ISO 27001

ISO 27001 management review: what clause 9.3 needs

21 September 2026 · 9 min read · CertAssist

The seven inputs clause 9.3.2 makes you cover, how often the review has to happen, the evidence an ISO 27001 auditor asks to see, and a two hour agenda that satisfies both.

An ISO 27001 management review is a meeting where top management formally reviews the information security management system to confirm it is still suitable, adequate and effective. Clause 9.3 of ISO/IEC 27001:2022 splits this into three parts: 9.3.1 says the review happens at planned intervals, 9.3.2 lists seven inputs that must be considered, and 9.3.3 says the results must include improvement decisions and any changes to the ISMS, recorded as documented information. There is no minimum frequency in the standard, and no fee attached to the review.

Diagram showing the seven ISO 27001 clause 9.3.2 management review inputs, being status of previous actions, changes in external and internal issues, changes in interested party needs, feedback on information security performance, feedback from interested parties, risk assessment and risk treatment status, and opportunities for improvement, feeding into the management review meeting, which produces the three clause 9.3.3 outputs of continual improvement decisions, changes needed to the ISMS, and documented information retained as evidence

What does ISO 27001 clause 9.3 actually require?

ISO 27001 clause 9.3 requires top management, not the security team, to review the ISMS at planned intervals. The 2022 edition restructured the clause into 9.3.1 General, 9.3.2 Management review inputs and 9.3.3 Management review results, where the 2013 edition ran it as a single block. The input list is now explicit and numbered, so a certification auditor can work down it item by item and ask where each one was covered. A review that discusses security in general terms but cannot be mapped back to the seven lettered inputs is the most common way organisations fail clause 9.3.

What are the seven management review inputs in clause 9.3.2?

ISO 27001 clause 9.3.2 lists seven inputs, lettered a to g. Each has evidence behind it that the auditor will ask to see, and the gap between "we talked about it" and "here is the pack we reviewed" is where nonconformities get raised.

Clause 9.3.2 inputWhat you bring to the reviewWhat the auditor checks
a) Status of actions from previous reviewsThe action log from the last review, with each item open, closed or carried forwardThat last year's actions were tracked, not quietly dropped
b) Changes in external and internal issuesUpdated clause 4.1 context: new markets, products, regulation, headcount, office or cloud regionThat the context record was revisited, including whether climate change is a relevant issue
c) Changes in interested party needs and expectationsUpdated clause 4.2 register: new customer security clauses, regulators, contractual obligationsThat new obligations arriving through sales contracts reached the ISMS
d) Feedback on information security performanceTrends in nonconformities and corrective actions, monitoring results, audit results, progress against objectivesTrends over time, not a single month. This is the input most often thin
e) Feedback from interested partiesCustomer security questionnaires, complaints, supplier assessments, staff reports, pen test feedbackThat outside signal reaches top management, not only the security owner
f) Results of risk assessment and risk treatment statusThe current risk register, changes since the last review, and risk treatment plan statusThat risks were reviewed at management level and treatment is progressing
g) Opportunities for continual improvementProposed improvements with an owner and a date against eachThat improvements were decided, not just listed

Input b now carries an extra obligation. Amendment 1:2024 added climate action wording to ISO 27001, so clause 4.1 requires the organisation to determine whether climate change is a relevant issue, and clause 4.2 notes that interested parties can have climate related requirements. The amendment does not say climate change must be relevant to you. It says you have to consider the question and record your determination, which is a one line entry in the review minutes rather than a project.

How often should management reviews be conducted?

ISO 27001 does not set a frequency. Clause 9.3.1 says "planned intervals", which means you choose the interval, write it down, and keep to it. In practice almost every certified organisation holds at least one full management review a year, because certification bodies run annual surveillance audits and look for a review in each audit period. Missing your own stated interval is a nonconformity even if the interval was generous, so a small team is better off committing to one thorough annual review than promising monthly reviews it will not hold.

Who has to attend an ISO 27001 management review?

Clause 9.3.1 puts the obligation on top management, which ISO defines as the person or group that directs and controls the organisation at the highest level. In a company of 5 to 200 people that usually means the chief executive or a founder, whoever owns engineering, and the ISMS owner who prepares the pack. A review chaired by the security manager with no executive present is a common clause 9.3 finding, because the standard asks for a governance decision and only top management can make one. Record attendance by name and role.

Timeline of a two hour ISO 27001 management review agenda showing fifteen minutes for previous actions and context changes, twenty five minutes for interested party needs and external feedback, thirty minutes for security performance covering nonconformities, monitoring results, audit results and objectives, twenty five minutes for risk assessment and risk treatment status, and twenty five minutes for improvement opportunities, resources and decisions, each segment labelled with the clause 9.3.2 input it covers

What does an ISO 27001 management review agenda look like?

A compliant ISO 27001 management review agenda is not long. Two hours covers all seven clause 9.3.2 inputs if the data pack is circulated beforehand and the meeting is spent on decisions rather than on reading. The agenda below names the input each item satisfies, which is the mapping an auditor looks for when comparing your minutes to the standard.

Agenda itemMinutesClause 9.3.2 input covered
Actions from the previous review, item by item15a
Changes in context, and the climate change determination15b
Changes in interested party needs, new contractual obligations10c
Nonconformities, corrective actions and incident trends15d
Monitoring results, internal audit results, objectives progress15d
Feedback from customers, suppliers and staff10e
Risk register changes and risk treatment plan status25f
Improvement opportunities, resources, and decisions taken15g and 9.3.3
Total120All seven inputs

What does the management review have to produce?

Clause 9.3.3 requires the results of the management review to include decisions on continual improvement opportunities and any needs for changes to the ISMS, with documented information retained as evidence. That is a short requirement with a sharp edge: a review that produces no decisions does not meet 9.3.3, however well attended it was. The evidence trail a certification auditor follows is the meeting invitation, the agenda, the attendance record, the data pack reviewed, the minutes, and the action log.

How much does an ISO 27001 management review cost?

An ISO 27001 management review carries no audit fee. Your certification body does not charge for it, because you run it yourself. Under ISO/IEC 17021-1 section 9, the certification body's job at surveillance is to verify the review happened and met the clause, not to conduct it. The only real cost is your own people's time. The hours below are planning estimates for a team of 5 to 200 people, not survey figures.

Line itemPlanning estimateNotes
Preparing the data pack4 to 8 hours, ISMS ownerThe bulk of the effort. Falls sharply if the risk register, audit results and action log already sit in one system
The meeting itself120 minutes for 3 to 6 peopleRoughly 6 to 12 person hours of executive time
Minutes and action log1 to 2 hoursWrite them the same day. Reconstructed minutes read as reconstructed minutes
Certification body fee for the reviewUS$0The review is internal. No separate charge from your auditor or certification body
Consultant to facilitate, optionalQuoted by the consultantUseful for a first review. Ask for the rate in writing before you book
Compliance platform, optionalCertAssist is US$225 per month as of September 2026Launch price, normally US$375 per month. Covers every CertAssist framework, not one

How is a management review different from an internal audit?

An ISO 27001 internal audit and an ISO 27001 management review are separate clauses with separate purposes, and auditors check both. The internal audit under clause 9.2 is an evidence gathering exercise run by someone independent of the area audited, and it produces findings. The management review under clause 9.3 is a governance meeting run by top management that consumes those findings, among six other inputs, and produces decisions. One collects, the other decides. Run the audit first, because audit results are an explicit input to the review.

What do auditors most often raise against clause 9.3?

Keeping the evidence in one place

Most of the pain in a management review is assembly rather than judgement: pulling the risk register out of a spreadsheet, the audit findings out of a document, the action log out of a project tool. CertAssist keeps the control set, the risk register, the nonconformity register, the evidence and the activity history on every change in one place, so the clause 9.3.2 data pack is largely already assembled, and your auditor gets read-only access to review it. CertAssist has no integrations by design, so it never needs access to your cloud, identity provider or code.

CertAssist will not run the meeting for you, and it is the wrong tool if what you want is automated evidence collection from your infrastructure. It does not replace your certification body either. The management review is a governance conversation between the people who run the organisation, and no platform can hold it for them.

Frequently asked questions

How often should management reviews be conducted?

ISO 27001 clause 9.3.1 requires management reviews at planned intervals but sets no minimum, so you choose the interval and document it. Most certified organisations hold one full review each year, because certification bodies run annual surveillance audits and look for a review in each audit period. Some hold a short quarterly check as well. Whatever interval you write down is the one you will be audited against.

What are the ISO 27001 management review requirements?

ISO 27001 requires top management to review the ISMS at planned intervals, to consider seven inputs listed in clause 9.3.2 covering previous actions, context changes, interested party changes, security performance, external feedback, risk assessment and treatment status, and improvement opportunities, and to produce results under clause 9.3.3 that include improvement decisions and any ISMS changes. Documented information must be retained as evidence.

How should top management provide evidence of its commitment to the ISMS?

Top management evidences commitment through records, not statements. For ISO 27001 clause 9.3 that means named executive attendance in the management review minutes, decisions signed off at that level, resources allocated in writing, and security objectives approved and tracked. An auditor tests commitment by asking who chaired the last review and what changed as a result of it.

Why is management review important?

The ISO 27001 management review is important because it is the only point in the standard where the people who control budget and priorities formally own the information security management system. Without it, the ISMS drifts into a documentation exercise run by one person. It is also mandatory: clause 9.3 is a requirement clause, so a missing review is a nonconformity at certification.

Is there an ISO 27001 management review template?

Templates are widely available, and the useful ones are structured around the seven clause 9.3.2 inputs rather than around a generic meeting format. A template is a starting point, not evidence. What an auditor examines is the completed record: the agenda, who attended, the data that was reviewed, the decisions taken, and the action log carrying those decisions to an owner and a date.

Related guides

Every ISO 27001 clause and control, in one place

CertAssist lays out every ISO 27001 control and clause, gives you editable policy and evidence templates, and lets your auditor review it all in one place, for a flat $225 a month.

See pricing Frameworks

← Back to the blog

Powerful in its simplicity.

Flat $225 a month, or $2,475 a year (12 months for the price of 11). All prices in USD.