Skip to content

Governance

Management review: which decisions leadership really has to make

The management review is not a status presentation. It is meant to decide on changes, performance, resources and improvements.

Back to ISO 27001

7 minute read · Content as of 21.07.2026

Inputs must be condensed so decisions can be made

Leadership does not need a list of every ticket. It needs deviations from the objectives, significant risk changes, trends, audit and incident patterns, and open resource decisions.

Outputs are decisions with an owner and a date

A documented acknowledgement is not enough when action is needed. Record decisions on improvements, changes to the ISMS and resources in a binding way.

  • What has changed in the context or scope?
  • Which objectives are being missed, and why?
  • Which risks exceed the acceptance criteria?
  • Which decisions does the team need now?

A good agenda reduces preparation effort

The free agenda starter separates mandatory inputs, management questions and decisions. That turns the meeting into a steering body instead of a round of presentations.

Sources used

  • ISO/IEC 27001:2022 · ISO · 2022 + Amd 1:2024
  • ISO/IEC 27004 · ISO · 2016
  • ISMS practice patterns · KaitoSec

Back to ISO 27001