9.3.1 — General
Three words that decide whether the ISMS survives another year: suitable, adequate, effective.
In plain language
In plain language: 9.3.1 requires top management — not a delegate, not a committee acting alone — to formally review the ISMS at planned intervals and judge whether it is still suitable for the organization, adequate for its risks, and effective at delivering security outcomes.
Position in the standard
Why this requirement exists
Delegating security entirely to an operational team, with leadership never actually looking at how the program is doing, is exactly the pattern this requirement is designed to prevent. An ISMS that only the security team ever reviews tends to optimize for what the security team can influence, while organizational-level problems — under-resourcing, conflicting priorities, scope creep — go unaddressed because nobody with the authority to fix them is looking.
Scenario: a company’s security team has flagged, for three straight quarters, that they lack the budget to remediate a known risk. Without a management review forcing that status in front of leadership on a fixed schedule, the flag stays buried in a team-level tracker indefinitely.
What the standard expects
The standard expects top management to review the organization’s ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. "Suitability" asks whether the ISMS still fits the organization as it exists today; "adequacy" asks whether it addresses the risks the organization actually faces; "effectiveness" asks whether it delivers the intended security outcomes. All three must be considered — a system can be perfectly documented and still fail on any one of them.
In practice
- Put management review on a fixed calendar (annually is common) so it happens on schedule rather than "when there is time."
- Make sure the people in the room actually have the authority to approve budget, resourcing, or scope changes — a review attended only by the security team is not a management review.
Evidence the auditor will ask for
- Calendar invites or minutes showing the review actually happened at the planned interval, with top management present.
- Attendance records confirming the participants had real decision-making authority.
Related requirements
9.3.2 Management review inputs
What this general review must actually consider.
Clause 5 Leadership
Management review is one of the clearest tests of the leadership commitment clause 5 requires.
Parent link: 9.3 Management review
Frequently asked questions
Who counts as "top management" for this review?
Get management review back on leadership’s calendar.
Sentrix schedules and packages your management review so it happens on time, with the right people, every cycle.