Clause 10 · Improvement

10.1 — Continual improvement

The shortest requirement in the standard, and one of the easiest to satisfy on paper while quietly failing in practice.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 10.1 requires you to keep making the ISMS better — more suitable, more adequate for your risks, more effective — as an ongoing posture, not a task you complete once and check off.

Position in the standard

Clause 10 · Improvement
10.1 · Continual improvement ← you are here
See also: 10.2

Why this requirement exists

Standards that only demand compliance with a fixed baseline eventually become obsolete as threats, technology, and the organization itself change. This requirement exists to keep the ISMS moving forward even when nothing has gone visibly wrong — because waiting for a nonconformity before improving means the system only ever reacts, never gets ahead.

Scenario: an organization passes three consecutive surveillance audits with zero nonconformities and concludes the ISMS needs no attention. Nobody is looking for ways to streamline the evidence collection process, tighten the risk criteria, or adopt better tooling — because nothing is technically broken. The ISMS is compliant, but stagnant, and 10.1 is exactly the requirement a sharp auditor invokes to ask what has actually improved since certification.

What the standard expects

The standard expects the organization to continually improve the suitability, adequacy, and effectiveness of the information security management system. Unlike 10.2, this is not tied to a specific trigger like a nonconformity — it is a general, ongoing obligation that draws on inputs from across the ISMS: monitoring results (9.1), internal audit findings (9.2), management review decisions (9.3), and corrective actions (10.2).

In practice

  • Keep a running log of improvement ideas sourced from monitoring, audits, and management review — not everything needs to become a formal project, but they should be visible somewhere.
  • Treat "zero nonconformities" as a starting point for asking what could be tightened, not as a finish line.
  • Bring at least one improvement initiative to each management review, even a small one, so the requirement stays visibly active rather than dormant.

Evidence the auditor will ask for

  • A record of improvement initiatives undertaken since the last audit, even modest ones.
  • Management review minutes showing improvement was discussed, not just compliance status.

Common pitfalls

  • Treating "no nonconformities" as proof the ISMS needs no attention.
  • No visible trail of improvement activity between audits, even when informal improvements did happen.

Related requirements

Parent link: Clause 10 · Improvement

2013 → 2022 mapping

2022 version 2013 version Nature of change
10.1 Continual improvement10.2 Continual improvementSame content, moved from 10.2 to 10.1

Frequently asked questions

Does 10.1 require a separate improvement plan document?
No — it can be demonstrated through existing records like management review minutes and audit follow-ups, as long as improvement activity is visible somewhere.

Keep improving even when nothing is technically broken.

Sentrix surfaces improvement opportunities from your monitoring, audits, and reviews so the ISMS keeps moving between certification cycles.