Sentrix

ISO 27001 guide · Clause 9

9.3.2 — Management review inputs

Clause 9.3.2 spells out the list of inputs leadership must consider during the review, so the meeting is a defined check rather than a vague status update.

By Sentrix · Published 2026-07-16

A checklist, not a vibe: this is the specific list of things leadership has to look at before it can claim the review actually happened.

Mandatory requirement · Documented information required: no

In plain language

9.3.2 spells out exactly what leadership must look at during the management review, so the meeting cannot be a vague status update—it has to cover a defined checklist of inputs drawn from across the whole ISMS.

Why this requirement exists

Without a defined input list, a management review tends to drift toward whatever the loudest voice in the room wants to discuss, while quieter but important signals—a slow-moving corrective action, a shift in what customers now demand contractually—get skipped entirely.

Scenario: a management review spends its entire hour on a new product launch and never gets to the fact that three corrective actions from the last internal audit are still open past their deadline. A review structured around the required inputs would have surfaced that item by design, not by luck.

What the standard expects

The standard expects management review to consider: the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties relevant to the ISMS; feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.

In practice

  • Build a standing agenda template with each required input as its own section, so nothing gets skipped from one review to the next.
  • Open every review by checking the status of actions from the previous one—an open item that quietly disappears is the fastest way to fail this sub-clause.
  • Pull metrics directly from 9.1 monitoring and findings directly from 9.2 internal audit rather than re-summarizing them from memory.

Evidence the auditor will ask for

  • Minutes or a review pack showing each required input was actually presented and discussed, not just listed on an agenda.
  • Traceability from previous review actions to their current status.

Common pitfalls

  • A review that covers business updates but skips several of the required inputs entirely.
  • Interested-party feedback that is never actually collected, so this input is presented with nothing behind it.

Related requirements

Sources

Frequently asked questions

Do we need a slide or section for every single input, every time?
Yes, each input needs to be addressed, even if briefly. "No significant change this quarter" is a valid answer for an input, but skipping it entirely is not. A standing agenda template with each required input as its own section is the simplest way to make sure nothing gets skipped from one review to the next.
What are the required inputs?
The status of actions from previous reviews; changes in external and internal issues and in the needs of interested parties; feedback on security performance, including trends in nonconformities, monitoring and audit results, and fulfilment of objectives; feedback from interested parties; the results of risk assessment and the status of the treatment plan; and opportunities for continual improvement.
What should the review open with?
The status of actions from the previous review. An open item that quietly disappears is the fastest way to fail this sub-clause, and the auditor will look for traceability from previous review actions to their current status. Then pull metrics directly from 9.1 monitoring and findings from 9.2 internal audit rather than re-summarizing them from memory.

Let's talk about your compliance program.

Last updated: 2026-09-17