Clause 9 · Performance evaluation

9.3.2 — Management review inputs

A checklist, not a vibe: this is the specific list of things leadership has to look at before it can claim the review actually happened.

Mandatory requirementDocumented information required: No

In plain language

In plain language: 9.3.2 spells out exactly what leadership must look at during the management review, so the meeting cannot be a vague status update — it has to cover a defined checklist of inputs drawn from across the whole ISMS.

Position in the standard

Clause 9 · Performance evaluation
9.3.2 · Management review inputs ← you are here
See also: 9.3.1 · 9.3.3

Why this requirement exists

Without a defined input list, a management review tends to drift toward whatever the loudest voice in the room wants to discuss, while quieter but important signals — a slow-moving corrective action, a shift in what customers now demand contractually — get skipped entirely.

Scenario: a management review spends its entire hour on a new product launch and never gets to the fact that three corrective actions from the last internal audit are still open past their deadline. A review structured around the required inputs would have surfaced that item by design, not by luck.

What the standard expects

The standard expects management review to consider: the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties relevant to the ISMS; feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.

In practice

  • Build a standing agenda template with each required input as its own section, so nothing gets skipped from one review to the next.
  • Open every review by checking the status of actions from the previous one — an open item that quietly disappears is the fastest way to fail this sub-clause.
  • Pull metrics directly from 9.1 monitoring and findings directly from 9.2 internal audit rather than re-summarizing them from memory.

Evidence the auditor will ask for

  • Minutes or a review pack showing each required input was actually presented and discussed, not just listed on an agenda.
  • Traceability from previous review actions to their current status.

Common pitfalls

  • A review that covers business updates but skips several of the required inputs entirely.
  • Interested-party feedback that is never actually collected, so this input is presented with nothing behind it.

Related requirements

Parent link: 9.3 Management review

Frequently asked questions

Do we need a slide or section for every single input, every time?
Yes, each input needs to be addressed, even if briefly — "no significant change this quarter" is a valid answer for an input, but skipping it entirely is not.

Never miss a required management review input again.

Sentrix pre-fills your management review agenda with live metrics, audit findings, and risk status pulled straight from your program.