iso27001partnersUK certification, costed Get a cost estimate

ISO 27001 management review: the required inputs, the decisions it must produce, and how it is checked

Written from the standards themselves · Editor-reviewed · Checked against the current editions on 20 September 2026
By the iso27001partners.co.uk editorial team · Published 20 September 2026 · Last reviewed 20 September 2026 · 8 min read
6 primary sources cited on this page. How we check what is on this site
What it must produce Decisions, with evidence

“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.” — harmonized-structure text 9.3.3, applied by ISO/IEC 27001.

The management review is the point at which top management looks at the information security management system as a whole and decides what to change. The text is short and specific: who reviews, what goes in, what must come out, and what has to be kept. This page quotes it and shows where the certification body checks it.

The five required inputs

“The management review shall include:”

Management review inputs (harmonized structure 9.3.2, verbatim) and what they can mean in an ISMS (our reading)
The management review shall includeIn an ISMS (our reading)
athe status of actions from previous management reviewsThe action log from the last review, with status and owners
bchanges in external and internal issues that are relevant to the [information security] management systemWhat has changed around the ISMS since last time — the clause 4.1 issues, revisited
cchanges in needs and expectations of interested parties that are relevant to the [information security] management systemNew customer, contract or regulatory requirements — clause 4.2, revisited
dinformation on the [information security] performance, including trends in: nonconformities and corrective actions; monitoring and measurement results; audit resultsYour nonconformity log, the monitoring and measurement results, and internal and external audit findings, shown as trends rather than lists
eopportunities for continual improvementImprovements proposed since the last review

These are the common inputs every harmonized-structure standard shares. ISO/IEC 27001:2022's own contents show the same three sub-clauses — 9.1 monitoring, measurement, analysis and evaluation; 9.2 internal audit (9.2.1 general, 9.2.2 internal audit programme); 9.3 management review (9.3.1 general, 9.3.2 inputs, 9.3.3 results) — but the standard can add information-security-specific inputs, and we have not read that part of it. We compared the common text with the standard where both can be read (clauses 4.1 to 6.3): 79–100% of the common wording appears in the standard.

Who reviews, and when

“Top management shall review the organization’s [information security] management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.”

Top management

The requirement is on top management, not on the ISMS manager. The people who run the system prepare the inputs; the people who direct the organisation review them and decide.

Planned intervals

No frequency is fixed. What is fixed is that every surveillance audit must include “internal audits and management review”, so a year without a review shows at that year's visit — our reading of how the two fit.

What it must produce

“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.”

“Documented information shall be available as evidence of the results of management reviews.”

Decisions, not a presentation

Two kinds of decision are named: on improvement opportunities, and on any need for change to the management system. Minutes that record a presentation and no decisions give the auditor nothing to sample against the requirement.

Where the decisions go next

Changes to the ISMS are themselves regulated: ISO/IEC 27001 clause 6.3 says “When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.” The review is one place where such a change is decided.

How the certification body checks it

At Stage 1

Stage 1 must “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”.

At Stage 2 and in the report

Stage 2 must include the auditing of “internal auditing and management review”, and the report must contain “a statement on the conformity and the effectiveness of the management system together with a summary of the evidence relating to: the capability of the management system to meet applicable requirements and expected outcomes; the internal audit and management review process”.

At surveillance and recertification

Every surveillance audit includes “internal audits and management review”, and at recertification “The recertification activity shall include the review of previous surveillance audit reports and consider the performance of the management system over the most recent certification cycle.” — three years of management review minutes are part of that picture. See recertification.

Inputs come from the rest of the system

The fourth input — trends in nonconformities, monitoring results and audit results — only exists if the other parts of the ISMS are producing it. An internal audit that found nothing and a nonconformity log that is empty leave the review with little to judge. See also nonconformities.

If you hold more than one standard

For integrated systems the accreditation rules list “Management Reviews that consider the overall business strategy and plan” as a characteristic of integration. One review can serve ISO 27001 and ISO 9001 together. See integrated management systems.

What to keep

The agenda showing each of the five inputs, the evidence presented for each, who attended, and the decisions with owners and dates. That is the documented information the text requires, and what Stage 2 and each surveillance audit will ask to see.

We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements are quoted from the published texts; the right-hand column and the frequency point are marked as our reading.

Where this fits

Common questions

What is an ISO 27001 management review?

A review by top management of the information security management system “at planned intervals, to ensure its continuing suitability, adequacy and effectiveness”, in the words of the harmonized-structure text ISO 27001 applies. It has required inputs and must produce decisions.

How often should the management review happen?

“At planned intervals” — the text does not fix a frequency. Because every surveillance audit must include “internal audits and management review”, there needs to be a review to show at each visit; that is our reading of how the two fit together.

What are the inputs to an ISO 27001 management review?

The common text lists five: the status of actions from previous reviews; changes in external and internal issues; changes in the needs and expectations of interested parties; information on performance, including trends in nonconformities and corrective actions, monitoring and measurement results and audit results; and opportunities for continual improvement. ISO/IEC 27001 may add information-security-specific inputs; we have not read that clause of the standard itself.

What should come out of a management review?

“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.” And “Documented information shall be available as evidence of the results of management reviews.” A review whose minutes record no decisions has not produced what the text asks for.

Who has to attend?

The text says “Top management shall review”. Who top management is depends on your organisation; what the text rules out is a review held only by the people who run the ISMS day to day.

Does the certification body check the management review?

Yes, repeatedly. Stage 1 must evaluate whether management reviews are being planned and performed, Stage 2 must audit management review, every surveillance audit must include it, and the audit report must summarise the evidence about it.

Can one management review cover ISO 27001 and ISO 9001?

Yes. For integrated management systems, the accreditation rules list “Management Reviews that consider the overall business strategy and plan” among the marks of integration.

Sources cited on this page

  1. ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
  2. ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
  3. BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
  4. BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
  5. BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
  6. IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)

Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.

Management review due before an audit?

Say when the audit is and what the last review decided.

Step 1 of 6
What has made this a live question?

Almost nobody certifies for its own sake. Whatever is pushing this usually also sets the deadline, so it is worth saying first.

When do you need the certificate in your hand?

Stage 1 and Stage 2 are separate visits with a gap between them, so the certificate always lands some weeks after the last audit day. A date inside three months is a different piece of work from a date inside a year.

How many people would be inside the scope?

Not your whole payroll — everyone doing work under your control inside the certified scope, contractors included. This is the number the audit-day table in ISO/IEC 27006-1 runs on, so it decides the audit fee before anything else does.

What exists already?

There is no wrong answer here and nothing to be embarrassed about. Most enquiries are at the first option.

How do you want the work done?

The three routes cost very different amounts and suit very different teams. If you have not decided, say so — that is a useful answer too.

Where should the consultancy reach you?

This is the only step that asks you to type anything.

By clicking “Send my enquiry” I agree that iso27001partners.co.uk may pass the details above to up to three ISO 27001 consultancies that advertise for my sector, so that they can contact me at the business details I have given. Consent is not a condition of anything — every page, table and calculator on this site works without it. You can withdraw consent at any time by replying to any message you receive, or by writing to us through the enquiry form on any page. We are not a certification body, not an accreditation body and not a consultancy; the disclaimer linked in the footer sets out the whole arrangement.

  • Your details go to consultancies only, and to no more than three
  • Free to you — consultancies pay us a fixed fee per enquiry, set in advance
  • No obligation, and no certification body is involved at this stage

Your enquiry is ready to send

Here is what happens after you submit:

  1. Your answers go to ISO 27001 consultancies that advertise for your sector.
  2. No more than three of them may contact you, using the details you gave.
  3. You decide who, if anyone, you speak to. You are committed to nothing.

We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.

Free enquiryFive clicks · no obligation Start now