Policy Register

Management review procedure

How top management reviews the management system: the inputs it must see, the decisions it must record, and how often.

How the register reads it

Also calledISMS review, management review minutes
FamilyGovernance and the management system
Document typeProcedure. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe information security lead (CISO or ISMS manager).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 27001 or ISO 27701 or ISO 22301 is ticked and no line resolves to it.
TemplateManagement review policy.

Which standards require it, and what each expects it to contain

3 requiring clauses, 3 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. A clause marked named is one of ISO/IEC 27001:2022's management clauses (4 to 10), named with its title and not quoted here.

ISO/IEC 27001:2022

Named, not quoted: 9.3named Management review.

ISO/IEC 27701:2025

ISO 27701 9.3.2 Management review inputs

The management review shall include consideration of the status of actions from previous management reviews; changes in external and internal issues that are relevant to the PIMS; changes in the needs and expectations of interested parties relevant to the PIMS; information on the PIMS performance including trends in nonconformities and corrective actions, monitoring and measurement results, and audit results; and opportunities for continual improvement. The Robere correspondence table records that the first edition's ISMS-derived inputs on fulfilment of objectives, interested party feedback and results of risk assessment are not carried as separate items.

Evidence an auditor accepts: Review input pack covering each required item; trend information on nonconformities, measurement and audit results; consideration of changes in context and interested party expectations
Common gap: Inputs that omit changes in privacy law or regulator expectations
Source: ISO/IEC 27701:2025

ISO 22301:2019

ISO 22301 9.3.2 Management review input

The review must consider the status of actions from previous reviews, changes in external and internal issues relevant to the BCMS, BCMS performance information including trends in nonconformities and corrective actions, monitoring and measurement results and audit results, feedback from interested parties, the need for changes including to policy and objectives, procedures and resources that could improve performance and effectiveness, information from the business impact analysis and risk assessment, the output of the evaluation of continuity documentation and capabilities, risks or issues not adequately addressed in any previous risk assessment, lessons learned and actions arising from near misses and disruptions, and opportunities for continual improvement.

Evidence an auditor accepts: Review pack demonstrably covering every required input; trend data rather than point in time figures for nonconformities, measurement and audits; near miss and disruption lessons presented with the actions arising
Common gap: Input pack covering audit results and little else
Source: ISO 22301:2019

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

Legal and regulatory register · Nonconformity and corrective action procedure