and priorities the ISMS needs.
Enactia’s AI-powered GRC platform brings controls, risks, audit findings and actions together so the input pack is ready when you need it. To see how it would work for your ISMS, contact us or book a demo or start your 14-day free trial.
This article is for general information and is not legal advice.
