A management review is the meeting where senior leadership examines how the security system is performing and decides what changes to make. It is the point at which information from audits, incidents, risks, and metrics turns into decisions with owners and budgets attached.
The standard requires a management review at planned intervals, and it specifies both what must be considered and what must come out of it. That structure is often treated as paperwork. Handled properly, a management review is the only forum where security competes for resources on the same terms as everything else the business is deciding.
Most organisations run this meeting badly for one reason - they treat it as a status update. Slides get presented, everyone nods, and the minutes record attendance rather than decisions. That version passes nothing and changes nothing. This page covers the inputs, the outputs, the agenda, and how the review connects to the rest of your information security management system.
What a Management Review Is For
Three purposes, in order of importance.
It tests whether the system is still suitable for the business as it exists now, not as it existed at implementation. Scope changes, new products, new markets, and new infrastructure all quietly outdate a system that was correct two years ago.
It confirms whether the system is effective - are objectives being met, are risks reducing, are incidents falling or at least being handled faster?
And it allocates resources. Findings without funding stay open. The review is where the trade-off between security work and other priorities gets made explicitly.
Who Should Attend
Top management must be present. A review chaired by the security manager with no executive in the room fails the requirement and, more importantly, cannot make resource decisions.
A workable attendee list includes the executive sponsor, the security or ISMS manager, IT leadership, HR, and the owner of any area with open findings. Clear roles and responsibilities make attendance obvious rather than negotiable.
Keep the room small enough that people speak. A review with twenty attendees becomes a presentation.
Management Review Inputs

Performance and Compliance Data
- Status of actions from the previous review
- Changes in external and internal issues relevant to security
- Security objectives and progress against them
- Nonconformities and corrective action status
- Monitoring and measurement results
- Audit results, both internal and external
- Feedback from interested parties, including customers and regulators
Audit results should come as trends, not a list. Three findings in access control over two years says something a single report does not, which is why ISMS audits outputs are more useful when aggregated.
Risk and Incident Information
- Results of risk assessment and status of the risk treatment plan
- Significant incidents and their causes
- Third-party and supplier performance
- Continuity and recovery test outcomes
- Opportunities for improvement
Incidents belong here in summary form. What leadership needs is the pattern - repeat causes, detection times, and whether the same control keeps failing. Linking each item back to the risk treatment plan keeps the discussion anchored to decisions already made.
Management Review Outputs
The output of the review is not minutes. It is a set of decisions. Every review should produce at least:
- Decisions on opportunities for continual improvement
- Decisions on any changes needed to the system
- Decisions on resource needs, with approval or explicit rejection
Each decision needs a named owner and a due date. A decision without both is a comment.
One habit separates strong reviews from weak ones: recording rejections. If leadership decides not to fund something, write that down with the reasoning. It closes the item honestly, shows risk was accepted at the right level, and stops the same request reappearing every quarter with no resolution.
A Practical Agenda That Fits Ninety Minutes
Long reviews lose the room. This sequence works because it front-loads accountability.

Previous actions (10 minutes). Closed, open, and overdue. Nothing else until this is done.
Objectives and metrics (15 minutes). Progress against targets, with variance explained.
Risk and incidents (20 minutes). Trends, repeat causes, and treatment plan status.
Audit and compliance (15 minutes). Findings by theme, plus any changes in legal or contractual obligations.
Change and context (10 minutes). New systems, markets, suppliers, or scope changes.
Decisions and resources (20 minutes). The part most agendas run out of time for. Protect it.
Send the data pack three working days ahead. Reviews collapse when the first thirty minutes are spent reading.
Getting the Frequency Right
Once a year satisfies the wording but rarely serves the business. Annual reviews mean a decision needed in February waits until November.
A pattern that works well: one full review annually, with shorter quarterly sessions covering actions, incidents, and risk changes only. The quarterly cadence keeps decisions moving and makes the annual review shorter, because most items are already resolved.
Trigger an additional review after any significant event - a major incident, a failed audit, an acquisition, or a substantial infrastructure change. Waiting for the calendar in those situations is how findings become repeat findings.
Common Failures in Management Reviews
Across compliance work, four patterns recur.
The review becomes a presentation, with no decisions recorded. Data arrives raw rather than as trends, so leadership cannot see what changed. Actions from the previous review are not tracked, which makes the whole cycle decorative. And the minutes summarise discussion instead of recording who decided what by when.
There is a fifth, quieter failure worth naming. Reviews often report only what looks good. If every metric in the pack is green, the pack is filtered, not the system healthy. A review that never surfaces bad news is not doing its job, and experienced auditors notice.
What Auditors Look for in the Records
Auditors rarely question whether the meeting happened. They test whether it functioned.
Expect them to ask for the minutes, then check three things: were all required inputs considered, are decisions recorded with owners and dates, and were the previous review's actions actually completed. A trail of overdue actions carried forward across three reviews is a finding in itself.
Keeping the record properly is a document control problem as much as a governance one, and the practices in this guide to document control apply directly - version history, approval, and retrievability all matter when the minutes are the evidence.
Managing Management Reviews in Effivity
Effivity's information security management software assembles the review pack from live data rather than from someone's spreadsheet. Audit findings, incident summaries, risk status, objective progress, and training completion feed straight into the review record.
Decisions are captured as tracked actions with owners and due dates, carried into the next review automatically so overdue items surface without anyone chasing. Minutes are version-controlled and timestamped, which makes them straightforward evidence during an external audit.
If you want to see how your own review pack would look assembled from live records, Get a Free Personalized Demo with your current objectives and open findings.
Frequently Asked Questions
It is a meeting where top management examines system performance and makes decisions about changes and resources. Its outputs are decisions, not just minutes.
At least annually, though quarterly short sessions work better for keeping decisions moving. Major incidents or scope changes should trigger an extra review.
Top management is required, along with the security manager, IT leadership, and owners of areas with open findings. Without executive presence, resource decisions cannot be made.
Previous actions, objectives, audit results, nonconformities, monitoring data, risk and incident status, and feedback from interested parties. Changes in context are also required.
Decisions on improvement opportunities, system changes, and resource needs. Each should carry a named owner and a due date.
Discussion and inputs can be circulated in writing, but decisions still need to be made and recorded by top management. Auditors will look for evidence of genuine consideration.