9.3 — Management review
The point where everything 9.1 and 9.2 surfaced actually reaches the people with the authority to act on it.
In plain language
In plain language: sub-clause 9.3 requires top management to formally review the ISMS at planned intervals, looking at a defined set of inputs — audit results, metrics, risk status, feedback — and to walk away with documented decisions about what needs to change.
Position in the standard
The sub-requirements of 9.3
9.3.1 General
The baseline expectation: leadership reviews the ISMS at planned intervals for continuing suitability, adequacy, and effectiveness.
9.3.2 Management review inputs
The specific list of things leadership must consider — from prior action status to risk treatment progress.
9.3.3 Management review results
What the review has to produce: documented decisions on improvement opportunities and needed changes.
How these requirements fit together
9.3.1 sets the cadence and the purpose: leadership steps back periodically to judge whether the ISMS as a whole is still fit for purpose. 9.3.2 makes sure that judgment is not made on gut feel — it lists the specific inputs the review must consider, from audit findings to risk treatment status to interested-party feedback, so nothing important gets left out of the conversation. 9.3.3 closes the loop by requiring the review to actually produce something: documented decisions, not just a meeting that happened. A management review with no 9.3.2 inputs is an opinion; a management review with no 9.3.3 outputs is a meeting with no consequences.
Need hands-on support running your management review? See our ISO 27001 certification support service
Turn management review into a real decision point.
Sentrix compiles your monitoring metrics, audit findings, and risk status into a ready-made management review pack.