10.1 — Continual improvement
The shortest requirement in the standard, and one of the easiest to satisfy on paper while quietly failing in practice.
In plain language
In plain language: 10.1 requires you to keep making the ISMS better — more suitable, more adequate for your risks, more effective — as an ongoing posture, not a task you complete once and check off.
Position in the standard
Why this requirement exists
Standards that only demand compliance with a fixed baseline eventually become obsolete as threats, technology, and the organization itself change. This requirement exists to keep the ISMS moving forward even when nothing has gone visibly wrong — because waiting for a nonconformity before improving means the system only ever reacts, never gets ahead.
Scenario: an organization passes three consecutive surveillance audits with zero nonconformities and concludes the ISMS needs no attention. Nobody is looking for ways to streamline the evidence collection process, tighten the risk criteria, or adopt better tooling — because nothing is technically broken. The ISMS is compliant, but stagnant, and 10.1 is exactly the requirement a sharp auditor invokes to ask what has actually improved since certification.
What the standard expects
The standard expects the organization to continually improve the suitability, adequacy, and effectiveness of the information security management system. Unlike 10.2, this is not tied to a specific trigger like a nonconformity — it is a general, ongoing obligation that draws on inputs from across the ISMS: monitoring results (9.1), internal audit findings (9.2), management review decisions (9.3), and corrective actions (10.2).
In practice
- Keep a running log of improvement ideas sourced from monitoring, audits, and management review — not everything needs to become a formal project, but they should be visible somewhere.
- Treat "zero nonconformities" as a starting point for asking what could be tightened, not as a finish line.
- Bring at least one improvement initiative to each management review, even a small one, so the requirement stays visibly active rather than dormant.
Evidence the auditor will ask for
- A record of improvement initiatives undertaken since the last audit, even modest ones.
- Management review minutes showing improvement was discussed, not just compliance status.
Common pitfalls
- Treating "no nonconformities" as proof the ISMS needs no attention.
- No visible trail of improvement activity between audits, even when informal improvements did happen.
Related requirements
10.2 Nonconformity and corrective action
The reactive counterpart: what happens when improvement is triggered by something going wrong.
9.3.3 Management review results
Continual improvement decisions are a required output of management review.
Parent link: Clause 10 · Improvement
2013 → 2022 mapping
Frequently asked questions
Does 10.1 require a separate improvement plan document?
Keep improving even when nothing is technically broken.
Sentrix surfaces improvement opportunities from your monitoring, audits, and reviews so the ISMS keeps moving between certification cycles.