The Management Reviews module supports the requirements of ISO 27001 Clause 9.3, which mandates that top management review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Management reviews are a critical governance mechanism that ensures senior leadership remains engaged with information security and makes informed decisions about the ISMS.

Creating a Management Review Record

Step 1: Schedule the Review

Click "Add Management Review" and enter the review title and planned review date. Assign the chair/reviewer and invite attendees.

Step 2: Prepare Input Items

Before the meeting, work through the required inputs checklist. Gather data, reports, and metrics for each input category. This preparation ensures the review meeting is productive and covers all required topics.

Step 3: Conduct the Review

During the meeting, discuss each input item and record decisions, action items, and resource needs. Use the Decisions and Actions textarea to capture key outcomes.

Step 4: Record Outputs

Document any decisions related to ISMS changes, resource needs, and improvement opportunities. Set the next review date.

Step 5: Upload Minutes

Attach the formal meeting minutes document for evidence and audit trail purposes.

Step 6: Track Action Items

Create action items arising from the review and track them to completion. These feed into the "status of actions from previous reviews" input for the next management review.

Form Fields Reference

FieldTypeRequiredDescription
Review TitleText inputRequiredA descriptive title for the management review. Example: "Q1 2026 ISMS Management Review", "Annual ISMS Strategic Review"
Review DateDate pickerRequiredThe date the management review meeting was held or is scheduled to be held
Chair / ReviewerText inputOptionalThe person chairing the review, typically the CISO, CIO, or a member of top management. Example: "Sarah Johnson, CISO"
AttendeesMulti-select / TextOptionalAll persons attending the management review. Should include top management representation and key ISMS stakeholders. Select from organisation users or type names.
Input ItemsChecklistOptionalA checklist of required inputs per Clause 9.3.2 (see detailed input items below). Mark each item as covered/not covered.
Decisions and ActionsTextareaOptionalRecord all decisions made and actions agreed during the review. Include who is responsible, what needs to be done, and by when.
Resource Needs IdentifiedTextareaOptionalAny resource requirements identified during the review (budget, personnel, tools, training). Clause 9.3.3 requires that outputs include decisions on resource needs.
Next Review DateDate pickerOptionalThe planned date for the next management review. ISO 27001 requires reviews at "planned intervals" (typically quarterly or semi-annually, minimum annually).
Minutes DocumentFile uploadOptionalUpload the formal meeting minutes as a PDF, Word document, or other format. This serves as documented evidence of the review for audit purposes.

Required Input Items (Clause 9.3.2)

ISO 27001 Clause 9.3.2 specifies mandatory inputs that must be considered during each management review. The module provides a checklist to ensure all items are covered:

Input ItemDescriptionWhere to Find Data in Venvera
Status of actions from previous management reviewsReview the action items from the last management review meeting. Report on which actions are completed, in progress, or overdue.Previous management review record → Action items
Changes in external and internal issuesConsider changes in the business environment, regulatory landscape, technology, threat landscape, organisational structure, or strategic direction that affect the ISMS.Risk assessments, regulatory updates, organisational change records
Information security performanceThis input has three sub-components that must all be covered:
   a) Nonconformities and corrective actionsSummary of NCs raised since the last review, their status, and effectiveness of corrective actions taken.Nonconformity Register → Dashboard and reports
   b) Audit resultsResults of internal and external audits conducted since the last review, including findings, trends, and areas of concern.Internal Audits module → Completed audits and findings
   c) Fulfilment of information security objectivesProgress towards achieving the defined information security objectives and KPIs.KPI dashboards, gap assessment scores, SoA progress
Feedback from interested partiesFeedback received from customers, partners, regulators, employees, or other stakeholders regarding information security.Customer complaints, supplier feedback, regulatory correspondence
Results of risk assessmentReview of the current risk profile, changes to risk levels, new risks identified, and risk treatment plan progress.Risk register, gap assessment results
Opportunities for improvementSuggestions for improving the ISMS, including process improvements, new controls, technology upgrades, or training enhancements.OFIs from audits, employee suggestions, industry best practices
⚠️
All seven input categories must be addressed in every management review. Certification auditors will check that management review minutes demonstrate coverage of all required inputs. Missing inputs are a common audit finding (Minor NC against Clause 9.3).

Action Item Tracking

Action items arising from the management review are tracked within the review record. Each action item includes:

  • Action description — what needs to be done
  • Responsible person — who is accountable
  • Due date — when it should be completed
  • Status — Not Started, In Progress, Completed
  • Completion notes — evidence of completion

Open action items from previous reviews automatically appear in the inputs for the next review, creating a continuous improvement loop.

💡
Schedule management reviews at consistent intervals (e.g., quarterly) and ensure top management attendance. If senior executives cannot attend, their delegate must have authority to make decisions on ISMS matters. Record attendees and their roles as evidence of management engagement.
ℹ️
Clause 9.3.3 requires the following outputs: decisions related to continual improvement opportunities, and any needs for changes to the ISMS. Ensure your Decisions and Actions section clearly captures both categories of output.