Certification
What a management review is actually for
It is a mandatory clause, it is easy to fake, and auditors know exactly what a faked one looks like.
Facts checked — 2026-09-11
What must a management review contain?
The standard sets out what a management review considers: the status of previous actions, changes in internal and external issues, feedback on performance including nonconformities, audit results, the fulfilment of objectives, and opportunities for improvement. The outputs are decisions — about changes, resources and improvement.
The reviews that fail are the ones with no decisions in them. A record showing that leadership met, noted that everything was fine and resolved nothing is evidence that the system is not being governed. A short review that allocated budget, changed an objective or accepted a risk is evidence that it is.
The bottom line
Minute the decisions, not the attendance. A review with no decisions in it is a meeting, not a management review.
Related services
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
Related insights
Certification
The Statement of Applicability, and why an auditor opens it first
The document that shows whether your management system has reasoning behind it — and the one most organisations build backwards.
Certification
Stage 1 and Stage 2: what each audit tests, and why Stage 1 is not a rehearsal
One checks that you are ready to be audited. The other is the audit. Both feed the certification decision.
Certification
ISO 27001:2013 certificates have expired — including the ones with later dates on them
The window closed on 31 October 2025. A lapsed holder is treated as a new client — which is the part most summaries leave out.