Management review procedure
How top management reviews the management system: the inputs it must see, the decisions it must record, and how often.
How the register reads it
| Also called | ISMS review, management review minutes |
|---|---|
| Family | Governance and the management system |
| Document type | Procedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted. |
| Expected owner | The information security lead (CISO or ISMS manager). |
| Review cadence | Annual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period). |
| On the gap list when | ISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it. |
| Template | Management review policy. |
Which standards require it, and what each expects it to contain
3 requiring clauses, 3 regimesShown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.
ISO/IEC 27001:2022
Named, not quoted: 9.3named Management review.
ISO/IEC 27701:2025
ISO 27701 9.3.2 Management review inputsThe management review shall include consideration of the status of actions from previous management reviews; changes in external and internal issues that are relevant to the PIMS; changes in the needs and expectations of interested parties relevant to the PIMS; information on the PIMS performance including trends in nonconformities and corrective actions, monitoring and measurement results, and audit results; and opportunities for continual improvement. The Robere correspondence table records that the first edition's ISMS-derived inputs on fulfilment of objectives, interested party feedback and results of risk assessment are not carried as separate items.
Common gap: Inputs that omit changes in privacy law or regulator expectations
Source: ISO/IEC 27701:2025
ISO 22301:2019
ISO 22301 9.3.2 Management review inputThe review must consider the status of actions from previous reviews, changes in external and internal issues relevant to the BCMS, BCMS performance information including trends in nonconformities and corrective actions, monitoring and measurement results and audit results, feedback from interested parties, the need for changes including to policy and objectives, procedures and resources that could improve performance and effectiveness, information from the business impact analysis and risk assessment, the output of the evaluation of continuity documentation and capabilities, risks or issues not adequately addressed in any previous risk assessment, lessons learned and actions arising from near misses and disruptions, and opportunities for continual improvement.
Common gap: Input pack covering audit results and little else
Source: ISO 22301:2019
Do this for every document on your list
Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.
Build a registerLegal and regulatory register · Nonconformity and corrective action procedure