Sentrix

ISO 27001 guide · Clause 10

10.1 — Continual improvement

Clause 10.1 requires you to continually improve the suitability, adequacy and effectiveness of the ISMS, as an ongoing posture rather than a task ticked off.

By Sentrix · Published 2026-07-16

The shortest requirement in the standard, and one of the easiest to satisfy on paper while quietly failing in practice.

Mandatory requirement · Documented information required: no

In plain language

10.1 requires you to keep making the ISMS better—more suitable, more adequate for your risks, more effective—as an ongoing posture, not a task you complete once and check off.

Why this requirement exists

Standards that only demand compliance with a fixed baseline eventually become obsolete as threats, technology, and the organization itself change. This requirement exists to keep the ISMS moving forward even when nothing has gone visibly wrong—because waiting for a nonconformity before improving means the system only ever reacts, never gets ahead.

Scenario: an organization passes three consecutive surveillance audits with zero nonconformities and concludes the ISMS needs no attention. Nobody is looking for ways to streamline the evidence collection process, tighten the risk criteria, or adopt better tooling—because nothing is technically broken. The ISMS is compliant, but stagnant, and 10.1 is exactly the requirement a sharp auditor invokes to ask what has actually improved since certification.

What the standard expects

The standard expects the organization to continually improve the suitability, adequacy, and effectiveness of the information security management system. Unlike 10.2, this is not tied to a specific trigger like a nonconformity—it is a general, ongoing obligation that draws on inputs from across the ISMS: monitoring results (9.1), internal audit findings (9.2), management review decisions (9.3), and corrective actions (10.2).

In practice

  • Keep a running log of improvement ideas sourced from monitoring, audits, and management review—not everything needs to become a formal project, but they should be visible somewhere.
  • Treat "zero nonconformities" as a starting point for asking what could be tightened, not as a finish line.
  • Bring at least one improvement initiative to each management review, even a small one, so the requirement stays visibly active rather than dormant.

Evidence the auditor will ask for

  • A record of improvement initiatives undertaken since the last audit, even modest ones.
  • Management review minutes showing improvement was discussed, not just compliance status.

Common pitfalls

  • Treating "no nonconformities" as proof the ISMS needs no attention.
  • No visible trail of improvement activity between audits, even when informal improvements did happen.

Related requirements

2013 → 2022 mapping

2022 version2013 versionNature of change
10.1 Continual improvement10.2 Continual improvementSame content, moved from 10.2 to 10.1

Sources

Frequently asked questions

Does 10.1 require a separate improvement plan document?
No. It can be demonstrated through existing records like management review minutes and audit follow-ups, as long as improvement activity is visible somewhere. The auditor will ask for a record of initiatives undertaken since the last audit, even modest ones, and for minutes showing improvement was discussed, not just compliance status.
Does zero nonconformities mean the ISMS needs nothing?
No. That is precisely the trap 10.1 targets: a compliant but stagnant ISMS. Treat "zero nonconformities" as a starting point for asking what could be tightened—streamlining evidence collection, tightening risk criteria, adopting better tooling—rather than as a finish line. A sharp auditor will ask what has actually improved since certification.
How is 10.1 different from 10.2?
10.2 is triggered by a specific event: a nonconformity to correct. 10.1 is a general, ongoing obligation with no trigger, drawing on inputs from across the ISMS—monitoring results, internal audit findings, management review decisions, and corrective actions—to improve the suitability, adequacy, and effectiveness of the system. One reacts; the other gets ahead.

Let's talk about your compliance program.

Last updated: 2026-09-17