Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Clause 9.3 is short and almost every organization underbuilds it. The requirement is not a meeting; it is a record showing leadership considered a specific list of inputs and decided something.
ISO/IEC 27001 clause 9.3 requires top management to review the ISMS at planned intervals, considering a specific list of inputs, and to retain documented information as evidence of the results. The outputs must include decisions about continual improvement opportunities and any need to change the ISMS. Annual is the minimum; quarterly is easier because each review covers less ground and the record looks alive. The commonest failure is minutes that record who attended and nothing else. Every required input needs its own heading in the record, every heading needs real content with a date on it, and every output needs a decision with an owner and a date. A certification body checks the minutes against the inputs, so a heading with nothing under it is a visible gap.
Clause 9.3 comes in three parts. The general part says top management shall review the organization's information security management system at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Those three words are the test the whole clause is built around, and they are not synonyms.
Suitability asks whether the ISMS still fits the business. If you were a fifteen person company selling to small businesses when you designed it and you now have eighty people and enterprise customers in regulated sectors, the ISMS may be functioning perfectly and still be unsuitable. Adequacy asks whether it covers what it needs to cover: are the right risks in scope, are the controls sufficient for the risks you face. Effectiveness asks whether it is achieving the intended outcomes, which is a question you can only answer with numbers.
The second part lists the inputs the review has to consider. The third part says the results of the review must include decisions related to continual improvement opportunities and any need for changes to the ISMS, and that documented information has to be retained as evidence of the results.
That is the whole clause. It is perhaps a page of the standard, and it is the clause that most often produces a nonconformity at surveillance audits, because it is easy to hold a meeting and hard to hold one that generates a record satisfying every element.
The standard requires a review. It does not require a meeting. What is audited is documented information evidencing the results, so the audit surface is entirely the record. If the review happened brilliantly and the record says "security update given, no issues", the clause is not met.
This cuts both ways, and the second direction is useful. A distributed review, where an input pack is circulated, comments are recorded in writing, and decisions are captured and confirmed by top management, can satisfy clause 9.3 without everyone sitting in a room. That is a legitimate structure for a company whose executives are in different time zones. What it cannot be is a document circulated with no evidence anyone engaged with it. Silence is not consideration.
In practice the meeting is the easier route because it manufactures the evidence naturally: an agenda that mirrors the required inputs, a pack tabled against it, and minutes that follow the agenda headings. Ninety minutes with the right people produces a defensible record. The same ninety minutes with no agenda produces minutes that say the ISMS was discussed.
The mental shift that fixes most management reviews is to write the minutes template before the meeting, with every required input as a fixed heading, and to treat the meeting as the exercise of filling it in. Anything you cannot fill in is a gap you have found in advance rather than one the auditor finds later.
Top management means the person or group who directs and controls the organization at the highest level within the scope of the ISMS. It is a role, not a title. At a fifty person company it is typically the CEO plus the CTO, and often the COO or the head of operations. At a subsidiary whose ISMS scope is that subsidiary, it is the subsidiary's leadership.
The test that matters is authority. The review is where risks get accepted, budget gets approved, and objectives get changed. If nobody in the room can accept a residual risk or commit money, the review cannot produce the outputs the clause requires and the record will show it, because every output will read as a recommendation rather than a decision.
The person who runs the ISMS presents; they are not the review. A management review chaired by the security manager with no executive present is the single most common structural failure of clause 9.3, and it is unarguable when the attendee list is in the minutes. The security manager can absolutely own the agenda, assemble the pack and write the minutes. They cannot be the reviewing body.
Beyond top management, invite the people who own the inputs: whoever runs engineering or infrastructure, whoever owns HR for the people controls, whoever owns customer contracts for the interested party requirements, and the internal auditor if there are findings to discuss. Six to eight people is a normal size. Record attendees by name and role, and record apologies, because an executive who has missed four consecutive reviews is a pattern an auditor will notice.
Where an executive genuinely cannot attend, get their input in writing before the meeting and reference it in the minutes. That is far better than an empty chair and it takes one email.
The standard says planned intervals. Certification bodies expect at least one management review inside every twelve month period, and at a certification audit they will want to see one that took place before the audit with the ISMS in something close to its current state. There is no requirement for the review to be annual, only for it to be planned and to happen.
Quarterly is the cadence we recommend and it is counterintuitively less work. Each quarterly review covers three months of incidents, three months of metrics and whatever audit activity fell in the quarter, which is a pack you can assemble in an hour. An annual review has to cover twelve months of everything, which means either a very long meeting or, more commonly, a shallow one that skims.
Quarterly also produces a record that is visibly alive. Four sets of minutes across the year, showing an item raised in Q1, actioned in Q2 and its effectiveness confirmed in Q3, demonstrates the continual improvement loop better than any narrative you could write. A single annual review can never show that within itself.
If quarterly is unrealistic, a workable compromise is one full review annually with the complete input set, plus two or three shorter interim reviews covering performance, incidents and open actions. Write the structure into your ISMS documentation so the intervals are genuinely planned rather than reconstructed. An organization whose documented interval is quarterly and which held two reviews last year has a nonconformity against its own requirements, which is a worse position than documenting annual and holding one.
Trigger an out-of-cycle review after anything significant: a serious incident, a major acquisition or divestment, a change of ISMS scope, or a certification audit with a major nonconformity. The record of an unscheduled review is strong evidence that leadership engagement is real.
Clause 9.3 names the inputs the review must consider. Treat each as a fixed heading. The first is the status of actions from previous management reviews. This is why the minutes have to carry an action register: every action from last time, its owner, and whether it is done, in progress with a revised date, or abandoned with a reason. An action carried forward three times with no comment is a finding waiting to be written, and it is a finding about management commitment rather than about the action itself.
The second is changes in external and internal issues relevant to the ISMS. This ties directly to clause 4.1, so bring the context analysis and say what moved: new markets, new regulation, a shift in the threat picture for your sector, headcount growth, a move to a new cloud region, the loss of a key person. Since the 2024 amendment the context clauses also require an explicit determination on whether climate change is a relevant issue, so if that determination changed, this is where it gets reported.
The third is changes in the needs and expectations of interested parties. This means customer contract terms, regulator expectations, investor or insurer requirements. Concretely: a new enterprise customer whose security schedule imposes a 24 hour breach notification obligation is a change in interested party requirements, and it has to reach this table because it may require a change to the incident response process.
The fourth is feedback on information security performance, and the standard breaks it into trends across four things: nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of the information security objectives. The word doing the work there is trends. A single period's numbers are data; two or more periods compared is a trend, and trends are what leadership can actually decide on.
For nonconformities and corrective actions, table how many were raised, how many closed, how many are overdue, and how many had their effectiveness confirmed. For monitoring and measurement, table the metrics you defined under clause 9.1 against their targets. For audit results, table the internal audit findings by area and grade plus any external audit outcomes. For objectives, table each objective from clause 6.2 with its target and its actual.
The fifth input is feedback from interested parties. In practice this is customer security questionnaires and their friction points, complaints, audit or assessment results a customer imposed on you, supplier and subprocessor communications, and anything staff raised through whatever channel you have. If enterprise deals keep stalling on the same three questionnaire items, that belongs here, because it is direct evidence of whether the ISMS is meeting a real business need.
The sixth is the results of risk assessment and the status of the risk treatment plan. Table what changed in the risk register since the last review: new risks, risks whose scores moved, risks closed. Table the treatment plan by status, and be honest about slippage with revised dates and reasons. This is also where residual risk acceptance happens, because the risk owners and top management are in the room and clause 6.1.3 requires that acceptance to be recorded.
The seventh is opportunities for continual improvement. This is the input people leave blank, and it is the one that connects to clause 10.1. Bring three or four candidate improvements with a rough cost and the benefit, drawn from audit findings, incident post-mortems, metric trends and staff suggestions. The review then picks. A review that considers no improvement opportunities cannot produce the output the clause requires, because the output is defined as decisions related to improvement opportunities.
One practical note on assembly: everything you table should be a dated artifact that exists independently of the review, not a slide written for it. The metrics report, the audit report, the risk register export, the corrective action register export, the incident summary. The pack is a covering document that points at them. This matters because the certification body will ask to see the underlying artifact, and a number that only exists in a slide has no source.
For a company under a couple of hundred people the pack is eight to fifteen pages and takes two to three hours to assemble if the underlying records are being kept properly. If it takes two weeks, the problem is not the review, it is that the metrics, the corrective action register and the risk register are being reconstructed rather than maintained.
Build it in this order. Pull the action register from the last minutes and update it. Export the corrective action register and count open, overdue and effectiveness-confirmed. Pull the metrics defined under 9.1 for the period and put them next to their targets. Summarise internal and external audit activity. List incidents with severity, time to contain, and whether any customer notification obligation was triggered. Export the risk register delta and the treatment plan status. Write the interested party changes from contracts and legal. Draft three improvement candidates. Write the context update last, because everything above informs it.
Circulate the pack at least two working days before the meeting. Executives who read the pack in advance ask decision-shaped questions; executives seeing it for the first time ask clarifying ones, and clarifying questions consume the time you needed for decisions.
Keep the pack forever, with the same date as the minutes. The minutes say the metrics were considered; the pack is what proves what the metrics said at the time. A certification body auditor asking "and what were the numbers you looked at in March" is asking for the pack.
The clause requires that the results of the review include decisions related to continual improvement opportunities and any need for changes to the ISMS. That is a narrower requirement than most organizations assume, and it is also more demanding, because both halves need something in them.
A management review that concludes nothing needs to change is possible, but it needs to say so explicitly and give a reason, and after a first-year ISMS at a growing company it is rarely credible. Far more common is a set of outputs across a small number of categories: improvements approved, changes to the ISMS scope or policies, changes to the information security objectives, resource decisions including headcount and budget and tooling, risk acceptances, and changes to the risk treatment plan.
Every output needs three things: what was decided, who owns it, and by when. "Increase the security training budget" is not an output. "Approved an additional 12,000 dollars for security training in FY27, owner Head of People, procurement complete by 30 November" is an output, and it survives being read back a year later.
Resource decisions deserve particular attention because clause 7.1 requires the organization to determine and provide the resources needed for the ISMS. A management review where the ISMS owner said they were short-handed, and the minutes record no decision either way, is evidence against clause 7.1 as well as 9.3. Record the decision even when the decision is no, along with the reasoning, because a considered no is defensible and silence is not.
Where the review accepts a residual risk, name the risk identifier, the residual score, and the person accepting it. That single line does double duty: it satisfies the record requirement here and it evidences the risk owner acceptance clause 6.1.3 asks for.
Structure the minutes as: date, attendees by name and role, apologies, then one heading per required input with what was tabled and what was said, then a decisions and actions table, then the date of the next review. Three to six pages. Nobody needs a transcript.
Under each input heading, write two things: the substance that was tabled, with a reference to the artifact and its date, and the conclusion reached. "Audit results: internal audit report dated 14 July 2026 tabled, four minor nonconformities in supplier management and access review timeliness, two closed, two open with revised dates in October. Reviewed as evidence of a recurring pattern in supplier management." That is enough for the auditor to follow the thread out to the underlying record.
Get the minutes approved. A named approver and an approval date, ideally the chair, turns the minutes from notes into documented information under clause 7.5. Circulate them within a week while the meeting is still recoverable from memory; minutes written six weeks later are thinner and it shows.
Carry the decisions and actions table forward verbatim into the next review's first agenda item. That mechanical continuity is what makes a series of reviews read as a management system rather than a series of meetings, and it is exactly what a surveillance auditor looks for when comparing this year's minutes to last year's.
At stage 1 the certification body reads the management review minutes as one of the core documents, alongside the scope, the Statement of Applicability, the risk assessment and the internal audit report. If no management review has ever taken place, you are not ready for stage 2, because a required clause has never been operated. This catches organizations that scheduled their first review for after certification.
At stage 2 they take the required input list and walk your minutes against it, heading by heading. An input with no content under it is a gap they can point to on the page. They then pick one or two inputs and follow them outwards: they ask to see the metrics report the minutes reference, or the audit report, or the risk register export, and they check the dates line up with the meeting.
They test the attendee list against the definition of top management. They ask who chaired, and whether the people present could approve budget and accept risk. They look at whether decisions were recorded with owners and dates, or whether the outputs are all recommendations.
At surveillance they compare consecutive reviews. Their questions are about continuity: were last review's actions closed, did the metrics move, did anything found in the internal audit reach the review and produce a decision. This is where quarterly cadence pays off, because a year of quarterly minutes answers all of that in the reading rather than requiring you to construct the argument.
One thing they are not doing is grading your security posture in this session. Clause 9.3 is a management system clause. Bad numbers honestly reported and acted on score better here than good numbers with no evidence of where they came from.
Minutes that record attendance and a summary but no decisions. The output requirement is explicit, so this is a direct nonconformity rather than an observation.
One or more required inputs with no content. Most often opportunities for continual improvement, feedback from interested parties, and changes in external and internal issues, in that order.
No top management present. The security lead reviewing their own management system does not satisfy a clause whose subject is top management.
Actions from the previous review never followed up, so the same items appear each time with no status.
Objectives discussed qualitatively because they were never made measurable under clause 6.2. If the objective is "improve security posture", the review has nothing to report against it and both clauses take a hit.
The review scheduled after the certification audit rather than before it, leaving stage 1 with no record to read.
A documented interval the organization did not meet. Committing to quarterly and holding two reviews is a nonconformity against your own requirements, which is the first test clause 9.2 and the auditors apply.
The pack tabled at the review no longer exists, so the minutes reference numbers that cannot be traced to a source.
Organizations implementing ISO 27001 for the first time hit an ordering problem: the review needs audit results, metrics and corrective actions, and in month four of implementation none of those exist yet. The answer is to hold the review anyway and report the true state, because the record of a review with thin inputs is worth far more than no record at all.
A sensible first-year sequence is to complete the risk assessment, the Statement of Applicability and the treatment plan, run the first internal audit, produce the first metrics report, and then hold the first management review with all of that in front of you. That review will have real content under every heading even if some of it is "first measurement period, no trend available yet", which is an honest and acceptable entry.
Do not hold a management review before the first internal audit. Audit results are a required input, and a review that records "no internal audit has been performed" against that heading has documented a gap for the certification body rather than closed one.
For sequencing against the wider program, our internal audit guide covers what has to come first, and the Statement of Applicability guide covers the risk documentation the review depends on.
| Required input | What you table | What the certification body checks |
|---|---|---|
| Status of actions from previous reviews | The action register from the last minutes, each item with owner, status, and a revised date where it has slipped. | That last review's actions are all accounted for, and that nothing has been carried forward repeatedly with no comment. |
| Changes in external and internal issues | The clause 4.1 context analysis, updated: headcount, markets, regulation, threat landscape, architecture, key-person changes. | That the context document exists, was updated, and that the update reflects changes they can see elsewhere in the business. |
| Changes in interested party needs and expectations | New or amended customer security schedules, regulatory changes, investor or insurer requirements, subprocessor obligations. | Whether a contractual commitment you have taken on has flowed through into a control or an action. |
| Nonconformities and corrective actions | Register export: raised, closed, overdue, and how many had an effectiveness review completed. | Whether effectiveness reviews are actually happening, and whether the same nonconformity is recurring across periods. |
| Monitoring and measurement results | The clause 9.1 metrics for the period next to their targets, with the previous period alongside so a trend is visible. | That the metrics match what clause 9.1 says you measure, and that the underlying report exists with the same date. |
| Audit results | Internal audit findings by area and grade, plus external audit or customer assessment outcomes in the period. | That the internal audit report reached the review and produced a decision, not just a note that it was received. |
| Fulfilment of information security objectives | Each clause 6.2 objective with its target, its actual, and an explanation for any miss. | That the objectives are measurable at all. Qualitative objectives produce a finding against 6.2 as well as 9.3. |
| Feedback from interested parties | Customer questionnaire friction, complaints, customer audit results, supplier notifications, staff-raised concerns. | That something real is recorded. This heading is blank more often than any other. |
| Risk assessment results and treatment status | Register delta since last review, treatment plan by status with revised dates, and any residual risk being accepted. | That risk acceptance is recorded with a named acceptor and a risk identifier, satisfying clause 6.1.3 as well. |
| Opportunities for continual improvement | Three or four candidates with rough cost and expected benefit, drawn from findings, incidents and metric trends. | That improvements were considered and decided on, since the required output is defined in terms of these decisions. |
The standard says at planned intervals rather than naming a frequency, but certification bodies expect at least one review inside every twelve month period, and one before your certification audit. Quarterly is usually less work in practice because each review covers three months of material rather than twelve, and it produces a record that visibly shows the improvement loop running.
Top management, meaning the people who direct and control the organization at the highest level within the ISMS scope, typically the CEO plus the CTO and often the COO. The test is authority: someone in the room has to be able to accept a residual risk and commit budget. The person who runs the ISMS presents the pack and writes the minutes but cannot be the reviewing body.
No. What clause 9.3 requires is a review and retained documented information evidencing the results. A distributed review with a circulated pack, recorded written input from top management and confirmed decisions can satisfy it. What it cannot be is a pack circulated with no evidence that anyone engaged with it, because silence is not consideration.
The results must include decisions related to continual improvement opportunities and any need for changes to the ISMS. In practice that means recorded decisions on improvements, scope or policy changes, changes to objectives, resources including budget and headcount, and risk acceptances. Each decision needs what was decided, who owns it, and by when. A recommendation with no owner and no date is not an output.
Minutes that record attendance and a discussion summary but no decisions, followed by one or more required inputs left with no content under them, most often opportunities for improvement and feedback from interested parties. Both are direct failures of an explicit requirement, so they tend to be raised as nonconformities rather than observations.
You can, but you should not. Audit results are a required input, so a review held first will record that no internal audit has been performed, which documents a gap for the certification body to read at stage 1. The workable first-year sequence is risk assessment, Statement of Applicability and treatment plan, first internal audit, first metrics report, then the first management review.
The minutes with attendees, every required input as a heading with what was tabled, and the decisions and actions with owners and dates, approved and dated. Keep the input pack too, with the same date, plus the underlying artifacts it points at: the metrics report, the audit report, the risk register export and the corrective action register export. The minutes prove consideration; the pack proves what was considered.
SOC 2 has no clause 9.3, but the Trust Services Criteria expect board or equivalent oversight of internal control and the timely communication of control deficiencies to people who can act on them. A quarterly leadership review with a fixed agenda, real metrics and recorded decisions satisfies both, which is why organizations pursuing both frameworks run one review rather than two.
traztech Workspace has all 93 Annex A controls and 25 ISMS clauses (4-10) of ISO 27001 written in plain English, with what the standard asks for, what to do about it, and somewhere to attach the proof. You answer them, it scores you, and nothing is locked behind an upgrade.
No credit card, no trial clock, no locked features. We make money when someone wants help closing the gaps, not from the Workspace.
| traztech Workspace | Other GRC platforms | |
|---|---|---|
| Licence cost | $0. Free forever, no card, no paid tier | $7,500 to $50,000 a year, on an annual contract |
| Control library, evidence register, policy templates, risk register, vendor questionnaires, readiness scoring | Included | Included |
| What it costs inside an engagement with us | $0. You need a workspace either way | Unchanged. The subscription sits on top of the fee |
| What it does to your audit quote | $11,000 off a five-figure quote on one engagement, for a documented readiness position | Nothing. The audit firm prices your readiness, not your tooling |
Pricing in the right column is what compliance automation platforms are publicly reported to charge; none of them publish a number, so treat it as a range rather than a quote. The $11,000 came off the audit firm's own number once the readiness position was documented (the engagement). Where a paid platform is the better buy, and the fuller comparison, is on the Workspace page.
We build the agenda, assemble the input pack from your real metrics and audit results, and write minutes your certification body can walk heading by heading.
Book a strategy callWant the human version?
Jacob sends a few short, practical notes on getting security and compliance right without the months of pain. No fluff, unsubscribe in one click. Reply anytime; it reaches him directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.
Track record
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.