Sentrix

ISO 27001 guide · Clause 9

Clause 9 — Performance evaluation

Clause 9 requires you to prove the ISMS works: monitor and measure your controls, audit the system independently, and have leadership formally review it.

By Sentrix · Published 2026-07-16

Requirement 9 · “Check” phase of the PDCA cycle

In plain language

You cannot claim the ISMS works—you have to prove it. Clause 9 is where the standard stops asking you to build things and starts asking you to check them: measure whether your controls are performing, audit the system with an independent eye, and have leadership formally review the results. It is the clause auditors weigh most heavily when deciding how much to trust everything else in your file, because a weak clause 9 usually means the rest of the ISMS is undocumented drift rather than a managed system.

What clause 9 covers

Clause 9 answers three questions, in ascending order of formality. First: are you actually watching your security performance day to day—what gets measured, how, and by whom (9.1)? Second: does an independent internal audit confirm the ISMS conforms to its own rules and to the standard (9.2)? Third: does top management step back, on a planned schedule, and formally decide whether the whole system is still suitable, adequate, and effective (9.3)? Each layer checks the one below it, which is exactly what an auditor is looking to see working.

Why it is central

Internal audit findings (9.2) are the single best predictor of how a certification audit will go: if your own internal audit consistently finds nothing, either your ISMS is unusually mature or your internal audit is not looking hard enough—and an external auditor will probe to find out which. Management review (9.3) closes the loop by forcing leadership to actually act on what 9.1 and 9.2 surface, which is what keeps clause 10 (improvement) from becoming a formality.

The documents that come out of clause 9

  • Evidence of monitoring and measurement results (9.1)
  • The internal audit programme (9.2.2)
  • Internal audit results and evidence the programme was implemented (9.2.2)
  • The results of management reviews (9.3.3)

Going further

Need hands-on support building your monitoring program, internal audit, and management review? See our ISO 27001 certification support service or contact us. The ISO 27001 framework page summarises the standard as a whole.

Sources

Frequently asked questions

What is the difference between 9.1 and 9.2?
9.1 is ongoing, operational monitoring of specific metrics (is MFA coverage complete? are backups completing?). 9.2 is a periodic, independent internal audit checking whether the whole ISMS—including whether 9.1 itself is being done properly—conforms to your own rules and to the standard. Each layer checks the one below it.
Who can perform the internal audit?
Anyone independent of the area being audited: an internal employee from a different team, or an external contractor for smaller organizations without enough internal separation. The requirement is objectivity and impartiality, not a specific credential. An auditor who reviews their own area of responsibility is the single most common finding against 9.2.
How often must management review happen?
The standard says "at planned intervals" without naming a frequency. Most organizations run it annually, aligned with the certification or surveillance audit cycle, with some choosing a semi-annual cadence for a more mature program. What matters is putting it on a fixed calendar rather than holding it "when there is time".

Let's talk about your compliance program.

Last updated: 2026-09-17