ISO 27001 guide · Clause 9
9.3.2 — Management review inputs
Clause 9.3.2 spells out the list of inputs leadership must consider during the review, so the meeting is a defined check rather than a vague status update.
By Sentrix · Published 2026-07-16
A checklist, not a vibe: this is the specific list of things leadership has to look at before it can claim the review actually happened.
Mandatory requirement · Documented information required: no
In plain language
9.3.2 spells out exactly what leadership must look at during the management review, so the meeting cannot be a vague status update—it has to cover a defined checklist of inputs drawn from across the whole ISMS.
Why this requirement exists
Without a defined input list, a management review tends to drift toward whatever the loudest voice in the room wants to discuss, while quieter but important signals—a slow-moving corrective action, a shift in what customers now demand contractually—get skipped entirely.
Scenario: a management review spends its entire hour on a new product launch and never gets to the fact that three corrective actions from the last internal audit are still open past their deadline. A review structured around the required inputs would have surfaced that item by design, not by luck.
What the standard expects
The standard expects management review to consider: the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties relevant to the ISMS; feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.
In practice
- Build a standing agenda template with each required input as its own section, so nothing gets skipped from one review to the next.
- Open every review by checking the status of actions from the previous one—an open item that quietly disappears is the fastest way to fail this sub-clause.
- Pull metrics directly from 9.1 monitoring and findings directly from 9.2 internal audit rather than re-summarizing them from memory.
Evidence the auditor will ask for
- Minutes or a review pack showing each required input was actually presented and discussed, not just listed on an agenda.
- Traceability from previous review actions to their current status.
Common pitfalls
- A review that covers business updates but skips several of the required inputs entirely.
- Interested-party feedback that is never actually collected, so this input is presented with nothing behind it.
Related requirements
- 9.1 Monitoring and measurement—one of the direct sources of performance feedback this input list requires.
- 9.2.2 Internal audit programme—audit results are one of the named required inputs.
- 9.3.3 Management review results—what these inputs must lead to.
- Parent clause: 9.3 Management review.
Sources
Frequently asked questions
- Do we need a slide or section for every single input, every time?
- Yes, each input needs to be addressed, even if briefly. "No significant change this quarter" is a valid answer for an input, but skipping it entirely is not. A standing agenda template with each required input as its own section is the simplest way to make sure nothing gets skipped from one review to the next.
- What are the required inputs?
- The status of actions from previous reviews; changes in external and internal issues and in the needs of interested parties; feedback on security performance, including trends in nonconformities, monitoring and audit results, and fulfilment of objectives; feedback from interested parties; the results of risk assessment and the status of the treatment plan; and opportunities for continual improvement.
- What should the review open with?
- The status of actions from the previous review. An open item that quietly disappears is the fastest way to fail this sub-clause, and the auditor will look for traceability from previous review actions to their current status. Then pull metrics directly from 9.1 monitoring and findings from 9.2 internal audit rather than re-summarizing them from memory.
Related pages
ISO 27001 guide · Clause 9
9.3 — Management review
Clause 9.3 requires top management to formally review the ISMS at planned intervals, against a defined set of inputs, and come away with documented decisions.
ISO 27001 guide · Clause 9
9.1 — Monitoring, measurement, analysis and evaluation
Clause 9.1 requires you to decide in advance what to measure in security, how, when and by whom, then to evaluate the results, not just collect numbers.
ISO 27001 guide · Clause 9
9.2.2 — Internal audit programme
Clause 9.2.2 requires a recurring audit programme: frequency, criteria and scope, impartial auditors, reporting to management and retained evidence.
ISO 27001 guide · Clause 9
9.3.3 — Management review results
Clause 9.3.3 requires the management review to produce documented decisions about continual improvement opportunities and any changes the ISMS needs.
Let's talk about your compliance program.
Last updated: 2026-09-17
