ISO 27001 management review: the required inputs, the decisions it must produce, and how it is checked
“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.” — harmonized-structure text 9.3.3, applied by ISO/IEC 27001.
The management review is the point at which top management looks at the information security management system as a whole and decides what to change. The text is short and specific: who reviews, what goes in, what must come out, and what has to be kept. This page quotes it and shows where the certification body checks it.
The five required inputs
“The management review shall include:”
| The management review shall include | In an ISMS (our reading) | |
|---|---|---|
| a | the status of actions from previous management reviews | The action log from the last review, with status and owners |
| b | changes in external and internal issues that are relevant to the [information security] management system | What has changed around the ISMS since last time — the clause 4.1 issues, revisited |
| c | changes in needs and expectations of interested parties that are relevant to the [information security] management system | New customer, contract or regulatory requirements — clause 4.2, revisited |
| d | information on the [information security] performance, including trends in: nonconformities and corrective actions; monitoring and measurement results; audit results | Your nonconformity log, the monitoring and measurement results, and internal and external audit findings, shown as trends rather than lists |
| e | opportunities for continual improvement | Improvements proposed since the last review |
These are the common inputs every harmonized-structure standard shares. ISO/IEC 27001:2022's own contents show the same three sub-clauses — 9.1 monitoring, measurement, analysis and evaluation; 9.2 internal audit (9.2.1 general, 9.2.2 internal audit programme); 9.3 management review (9.3.1 general, 9.3.2 inputs, 9.3.3 results) — but the standard can add information-security-specific inputs, and we have not read that part of it. We compared the common text with the standard where both can be read (clauses 4.1 to 6.3): 79–100% of the common wording appears in the standard.
Who reviews, and when
“Top management shall review the organization’s [information security] management system, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.”
Top management
The requirement is on top management, not on the ISMS manager. The people who run the system prepare the inputs; the people who direct the organisation review them and decide.
Planned intervals
No frequency is fixed. What is fixed is that every surveillance audit must include “internal audits and management review”, so a year without a review shows at that year's visit — our reading of how the two fit.
What it must produce
“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.”
“Documented information shall be available as evidence of the results of management reviews.”
Decisions, not a presentation
Two kinds of decision are named: on improvement opportunities, and on any need for change to the management system. Minutes that record a presentation and no decisions give the auditor nothing to sample against the requirement.
Where the decisions go next
Changes to the ISMS are themselves regulated: ISO/IEC 27001 clause 6.3 says “When the organization determines the need for changes to the information security management system, the changes shall be carried out in a planned manner.” The review is one place where such a change is decided.
How the certification body checks it
At Stage 1
Stage 1 must “evaluate if the internal audits and management reviews are being planned and performed, and that the level of implementation of the management system substantiates that the client is ready for stage 2”.
At Stage 2 and in the report
Stage 2 must include the auditing of “internal auditing and management review”, and the report must contain “a statement on the conformity and the effectiveness of the management system together with a summary of the evidence relating to: the capability of the management system to meet applicable requirements and expected outcomes; the internal audit and management review process”.
At surveillance and recertification
Every surveillance audit includes “internal audits and management review”, and at recertification “The recertification activity shall include the review of previous surveillance audit reports and consider the performance of the management system over the most recent certification cycle.” — three years of management review minutes are part of that picture. See recertification.
Inputs come from the rest of the system
The fourth input — trends in nonconformities, monitoring results and audit results — only exists if the other parts of the ISMS are producing it. An internal audit that found nothing and a nonconformity log that is empty leave the review with little to judge. See also nonconformities.
If you hold more than one standard
For integrated systems the accreditation rules list “Management Reviews that consider the overall business strategy and plan” as a characteristic of integration. One review can serve ISO 27001 and ISO 9001 together. See integrated management systems.
What to keep
The agenda showing each of the five inputs, the evidence presented for each, who attended, and the decisions with owners and dates. That is the documented information the text requires, and what Stage 2 and each surveillance audit will ask to see.
We do not audit, certify or consult, and are paid the same fixed fee per enquiry whichever firm you use. The requirements are quoted from the published texts; the right-hand column and the frequency point are marked as our reading.
Where this fits
Common questions
What is an ISO 27001 management review?
A review by top management of the information security management system “at planned intervals, to ensure its continuing suitability, adequacy and effectiveness”, in the words of the harmonized-structure text ISO 27001 applies. It has required inputs and must produce decisions.
How often should the management review happen?
“At planned intervals” — the text does not fix a frequency. Because every surveillance audit must include “internal audits and management review”, there needs to be a review to show at each visit; that is our reading of how the two fit together.
What are the inputs to an ISO 27001 management review?
The common text lists five: the status of actions from previous reviews; changes in external and internal issues; changes in the needs and expectations of interested parties; information on performance, including trends in nonconformities and corrective actions, monitoring and measurement results and audit results; and opportunities for continual improvement. ISO/IEC 27001 may add information-security-specific inputs; we have not read that clause of the standard itself.
What should come out of a management review?
“The results of the management review shall include decisions related to continual improvement opportunities and any need for changes to the [information security] management system.” And “Documented information shall be available as evidence of the results of management reviews.” A review whose minutes record no decisions has not produced what the text asks for.
Who has to attend?
The text says “Top management shall review”. Who top management is depends on your organisation; what the text rules out is a review held only by the people who run the ISMS day to day.
Does the certification body check the management review?
Yes, repeatedly. Stage 1 must evaluate whether management reviews are being planned and performed, Stage 2 must audit management review, every surveillance audit must include it, and the audit report must summarise the evidence about it.
Can one management review cover ISO 27001 and ISO 9001?
Yes. For integrated management systems, the accreditation rules list “Management Reviews that consider the overall business strategy and plan” among the marks of integration.
Sources cited on this page
- ISO/IEC Harmonized structure for MSS with guidance for use (formerly Annex SL Appendix 2 of the ISO/IEC Directives, Part 1), approved 30 July 2025
- ISO/IEC 27001:2022, official preview (clauses 1 to 6.3 and contents), read first-hand
- BS EN ISO/IEC 17021-1:2015, clauses 9.3.1.2–9.3.1.4 (initial certification audit), full text
- BS EN ISO/IEC 17021-1:2015, clauses 9.1.3, 9.5.4 and 9.6 (audit programme, surveillance, recertification, suspension), full text
- BS EN ISO/IEC 17021-1:2015, clauses 3.11–3.13 and 9.4.5–9.5.3 (nonconformities, audit findings, the certification decision), full text
- IAF MD 11:2023, Application of ISO/IEC 17021-1 for Audits of Integrated Management Systems (Issue 3)
Every figure above was read from the source it is attributed to on 20 September 2026. Figures that are our own arithmetic rather than a published rule are labelled as estimates wherever they appear. How we check this.
Management review due before an audit?
Say when the audit is and what the last review decided.
Your enquiry is ready to send
Here is what happens after you submit:
- Your answers go to ISO 27001 consultancies that advertise for your sector.
- No more than three of them may contact you, using the details you gave.
- You decide who, if anyone, you speak to. You are committed to nothing.
We are not a certification body and cannot issue, arrange or influence a certificate. Only a UKAS-accredited certification body can do that, and you appoint it yourself.