The management review is a central governance mechanism within an ISO 27001-compliant ISMS. It is the mechanism by which top management demonstrates it is actively directing the Information Security Management System (ISMS). The management review records are one of the most revealing documents for ISO 27001 audit.
ISO 27001 Clause 9.3 requires top management to review the ISMS at planned intervals to confirm it remains suitable, adequate, and effective (Source: ISO/IEC 27001:2022). The 2022 revision restructured this into three explicit sub-clauses, each demanding a distinct category of documented evidence:
- 9.3.1 (General)
- 9.3.2 (Inputs)
- 9.3.3 (Results)
Understanding what an auditor examines in each sub-clause is essential for any organization pursuing or maintaining ISO 27001 certification. This article explains the audit perspective: what evidence auditors collect, what failure patterns they recognize, and why the management review in ISO 27001 is a load-bearing document rather than a procedural formality.
Concern
An ISO 27001 management review can become a recurring meeting with limited audit value when minutes record topics rather than management evaluation and decisions. For ISO 27001 certification, auditors examine whether documented results demonstrate meaningful oversight of the ISMS.
Overview
ISO 27001 Clause 9.3 is split into three sub-clauses: 9.3.1 (General), 9.3.2 (Management Review Inputs), and 9.3.3 (Management Review Results). Each sub-clause demands specific, verifiable evidence. Auditors examine minutes, attendance records, action trackers, and resource decisions across multiple review cycles.
Solution
Understand exactly what a certification auditor is looking for. For ISO 27001 certification, auditors evaluate traceability from review inputs to management decisions and documented results. Ensure every management review produces that evidence — underlying records and decisions — before the audit begins.
The Inputs Auditors Cross-Check Against ISMS Evidence
Clause 9.3 — How the 2022 Split Changes Audit Evidence
Before the 2022 revision, ISO 27001 Clause 9.3 was a single block of text. ISO 27001:2022 separated it into three sub-clauses, and that structural change has direct audit implications.
Clause 9.3.1
Clause 9.3.1 establishes the general obligation: top management shall conduct reviews at planned intervals. Auditors interpret "planned intervals" as a scheduled, recurring event — not an ad hoc discussion. Evidence required: a documented schedule or calendar entry, and records showing the review occurred on or near that schedule.
Clause 9.3.2 — Management Review Inputs
Under ISO 27001 Clause 9.3.2, the management review considers seven main input areas:
- Status of actions from previous management reviews.
- Changes in relevant external and internal issues.
- Changes in relevant needs and expectations of interested parties.
- Information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfillment of information security objectives.
- Feedback from interested parties.
- Results of risk assessment and the status of the risk treatment plan.
- Opportunities for continual improvement.
This structure gives an auditor a defined basis for examining management review in ISO 27001.
Clause 9.3.3 — Management Review Results
Management review results are now a standalone output requirement. The results must include decisions on continual improvement opportunities and any changes needed to the ISMS. Auditors look for explicit resolution statements, named owners, and deadlines.
A practical implication: the ISO 27001 management review template an organization uses must be structured to produce Clause 9.3.3-compliant outputs.
Once the inputs and outputs required under ISO 27001 Clause 9.3 are established, auditors examine the records supporting each review cycle.
The Auditor's Evidence Checklist: What Gets Examined and Why
Decisions Rather Than Meeting Summaries
ISO 27001 Clause 9.3.3 requires management review results to include decisions related to continual improvement opportunities and any need for changes to the ISMS. The organization must retain documented information for the auditor to have access to a consistent evidence trail.
-
Meeting minutes and agenda
Auditors sample minutes from multiple review cycles, typically the two or three most recent. They verify that all seven ISO 27001 Clause 9.3.2 inputs appear in each set of minutes.
-
Attendance records
The standard requires top management to conduct the review and not delegate it entirely. Auditors check attendance sheets for evidence that an individual with genuine executive authority (CEO, COO, or equivalent) was present.
-
Action continuity
Auditors trace specific action items across consecutive reviews. If review cycle one records an action to increase security awareness training budget, the auditor expects review cycle two to show a status update with a recorded reason.
-
Resource decisions
When the management review is the only documented evidence of a resource decision, such as additional budget, a new tool, or a headcount change, auditors examine it carefully. The decision must be explicit and attributable to top management.
-
Objective fulfillment data
Auditors check that performance metrics presented in the review are consistent with data from Clause 9.1 monitoring activities. Inconsistency between the two sources, such as incident counts that differ between the monitoring log and the review pack, raises questions about data integrity.
How Auditors Distinguish Genuine Oversight from Retrospective Documentation
An important consideration when auditors evaluate management review evidence is whether it reflects actual management engagement or retrospective documentation.
-
Timestamp and metadata consistency
Documents created, edited, or signed close together, especially within days of an audit, suggest retrospective preparation. Auditors note file metadata where accessible and cross-reference document dates against email or calendar records.
-
Decision specificity
Minutes that record genuine management reviews contain specific, attributable decisions: "The board approved an additional $40,000 for endpoint detection tooling, to be procured by Q3."
-
Cross-referencing with other ISMS records
Auditors compare review outputs with corrective action registers, risk treatment plans, and ISMS objective trackers. Absence of expected downstream changes may prompt further examination.
-
Interview responses
During certification audits, auditors interview top management directly. It may reveal whether executives have genuine recall of the review or are unfamiliar with its content.
ISO 27001 Management Review and Its Intersection with Annex A Controls
Management review evidence also intersects with several Annex A controls that address management direction, independent review, and compliance monitoring — a relationship that matters for ISO 27001 certification because auditors examine both simultaneously:
-
Management Responsibilities (Control 5.4)
Control 5.4 requires management to actively direct information security within the organization. The management review is one of the primary mechanisms through which Control 5.4 is evidenced.
-
Independent Review of Information Security (Control 5.35)
Control 5.35 requires that the organization's approach to managing information security is reviewed independently at planned intervals. 5.35 concerns independent review or an internal audit conducted by someone independent of the function being audited.
-
Compliance with Policies, Rules and Standards (Control 5.36)
Control 5.36 requires that compliance with the ISMS policy and controls is regularly reviewed. Management review outputs that record objective attainment data contribute evidence for this control.
Conclusion
The management review in ISO 27001 is a governance instrument that an independent certification auditor uses to assess whether top management is genuinely directing the ISMS. The 2022 revision made that instrument more precise by separating inputs (Clause 9.3.2) from results (Clause 9.3.3), requiring organizations to demonstrate not just that topics were discussed but that decisions were made and acted upon.
Organizations pursuing ISO 27001 certification should design their management review process to produce contemporaneous, decision-specific records. When an independent CPA firm such as CertPro conducts a certification audit, it is the structured and traceable evidence attributable to top management that forms the basis of the audit opinion on ISMS effectiveness.


