Clause 9 — Performance evaluation
You cannot claim the ISMS works — you have to prove it. Clause 9 is where the standard stops asking you to build things and starts asking you to check them: measure whether your controls are performing, audit the system with an independent eye, and have leadership formally review the results. It is the clause auditors weigh most heavily when deciding how much to trust everything else in your file, because a weak clause 9 usually means the rest of the ISMS is undocumented drift rather than a managed system.
The structure of clause 9
What clause 9 covers
Clause 9 answers three questions, in ascending order of formality. First: are you actually watching your security performance day to day — what gets measured, how, and by whom (9.1)? Second: does an independent internal audit confirm the ISMS conforms to its own rules and to the standard (9.2)? Third: does top management step back, on a planned schedule, and formally decide whether the whole system is still suitable, adequate, and effective (9.3)? Each layer checks the one below it, which is exactly what an auditor is looking to see working.
Why it is central
Internal audit findings (9.2) are the single best predictor of how a certification audit will go: if your own internal audit consistently finds nothing, either your ISMS is unusually mature or your internal audit is not looking hard enough — and an external auditor will probe to find out which. Management review (9.3) closes the loop by forcing leadership to actually act on what 9.1 and 9.2 surface, which is what keeps clause 10 (improvement) from becoming a formality.
The documents that come out of clause 9
- Evidence of monitoring and measurement results (9.1)
- The internal audit programme (9.2.2)
- Internal audit results and evidence the programme was implemented (9.2.2)
- The results of management reviews (9.3.3)
Frequently asked questions
What is the difference between 9.1 and 9.2?
Who can perform the internal audit?
How often must management review happen?
Need hands-on support building your monitoring program, internal audit, and management review? See our ISO 27001 certification support service
Prove your ISMS works — not just that it exists.
Sentrix tracks your monitoring metrics, internal audit findings, and management review actions in one place — so clause 9 stops being a scramble before every surveillance audit.