Clause 9 · Performance evaluation

9.3.1 — General

Three words that decide whether the ISMS survives another year: suitable, adequate, effective.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 9.3.1 requires top management — not a delegate, not a committee acting alone — to formally review the ISMS at planned intervals and judge whether it is still suitable for the organization, adequate for its risks, and effective at delivering security outcomes.

Position in the standard

Clause 9 · Performance evaluation
9.3.1 · General ← you are here
See also: 9.3.2 · 9.3.3

Why this requirement exists

Delegating security entirely to an operational team, with leadership never actually looking at how the program is doing, is exactly the pattern this requirement is designed to prevent. An ISMS that only the security team ever reviews tends to optimize for what the security team can influence, while organizational-level problems — under-resourcing, conflicting priorities, scope creep — go unaddressed because nobody with the authority to fix them is looking.

Scenario: a company’s security team has flagged, for three straight quarters, that they lack the budget to remediate a known risk. Without a management review forcing that status in front of leadership on a fixed schedule, the flag stays buried in a team-level tracker indefinitely.

What the standard expects

The standard expects top management to review the organization’s ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. "Suitability" asks whether the ISMS still fits the organization as it exists today; "adequacy" asks whether it addresses the risks the organization actually faces; "effectiveness" asks whether it delivers the intended security outcomes. All three must be considered — a system can be perfectly documented and still fail on any one of them.

In practice

  • Put management review on a fixed calendar (annually is common) so it happens on schedule rather than "when there is time."
  • Make sure the people in the room actually have the authority to approve budget, resourcing, or scope changes — a review attended only by the security team is not a management review.

Evidence the auditor will ask for

  • Calendar invites or minutes showing the review actually happened at the planned interval, with top management present.
  • Attendance records confirming the participants had real decision-making authority.

Related requirements

Parent link: 9.3 Management review

Frequently asked questions

Who counts as "top management" for this review?
The person or group who directs and controls the organization at the highest level — for a small company, that might be the founder or CEO; for a larger one, a senior executive with real authority over resourcing.

Get management review back on leadership’s calendar.

Sentrix schedules and packages your management review so it happens on time, with the right people, every cycle.