# Management review procedure

Source: https://aestech.com.au/policy-templates/#management-review-procedure
Markdown URL: https://aestech.com.au/policy-templates/management-review-procedure.md

Runs the clause 9.3 management review, with a standing agenda, required inputs, outputs and action tracking.

Frameworks: ISO 27001

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This procedure defines how [Company Pty Ltd] top management reviews the ISMS at planned intervals, per ISO/IEC 27001:2022 clause 9.3, to confirm it remains suitable, adequate and effective, and to decide on changes and resources.

2. Scope
Covers the full ISMS scope. Applies to [CEO, CTO, ISMS Manager, and heads of relevant functions].

3. Cadence and attendance
3.1 Reviews are held at least [twice per year / quarterly], and additionally after a major incident, significant organisational change, or an adverse audit result.
3.2 Quorum requires [the CEO or delegate] plus the [ISMS Manager]. The [ISMS Manager] chairs and prepares the input pack, circulated at least [5] business days before the meeting.

4. Required inputs
The input pack must address every clause 9.3.2 item: status of actions from previous reviews; changes in external and internal issues relevant to the ISMS; changes in interested party needs and expectations; feedback on security performance including nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of security objectives; feedback from interested parties; risk assessment results and risk treatment plan status; and opportunities for continual improvement.

5. Standing agenda
1. Actions from the previous review: status and overdue items
2. Changes to internal and external issues, and to interested party requirements
3. Security objectives: performance against metrics and targets
4. Internal and external audit results
5. Nonconformities, corrective actions and their effectiveness
6. Incidents, near misses and lessons learned since last review
7. Risk assessment update and risk treatment plan progress
8. Risk acceptance decisions requiring management sign-off
9. Supplier and third party security performance
10. Resources: budget, staffing, training needs
11. Opportunities for continual improvement
12. Decisions, new actions, owners and due dates

6. Outputs
Recorded decisions must cover: continual improvement opportunities adopted, any needed changes to the ISMS (scope, policy, objectives, risk criteria), and resource decisions. Each action gets an owner and a due date.

7. Minutes and action tracking
7.1 The [ISMS Manager] issues minutes within [5] business days, capturing attendees, inputs considered, decisions and actions.
7.2 Actions are logged in the [action register / ticketing system] and tracked to closure; overdue actions open the next review.

8. Roles and responsibilities
[Top management]: attends, decides, allocates resources. [ISMS Manager]: schedules, prepares inputs, chairs, records, chases actions. Function heads: supply input data for their areas.

9. Records
Retain input packs, minutes and action logs for at least [3] years in [location]; these are primary evidence for clause 9.3 at certification audits.

10. Review
Review this procedure annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date].
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md