ISO 27001 guide · Clause 10
10.1 — Continual improvement
Clause 10.1 requires you to continually improve the suitability, adequacy and effectiveness of the ISMS, as an ongoing posture rather than a task ticked off.
By Sentrix · Published 2026-07-16
The shortest requirement in the standard, and one of the easiest to satisfy on paper while quietly failing in practice.
Mandatory requirement · Documented information required: no
In plain language
10.1 requires you to keep making the ISMS better—more suitable, more adequate for your risks, more effective—as an ongoing posture, not a task you complete once and check off.
Why this requirement exists
Standards that only demand compliance with a fixed baseline eventually become obsolete as threats, technology, and the organization itself change. This requirement exists to keep the ISMS moving forward even when nothing has gone visibly wrong—because waiting for a nonconformity before improving means the system only ever reacts, never gets ahead.
Scenario: an organization passes three consecutive surveillance audits with zero nonconformities and concludes the ISMS needs no attention. Nobody is looking for ways to streamline the evidence collection process, tighten the risk criteria, or adopt better tooling—because nothing is technically broken. The ISMS is compliant, but stagnant, and 10.1 is exactly the requirement a sharp auditor invokes to ask what has actually improved since certification.
What the standard expects
The standard expects the organization to continually improve the suitability, adequacy, and effectiveness of the information security management system. Unlike 10.2, this is not tied to a specific trigger like a nonconformity—it is a general, ongoing obligation that draws on inputs from across the ISMS: monitoring results (9.1), internal audit findings (9.2), management review decisions (9.3), and corrective actions (10.2).
In practice
- Keep a running log of improvement ideas sourced from monitoring, audits, and management review—not everything needs to become a formal project, but they should be visible somewhere.
- Treat "zero nonconformities" as a starting point for asking what could be tightened, not as a finish line.
- Bring at least one improvement initiative to each management review, even a small one, so the requirement stays visibly active rather than dormant.
Evidence the auditor will ask for
- A record of improvement initiatives undertaken since the last audit, even modest ones.
- Management review minutes showing improvement was discussed, not just compliance status.
Common pitfalls
- Treating "no nonconformities" as proof the ISMS needs no attention.
- No visible trail of improvement activity between audits, even when informal improvements did happen.
Related requirements
- 10.2 Nonconformity and corrective action—the reactive counterpart: what happens when improvement is triggered by something going wrong.
- 9.3.3 Management review results—continual improvement decisions are a required output of management review.
- Parent clause: Clause 10 Improvement.
2013 → 2022 mapping
| 2022 version | 2013 version | Nature of change |
|---|---|---|
| 10.1 Continual improvement | 10.2 Continual improvement | Same content, moved from 10.2 to 10.1 |
Sources
Frequently asked questions
- Does 10.1 require a separate improvement plan document?
- No. It can be demonstrated through existing records like management review minutes and audit follow-ups, as long as improvement activity is visible somewhere. The auditor will ask for a record of initiatives undertaken since the last audit, even modest ones, and for minutes showing improvement was discussed, not just compliance status.
- Does zero nonconformities mean the ISMS needs nothing?
- No. That is precisely the trap 10.1 targets: a compliant but stagnant ISMS. Treat "zero nonconformities" as a starting point for asking what could be tightened—streamlining evidence collection, tightening risk criteria, adopting better tooling—rather than as a finish line. A sharp auditor will ask what has actually improved since certification.
- How is 10.1 different from 10.2?
- 10.2 is triggered by a specific event: a nonconformity to correct. 10.1 is a general, ongoing obligation with no trigger, drawing on inputs from across the ISMS—monitoring results, internal audit findings, management review decisions, and corrective actions—to improve the suitability, adequacy, and effectiveness of the system. One reacts; the other gets ahead.
Related pages
ISO 27001 guide · Clause 10
Clause 10 — Improvement
Clause 10 requires the ISMS to keep improving and to respond properly to every nonconformity: react, fix the root cause, verify the fix and adjust the system.
ISO 27001 guide · Clause 10
10.2 — Nonconformity and corrective action
Clause 10.2 requires you to react to each nonconformity, eliminate its root cause, verify that the corrective action worked, and retain evidence of each step.
ISO 27001 guide · Clause 9
9.3.3 — Management review results
Clause 9.3.3 requires the management review to produce documented decisions about continual improvement opportunities and any changes the ISMS needs.
Let's talk about your compliance program.
Last updated: 2026-09-17
