GuideGlobalISO/IEC 27001

ISO/IEC 27001 Internal Audit and Management Review

Internal audit objectively tests conformity and effective implementation; management review is top management's review of the ISMS's continuing suitability, adequacy, and effectiveness.

The same meeting does not automatically satisfy both requirements. Preserve auditor objectivity, required review inputs, decisions, actions, owners, and follow-up evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

and management review are different but connected parts of the ISO/IEC 27001 ISMS. An internal audit is a planned, objective check that the ISMS conforms to the organization's own requirements and to ISO/IEC 27001, and that it is effectively implemented and maintained. A management review is a planned top-management review of the ISMS to confirm its continuing suitability, adequacy, and effectiveness. Internal audits feed management review with findings, trends, corrective actions, and improvement needs.

Section 1

How are internal audit and management review different?

is the organization's objective and impartial check that the ISMS conforms to its own requirements and ISO/IEC 27001 and is effectively implemented and maintained. Management review is top management's planned evaluation of whether the ISMS remains suitable, adequate, and effective.

The audit produces evidence and results. Management review considers audit results alongside the other Clause 9.3 inputs, then records decisions about continual-improvement opportunities and any needed ISMS changes.

Neither activity substitutes for the other. A management meeting cannot replace an programme, and an audit report does not show that top management made the decisions required by Clause 9.3.

  • : define criteria and scope for each audit, select objective and impartial auditors, report results to relevant management, and retain programme and result evidence.
  • Management review: include top management, cover the required inputs, record the required decisions, and retain evidence of the results.
  • Connection: send audit results, corrective-action status, risk changes, and objective performance into management review without treating the review as the audit itself.
Section 2

Which audit and review records demonstrate the cycle?

For , retain the programme's frequency, methods, responsibilities, planning, and reporting, plus each audit's criteria, scope, auditor assignment, evidence sampled, results, and report to relevant management. When establishing the programme, consider process importance and previous audit results.

For management review, retain evidence of the results, including decisions about continual-improvement opportunities and any needed ISMS changes. Tracking actions, owners, and dates is a practical way to support the required review of prior-action status at the next meeting.

  • Audit record: objective, criteria, scope, auditor, date, method, samples, result, finding, and report recipient.
  • Review record: participants from top management, required inputs, decisions, actions, owner, deadline, and prior-action status.
  • Traceability record: finding to nonconformity, cause evaluation, correction, corrective action, effectiveness review, and management visibility.
  • Independence record: why the selected auditor can perform the work objectively and impartially.
Section 3

How should findings become management decisions and actions?

Report internal-audit results to relevant management. Determine whether each result shows a nonconformity that triggers Clause 10.2, a risk or improvement input, or an unresolved evidence question. The classification should follow the audit criteria and objective evidence.

For a nonconformity, react and correct it, address consequences, evaluate causes and whether similar issues exist, implement needed action, and review effectiveness. Management review should see trends, recurring failures, overdue actions, resource constraints, and changes that require leadership decisions.

  • Record the requirement, objective evidence, affected scope, owner, correction, cause, corrective action, due date, and effectiveness method.
  • Look for similar nonconformities elsewhere rather than closing only the sampled instance.
  • Escalate systemic or resource-dependent actions to top management with a concrete decision request.
Section 4

Which independence and governance mistakes weaken the process?

The audit process must be objective and impartial. ISO/IEC 27001 does not prescribe a job title, department, or organizational chart for internal auditors. When an auditor helped design or operate the work under review, document safeguards or choose another auditor so the assignment still meets the objectivity and impartiality requirement.

Management review fails when top management is absent, required inputs are summarized without evidence, or the output is only 'continue as planned.' The retained record should show actual leadership decisions and any needed ISMS changes.

  • Do not let control owners close their own audit findings without independent verification where objectivity would be impaired.
  • Do not combine and management review into one undocumented conversation that satisfies neither clause.
  • Do not replace corrective action with a policy rewrite when the cause or operating failure remains unresolved.
Section 5

How should the audit programme and review cadence evolve?

At each programme update, consider process importance and previous audit results, preserve objectivity in auditor selection, and adjust frequency or scope when changed risks, processes, or recurring findings warrant it. The standard requires audits at planned intervals but does not prescribe an annual cycle.

Management review also runs at planned intervals, with no universal annual frequency. Track its decisions about improvement and needed ISMS changes to owners and closure evidence; record resource, objective, scope, or risk-treatment changes when top management decides they are needed.

  • Set a review date and a change-trigger rule.
  • Track findings until closure and connect them to corrective actions or risk acceptance.
  • Use management review to decide needed ISMS changes and improvement actions, including resources, scope, risk criteria, or evidence controls where relevant.
Primary sources

References and citations

iso.org
Referenced sections
  • Clauses 9.2 and 9.3 require planned internal audits and management reviews but do not prescribe a universal annual frequency.
"Information security management systems — Requirements"
iso.org
Referenced sections
  • This source supports control implementation guidance and control-implementation expectations supporting ISO/IEC 27001 governance.
"Information security controls"
iso.org
Referenced sections
  • This source supports risk treatment and monitoring context that informs control decisions and residual risk handling.
"Guidance on managing information security risks"
Related guides

Explore more topics

ISO/IEC 27001 Annex A Control Evidence Guide
Build useful ISO/IEC 27001:2022 Annex A control evidence: selected controls, SoA rationale, owners, implementation proof, effectiveness checks, audit records, and improvement actions.
ISO/IEC 27001 Annex A Control Ownership FAQ
How to assign practical owners for ISO/IEC 27001 Annex A controls without confusing control ownership with the standard's required risk-owner accountability.
ISO/IEC 27001 Audit Readiness Guide
Prepare ISO/IEC 27001 audit evidence across ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, internal audit, management review, and corrective actions.
ISO/IEC 27001 Certification Body Evidence FAQ
What ISO/IEC 27001 certification auditors may sample, how to connect requirements to operating evidence, and what the certification body does not own.
ISO/IEC 27001 Certification Stage Workflow
Plan optional ISO/IEC 27001 certification from scope readiness through Stage 1, Stage 2, findings, certification decision, surveillance, and recertification.
ISO/IEC 27001 Compliance Guide: ISMS Evidence
Build ISO/IEC 27001:2022 conformity evidence for ISMS scope, leadership, risk assessment and treatment, the Statement of Applicability, operations, audits, management review, and corrective action.
ISO/IEC 27001 FAQ: ISMS Scope, Risk and SoA
Practical ISO/IEC 27001 FAQ covering ISMS scope, risk assessment, risk treatment, Statement of Applicability, Annex A controls, certification evidence, audits, management review, and surveillance readiness.
ISO/IEC 27001 Implementation Roadmap Guide
A practical ISO/IEC 27001:2022 roadmap from context and scope through risk treatment, the SoA, control operation, internal audit, management review, corrective action, and optional certification.
ISO/IEC 27001 Internal Audit FAQ
How should teams run ISO/IEC 27001 internal audits: who should own each step, what evidence is expected, and how findings are resolved.
ISO/IEC 27001 Management Review FAQ
What ISO/IEC 27001 management review must consider, what top management must decide, what evidence to retain, and how to set the cadence.
ISO/IEC 27001 Requirements Guide
Plain-language guide to ISO/IEC 27001:2022 Clauses 4-10: context, leadership, planning, support, operation, performance evaluation, improvement, and Annex A control selection.
ISO/IEC 27001 Risk Acceptance FAQ
How ISO/IEC 27001 risk acceptance works: criteria, risk-owner approval, residual-risk evidence, external obligations, and reassessment triggers.
ISO/IEC 27001 Risk Treatment and Residual Risk Guide
Connect ISO/IEC 27001 risk-treatment choices, necessary controls, the treatment plan, Statement of Applicability, residual-risk acceptance, owners, evidence, and review triggers.
ISO/IEC 27001 Risk Treatment Register Workflow
Build an ISO/IEC 27001 risk-treatment register that links assessed risks to treatment options, controls, SoA entries, actions, owners, residual-risk approval, evidence, and review triggers.
ISO/IEC 27001 SoA Exclusions FAQ
How should teams justify Statement of Applicability exclusions under ISO/IEC 27001? Practical answer with owners, evidence, review triggers, and external source references.
ISO/IEC 27001 SoA: workflow for gathering and documenting control evidence
Operate the ISO/IEC 27001 Statement of Applicability as a live evidence index linking necessary controls, Annex A inclusion and exclusion rationale, implementation status, owners, and proof.
ISO/IEC 27001 Statement of Applicability template: Annex A control selection and justification
Practical ISO/IEC 27001:2022 Statement of Applicability template fields for necessary controls, Annex A applicability, inclusion and exclusion rationale, status, owners, evidence, and review history.
ISO/IEC 27001 Surveillance Audits FAQ
What ISO/IEC 27001 surveillance audits check, how they differ from internal audit and recertification, and what evidence to maintain between audits.
ISO/IEC 27001 vs NIS2 Comparison
Compare voluntary ISO/IEC 27001 ISMS conformity and optional certification with NIS2 legal duties, entity scope, management accountability, incident reporting, supervision, and penalties.
ISO/IEC 27001 vs NIST CSF 2.0 Comparison
Compare ISO/IEC 27001:2022's certifiable ISMS requirements with NIST CSF 2.0's cybersecurity outcomes, Profiles, Tiers, Functions, evidence uses, and adoption choices.
ISO/IEC 27001 vs SOC 2 Comparison
Compare ISO/IEC 27001 certification with SOC 2 examination reports: criteria, scope, assurance period, auditor and certification-body roles, deliverables, evidence reuse, and claim limits.