The management review is the occasion at which top management decides about the management system. ISO/IEC 27001 requires it in clause 9.3 at planned intervals and attaches a clear expectation: management evaluates whether the ISMS is still suitable, adequate and effective. What has to come out of it is a documented decision with owners, dates and, where needed, resources. Minutes recording a presentation are not that.
Inputs
The standard lists what has to be in front of management. That includes:
- the status of actions from previous reviews,
- changes in external and internal issues and in the requirements of interested parties,
- feedback on the performance of the ISMS, in particular nonconformities and corrective actions, monitoring and measurement results, audit results and the extent to which security objectives have been met,
- feedback from interested parties,
- the results of the risk assessment and the state of the risk treatment plan,
- opportunities for continual improvement.
The list is a minimum requirement for how well informed management has to be, not an agenda. Reproduce it one for one in slides and you produce a presentation; use it as a basis for decisions and it serves its purpose.
Outputs
What is required are decisions on opportunities for improvement and on the need to change the management system. Typically those are resolutions about the scope, about security objectives and metrics, about resources and roles, about how open nonconformities are to be handled, and about accepting or refusing risks above the acceptance threshold. Every one of those decisions belongs in the documented information with a date, an owner and a deadline.
Who takes part
Top management means the level that can approve resources and set priorities bindingly; in a mid-sized company, the managing directors. The information security officer or CISO prepares the material and presents it, but does not decide. A management review held without management does not meet the requirement, and auditors check this point reliably.
Interval and format
The standard says planned intervals, not a fixed cycle. An annual overall review is widespread, but on its own it creates a long window for reacting. A staged format has proved itself: a short steering session at shorter intervals for open nonconformities, metrics and risks, plus the full review with all required inputs once a year. What matters is that the chosen interval is defined, justified and kept to.
Metrics that can carry a decision
| Metric | What it shows | Possible decision |
|---|---|---|
| Open nonconformities by age | whether corrective actions are being completed | escalation, additional resources, revised deadlines |
| Share of overdue actions per area | where implementation is stalling | reprioritisation, change of ownership |
| Risks above the acceptance threshold | whether the assumptions made still hold | treatment, or acceptance with a review date |
| Coverage of the audit programme | whether the relevant areas were actually examined | adjustment of the programme |
| Share of expired evidence | whether the evidence base is current | renewal rhythm, automation |
| Incidents by category and recurrence | whether causes were genuinely removed | renewed root cause analysis |
Metrics with no target value and no owner behind them produce no decision. The organisation sets the target values itself; there are no normative specifications for them.
Where the review falls short
- The review took place, but without the required inputs.
- Topics were discussed, but no decisions were taken.
- Resolutions are documented, but with no owner and no deadline.
- The review repeats the audit report instead of evaluating it.
- Actions from the last review no longer appear in the next one.
Where the input for clause 9.3 comes from
The effort in a management review lies in the pack, not in the meeting. Clause 9.3 requires a fixed list of inputs, and in many organisations each comes from a different source: audit results from a report, nonconformities from a tracker, objectives from a spreadsheet, risk from a register.
In Rizzqo they come from one estate. Open requirements per object, nonconformities as open items with an owner, objective attainment as computed coverage and the risk picture as exposure in euros all sit against the same objects and cannot drift apart. A daily snapshot supplies the time axis, so leadership judges a development rather than a moment. The accountability question is answerable too, because every open requirement carries a named assignee.