Sentrix

ISO 27001 guide · Clause 9

9.3 — Management review

Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.

By Sentrix · Published 2026-07-16

The point where everything 9.1 and 9.2 surfaced actually reaches the people with the authority to act on it.

Mandatory requirement

In plain language

Sub-clause 9.3 requires top management to formally review the ISMS at planned intervals, looking at a defined set of inputs—audit results, metrics, risk status, feedback—and to walk away with documented decisions about what needs to change.

How these requirements fit together

9.3.1 sets the cadence and the purpose: leadership steps back periodically to judge whether the ISMS as a whole is still fit for purpose. 9.3.2 makes sure that judgment is not made on gut feel—it lists the specific inputs the review must consider, from audit findings to risk treatment status to interested-party feedback, so nothing important gets left out of the conversation. 9.3.3 closes the loop by requiring the review to actually produce something: documented decisions, not just a meeting that happened. A management review with no 9.3.2 inputs is an opinion; a management review with no 9.3.3 outputs is a meeting with no consequences.

Going further

Need hands-on support running your management review? See our ISO 27001 certification support service. Parent clause: Clause 9 Performance evaluation.

Sources

Frequently asked questions

How often must management review happen?
The standard says "at planned intervals" without naming a frequency. Most organizations run it annually, aligned with the certification or surveillance audit cycle, with some choosing a semi-annual cadence for a more mature program. What matters is putting it on a fixed calendar so it happens on schedule rather than "when there is time".
Who has to take part in the management review?
Top management itself—not a delegate, not a committee acting alone. The people in the room must actually have the authority to approve budget, resourcing, or scope changes. A review attended only by the security team is not a management review, and the auditor will check through attendance records that the participants had real decision-making authority.
What does the management review have to produce?
Documented decisions related to continual improvement opportunities and any needs for changes to the ISMS, kept as evidence. A management review with no 9.3.2 inputs is an opinion; a review with no 9.3.3 outputs is a meeting with no consequences. A decisions log with owners and deadlines is the simplest form.

Let's talk about your compliance program.

Last updated: 2026-09-17