The management review is the ISMS process that finishes fastest and hollows out most often. Once a year, the secretariat's deck is read aloud to the board for thirty minutes, "no particular comments" goes into the minutes, and that is that. It exists as a document, but it is not what the standard asks for.
What the standard asks of top management is a review of whether the ISMS remains suitable, adequate and effective — and a decision to change it where it is not. This is not a briefing; it is the forum where resources, scope, policy and risk acceptance are decided. Minutes in which nothing was decided are themselves evidence that effectiveness was never reviewed.
This article covers how to assemble the inputs, what top management actually decides, the right level of detail for the minutes, and whether once a year is enough. For the Clause 5 foundation see Clause 5: Leadership; for the wider Clause 9 picture, Clause 9: Performance Evaluation; for the standard as a whole, What Is an ISMS (ISO/IEC 27001)?.
Disclaimer: This article is general information. The authoritative texts are ISO/IEC 27001 (JIS Q 27001) itself and the publications of the accreditation and certification bodies. Base actual decisions on those.
Why This Is Where People Get Stuck
Three causes account for nearly every hollowed-out management review.
First, the inputs are a list of numbers. Three nonconformities from internal audit, five incidents, 98% training completion. If the deck does not say whether that is good or bad and what should change, management has nothing to decide on. Every number needs context that makes it decidable — distance from target, comparison with the prior period, and the secretariat's own reading.
Second, the questions to be decided were never set in advance. A deck that opens with "for your information" contains no motions. Management's time is finite; unless you lead with "we ask for a decision on these three points," no discussion happens.
Third, the secretariat decides in management's place. Budget is short so the control slips to next year; this residual risk will be accepted. When the ISMS secretariat makes those calls alone and reports them after the fact, auditors record it as "no evidence that top management made the decision."
All three are fixed in preparation, not by making the meeting longer.
What Gets Decided
The inputs the standard requires
Clause 9.3 enumerates what the review must consider. Paraphrased into practice:
| Input | What you prepare | Owner |
|---|---|---|
| Status of actions from previous reviews | Prior minutes' decision list with completion status and reasons | Secretariat |
| Changes in external and internal issues | Legal changes, business changes, reorganisation, new services | Secretariat + business units |
| Changes in interested parties' needs and expectations | Shifts in customer security requirements, regulator and industry movement | Sales / Legal |
| Nonconformities and corrective actions | List and progress of findings from internal audit, external audit and daily operation | Secretariat |
| Monitoring and measurement results | KPI actuals against targets | Metric owners |
| Audit results | Internal audit report, last certification audit report | Internal audit lead |
| Fulfilment of information security objectives | Met / not met per objective, with reasons for misses | Objective owners |
| Feedback from interested parties | Customer findings, gaps surfaced by security questionnaires | Sales / Secretariat |
| Risk assessment results and treatment plan status | New risks, changed levels, treatment progress | Secretariat + risk owners |
| Opportunities for continual improvement | Secretariat's proposals requiring a decision | Secretariat |
The one most often missing is "changes in interested parties' needs and expectations." It was made explicit in the 2022 edition, yet decks frequently omit it. For a healthcare company this is exactly where shifts in what customer hospitals require belong — revisions to the three-ministry guidelines, tighter procurement specifications, changes in how the personal information law is enforced.
What top management actually decides
The required outputs are decisions on opportunities for continual improvement and on any need for change to the ISMS. In working terms, that is four kinds of decision:
| Type of decision | Examples |
|---|---|
| Allocation of resources | Next year's security budget, headcount, external support, tool purchases |
| Changes to scope or structure | Whether a new site or service enters the ISMS scope, changes of responsible officers, reorganisation |
| Revision of policy and objectives | Amending the security policy, setting next period's objectives and KPIs, changing targets |
| Acceptance of risk | Whether to accept residual risk that cannot be treated, or extend a treatment deadline |
Minutes in which none of these four appear are a symptom of a review that is not working. Conversely, if the secretariat prepares items along these four lines, the meeting becomes a decision forum by construction.
See Setting Security Objectives and KPIs and Risk Treatment Plans and Acceptance.
How to Run It
1. Place it in the annual cycle (2–3 months ahead)
The review does not stand alone. It must sit in the sequence internal audit → corrective actions raised → management review → next period's plan. Holding it before audit results exist strips out a principal input.
| Timing | Activity |
|---|---|
| 3 months before year end | Internal audit |
| 2 months before | Corrective actions raised; KPI actuals compiled |
| 1 month before | Management review |
| Start of new period | Objectives, KPIs and treatment plan fixed |
| During the year | Surveillance audit (per the certification body's schedule) |
See Running an Internal Audit and Preparing for Surveillance Audits.
2. Build the input pack (2 weeks ahead)
Keep each item to one page or less, and put the secretariat's reading on every page in a line or two. No page is numbers alone.
| Weak | Strong |
|---|---|
| Internal audit: 3 nonconformities, 5 observations | Internal audit: 3 nonconformities. Two are missing supplier-review records; the cause is that review scheduling depends on individuals. Remediation requires systematising reviews (≈10 person-days) |
| Training completion 98% | Training completion 98% (target 100%). The two outstanding are on extended leave. A decision is needed on adding a return-to-work training rule |
| 5 incidents | 5 incidents (prior period 7). Four were misdirected email, all in one department. A pre-send confirmation control should be considered |
3. Put the motions first (1 week ahead)
Open the pack with "decisions requested today" — three to five items, circulated in advance, each with the secretariat's proposal, the resources required, and the risk of not deciding.
For example:
- Approve next year's security budget of ¥X (proposal: approve; covers systematised supplier review and company-wide MFA)
- Include the new SaaS offering in ISMS scope (proposal: include; customer hospitals require it)
- Accept residual risk regarding supplier A's sub-processor (proposal: accept, conditional on an annual on-site check)
4. Hold the meeting
Take motions first, reports second. That prevents decisions being deferred when time runs out.
Top management — the representative director or equivalent decision-maker — must attend. A record showing only delegates is a structure auditors probe. Where attendance is genuinely impossible, retain evidence of approval of the decisions (signature, electronic approval, an explicit email).
5. Write the minutes
The level of detail is the most practical question here; the next section covers it.
6. Convert decisions into plans (within 2 weeks)
Turn each decision into a task with an owner, a deadline and a completion criterion. Without this, the next review cannot report on "status of actions from previous reviews." Items that belong in corrective action go onto the form in Writing a Corrective Action Report.
The right level of detail in the minutes
The test is whether a third party reading later — an auditor, a new staff member, a customer's audit team — can reconstruct what was discussed and what was decided.
| Element | How to write it |
|---|---|
| Date, place, attendees | State roles. Make top management's attendance explicit |
| Inputs | Headings following the 9.3 items, with what was reported under each |
| Substance of discussion | Who raised which point and how it was considered, including dissent |
| Decisions | What was decided: approved / rejected / approved with conditions / deferred |
| Reasons | Why. A decision not to act always needs a reason |
| Owner and deadline | For each decision |
| Next meeting | When, and what it will cover |
Avoid:
- "No comments" as the only record of discussion
- "Approved" without identifying what was approved
- Attaching the deck instead of recording decisions in the body
- Ending on "to be considered" with no owner or date
The record of a decision not to act matters most. Declining an improvement proposal, accepting a residual risk, deferring a control to next year — all are legitimate management decisions, but without a stated reason they are indistinguishable from not having noticed. After an incident, that difference is large.
One caution: do not write detailed vulnerability or attack specifics into the minutes. Minutes are often requested in customer audits. Keep the detail in a separate controlled document and reference it.
Where It Goes Wrong
Is once a year enough?
The standard requires review "at planned intervals" — it does not prescribe annually. Annual works when the business and its risk profile are stable. In any of the following, annual leaves decisions too late:
| Situation | Recommended approach |
|---|---|
| New service launch or large migration | Hold an extraordinary review at the change-planning stage |
| A major incident | Extraordinary review afterwards (approve remediation, allocate resources) |
| M&A, new sites, significant reorganisation | Extraordinary review to decide the scope change |
| Revised laws or guidelines | Extraordinary review with the impact assessment |
| Fast-growing organisation | Make it twice yearly |
The most workable pattern is one full annual review plus lighter quarterly ones. The full review covers all 9.3 inputs; the quarterly covers three things — progress on prior decisions, KPI actuals, new risks. If you do this, state both in the procedure. Calling a partial review a management review while omitting required inputs invites a finding.
Internal audit and review held on the same day
There is then no time to digest the findings, and no root-cause analysis to base resource decisions on. Leave at least two weeks, preferably a month.
The secretariat writes the pack, writes the minutes and makes the decisions
Auditors see through this. Minutes containing no remark from any business unit, with every decision matching the secretariat's proposal, put top management's involvement in question. Deliberately record executives' questions and instructions.
Prior decisions are never tracked
The first required input is the status of previous decisions, yet that section is routinely blank. Maintain a one-sheet decision register and open every meeting with it.
A missed KPI passes without explanation
"Target 100%, actual 85%" with no cause and no action means Clause 9 monitoring is not feeding Clause 10 improvement. Make every missed objective a motion: cause, and whether the target stands or the plan changes.
No approval record on the minutes
Minutes signed only by their author are weak evidence. The form does not matter — electronic approval, circulation record, email — but the fact of approval must be traceable.
Healthcare Examples
A healthcare SaaS provider
The distinctive agenda item is change in what customer hospitals require. Guideline revisions and tighter hospital procurement specifications convert directly into cost. Feeding these from the sales team as "changes in interested parties' expectations" links the review to revenue discussion. See The Governance Volume: What Management Is Responsible For and Three-Ministry Guidelines.
The second is access to production patient data. How often engineers read live data during incident handling, and whether request and approval records are complete. Track it monthly in log review and bring only trends and exceptions to the review.
A PHR operator
Consent capture and withdrawal versus actual data use becomes an agenda item. Has a new feature pushed data use beyond the existing consent scope? This is precisely where business and security judgement overlap. See ISMS for PHR Operators.
A clinical trial systems company
Bring audit-trail integrity metrics as a standing item: log gaps, clock-sync drift, restore-test results. These are integrity and availability concerns that confidentiality-centric KPIs miss.
A SaMD developer
Whether to hold the ISMS review and the QMS (ISO 13485) review as one meeting or two is a real question. Either is acceptable, but a combined meeting's minutes must make clear that every 9.3 input was covered. Blending the agendas invites "we cannot confirm that item was discussed" in both audits. See SaMD, ISMS and ISO 13485.
A small organisation
Where management and secretariat overlap in person, you get "I report to myself and approve it." Even then, separate the roles explicitly in the minutes — report and decision as distinct entries — and the evidence holds. See ISMS for Small Organisations.
Conclusion
- The review is not a briefing; it decides resources, scope, policy and risk acceptance
- Inputs need gap to target, prior-period comparison and the secretariat's reading — never bare numbers
- Minutes must carry substance of discussion, the decision, and the reason — above all for decisions not to act
- The standard does not say annual. Twice a year, or annual plus quarterly light reviews, suits fast-changing organisations
- Leave two weeks to a month between internal audit and the review
- Convert decisions into owned, dated, testable tasks and open the next review with them
Improvement decisions feed Clause 10: Improvement and are tracked on the form in Writing a Corrective Action Report. Scope changes return to Defining ISMS Scope; structural changes, to Clause 5: Leadership.
Pottech supports ISMS certification and operation with a focus on healthcare. Agenda design and minute templates for the management review are where first-year operation stumbles, and auditors always look. See ISMS Certification Support or contact us.
References and Sources
- Information Management System Accreditation Center (ISMS-AC)
- ISO/IEC 27001 Information security management systems | ISO
- Japanese Industrial Standards Committee (JISC)
- Guidelines for the Safe Management of Medical Information Systems | MHLW
- Personal Information Protection Commission, Japan
Note: interpretation of requirements and the handling of accreditation and certification are governed by the standard itself and by the publications of the accreditation and certification bodies, and may change with revisions.