You will have management oversight and a management review team that meets regularly and covers the core components of the standard. It requires you to implement information security from the top down with leadership commitment.
In this guide you will learn how to implement ISO 27001 Clause 9.3 and pass your audit from ISO 27001 Lead Auditor Stuart Barker – author of the ultimate ISO 27001 Toolkit.
Table of contents
- Key Takeaways
- What is ISO 27001 Clause 9.3 Management Review?
- What are the ISO 27001:2022 Changes to Clause 9.3?
- ISO 27001 Clause 9.3 Training Video
- Implementation Guide
- How to conduct an ISO 27001 Management Review
- ISO 27001 Management Review Template
- How to Implement ISO 27001 Clause 9.3
- What the auditor will check
- ISO 27001 Clause 9.3 FAQ
Key Takeaways

- Your management team will meet regularly
- They will follow a structured agenda
- You will show you have top down leadership commitment
- You need it for ISO 27001 certification
What is ISO 27001 Clause 9.3 Management Review?
ISO 27001 Management Review requires an organisation to conduct a Management Review Meeting at regular intervals and follow a structure, defined agenda. By doing this we can ensure we have an effective information security management system that is achieving it’s intended outcomes.
The requirement is that the management review
- Reviews the status of actions from previous management reviews
- Records changes in external and internal issues that are relevant to the information security management system
- Records changes in needs and expectations of interested parties that are relevant to the information security management system
- Reviews the information security performance
- Ensures the fulfilment of information security objectives
- Takes account of feedback from interested parties
- Oversees the results of risk assessment and status of risk treatment plan
- Reviews opportunities for continual improvement
What are the ISO 27001:2022 Changes to Clause 9.3?
There is nothing significant that has changed to the ISO 27001 Clause 9.3 Management Review in the 2022 update. The change is wording and clarification change with a change to the layout of how the requirements are presented. Rather than one clause they have split out elements into 3 sub clauses for enhanced clarity.
ISO 27001:2022 Clause 9.3 Management Review
This clause has now had the wording removed and wording shifted to three new separate sub clauses.
ISO 27001:2022 Clause 9.3.1 General – New clause
Top management shall review the organisation’s information security management system at planned intervals to ensure its continuing suitability, adequacy and effectiveness.
ISO 27001:2022 Clause 9.3.2 Management Review Inputs – New clause
The management review shall include consideration of:
a) the status of actions from previous management reviews;
b) changes in external and internal issues that are relevant to the information security management system;
c) changes in needs and expectations of interested parties that are relevant to the information security management system;
d) feedback on the information security performance, including trends in:
1) nonconformities and corrective actions;
2) monitoring and measurement results;
3) audit results;
4) fulfilment of information security objectives
e) feedback from interested parties;
f) results of risk assessment and status of risk treatment plan;
g) opportunities for continual improvement.
ISO 27001:2022 Clause 9.3.3 Management Review Results – New clause
The results of the management review shall include decisions related to continual improvement opportunities and any needs for changes to the information security management system.
Documented information shall be available as evidence of the results of management reviews.
ISO 27001 Clause 9.3 Training Video
In this free training video I show you how to implement ISO 27001 Clause 9.3 and pass your audit.
Implementation Guide
There are many ways to conduct management reviews.
Follow the culture of your organisation on how you conduct meetings. They can be remote, they can be in person. It is best to follow the best practice of your organisation.
Good practice also includes allocate roles within the meeting to keep the meeting on track. This is not a requirement of the standard but good practice.
Consider allocating the role of a time keeper to keep you on time, a minute taker responsible for the minutes and meeting chair to guide and chair the meeting.
How to conduct an ISO 27001 Management Review
For detailed step by step guidance read – How to conduct an ISO 27001 Management Review Meeting
ISO 27001 Management Review Template
The ISO 27001 Management Review Template is the mandatory ISO 27001 Management Review agenda and comes with a detailed step-by-step guide on how to do a management review.
How to Implement ISO 27001 Clause 9.3
There are many ways to conduct management reviews.
Follow the culture of your organisation on how you conduct meetings. They can be remote, they can be in person. It is best to follow the best practice of your organisation.
Time needed: 1 hour and 30 minutes.
How to implement ISO 27001 Clause 9.3 Management Review
- Decide who will attend the ISO 27001 Management Review Meeting
Decide who will attend the ISO 27001 management review team meetings. It should include the information security manager, a member of the senior leadership team and members from each department in the organisation. This should then be documented in your roles and responsibilities documentation. Make sure that the members are added to the competency matrix.
- Create your meeting agenda and book your meetings
Create your ISO 27001 Management Review Meeting agenda based on the requirements of the standard, including all mandatory topics.
- Schedule your ISO 27001 Management Review Meetings for the year
Forward plan and schedule your meetings for the year.
- Conduct your meetings keeping minutes
Conduct your ISO 27001 Management Review Meetings and be sure to minute and keep copies of minutes.
What the auditor will check
The auditor is going to check a number of areas for compliance with Clause 9.3. Lets go through them
1. That roles are defined and assigned
The auditor will look for evidence that you have defined the roles for the management review team. They will want to see representation for the in scope areas. For best practice they will be looking for one representative of each in scope department, at least one member of senior leadership, deputies for everyone.
2. That management meetings have happened and are planned
They will be looking to see that management reviews have taken place and that future management reviews are planned in. It is likely to be the case that they will look for calendar entries and also, most important of all, they are looking for minutes and documentation of those management reviews.
ISO 27001 Clause 9.3 FAQ
ISO 27001 Clause 9.3 Management Review requires an organisation to hold a regular management review meeting that follows the structure and requirements of the ISO 27001 standard.
ISO 27001 Clause 9.3 Management Review compliance is evidenced by having Management Review Meetings scheduled through out the year and evidence that meetings have occurred with meeting minutes available.
You can download ISO 27001 Clause 9.3 Management Review in the High Table ISO 27001 Toolkit.
If you do not do ISO 27001 management reviews and minute them then you will not achieve ISO 27001 certification. In addition your management system will not operate as intended and will not be effective.
You perform ISO 27001 management reviews monthly. If you cannot then at least once every 3 months.
The information security manager ensures that the meeting takes place. The meeting is attended by the information security manager, senior leadership representative and representatives from each department in the organisation.
Management reviews are reported to the senior leadership team.
Stuart Barker
ISO 27001 Ninja
Stuart Barker is a veteran practitioner with over 30 years of experience in systems security and risk management. Holding an MSc in Software and Systems Security, he combines academic rigour with extensive operational experience, including a decade leading Data Governance for General Electric (GE).
As a qualified ISO 27001 Lead Auditor, Stuart possesses distinct insight into the specific evidence standards required by certification bodies. His toolkits represent an auditor-verified methodology designed to minimise operational friction while guaranteeing compliance.


