Management Reviews provide governance oversight for your ECC compliance programme. The NCA expects organisations to demonstrate that senior leadership is actively involved in cybersecurity governance, not just the technical team.

Why Management Reviews Matter

ECC Domain 1 (Cybersecurity Governance) specifically requires management commitment and oversight. Documented management reviews serve as evidence that leadership:

  • Understands the organisation's cybersecurity posture
  • Reviews compliance progress and risk exposure
  • Approves resource allocation for remediation
  • Makes informed decisions about risk acceptance

Creating a Management Review

Schedule the review

Click "New Management Review". Set the review date, add attendees, and select the topics to cover. Best practice is to conduct management reviews at least quarterly.

Prepare the agenda

The review form includes pre-defined sections aligned with ECC governance requirements: compliance status, gap assessment results, audit findings, incident summary, risk register updates, and resource needs.

Document decisions

Record all decisions made during the review, including risk acceptance decisions, budget approvals, and policy change directives. Each decision can be assigned an action owner and follow-up date.

Capture action items

Add action items arising from the review. Each action item has an owner, priority, and due date. These items appear on the dashboard and generate reminders as due dates approach.

Review Content

SectionWhat to Cover
Compliance StatusCurrent ECC compliance score, changes since last review, domain-level trends
Gap AssessmentLatest gap assessment results, priority remediation items, progress on open gaps
Audit FindingsOpen audit findings, corrective action progress, overdue items
IncidentsCybersecurity incidents since last review, lessons learned, NCA notifications
Risk RegisterTop risks, changes in risk ratings, new risks identified
ResourcesBudget utilisation, staffing, tooling, and training needs
ℹ️
Management review records are stored in the audit trail and can be exported as PDF for NCA auditors. Include attendee names and roles to demonstrate appropriate governance participation.