Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 27001 management review inputs required by clause 9.3.2, listed a to g

ISO 27001 Management Review: The Complete 2026 Guide

The ISO 27001 management review is the meeting most teams treat as a formality and most auditors treat as a test. Clause 9.3 is short — three sub-clauses, barely half a page of the standard — but it is where an auditor finds out whether your information security management system is actually governed or merely documented. A review with no top management in the room, or no decisions recorded, is one of the fastest routes to a major nonconformity.

This guide covers what clause 9.3 requires, the seven inputs you must table, how often to hold the meeting, what the output has to look like, and the mistakes that turn a 60-minute meeting into a corrective action.

What clause 9.3 requires

Every ISO 27001 management review rests on clause 9.3 of ISO/IEC 27001:2022, which splits into three parts. Clause 9.3.1 says top management shall review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Clause 9.3.2 lists what the review must consider. Clause 9.3.3 says the results shall include decisions related to continual improvement opportunities and any need for changes to the ISMS, and that documented information shall be available as evidence.

Two words in 9.3.1 do most of the work. Top management means the people who can allocate budget and headcount, not the security team reporting to itself. Planned intervals means you decide the cadence and then keep to it — the standard sets no number, but it does expect you to honor the schedule you set.

An ISO 27001 management review is also not an internal audit. The internal audit under clause 9.2 checks conformity; the review under 9.3 is where leadership acts on what the audit found. Audit results are an input to the review, not a substitute for it.

The seven ISO 27001 management review inputs

Clause 9.3.2 lists inputs a) to g). Miss one and you have a gap an auditor can point at. Here is each input with the evidence that satisfies it.

InputWhat clause 9.3.2 asks forEvidence to table
a)Status of actions from previous management reviewsAction log with owner, due date and closure status
b)Changes in external and internal issues relevant to the ISMSUpdated context analysis: new markets, systems, suppliers, regulations
c)Changes in the needs and expectations of interested partiesUpdated interested party register, new customer or regulator requirements
d)Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of objectivesKPI pack, incident and nonconformity trend data, internal and external audit reports, objectives scorecard
e)Feedback from interested partiesCustomer security questionnaires, complaints, supplier and regulator correspondence
f)Results of risk assessment and status of the risk treatment planRisk register changes, treatment plan progress, residual risk acceptance
g)Opportunities for continual improvementImprovement backlog, ideas from staff, audit observations
The ISO 27001 management review inputs required by clause 9.3.2 and the evidence that satisfies each.

Input c) is the one that catches teams still running a 2013-era agenda. Explicit consideration of changing interested party expectations was added in the 2022 revision, published on 25 October 2022, and auditors do look for it.

The climate input people miss

Amendment 1:2024 added climate change to clauses 4.1 and 4.2 of ISO 27001 and 30 other management system standards. You must determine whether climate change is a relevant issue for your ISMS, and note that interested parties can have climate-related requirements. Because 4.1 and 4.2 feed inputs b) and c), the question lands squarely in your ISO 27001 management review.

The answer can legitimately be “considered, not material” — a SaaS company with no physical estate may conclude climate change does not affect its information security risk. What is not acceptable is silence. Record the consideration and the conclusion in the minutes. The amendment is free from ISO, and it applies to your certificate whether or not anyone told you.

How often should you hold it?

The standard says planned intervals and stops there. In practice, this is what certification bodies expect to see:

CadenceFitsWatch out for
Annual (minimum)Small, stable organizations with a narrow ISMS scopeOne missed meeting means a whole cycle with no review evidence
QuarterlyMost mid-market organizations; the common defaultReviews shrinking into status updates with no decisions
Monthly or continuousHigh-change environments, regulated sectors, multi-site scopesTop management attendance slipping to delegates
Typical ISO 27001 management review cadences and their failure modes.

You can split the agenda across the year — risk in Q1, performance in Q2 and so on — provided every input in 9.3.2 is covered within your stated interval and you can show that on a single page. A full ISO 27001 management review before your Stage 2 audit is effectively mandatory: with no review on record, the auditor cannot verify that top management has ever exercised oversight.

What the output has to look like

Clause 9.3.3 requires decisions, not discussion. Minutes that read “the team discussed incident trends” prove nothing. Minutes that read “agreed to fund an additional analyst by Q3 to reduce the alert backlog — owner: CTO, due 30 September” prove governance.

Your record should carry the date, attendees with roles (showing top management present), each 9.3.2 input with the evidence tabled, decisions taken, changes agreed to the ISMS, resources committed, and actions with owners and due dates. That record is mandatory documented information — clause 9.3.3 says it shall be available as evidence, so an unwritten review does not exist as far as your certificate is concerned.

Where auditors raise nonconformities

  • No top management present. A review chaired by the security manager with no executive in the room fails 9.3.1 on its face.
  • Missing inputs. Most commonly c) interested party changes, f) risk treatment status, and the climate consideration.
  • Decisions without owners or dates. This reads as discussion, not review.
  • Actions never closed. Input a) exists precisely so last cycle’s promises get chased. An action log with three-year-old open items is worse than no log.
  • One review held the week before the audit. Auditors check dates against your stated interval, and a single rushed meeting signals a paper exercise.
  • Confusing the review with the audit. If your minutes are just the internal audit report reprinted, you have evidence of 9.2 and none of 9.3. When findings do arise, handle them through your nonconformity and corrective action process and bring the status back to the next review.

A 60-minute agenda that satisfies clause 9.3

  1. Actions from last time (5 min) — input a). Closed, open, overdue.
  2. Context and interested parties (10 min) — inputs b) and c). New systems, suppliers, regulations, customer requirements, climate consideration.
  3. Performance (20 min) — input d). Objectives scorecard, incident and nonconformity trends, monitoring results, internal and external audit results.
  4. Feedback (5 min) — input e). Customer questionnaires, complaints, regulator contact.
  5. Risk (10 min) — input f). Register changes, treatment plan progress, residual risk to accept.
  6. Improvement and decisions (10 min) — input g) and clause 9.3.3. Agree changes, resources, owners and dates.

Run that agenda quarterly and the ISO 27001 management review stops being an audit chore and starts being the meeting where security actually gets funded.

Documenting it without starting from a blank page

The evidence burden for an ISO 27001 management review is procedural: a review procedure, a meeting notification, a minutes template structured around the seven inputs, and an action log that survives between meetings. Our ISO 27001 Toolkit includes those alongside 162 editable ISMS templates — policies, procedures, registers and the Statement of Applicability — for $99. If you are earlier in the journey, start with the ISO 27001 certification guide, and check the clause changes in ISO 27001:2022 before you set your agenda.

ISO 27001 management review FAQ

How often is an ISO 27001 management review required?

At planned intervals you define. The standard sets no frequency. Annual is the practical minimum, quarterly is the common default, and whatever you choose must be documented and honored.

Who must attend?

Top management — people with authority over budget, resources and ISMS direction. In a small company that is the CEO or a founder; in a larger one it is typically an executive sponsor plus the CISO or ISMS owner. Attendance must be recorded, because an ISO 27001 management review without a decision-maker present does not meet clause 9.3.1.

Is a management review the same as an internal audit?

No. Clause 9.2 internal audit checks whether the ISMS conforms and works. Clause 9.3 review is leadership deciding what to do about it. Audit results are one of the seven inputs to the review.

What documentation does clause 9.3 require?

Documented information as evidence of the results of the review. Practically: minutes with date, attendees, the inputs covered, decisions taken, and actions with owners and due dates. A procedure and standing agenda are not required by the standard but make the evidence consistent.

Can we combine the review with an existing leadership meeting?

Yes, and it is often the most sustainable approach. Add a standing ISMS item to an existing executive meeting, cover the 9.3.2 inputs, and minute the security decisions separately so the evidence is easy to hand to an auditor.

What happens if we skip one?

If you miss your own stated interval, expect a nonconformity — minor if it is a one-off with a corrective action, potentially major if there is no review evidence for the certification cycle at all.

The bottom line

Clause 9.3 asks for one meeting, seven inputs and a record of decisions. Treat the ISO 27001 management review as governance rather than paperwork: put a real decision-maker in the chair, table every input, write down who agreed to do what by when, and close the actions before the next one. Do that and this clause becomes the easiest part of your audit rather than the part that costs you a finding.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.