Back to blog
Audit

The management review: the meeting that certifies your ISMS

A mandatory ISO 27001 clause that most organisations treat as a formality - and then fail on. What inputs are required, what outputs must be recorded, and how to run one that is genuinely useful.
GRC Copilot Team
The management review: the meeting that certifies your ISMS

The management review is where top management formally examines whether the management system is working and decides what to change. It is a mandatory ISO 27001 clause with prescribed inputs and outputs - and its absence, or its reduction to a five-minute agenda item, is one of the most common nonconformities at certification.

Why it exists

Everything else in the standard can be delegated. This clause forces leadership to look at the whole system, on the record, and make decisions about it. It is the mechanism that stops an ISMS becoming a compliance function that leadership never engages with.

Required inputs

ISO 27001 specifies what must be considered. Missing any of these is a straightforward finding:

  • Status of actions from previous management reviews
  • Changes in internal and external issues relevant to the ISMS
  • Changes in the needs and expectations of interested parties
  • Feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives
  • Feedback from interested parties
  • Results of risk assessment and status of the risk treatment plan
  • Opportunities for continual improvement
The word "trends" matters. Presenting this quarter's numbers without comparison does not satisfy the clause - leadership is expected to see direction, not a snapshot.

Required outputs

The review must produce decisions relating to continual improvement opportunities and any need for changes to the management system. This is the part organisations most often miss: a meeting that reviewed information but decided nothing does not meet the requirement.

Every review should end with a short list of decisions and actions, each with an owner and a date.

Assemble the review pack from live data

GRC Copilot produces the posture, risk, audit and objective status that management review requires - so the pack is generated rather than rebuilt each cycle.

Who must attend

"Top management" - people with the authority to allocate resources and change direction. In a small company that is the executive team or founders; in a larger one it may be an information security steering committee with genuine executive membership.

A review attended only by the security team and a middle manager will be challenged. The auditor is testing leadership engagement, and attendance is the evidence.

Frequency

The standard says "at planned intervals" without prescribing a number. Annually is the minimum most organisations adopt; quarterly is common where the environment changes quickly. Whatever you commit to in your own documentation is what you will be tested against - so do not write quarterly and hold one.

Running one that is actually useful

  1. Circulate the pack in advance. Reading the data in the room wastes executive time and produces no decisions.
  2. Lead with decisions required, not with a data tour. Put the three things you need leadership to decide at the front.
  3. Show trends against objectives - are we improving, and against what target.
  4. Be honest about what is not working. A review presenting universal success invites scepticism and produces no change.
  5. Cover resources explicitly. This is the forum where "we cannot do this without another person or budget" belongs on the record.
  6. Close last cycle's actions before opening new ones.

Minutes are the evidence

The auditor will read them. Good minutes record who attended, which inputs were presented, what was discussed - including disagreement - what was decided, and who owns each action by when. Minutes that read "the ISMS was reviewed and found effective" satisfy nobody and are a finding in themselves.

Common nonconformities

  • No management review held, or held after the audit was scheduled.
  • Required inputs missing - typically risk treatment status or interested-party feedback.
  • No documented decisions or actions.
  • Top management absent.
  • Prior actions never closed.
  • Held less often than your own policy commits to.

Frequently asked questions

Can it be part of an existing leadership meeting?

Yes, provided the required inputs are covered and minuted distinctly. Many organisations run it as a standing agenda item with its own pack and minutes.

How long should it take?

An hour or two is typical if the pack was read in advance. The length matters less than the decisions produced.

Do other frameworks require it?

ISO management system standards do - 27001, 22301, 42001, 9001. SOC 2 and regional frameworks expect governance oversight in substance, and NIS2 and DORA place explicit accountability on management bodies.

What if leadership will not engage?

That is itself the finding, and worth surfacing honestly - certification requires demonstrated leadership commitment, so it cannot be worked around by the security team alone.

Key takeaways

  • Inputs are prescribed - missing one is a finding.
  • The output must be decisions, not a discussion.
  • Top management attendance is the evidence of leadership commitment.
  • Minutes are what the auditor reads - record decisions, owners and dates.
#management-review #iso27001 #governance #minutes #leadership