- Clauses 9.2 and 9.3 require planned internal audits and management reviews but do not prescribe a universal annual frequency.
"Information security management systems — Requirements"
Internal audit objectively tests conformity and effective implementation; management review is top management's review of the ISMS's continuing suitability, adequacy, and effectiveness.
The same meeting does not automatically satisfy both requirements. Preserve auditor objectivity, required review inputs, decisions, actions, owners, and follow-up evidence.
Structured answer sets in this page tree.
Cited legal and guidance references.
and management review are different but connected parts of the ISO/IEC 27001 ISMS. An internal audit is a planned, objective check that the ISMS conforms to the organization's own requirements and to ISO/IEC 27001, and that it is effectively implemented and maintained. A management review is a planned top-management review of the ISMS to confirm its continuing suitability, adequacy, and effectiveness. Internal audits feed management review with findings, trends, corrective actions, and improvement needs.
is the organization's objective and impartial check that the ISMS conforms to its own requirements and ISO/IEC 27001 and is effectively implemented and maintained. Management review is top management's planned evaluation of whether the ISMS remains suitable, adequate, and effective.
The audit produces evidence and results. Management review considers audit results alongside the other Clause 9.3 inputs, then records decisions about continual-improvement opportunities and any needed ISMS changes.
Neither activity substitutes for the other. A management meeting cannot replace an programme, and an audit report does not show that top management made the decisions required by Clause 9.3.
Track audit scope, samples, results, corrective actions, management-review inputs, decisions, owners, and follow-up evidence.
Create assigned audit tasks, evidence requests, management decisions, and follow-up checkpoints.
Review your current scope, evidence gaps, and next implementation steps.
For , retain the programme's frequency, methods, responsibilities, planning, and reporting, plus each audit's criteria, scope, auditor assignment, evidence sampled, results, and report to relevant management. When establishing the programme, consider process importance and previous audit results.
For management review, retain evidence of the results, including decisions about continual-improvement opportunities and any needed ISMS changes. Tracking actions, owners, and dates is a practical way to support the required review of prior-action status at the next meeting.
Report internal-audit results to relevant management. Determine whether each result shows a nonconformity that triggers Clause 10.2, a risk or improvement input, or an unresolved evidence question. The classification should follow the audit criteria and objective evidence.
For a nonconformity, react and correct it, address consequences, evaluate causes and whether similar issues exist, implement needed action, and review effectiveness. Management review should see trends, recurring failures, overdue actions, resource constraints, and changes that require leadership decisions.
The audit process must be objective and impartial. ISO/IEC 27001 does not prescribe a job title, department, or organizational chart for internal auditors. When an auditor helped design or operate the work under review, document safeguards or choose another auditor so the assignment still meets the objectivity and impartiality requirement.
Management review fails when top management is absent, required inputs are summarized without evidence, or the output is only 'continue as planned.' The retained record should show actual leadership decisions and any needed ISMS changes.
At each programme update, consider process importance and previous audit results, preserve objectivity in auditor selection, and adjust frequency or scope when changed risks, processes, or recurring findings warrant it. The standard requires audits at planned intervals but does not prescribe an annual cycle.
Management review also runs at planned intervals, with no universal annual frequency. Track its decisions about improvement and needed ISMS changes to owners and closure evidence; record resource, objective, scope, or risk-treatment changes when top management decides they are needed.
"Information security management systems — Requirements"
"Information security controls"
"Guidance on managing information security risks"