GuideManagement Review

How to Run an Effective Management Review

What to include in your management review, how to structure the agenda, and what output auditors expect to see.

Updated 9 Mar 2026

Why Management Reviews Matter

ISO 27001 requires top management to review the ISMS at planned intervals. This isn't a formality — it's where strategic decisions about your security programme are made.

Required Inputs (Clause 9.3)

Your management review must consider:

1Status of actions from previous reviews
2Changes in external/internal issues — relevant to the ISMS
3Feedback on information security performance — :

- Nonconformities and corrective actions

- Monitoring and measurement results

- Audit results

- Fulfilment of objectives

4Feedback from interested parties
5Results of risk assessment and treatment plan status
6Opportunities for continual improvement

Required Outputs

The review must produce decisions on:

Continual improvement opportunities
Any changes needed to the ISMS
Resource needs

Practical Tips

Schedule regularly — quarterly for the first year, then at least annually
Use a structured agenda — map inputs directly to agenda items
Record decisions, not just discussions — auditors want to see what was decided
Assign action owners and deadlines
Keep minutes concise but complete

Common Mistakes

Treating it as a presentation rather than a decision-making meeting
Not including actual security metrics
Missing required inputs
No follow-up on actions from previous reviews

Related Modules

Documents
Calendar
Objectives

Related Controls / Clauses

9.3
5.1
6.2

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.