Home/ ISO 27001 clauses guide/ Clause 9 · Performance evaluation
Requirement 9 · “Check” phase of the PDCA cycle

Clause 9 — Performance evaluation

You cannot claim the ISMS works — you have to prove it. Clause 9 is where the standard stops asking you to build things and starts asking you to check them: measure whether your controls are performing, audit the system with an independent eye, and have leadership formally review the results. It is the clause auditors weigh most heavily when deciding how much to trust everything else in your file, because a weak clause 9 usually means the rest of the ISMS is undocumented drift rather than a managed system.

The structure of clause 9

What clause 9 covers

Clause 9 answers three questions, in ascending order of formality. First: are you actually watching your security performance day to day — what gets measured, how, and by whom (9.1)? Second: does an independent internal audit confirm the ISMS conforms to its own rules and to the standard (9.2)? Third: does top management step back, on a planned schedule, and formally decide whether the whole system is still suitable, adequate, and effective (9.3)? Each layer checks the one below it, which is exactly what an auditor is looking to see working.

Why it is central

Internal audit findings (9.2) are the single best predictor of how a certification audit will go: if your own internal audit consistently finds nothing, either your ISMS is unusually mature or your internal audit is not looking hard enough — and an external auditor will probe to find out which. Management review (9.3) closes the loop by forcing leadership to actually act on what 9.1 and 9.2 surface, which is what keeps clause 10 (improvement) from becoming a formality.

The documents that come out of clause 9

  • Evidence of monitoring and measurement results (9.1)
  • The internal audit programme (9.2.2)
  • Internal audit results and evidence the programme was implemented (9.2.2)
  • The results of management reviews (9.3.3)

Frequently asked questions

What is the difference between 9.1 and 9.2?
9.1 is ongoing, operational monitoring of specific metrics (is MFA coverage at 100%? are backups completing?). 9.2 is a periodic, independent internal audit checking whether the whole ISMS — including whether 9.1 itself is being done properly — conforms to your own rules and to the standard.
Who can perform the internal audit?
Anyone independent of the area being audited — an internal employee from a different team, or an external contractor. The requirement is objectivity and impartiality, not a specific credential.
How often must management review happen?
The standard says "at planned intervals," without naming a frequency. Most organizations run it annually, aligned with the certification or surveillance audit cycle, with some choosing a semi-annual cadence for a more mature program.

Need hands-on support building your monitoring program, internal audit, and management review? See our ISO 27001 certification support service

↑ Back to the 7-clause guide

Prove your ISMS works — not just that it exists.

Sentrix tracks your monitoring metrics, internal audit findings, and management review actions in one place — so clause 9 stops being a scramble before every surveillance audit.