ISO27K

ISO 27001 management review: clause 9.3

Clause 9.3 asks top management to review the management system at planned intervals against a fixed list of inputs. It is a meeting with minutes. It is also, along with the internal audit, one of the two records a certification body checks before it will let you book stage 2.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

An ISO 27001 management review is a meeting of top management, required by clause 9.3, that has to cover seven specified inputs and record two kinds of output. One of those inputs breaks into four separate trend items, so an agenda that covers everything has ten lines on it. It takes 60 to 90 minutes when the pack is prepared properly, it has to happen before stage 2, and there is no version of this requirement that can be satisfied after the fact, because the minutes carry a date.

7 inputs Required by clause 9.3.2, one of which has four parts

60 to 90 min A real review, with the pack circulated beforehand

What clause 9.3.2 requires on the agenda

The list is closed. You can add to it, and you cannot leave any of it out. This is the table to build your agenda from, and the right-hand column is what an auditor looks for in the minutes when they check that the item was actually discussed rather than listed.

Clause 9.3.2 inputs and what the minutes have to show for each
Required inputWhat the minutes must show
a) Status of actions from previous management reviewsEach prior action, its owner, and whether it closed. At the first review, a note that there are none
b) Changes in external and internal issues relevant to the ISMSA named change: a new customer segment, a new jurisdiction, an acquisition, a change in Canadian privacy obligations
c) Changes in the needs and expectations of interested partiesNew contractual security terms, a customer asking for ISO 42001, a regulator's guidance
d) 1) Trends in nonconformities and corrective actionsHow many were raised, how many closed, whether the same cause recurs
d) 2) Monitoring and measurement resultsThe clause 9.1 metrics with actual numbers, compared against the previous period
d) 3) Audit resultsInternal audit findings, and any certification body findings from the last visit
d) 4) Fulfilment of information security objectivesEach clause 6.2 objective against its target, with the gap discussed rather than reported
e) Feedback from interested partiesCustomer security questionnaires, complaints, supplier assessments, staff reports
f) Results of risk assessment and status of the risk treatment planWhat changed in the register and what is overdue in the treatment plan
g) Opportunities for continual improvementItems raised by management, not only items inherited from the audit
Agenda lines needed to cover clause 9.3.2 in full10, from seven lettered inputs

Clause 9.3.3 then requires the outputs: decisions related to opportunities for continual improvement, and any need for changes to the management system. The word decisions is the operative one. Minutes that record ten topics as noted and produce no decision have failed the output requirement even though every input was covered.

How often does a management review have to happen

The standard says at planned intervals. It does not say annually, and the near-universal practice of holding one meeting a year in the month before the audit is a choice rather than a requirement. Quarterly is easier, not harder, for a reason worth understanding before you set the cadence.

Annual
One long meeting with twelve months of material. Every input has to be assembled at once, the metrics comparison is against a year-old baseline, and if the meeting slips by a month the interval was not the planned interval. It is also the version that reads as an audit preparation exercise.
Quarterly
Four short meetings, each with one quarter of material and a working comparison against the previous quarter. Actions from the last review are recent enough to have moved. A missed quarter is recoverable. This is the cadence that makes clause 9.3 a) produce something other than a blank row.
Ad hoc on top
Legitimate and useful. A significant incident, an acquisition or a major scope change is a reason to convene one, and doing so is direct evidence of the leadership integration clause 5.1 asks for.

Whatever you choose, write it in the ISMS as the planned interval and then hold to it. An auditor comparing a documented quarterly cadence against three meetings in eighteen months is looking at a nonconformity against your own system, which is a worse finding than a documented annual cadence you kept.

Who has to be in the room

Top management, which under clause 3 means the people who direct and control the organization at the highest level. The review is theirs. A meeting run by the security lead who then sends the output to the CEO for approval is not a management review, and it is the most common way this requirement is missed by companies who believe they have met it.

  1. Top management. Non-negotiable, and if the CEO cannot attend, reschedule rather than proceed.
  2. Whoever holds the clause 5.3 duty for reporting ISMS performance. They present, they do not chair.
  3. The engineering or operations lead, because most of the measurement data and most of the improvement decisions land on them.
  4. Whoever owns customer contracts, for input e), since they hold the security questionnaires and the contractual security terms.
  5. Optionally the internal auditor for the audit results item, though not as a standing attendee.

A worked agenda you can send as the invite

Quarterly ISMS management review, 90 minutes

1. Actions from the last review, 10 minutes. 2. Changes in context and in interested party requirements, 10 minutes, covering new customers, new jurisdictions and contract changes. 3. Nonconformities and corrective actions, 10 minutes, with the trend across quarters. 4. Measurement results against the clause 9.1 metrics, 15 minutes. 5. Audit results, internal and external, 10 minutes. 6. Objectives against target, 15 minutes. 7. Risk assessment changes and risk treatment plan status, 15 minutes. 8. Improvement opportunities and decisions, 15 minutes, ending with named owners and dates.

Circulate the pack two working days ahead. The pack is what makes the meeting short: the numbers and the register extracts go in the document, and the meeting spends its time on the four or five things that need a decision. A review that spends 60 minutes having data read aloud produces minutes with no decisions in them, which fails clause 9.3.3.

What the minutes have to contain

Date, attendees and apologies
Attendance is evidence of the top management requirement. Record who was absent and why.
Each required input, with the substance
Not just the heading. One or two sentences of what was said and what the numbers were. A minute reading "objectives: discussed" satisfies nothing.
Decisions, separately headed
Clause 9.3.3 asks for decisions on improvement opportunities and on changes to the ISMS. Put them under their own heading so the auditor can find them without reading the whole document.
Actions with owner and date
These become the input a) at the next review, which is the mechanism that makes the requirement a loop rather than a ritual.
Resource decisions
Anything approved or declined. This is also the cleanest evidence for clause 5.1 c) on providing resources, so record the number.
Approval
Signed or acknowledged by the chair, version controlled under clause 7.5, and retained for the full certification cycle.

What happens if there is no management review before stage 2

The stage 2 audit does not proceed, or it proceeds and produces a major nonconformity against clause 9.3. Certification bodies check for the internal audit and the management review at stage 1 precisely so this is caught while there is still time, which is one of the reasons stage 1 exists at all. The usual outcome is that stage 2 moves by four to eight weeks while you hold the review and gather the inputs it needs, and moving an audit date has a cost of its own because auditor calendars are booked out. What a major finding means mechanically, and how long you get to close it, is on the nonconformity page.

The review needs the internal audit to have happened first

Input d) 3) is audit results, so the review cannot be complete until the internal audit has produced findings. That ordering constraint is what compresses the last two months of a first certification project: measurement, then internal audit, then management review, then stage 1. Booking the independent internal auditor late is the step that pushes all three.

When quarterly is genuinely too much

The counter-case, because four meetings a year of senior time is a real cost. For a company under about twenty-five people with one product, one cloud account and few changes, two reviews a year is defensible and the second one can be short. What makes it work is that the inputs are genuinely thin: if there were no nonconformities, no scope changes, no new interested party requirements and no incidents in six months, a 30-minute review that records exactly that is honest and complete.

What does not work is halving the frequency because assembling the pack is tedious. If the metrics are hard to produce, the problem is clause 9.1 rather than clause 9.3, and the fix is to choose measurements that come out of systems you already run rather than ones that need a manual count. The clause overview shows where 9.1, 9.2 and 9.3 sit in relation to each other, and the surveillance audit page covers what happens to all of this in years two and three.

Get your first management review run properly

Tell us where you are in the project and we will match you with Canadian firms who will build the pack and chair the first one with you.

Get matched

Common questions

How often does an ISO 27001 management review have to happen?

At planned intervals, which is whatever you documented, and at minimum often enough that the system is genuinely reviewed. Annual is the common choice and quarterly is easier to evidence because each meeting has less to cover and the actions from the previous one are recent. What matters at audit is that you kept to the interval you wrote down.

Who has to attend the management review?

Top management, meaning the people who direct and control the organization at the highest level. In a small Canadian company that is the founder or CEO plus one or two others. A meeting held by the security team and circulated upward afterwards does not satisfy clause 9.3, and it is the most common failure of this requirement.

Can the management review be part of an existing leadership meeting?

Yes, and it often should be. Clause 9.3 does not require a dedicated meeting, it requires that the inputs are reviewed by top management and the outputs recorded. A standing security item on a monthly leadership meeting works well, provided the minutes clearly cover all the required inputs across the cycle and the decisions are identifiable as such.

What if we have nothing to report against an input?

Record that. A minute saying there were no nonconformities in the period and no changes to interested party requirements satisfies the input. What fails is silence, because an auditor cannot distinguish between an item considered and found empty and an item never raised.

Does the management review have to happen before stage 2?

Yes. Along with the internal audit it is one of the two clause 9 records a certification body expects to see at stage 1, and its absence is the single most common reason a stage 2 date moves. Plan it for at least four weeks before stage 2 so any actions it raises have somewhere to go.

How long should the minutes be?

Two to four pages for a quarterly review. Long enough that each required input has substance recorded against it and the decisions are separately identifiable, short enough that they were written the same week. Minutes written from memory two months later usually show it, and the version date tells the auditor when they were created.