Back to Columns
ISMS & Certification13 min read

Running a Management Review and Writing the Minutes

September 14, 2026

Running a Management Review and Writing the Minutes
Share this article

The management review is the ISMS process that finishes fastest and hollows out most often. Once a year, the secretariat's deck is read aloud to the board for thirty minutes, "no particular comments" goes into the minutes, and that is that. It exists as a document, but it is not what the standard asks for.

What the standard asks of top management is a review of whether the ISMS remains suitable, adequate and effective — and a decision to change it where it is not. This is not a briefing; it is the forum where resources, scope, policy and risk acceptance are decided. Minutes in which nothing was decided are themselves evidence that effectiveness was never reviewed.

This article covers how to assemble the inputs, what top management actually decides, the right level of detail for the minutes, and whether once a year is enough. For the Clause 5 foundation see Clause 5: Leadership; for the wider Clause 9 picture, Clause 9: Performance Evaluation; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.

Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.

Why This Is Where People Get Stuck

Three causes account for nearly every hollowed-out management review.

First, the inputs are a list of numbers. Three nonconformities from internal audit, five incidents, 98% training completion. If the deck does not say whether that is good or bad and what should change, management has nothing to decide on. Every number needs context that makes it decidable — distance from target, comparison with the prior period, and the secretariat's own reading.

Second, the questions to be decided were never set in advance. A deck that opens with "for your information" contains no motions. Management's time is finite; unless you lead with "we ask for a decision on these three points," no discussion happens.

Third, the secretariat decides in management's place. Budget is short so the control slips to next year; this residual risk will be accepted. When the ISMS secretariat makes those calls alone and reports them after the fact, auditors record it as "no evidence that top management made the decision."

All three are fixed in preparation, not by making the meeting longer.

What Gets Decided

The inputs the standard requires

Clause 9.3 enumerates what the review must consider. Paraphrased into practice:

InputWhat you prepareOwner
Status of actions from previous reviewsPrior minutes' decision list with completion status and reasonsSecretariat
Changes in external and internal issuesLegal changes, business changes, reorganisation, new servicesSecretariat + business units
Changes in interested parties' needs and expectationsShifts in customer security requirements, regulator and industry movementSales / Legal
Nonconformities and corrective actionsList and progress of findings from internal audit, external audit and daily operationSecretariat
Monitoring and measurement resultsKPI actuals against targetsMetric owners
Audit resultsInternal audit report, last certification audit reportInternal audit lead
Fulfilment of information security objectivesMet / not met per objective, with reasons for missesObjective owners
Feedback from interested partiesCustomer findings, gaps surfaced by security questionnairesSales / Secretariat
Risk assessment results and treatment plan statusNew risks, changed levels, treatment progressSecretariat + risk owners
Opportunities for continual improvementSecretariat's proposals requiring a decisionSecretariat

The one most often missing is "changes in interested parties' needs and expectations." It was made explicit in the 2022 edition, yet decks frequently omit it. For a healthcare company this is exactly where shifts in what customer hospitals require belong — revisions to the three-ministry guidelines, tighter procurement specifications, changes in how the personal information law is enforced.

What top management actually decides

The required outputs are decisions on opportunities for continual improvement and on any need for change to the ISMS. In working terms, that is four kinds of decision:

Type of decisionExamples
Allocation of resourcesNext year's security budget, headcount, external support, tool purchases
Changes to scope or structureWhether a new site or service enters the ISMS scope, changes of responsible officers, reorganisation
Revision of policy and objectivesAmending the security policy, setting next period's objectives and KPIs, changing targets
Acceptance of riskWhether to accept residual risk that cannot be treated, or extend a treatment deadline

Minutes in which none of these four appear are a symptom of a review that is not working. Conversely, if the secretariat prepares items along these four lines, the meeting becomes a decision forum by construction.

See Setting Security Objectives and KPIs and Risk Treatment Plans and Acceptance.

How to Run It

1. Place it in the annual cycle (2–3 months ahead)

The review does not stand alone. It must sit in the sequence internal audit → corrective actions raised → management review → next period's plan. Holding it before audit results exist strips out a principal input.

TimingActivity
3 months before year endInternal audit
2 months beforeCorrective actions raised; KPI actuals compiled
1 month beforeManagement review
Start of new periodObjectives, KPIs and treatment plan fixed
During the yearSurveillance audit (per the certification body's schedule)

See Running an Internal Audit and Preparing for Surveillance Audits.

2. Build the input pack (2 weeks ahead)

Keep each item to one page or less, and put the secretariat's reading on every page in a line or two. No page is numbers alone.

WeakStrong
Internal audit: 3 nonconformities, 5 observationsInternal audit: 3 nonconformities. Two are missing supplier-review records; the cause is that review scheduling depends on individuals. Remediation requires systematising reviews (≈10 person-days)
Training completion 98%Training completion 98% (target 100%). The two outstanding are on extended leave. A decision is needed on adding a return-to-work training rule
5 incidents5 incidents (prior period 7). Four were misdirected email, all in one department. A pre-send confirmation control should be considered

3. Put the motions first (1 week ahead)

Open the pack with "decisions requested today" — three to five items, circulated in advance, each with the secretariat's proposal, the resources required, and the risk of not deciding.

For example:

  • Approve next year's security budget of ¥X (proposal: approve; covers systematised supplier review and company-wide MFA)
  • Include the new SaaS offering in ISMS scope (proposal: include; customer hospitals require it)
  • Accept residual risk regarding supplier A's sub-processor (proposal: accept, conditional on an annual on-site check)

4. Hold the meeting

Take motions first, reports second. That prevents decisions being deferred when time runs out.

Top management — the representative director or equivalent decision-maker — must attend. A record showing only delegates is a structure auditors probe. Where attendance is genuinely impossible, retain evidence of approval of the decisions (signature, electronic approval, an explicit email).

5. Write the minutes

The level of detail is the most practical question here; the next section covers it.

6. Convert decisions into plans (within 2 weeks)

Turn each decision into a task with an owner, a deadline and a completion criterion. Without this, the next review cannot report on "status of actions from previous reviews." Items that belong in corrective action go onto the form in Writing a Corrective Action Report.

The right level of detail in the minutes

The test is whether a third party reading later — an auditor, a new staff member, a customer's audit team — can reconstruct what was discussed and what was decided.

ElementHow to write it
Date, place, attendeesState roles. Make top management's attendance explicit
InputsHeadings following the 9.3 items, with what was reported under each
Substance of discussionWho raised which point and how it was considered, including dissent
DecisionsWhat was decided: approved / rejected / approved with conditions / deferred
ReasonsWhy. A decision not to act always needs a reason
Owner and deadlineFor each decision
Next meetingWhen, and what it will cover

Avoid:

  • "No comments" as the only record of discussion
  • "Approved" without identifying what was approved
  • Attaching the deck instead of recording decisions in the body
  • Ending on "to be considered" with no owner or date

The record of a decision not to act matters most. Declining an improvement proposal, accepting a residual risk, deferring a control to next year — all are legitimate management decisions, but without a stated reason they are indistinguishable from not having noticed. After an incident, that difference is large.

One caution: do not write detailed vulnerability or attack specifics into the minutes. Minutes are often requested in customer audits. Keep the detail in a separate controlled document and reference it.

Where It Goes Wrong

Is once a year enough?

The standard requires review "at planned intervals" — it does not prescribe annually. Annual works when the business and its risk profile are stable. In any of the following, annual leaves decisions too late:

SituationRecommended approach
New service launch or large migrationHold an extraordinary review at the change-planning stage
A major incidentExtraordinary review afterwards (approve remediation, allocate resources)
M&A, new sites, significant reorganisationExtraordinary review to decide the scope change
Revised laws or guidelinesExtraordinary review with the impact assessment
Fast-growing organisationMake it twice yearly

The most workable pattern is one full annual review plus lighter quarterly ones. The full review covers all 9.3 inputs; the quarterly covers three things — progress on prior decisions, KPI actuals, new risks. If you do this, state both in the procedure. Calling a partial review a management review while omitting required inputs invites a finding.

Internal audit and review held on the same day

There is then no time to digest the findings, and no root-cause analysis to base resource decisions on. Leave at least two weeks, preferably a month.

The secretariat writes the pack, writes the minutes and makes the decisions

Auditors see through this. Minutes containing no remark from any business unit, with every decision matching the secretariat's proposal, put top management's involvement in question. Deliberately record executives' questions and instructions.

Prior decisions are never tracked

The first required input is the status of previous decisions, yet that section is routinely blank. Maintain a one-sheet decision register and open every meeting with it.

A missed KPI passes without explanation

"Target 100%, actual 85%" with no cause and no action means Clause 9 monitoring is not feeding Clause 10 improvement. Make every missed objective a motion: cause, and whether the target stands or the plan changes.

No approval record on the minutes

Minutes signed only by their author are weak evidence. The form does not matter — electronic approval, circulation record, email — but the fact of approval must be traceable.

Healthcare Examples

A healthcare SaaS provider

The distinctive agenda item is change in what customer hospitals require. Guideline revisions and tighter hospital procurement specifications convert directly into cost. Feeding these from the sales team as "changes in interested parties' expectations" links the review to revenue discussion. See The Governance Volume: What Management Is Responsible For and Three-Ministry Guidelines.

The second is access to production patient data. How often engineers read live data during incident handling, and whether request and approval records are complete. Track it monthly in log review and bring only trends and exceptions to the review.

A PHR operator

Consent capture and withdrawal versus actual data use becomes an agenda item. Has a new feature pushed data use beyond the existing consent scope? This is precisely where business and security judgement overlap. See ISMS for PHR Operators.

A clinical trial systems company

Bring audit-trail integrity metrics as a standing item: log gaps, clock-sync drift, restore-test results. These are integrity and availability concerns that confidentiality-centric KPIs miss.

A SaMD developer

Whether to hold the ISMS review and the QMS (ISO 13485) review as one meeting or two is a real question. Either is acceptable, but a combined meeting's minutes must make clear that every 9.3 input was covered. Blending the agendas invites "we cannot confirm that item was discussed" in both audits. See SaMD, ISMS and ISO 13485.

A small organisation

Where management and secretariat overlap in person, you get "I report to myself and approve it." Even then, separate the roles explicitly in the minutes — report and decision as distinct entries — and the evidence holds. See ISMS for Small Organisations.

Conclusion

  1. The review is not a briefing; it decides resources, scope, policy and risk acceptance
  2. Inputs need gap to target, prior-period comparison and the secretariat's reading — never bare numbers
  3. Minutes must carry substance of discussion, the decision, and the reason — above all for decisions not to act
  4. The standard does not say annual. Twice a year, or annual plus quarterly light reviews, suits fast-changing organisations
  5. Leave two weeks to a month between internal audit and the review
  6. Convert decisions into owned, dated, testable tasks and open the next review with them

Improvement decisions feed Clause 10: Improvement and are tracked on the form in Writing a Corrective Action Report. Scope changes return to Defining ISMS Scope; structural changes, to Clause 5: Leadership.

Pottech supports ISMS certification and operation with a focus on healthcare. Agenda design and minute templates for the management review are where first-year operation stumbles, and auditors always look. See ISMS Certification Support or contact us.

References and Sources

Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.

Share this article

Related Articles

ISMS & Certification

Reading the 37 Organizational Controls

The 37 organizational controls of Annex A.5, grouped into eight clusters rather than translated one by one: policy and governance, assets and classification, access policy, suppliers and cloud, threat intelligence, incident management, continuity, and compliance. What each cluster is asking for, and what you end up producing.

September 14, 2026
ISMS & Certification

Annex A 2022: 93 Controls Across Four Themes

A map of the 93 Annex A controls in ISO/IEC 27001:2022 across four themes — 37 organizational, 8 people, 14 physical, 34 technological. Why there is no duty to implement all 93, how inclusion and exclusion are justified in the Statement of Applicability, what the attributes are for, and the order a healthcare company should work in.

September 14, 2026
ISMS & Certification

Reading the 8 People Controls

The 8 people controls of Annex A.6, grouped into entry, employment, exit, where people work, and reporting culture. How they connect to existing employment rules, how to handle segregation of duties when the team is too small for it, and how far to go on remote working — written for healthcare companies.

September 14, 2026
ISMS & Certification

Reading the 14 Physical Controls

The 14 physical controls of Annex A.7 in five clusters, with a concrete treatment of what a fully remote, cloud-only organisation can exclude and what must be reassigned to home-working rules and supplier management — data centres, media and disposal, and equipment off premises.

September 14, 2026
AI Karte

Explore AI Karte

An AI-native EHR connecting reception, documentation, accounting, claims, and analytics into one cycle.

View the product page

ISMS Certification Support as an Option

From scope design and documentation to training, internal audit, and dealing with the certification body. Pottech supports healthcare companies through ISO/IEC 27001 certification end to end.