Back to Columns
ISMS & Certification12 min read

Clause 9: Performance Evaluation — Monitoring, Measurement, and Internal Audit

September 14, 2026

Clause 9: Performance Evaluation — Monitoring, Measurement, and Internal Audit
Share this article

Clause 9 is where ISMS schedules most often break. Once the procedures and the Statement of Applicability are finished, it feels like only the audit remains — but certification requires records of one completed cycle of internal audit and management review. You cannot present for audit with documents alone.

Clause 9 also has internal dependencies. Without monitoring results there is little for an internal audit to examine; without audit results the management review inputs are empty. Three activities have to run in sequence, and the time for that has to be reserved by working backwards from the audit date.

This article sets out the three activities required by clause 9 (Performance evaluation), separating design decisions from how auditors examine them. "What to measure" and "auditor independence" get extra attention, because they are where small organisations get stuck.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

What Clause 9 Asks For

Three subclauses, and it helps to read them as evaluation getting progressively coarser as the decision-maker gets more senior.

SubclauseActivityWho performs itOutput
9.1 Monitoring, measurement, analysis and evaluationMeasure the agreed indicators continuously; analyse and evaluate the resultsOperating departmentsMeasurement results with evaluation
9.2 Internal auditAudit whether the ISMS conforms to the standard and to your own requirements, and is effectively implemented and maintainedAuditors independent of the area auditedAudit report, nonconformities and observations
9.3 Management reviewEvaluate the ISMS's continuing suitability, adequacy, and effectiveness from defined inputsTop managementImprovement opportunities, decisions to change the ISMS

Clause 8 executes, clause 9 checks, clause 10 fixes — the C and A of the cycle. See Clause 4: Context, Clause 5: Leadership, Clause 6: Planning, Clause 7: Support, Clause 8: Operation, and the overview in What Is an ISMS.

9.1 — what, how, when, who

9.1 asks you to determine and document:

  • what is monitored and measured (which ISMS processes and controls)
  • by what methods — and the methods must produce comparable and reproducible results
  • when measurement is performed
  • who performs it
  • when and by whom the results are analysed and evaluated

The last item is the one that gets dropped. If you do not separately name who evaluates, you end up collecting numbers nobody reads.

9.2 — auditor independence

Internal audit confirms two things: that the ISMS conforms to the standard and to your own requirements, and that it is effectively implemented and maintained. The core requirement is auditor objectivity and impartiality — in practice, not auditing your own work.

Audits are also planned as a programme, not as one-off events: frequency, methods, responsibilities, planning requirements, and reporting, taking into account the importance of the processes concerned and the results of previous audits.

9.3 — management review inputs

Top management performs the review at planned intervals. The standard enumerates the inputs, and dropping even one of them is a common route to a nonconformity. The table below serves as a template.

What You Actually Produce

SubclauseArtefactKey points
9.1Monitoring and measurement plan (subject, method, frequency, performer, evaluator)Map one-to-one against information security objectives; never leave an objective without a method
9.1Measurement records with evaluation commentsDo not leave bare numbers — add a line judging performance against the target
9.2Internal audit programme (annual plan)State scope, frequency, auditor assignment, and how independence is secured
9.2Audit checklistCover the clauses and the controls marked applicable in the SoA; reuse is fine, but add last year's findings
9.2Internal audit reportRecord conformities too; for nonconformities state the fact, the evidence, and the requirement, then hand off to corrective action
9.3Management review minutesUse a format with a field per required input; name attendees and decisions

See Running an Internal Audit and Management Review in Practice.

Never set an objective you cannot measure

Objectives (clause 6) and indicators (clause 9) should be designed together. Set objectives first and bolt measurement on afterwards, and you will always be left with something unmeasurable.

Poor objectiveWhy it cannot be measuredMeasurable rewrite
Raise employee security awareness"Awareness" has no observable100% completion of annual training; 95% scoring 80+ on the comprehension test
Zero incidentsCannot distinguish success from luck, and suppresses reportingMean time from detection to first report under two hours
Strengthen securityNo subject, no threshold90%+ of critical and high vulnerabilities remediated within 14 days of detection
Manage suppliers appropriatelyNo definition of "appropriate"100% annual check sheet return rate; zero overdue

Set targets at a level that is achievable with effort. Carrying a permanently missed target means explaining the same thing at every review, which actually stalls improvement. See Setting Security Objectives and KPIs.

Where It Goes Wrong

1. A small organisation cannot achieve auditor independence

At 20–30 people, the person who runs IT is usually also the ISMS secretariat. If they audit their own area, independence fails.

Three realistic options:

ApproachPreconditionWatch out for
Cross-audit between departmentsTwo or more genuinely independent areas existReciprocal leniency; make the checklist strict
Management or corporate functions auditThey are uninvolved in the work auditedTechnical depth suffers; pair with external help for technical areas
Use external auditorsBudget existsCheck whether the internal audit manager role can also be outsourced

The standard requires internal appointment for top management and the ISMS manager and officers; the internal audit manager and auditors can be outsourced. For small organisations this is usually the most practical route. See ISMS for Small Organisations.

2. The audit becomes a document-existence check

A checklist that only asks "does the procedure exist?" finishes in thirty minutes and finds nothing. That does not verify effectiveness.

Effectiveness requires sampling a record and tracing it: "Show me three access grant requests. Who approved them, and when were leavers' permissions revoked?" At that depth, divergence from reality becomes visible.

3. Zero nonconformities in the internal audit

An organisation whose first internal audit finds nothing is sometimes told at the certification audit that its internal audit is not functioning — a freshly built ISMS with no defects is implausible.

Raising nonconformities is the internal audit working, not failing. Records of finding and correcting them are the evidence that the mechanism turns.

4. Management review inputs go missing

There are many required inputs, and without a field per item in the minutes template, something is always dropped. Use this as the template.

InputTypical contentRisk of omission
Status of actions from previous reviewsImplementation status and reasons for open itemsMedium
Changes in external and internal issues relevant to the ISMSBusiness change, revised laws and guidelines, reorganisationHigh
Changes in needs and expectations of interested partiesCustomer requirements, client demands, regulatory directionHighest (made explicit in the 2022 edition)
Nonconformities and corrective actionsCounts and status from audits, certification audits, incidentsLow
Monitoring and measurement resultsActuals for the 9.1 indicatorsLow
Audit resultsInternal audits and external audits including surveillanceLow
Fulfilment of information security objectivesMet/missed per objective, with causesMedium
Feedback from interested partiesCustomer findings, queries raised in check sheet responsesHigh
Results of risk assessment and status of the risk treatment planLatest assessment, residual risk, treatment progressMedium
Opportunities for continual improvementImprovement proposals, next-period prioritiesMedium

Do not forget the outputs. A management review produces opportunities for continual improvement and decisions on changes to the ISMS. Minutes that record only "a report was received," with no decisions, are judged not to be a review.

5. Sequencing and timing

Run the internal audit immediately before the certification audit and there is no time to correct findings. Run it too early and changes made afterwards go unverified.

In practice, internal audit six to eight weeks before the stage 2 audit, with management review two to three weeks later works well, leaving room for corrective action and effectiveness verification. See The ISMS Timeline.

What Auditors Look At

FocusTypical questionPreparation
Measurement design"How is this indicator measured? Would anyone calculating it get the same number?"Write the method down as a procedure; be able to show the source data
Link to objectives"Where can I see performance against this objective?"Cross-reference the objectives register and the measurement records
Auditor independence"Is this auditor involved in the area they audited?"State independence arrangements in the programme; show the contract if outsourced
Audit coverage"In which cycle are the controls marked applicable in the SoA audited?"Show an annual or three-year coverage plan
Audit depth"What evidence produced this finding?"Record the identifiers of the evidence examined in the report
Who performed the review"Did top management attend?"Minutes should show executive attendance; if absent, show alternative involvement
Review decisions"What was decided here, and was it done?"Number the decisions and report their status at the next review

Stage 1 examines plans and formats; stage 2 examines execution and depth. See What Stage 1 Audits Examine, What Stage 2 Audits Examine, and Common Nonconformities.

Healthcare Examples

Include indicators specific to medical information

Alongside general IT metrics, indicators tied to how medical information is handled double as material for answering customer questions.

Example indicatorMethodFrequency
Privileged access sessions to production holding medical information, and approval rateIdP or bastion log aggregationMonthly
On-time response rate to security enquiries from customer hospitalsEnquiry registerQuarterly
Annual assessment completion rate for suppliers (cloud, maintenance)Supplier registerAnnual
Restore-test success rate from backupsRestore test recordsHalf-yearly
14-day remediation rate for critical and high vulnerabilitiesVulnerability management toolMonthly

Audit three-ministry guideline compliance in the same pass

If you serve hospitals, running the ISMS internal audit and guideline compliance checks separately doubles the effort. Merging guideline-derived items into the audit checklist produces evidence for both in one pass. See Integrating ISMS Documents with the Three-Ministry Guidelines and Japan's Three-Ministry Guidelines.

Feed changing customer requirements into the review

"Changes in the needs and expectations of interested parties" is the most-missed input, and healthcare companies have concrete material for it: changes in the questions on security check sheets from customer hospitals, new requirements added to procurement specifications, findings raised in hospital-side audits. See Security Check Sheets for Vendors for the buyer's view.

Turn log review into an indicator

Collecting access logs and reviewing them are different things. Including the review completion rate among your 9.1 indicators keeps the practice from becoming nominal. See Reviewing EMR Access Logs.

Conclusion

  1. Certification requires records of one completed cycle of internal audit and management review — documents alone are not enough
  2. 9.1 covers what, how, when, and who, plus who evaluates the results and when. Separate the measurer from the reviewer
  3. Never set an objective you cannot measure. Design objectives and methods together
  4. Internal audit turns on not auditing your own work. Small organisations can outsource the audit manager and auditors
  5. Finding nonconformities is the audit succeeding. A run of zeroes invites scrutiny
  6. Give the management review a field per required input — "changes in interested parties' needs and expectations" is the most commonly missed
  7. Place the internal audit six to eight weeks before stage 2, leaving time for correction and verification

Pottech supports ISMS certification with a focus on healthcare: designing measurement indicators, building the internal audit programme, and facilitating the management review. We can serve as your internal audit manager and internal auditors — which matters most for small organisations struggling with independence.

See ISMS Certification Support for scope and pricing, or contact us to discuss your situation.

References and Sources

Note: interpretation of requirements and the handling of certification are governed by the standard itself and by the publications of accreditation and certification bodies. Audit practice varies between bodies and auditors.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.