ISO 27001 guide · Clause 9
9.3.1 — General
Clause 9.3.1 requires top management to review the ISMS at planned intervals and judge whether it remains suitable, adequate for its risks and effective.
By Sentrix · Published 2026-07-16
Three words that decide whether the ISMS survives another year: suitable, adequate, effective.
Mandatory requirement · Documented information required: no
In plain language
9.3.1 requires top management—not a delegate, not a committee acting alone—to formally review the ISMS at planned intervals and judge whether it is still suitable for the organization, adequate for its risks, and effective at delivering security outcomes.
Why this requirement exists
Delegating security entirely to an operational team, with leadership never actually looking at how the program is doing, is exactly the pattern this requirement is designed to prevent. An ISMS that only the security team ever reviews tends to optimize for what the security team can influence, while organizational-level problems—under-resourcing, conflicting priorities, scope creep—go unaddressed because nobody with the authority to fix them is looking.
Scenario: a company’s security team has flagged, for three straight quarters, that they lack the budget to remediate a known risk. Without a management review forcing that status in front of leadership on a fixed schedule, the flag stays buried in a team-level tracker indefinitely.
What the standard expects
The standard expects top management to review the organization’s ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. "Suitability" asks whether the ISMS still fits the organization as it exists today; "adequacy" asks whether it addresses the risks the organization actually faces; "effectiveness" asks whether it delivers the intended security outcomes. All three must be considered—a system can be perfectly documented and still fail on any one of them.
In practice
- Put management review on a fixed calendar (annually is common) so it happens on schedule rather than "when there is time."
- Make sure the people in the room actually have the authority to approve budget, resourcing, or scope changes—a review attended only by the security team is not a management review.
Evidence the auditor will ask for
- Calendar invites or minutes showing the review actually happened at the planned interval, with top management present.
- Attendance records confirming the participants had real decision-making authority.
Related requirements
- 9.3.2 Management review inputs—what this general review must actually consider.
- Clause 5 Leadership—management review is one of the clearest tests of the leadership commitment clause 5 requires.
- Parent clause: 9.3 Management review.
Sources
Frequently asked questions
- Who counts as "top management" for this review?
- The person or group who directs and controls the organization at the highest level. For a small company, that might be the founder or CEO; for a larger one, a senior executive with real authority over resourcing. What matters is that the people in the room can approve budget, resourcing, or scope changes—not a delegate or a committee acting alone.
- What do "suitability, adequacy, and effectiveness" mean?
- Suitability asks whether the ISMS still fits the organization as it exists today; adequacy, whether it addresses the risks the organization actually faces; effectiveness, whether it delivers the intended security outcomes. All three must be considered at every review: a system can be perfectly documented and still fail on any one of them.
- What evidence will the auditor ask for under 9.3.1?
- Calendar invites or minutes showing the review actually happened at the planned interval, with top management present, and attendance records confirming the participants had real decision-making authority. A review held "when there is time" or attended only by the security team does not satisfy the requirement.
Related pages
ISO 27001 guide · Clause 9
9.3 — Management review
Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.
ISO 27001 guide · Clause 9
9.3.2 — Management review inputs
Clause 9.3.2 spells out the list of inputs leadership must consider during the review, so the meeting is a defined check rather than a vague status update.
ISO 27001 guide · Plan
Clause 5 — Leadership
ISO 27001:2022 clause 5 covers leadership commitment, the information security policy and assigned roles: the accountability every other clause depends on.
Let's talk about your compliance program.
Last updated: 2026-09-17
