9.3.2 — Management review inputs
A checklist, not a vibe: this is the specific list of things leadership has to look at before it can claim the review actually happened.
In plain language
In plain language: 9.3.2 spells out exactly what leadership must look at during the management review, so the meeting cannot be a vague status update — it has to cover a defined checklist of inputs drawn from across the whole ISMS.
Position in the standard
Why this requirement exists
Without a defined input list, a management review tends to drift toward whatever the loudest voice in the room wants to discuss, while quieter but important signals — a slow-moving corrective action, a shift in what customers now demand contractually — get skipped entirely.
Scenario: a management review spends its entire hour on a new product launch and never gets to the fact that three corrective actions from the last internal audit are still open past their deadline. A review structured around the required inputs would have surfaced that item by design, not by luck.
What the standard expects
The standard expects management review to consider: the status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in the needs and expectations of interested parties relevant to the ISMS; feedback on information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of information security objectives; feedback from interested parties; the results of risk assessment and the status of the risk treatment plan; and opportunities for continual improvement.
In practice
- Build a standing agenda template with each required input as its own section, so nothing gets skipped from one review to the next.
- Open every review by checking the status of actions from the previous one — an open item that quietly disappears is the fastest way to fail this sub-clause.
- Pull metrics directly from 9.1 monitoring and findings directly from 9.2 internal audit rather than re-summarizing them from memory.
Evidence the auditor will ask for
- Minutes or a review pack showing each required input was actually presented and discussed, not just listed on an agenda.
- Traceability from previous review actions to their current status.
Common pitfalls
- A review that covers business updates but skips several of the required inputs entirely.
- Interested-party feedback that is never actually collected, so this input is presented with nothing behind it.
Related requirements
9.1 Monitoring and measurement
One of the direct sources of performance feedback this input list requires.
9.2.2 Internal audit programme
Audit results are one of the named required inputs.
9.3.3 Management review results
What these inputs must lead to.
Parent link: 9.3 Management review
Frequently asked questions
Do we need a slide or section for every single input, every time?
Never miss a required management review input again.
Sentrix pre-fills your management review agenda with live metrics, audit findings, and risk status pulled straight from your program.