Sentrix

ISO 27001 guide · Clause 10

Clause 10 — Improvement

Clause 10 requires the ISMS to keep improving and to respond properly to every nonconformity: react, fix the root cause, verify the fix and adjust the system.

By Sentrix · Published 2026-07-16

Requirement 10 · “Act” phase of the PDCA cycle

In plain language

The last of the seven certifiable clauses, and the one that turns everything clause 9 finds into something that actually changes. Clause 10 requires the ISMS to keep getting better over time, and to respond properly whenever something goes wrong: react to the problem, fix its root cause so it does not come back, and update the system if the fix reveals the ISMS itself needs to change. Without clause 10, clause 9’s audits and reviews would just be a record of problems nobody acted on.

What clause 10 covers

Clause 10 is the shortest of the seven certifiable clauses and, like clause 8, has no sub-clauses beneath its two requirements. 10.1 sets a standing obligation: the ISMS must continually improve, on an ongoing basis, not just at renewal. 10.2 sets the discipline for handling things that go wrong—react, correct the root cause, verify the fix worked, and change the ISMS itself if needed. Together they are what keeps the whole system from calcifying the moment the certificate is issued.

A reordering worth knowing about

If you have ever seen the 2013 version of this standard, note that the two sub-clauses swapped places. In 2013, 10.1 was “Nonconformity and corrective action” and 10.2 was “Continual improvement.” The 2022 revision flipped the order—10.1 is now Continual improvement, 10.2 is Nonconformity and corrective action—putting the forward-looking requirement first. The substance of both requirements is largely unchanged; only their numbering and sequence moved.

The documents that come out of clause 10

  • Evidence of the nature of each nonconformity and any action taken in response (10.2)
  • The results of each corrective action (10.2)

10.1 (continual improvement) sets an ongoing obligation rather than a discrete deliverable, so it does not itself require a standalone document.

Going further

Need hands-on support closing the loop on audit findings? See our ISO 27001 certification support service or contact us. The ISO 27001 framework page summarises the standard as a whole.

Sources

Frequently asked questions

Why did 10.1 and 10.2 swap in the 2022 version?
The 2022 revision put continual improvement first to emphasize that improvement is an ongoing posture, not just a reaction to problems. The content of both requirements stayed largely the same: only the order and numbering changed. In 2013, 10.1 was “Nonconformity and corrective action” and 10.2 was “Continual improvement.”
Do I need a formal corrective action process?
Yes. 10.2 requires a defined way to react to nonconformities, investigate root cause, implement fixes, and verify they worked, with documented evidence at each step: the nature of each nonconformity, the actions taken, and the results of corrective actions. A single register capturing every finding is the simplest form.
Does 10.1 require a separate document?
No. 10.1 sets an ongoing obligation rather than a discrete deliverable, so it does not itself require a standalone document. It is demonstrated through existing records—management review minutes showing improvement was discussed, audit follow-ups, a log of improvement initiatives—as long as improvement activity is visible somewhere between audits.

Let's talk about your compliance program.

Last updated: 2026-09-17