Clause 10 — Improvement
The last of the seven certifiable clauses, and the one that turns everything clause 9 finds into something that actually changes. Clause 10 requires the ISMS to keep getting better over time, and to respond properly whenever something goes wrong: react to the problem, fix its root cause so it does not come back, and update the system if the fix reveals the ISMS itself needs to change. Without clause 10, clause 9’s audits and reviews would just be a record of problems nobody acted on.
The structure of clause 10
What clause 10 covers
Clause 10 is the shortest of the seven certifiable clauses and, like clause 8, has no sub-clauses beneath its two requirements. 10.1 sets a standing obligation: the ISMS must continually improve, on an ongoing basis, not just at renewal. 10.2 sets the discipline for handling things that go wrong — react, correct the root cause, verify the fix worked, and change the ISMS itself if needed. Together they are what keeps the whole system from calcifying the moment the certificate is issued.
A reordering worth knowing about
If you have ever seen the 2013 version of this standard, note that the two sub-clauses swapped places. In 2013, 10.1 was “Nonconformity and corrective action” and 10.2 was “Continual improvement.” The 2022 revision flipped the order — 10.1 is now Continual improvement, 10.2 is Nonconformity and corrective action — putting the forward-looking requirement first. The substance of both requirements is largely unchanged; only their numbering and sequence moved.
The documents that come out of clause 10
- Evidence of the nature of each nonconformity and any action taken in response (10.2)
- The results of each corrective action (10.2)
10.1 (continual improvement) sets an ongoing obligation rather than a discrete deliverable, so it does not itself require a standalone document.
Frequently asked questions
Why did 10.1 and 10.2 swap in the 2022 version?
Do I need a formal corrective action process?
Need hands-on support closing the loop on audit findings? See our ISO 27001 certification support service
Turn every finding into a closed corrective action.
Sentrix tracks nonconformities from root cause to verified fix, and keeps a running record of continual improvement.