The seven inputs clause 9.3.2 makes you cover, how often the review has to happen, the evidence an ISO 27001 auditor asks to see, and a two hour agenda that satisfies both.
An ISO 27001 management review is a meeting where top management formally reviews the information security management system to confirm it is still suitable, adequate and effective. Clause 9.3 of ISO/IEC 27001:2022 splits this into three parts: 9.3.1 says the review happens at planned intervals, 9.3.2 lists seven inputs that must be considered, and 9.3.3 says the results must include improvement decisions and any changes to the ISMS, recorded as documented information. There is no minimum frequency in the standard, and no fee attached to the review.
ISO 27001 clause 9.3 requires top management, not the security team, to review the ISMS at planned intervals. The 2022 edition restructured the clause into 9.3.1 General, 9.3.2 Management review inputs and 9.3.3 Management review results, where the 2013 edition ran it as a single block. The input list is now explicit and numbered, so a certification auditor can work down it item by item and ask where each one was covered. A review that discusses security in general terms but cannot be mapped back to the seven lettered inputs is the most common way organisations fail clause 9.3.
ISO 27001 clause 9.3.2 lists seven inputs, lettered a to g. Each has evidence behind it that the auditor will ask to see, and the gap between "we talked about it" and "here is the pack we reviewed" is where nonconformities get raised.
| Clause 9.3.2 input | What you bring to the review | What the auditor checks |
|---|---|---|
| a) Status of actions from previous reviews | The action log from the last review, with each item open, closed or carried forward | That last year's actions were tracked, not quietly dropped |
| b) Changes in external and internal issues | Updated clause 4.1 context: new markets, products, regulation, headcount, office or cloud region | That the context record was revisited, including whether climate change is a relevant issue |
| c) Changes in interested party needs and expectations | Updated clause 4.2 register: new customer security clauses, regulators, contractual obligations | That new obligations arriving through sales contracts reached the ISMS |
| d) Feedback on information security performance | Trends in nonconformities and corrective actions, monitoring results, audit results, progress against objectives | Trends over time, not a single month. This is the input most often thin |
| e) Feedback from interested parties | Customer security questionnaires, complaints, supplier assessments, staff reports, pen test feedback | That outside signal reaches top management, not only the security owner |
| f) Results of risk assessment and risk treatment status | The current risk register, changes since the last review, and risk treatment plan status | That risks were reviewed at management level and treatment is progressing |
| g) Opportunities for continual improvement | Proposed improvements with an owner and a date against each | That improvements were decided, not just listed |
Input b now carries an extra obligation. Amendment 1:2024 added climate action wording to ISO 27001, so clause 4.1 requires the organisation to determine whether climate change is a relevant issue, and clause 4.2 notes that interested parties can have climate related requirements. The amendment does not say climate change must be relevant to you. It says you have to consider the question and record your determination, which is a one line entry in the review minutes rather than a project.
ISO 27001 does not set a frequency. Clause 9.3.1 says "planned intervals", which means you choose the interval, write it down, and keep to it. In practice almost every certified organisation holds at least one full management review a year, because certification bodies run annual surveillance audits and look for a review in each audit period. Missing your own stated interval is a nonconformity even if the interval was generous, so a small team is better off committing to one thorough annual review than promising monthly reviews it will not hold.
Clause 9.3.1 puts the obligation on top management, which ISO defines as the person or group that directs and controls the organisation at the highest level. In a company of 5 to 200 people that usually means the chief executive or a founder, whoever owns engineering, and the ISMS owner who prepares the pack. A review chaired by the security manager with no executive present is a common clause 9.3 finding, because the standard asks for a governance decision and only top management can make one. Record attendance by name and role.
A compliant ISO 27001 management review agenda is not long. Two hours covers all seven clause 9.3.2 inputs if the data pack is circulated beforehand and the meeting is spent on decisions rather than on reading. The agenda below names the input each item satisfies, which is the mapping an auditor looks for when comparing your minutes to the standard.
| Agenda item | Minutes | Clause 9.3.2 input covered |
|---|---|---|
| Actions from the previous review, item by item | 15 | a |
| Changes in context, and the climate change determination | 15 | b |
| Changes in interested party needs, new contractual obligations | 10 | c |
| Nonconformities, corrective actions and incident trends | 15 | d |
| Monitoring results, internal audit results, objectives progress | 15 | d |
| Feedback from customers, suppliers and staff | 10 | e |
| Risk register changes and risk treatment plan status | 25 | f |
| Improvement opportunities, resources, and decisions taken | 15 | g and 9.3.3 |
| Total | 120 | All seven inputs |
Clause 9.3.3 requires the results of the management review to include decisions on continual improvement opportunities and any needs for changes to the ISMS, with documented information retained as evidence. That is a short requirement with a sharp edge: a review that produces no decisions does not meet 9.3.3, however well attended it was. The evidence trail a certification auditor follows is the meeting invitation, the agenda, the attendance record, the data pack reviewed, the minutes, and the action log.
An ISO 27001 management review carries no audit fee. Your certification body does not charge for it, because you run it yourself. Under ISO/IEC 17021-1 section 9, the certification body's job at surveillance is to verify the review happened and met the clause, not to conduct it. The only real cost is your own people's time. The hours below are planning estimates for a team of 5 to 200 people, not survey figures.
| Line item | Planning estimate | Notes |
|---|---|---|
| Preparing the data pack | 4 to 8 hours, ISMS owner | The bulk of the effort. Falls sharply if the risk register, audit results and action log already sit in one system |
| The meeting itself | 120 minutes for 3 to 6 people | Roughly 6 to 12 person hours of executive time |
| Minutes and action log | 1 to 2 hours | Write them the same day. Reconstructed minutes read as reconstructed minutes |
| Certification body fee for the review | US$0 | The review is internal. No separate charge from your auditor or certification body |
| Consultant to facilitate, optional | Quoted by the consultant | Useful for a first review. Ask for the rate in writing before you book |
| Compliance platform, optional | CertAssist is US$225 per month as of September 2026 | Launch price, normally US$375 per month. Covers every CertAssist framework, not one |
An ISO 27001 internal audit and an ISO 27001 management review are separate clauses with separate purposes, and auditors check both. The internal audit under clause 9.2 is an evidence gathering exercise run by someone independent of the area audited, and it produces findings. The management review under clause 9.3 is a governance meeting run by top management that consumes those findings, among six other inputs, and produces decisions. One collects, the other decides. Run the audit first, because audit results are an explicit input to the review.
Most of the pain in a management review is assembly rather than judgement: pulling the risk register out of a spreadsheet, the audit findings out of a document, the action log out of a project tool. CertAssist keeps the control set, the risk register, the nonconformity register, the evidence and the activity history on every change in one place, so the clause 9.3.2 data pack is largely already assembled, and your auditor gets read-only access to review it. CertAssist has no integrations by design, so it never needs access to your cloud, identity provider or code.
CertAssist will not run the meeting for you, and it is the wrong tool if what you want is automated evidence collection from your infrastructure. It does not replace your certification body either. The management review is a governance conversation between the people who run the organisation, and no platform can hold it for them.
ISO 27001 clause 9.3.1 requires management reviews at planned intervals but sets no minimum, so you choose the interval and document it. Most certified organisations hold one full review each year, because certification bodies run annual surveillance audits and look for a review in each audit period. Some hold a short quarterly check as well. Whatever interval you write down is the one you will be audited against.
ISO 27001 requires top management to review the ISMS at planned intervals, to consider seven inputs listed in clause 9.3.2 covering previous actions, context changes, interested party changes, security performance, external feedback, risk assessment and treatment status, and improvement opportunities, and to produce results under clause 9.3.3 that include improvement decisions and any ISMS changes. Documented information must be retained as evidence.
Top management evidences commitment through records, not statements. For ISO 27001 clause 9.3 that means named executive attendance in the management review minutes, decisions signed off at that level, resources allocated in writing, and security objectives approved and tracked. An auditor tests commitment by asking who chaired the last review and what changed as a result of it.
The ISO 27001 management review is important because it is the only point in the standard where the people who control budget and priorities formally own the information security management system. Without it, the ISMS drifts into a documentation exercise run by one person. It is also mandatory: clause 9.3 is a requirement clause, so a missing review is a nonconformity at certification.
Templates are widely available, and the useful ones are structured around the seven clause 9.3.2 inputs rather than around a generic meeting format. A template is a starting point, not evidence. What an auditor examines is the completed record: the agenda, who attended, the data that was reviewed, the decisions taken, and the action log carrying those decisions to an owner and a date.
CertAssist lays out every ISO 27001 control and clause, gives you editable policy and evidence templates, and lets your auditor review it all in one place, for a flat $225 a month.
See pricing FrameworksFlat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.