ISO 27001 management review: agenda, inputs and minutes

Clause 9.3 is the cheapest clause to pass and one of the most commonly failed. Here is the working agenda, the mandatory inputs in plain language, and what the minutes need to contain for an auditor to sign it off.

Michael McCarroll 11 min read Updated August 2026

Step 1 — Get the right people and cadence

Step 1

Fix the interval and diarise it

Set the cadence in your ISMS documentation — quarterly reviews with an extended annual one is the pattern that survives audit best. Put the dates in calendars for the full year so a missed meeting is visible before the certification body finds it.
Step 2

Invite people who can decide

Top management, the ISMS owner, and leads for IT, HR, operations and any function with material risk. If someone essential cannot attend, capture their written input and reference it in the minutes.

Step 2 — The working agenda

Copy this agenda directly. Each item maps to a clause 9.3 input, so the minutes double as your audit evidence.

  1. Actions from the last review — status of every action, closed or carried with a reason.
  2. Internal and external changes — new regulation, contracts, technology, restructures, sites, suppliers.
  3. Interested parties — customer security requirements, regulator expectations, employee feedback.
  4. Security performance — incidents, nonconformities and corrective actions, monitoring and measurement results, internal audit results, objective achievement.
  5. Risk and treatment status — new and changed risks, overdue treatments, residual risk acceptance.
  6. Supplier and third-party assurance — reviews completed, issues raised, contract changes.
  7. Resources — headcount, budget, tooling and competence gaps.
  8. Continual improvement — opportunities identified and prioritised.
  9. Decisions and actions — owner and due date for each.

Step 3 — Prepare the pack before the meeting

Step 3

Turn data into a one-page dashboard

Open risks by score, overdue treatments, incidents by category, audit findings open versus closed, objective progress, policy acknowledgement rate, access review completion. Numbers drive decisions; narrative does not.
Step 4

Pre-circulate 48 hours ahead

Send the pack with the agenda so the meeting is spent deciding, not reading. Record the circulation — it evidences that top management had the information.

Management review checklist

  • Review held within the interval stated in your ISMS documentation.
  • Attendance list captured, including top management.
  • Previous actions reviewed and status recorded for each.
  • All nine agenda items above covered and minuted.
  • Performance data attached or referenced, not just described.
  • Risk register and treatment plan status reviewed.
  • Every decision has an owner and a due date.
  • Resource decisions recorded explicitly, including "no change required".
  • Minutes approved and stored as documented information under clause 7.5.
  • Actions transferred into the tracked action log, not left in the minutes.

Writing minutes an auditor accepts

Step 5

Mirror the input list

Use the agenda headings as minute headings. An auditor scanning for "monitoring and measurement results" should find that exact phrase.
Step 6

End with a decision table

Decision, rationale, owner, due date, status. This single table is what turns clause 9.3 from a meeting into a management system.

Frequently asked questions

How often should a management review be held?
Clause 9.3 says at planned intervals. Annual is the minimum most certification bodies accept, but quarterly reviews are easier to evidence and stop the meeting becoming a two-hour catch-up before the audit. Many organisations run a short quarterly review and one deeper annual review.
Who has to attend?
Top management — the people who can allocate resource and change direction. In an SME that is usually the managing director or CEO, the person accountable for the ISMS, and function leads for IT, HR and operations. Attendance is evidence: record who was present and, if someone essential was absent, how their input was provided.
What inputs are mandatory?
Status of actions from previous reviews; changes in internal and external issues relevant to the ISMS; interested party needs; feedback on information security performance including nonconformities, monitoring results, audit results and objective achievement; feedback from interested parties; risk assessment and risk treatment plan status; and opportunities for continual improvement.
What counts as an output?
Decisions related to continual improvement opportunities and any need for changes to the ISMS — including resource decisions. An output is a decision with an owner and a date, not a discussion note.
Can the management review be part of another meeting?
Yes, provided the ISMS agenda items are clearly identified and minuted separately. A standing agenda block in a monthly leadership meeting works well; a passing mention in general AOB does not.
What is the most common audit finding on clause 9.3?
Minutes that record discussion but no decisions, or that skip mandatory inputs. Structure the minutes around the clause 9.3 input list so the auditor can tick each item, and end with a decision table containing owner and due date.

Generate the management review pack from live data

Risk, audit, incident, objective and policy metrics assembled into a clause 9.3 agenda, with decisions tracked as actions and the minutes stored as controlled documented information.

ISO-STANDARD.app ships a ready-to-adopt ISO 27001 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Related guides
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →