SGRII Insights  ·  ISO 27001:2022  ·  2026

Your Management Review Is a Presentation. ISO 27001 Clause 9 Requires It to Be a System Decision Mechanism. These Are Not the Same Thing.

Year-two surveillance audits expose what certification accepted: ISMS programmes generating metrics without analysis, running audits without operational testing, and conducting management reviews without governance decisions. Clause 9 is not three compliance activities — it is one connected performance system.

S

SGRII Performance & Digital Solutions

ISMS Practice  ·  April 2026  ·  12 min read

S

SGRII Pillar Lens

Systems

A systems perspective on Clause 9 recognises that monitoring, audit, and management review are not three independent compliance activities. They are three components of a single performance system: measurement produces data, audit interrogates that data against the standard, and management review uses both to make decisions about the system’s future direction. When these three operate independently — monitoring generating metrics nobody analyses, audit producing findings nobody escalates, management review reviewing summaries nobody challenges — the performance system has components but no function. The ISMS is generating noise, not signal.

Year-two surveillance audits are the graveyard of ISMS credibility. What certification revealed as a compliant system is now tested against a different question: has this system demonstrated genuine improvement since certification? Is it producing the outcomes it was designed to produce? Does the performance evaluation system generate insight that the organisation acts on?

The answer, with a frequency that should concern every ISMS manager approaching a first surveillance audit, is: no. The monitoring system reports activity. The internal audit programme reviews documents. The management review receives summaries. And nothing demonstrably changes.

What Clause 9 Actually Requires

Clause 9.1 requires the organisation to determine what needs to be monitored and measured (including information security processes and controls), the methods for monitoring, measurement, analysis, and evaluation that will produce valid results, when monitoring and measurement should be performed, who should perform them, when results should be analysed and evaluated, and who should analyse and evaluate those results. The documented information that evidences monitoring must be retained.

Clause 9.2 requires internal audits at planned intervals to determine whether the ISMS conforms to the organisation’s own requirements and the standard’s requirements, and is effectively implemented and maintained. Internal auditors must be selected to ensure objectivity and impartiality. The audit programme, results, and findings must be retained as documented information. Clause 9.3 requires management review of the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. The review must consider a mandatory set of inputs and produce outputs including decisions on improvement opportunities and resource needs.

Three clauses. Three interconnected components of a performance system. Each generates outputs that feed the others. Clause 9.1 monitoring outputs are inputs to Clause 9.3 management review. Clause 9.2 audit findings are inputs to Clause 9.3 management review. Clause 9.3 decisions are inputs to Clause 10 improvement and Clause 6 planning. The standard has designed a learning cycle. Most implementations have produced three separate compliance activities.

A management review that summarises data without producing decisions is not a management review — it is a management briefing. The standard requires outputs, not attendees. Resource allocation decisions, scope changes, objective revisions, improvement actions with owners — these are what Clause 9.3 requires the meeting to produce.

The Measurement Failure: Activity Metrics Instead of Effectiveness Metrics

Clause 9.1 measurement programmes in most ISMS implementations track: training completion rate, audit finding count, incident count, vulnerability count, and policy review completion. These are activity metrics. They measure what happened, not whether it worked. They are the information security equivalent of measuring the number of prescriptions written rather than whether patients recovered.

Effectiveness metrics are different. An effectiveness metric for access control asks: what percentage of privileged access reviews identified an inappropriate access grant, and how long did remediation take? An effectiveness metric for vulnerability management asks: what is the mean time to remediation for critical vulnerabilities, and is it trending towards or away from the defined SLA? An effectiveness metric for awareness training asks: what is the phishing simulation click rate, and did it change after the last awareness campaign?

These metrics require data that most ISMS programmes do not collect in a structured way. They require that controls produce measurable outputs, not just that controls are in place. And they require that measurement results are analysed — not just reported. The difference between reporting a metric and analysing it is the difference between monitoring and performance evaluation. Clause 9.1 requires the latter.

What a Connected Clause 9 Performance System Looks Like

1

Clause 9.1 effectiveness metrics defined for each significant control category: access management, vulnerability management, incident response, awareness, change control — measuring outcomes, not activities

2

Measurement results analysed on a defined cycle and presented with trend analysis — not just current values, but directional performance data showing whether the ISMS is improving

3

Clause 9.2 internal audit programme covering the full ISMS scope over the audit cycle — all clauses, all significant Annex A control areas — with competent, independent auditors and findings linked to corrective action

4

Clause 9.3 management review structured around mandatory inputs producing mandatory governance outputs: decisions on resources, scope, objectives, and improvement priorities — documented with owners and timelines

5

Management review outputs explicitly feeding Clause 10 (improvement actions) and Clause 6 (updated risk assessment or objectives) — creating the evidential chain between performance evaluation and system change

THE SGRII ISO 27001:2022 ISMS FRAMEWORK

The SGRII ISMS Framework addresses Clause 9 as a connected performance system: measurement produces data, audit interrogates that data, management review converts it into governance decisions. Each mechanism feeds the next.

Includes: ISMS Effectiveness Measurement Framework (outcome metrics, not activity metrics), Internal Audit Programme (all clauses + all 4 Annex A themes), Management Review Decision Record (mandatory governance outputs with traceability to Clause 10).

GET THE ISMS FRAMEWORK — FROM $149 ›

The Internal Audit Credibility Problem

Clause 9.2 requires that internal auditors be selected to ensure objectivity and impartiality. In practice, ISMS internal audits are frequently conducted by the ISMS Manager auditing their own system, or by IT team members auditing processes they are operationally responsible for. This is not impartiality. It is a structural conflict that most certification bodies accept because the only visible alternative — external audit resources — costs money.

The deeper issue is audit scope. Most ISMS internal audit programmes audit the clause structure: Clause 4 reviewed, Clause 5 reviewed, Clause 6 reviewed. Annex A controls are either sampled superficially or omitted. The result is an internal audit programme that confirms the documentation exists and the procedures are written, without ever testing whether the controls are operating. An internal audit that does not test operational effectiveness is a document review with a checklist. It is not an audit.

What Auditors Actually Evaluate — ISO 19011 Perspective

Auditors will examine the internal audit programme for scope completeness. If Annex A controls have not been audited within the audit cycle, Clause 9.2 has not been fully satisfied. All ninety-three Annex A controls, or meaningful sampling across all four control themes, must be included in the internal audit scope.

Auditors will assess internal auditor competence records. Clause 9.2 and ISO 19011 both require auditor competence. A competence record consists of more than an ISO 27001 certificate — it requires demonstrated audit skills, ideally evidenced through ISO 19011 training or equivalent.

Auditors will examine the last two management review records and look for evidence of decisions. Summaries without decisions are a finding. Action items without owners and deadlines are a finding. A review whose outputs cannot be traced to subsequent changes in the ISMS is evidence that management review is a reporting event, not a governance mechanism.

Auditors will ask for the measurement framework and test whether metrics reflect effectiveness or activity. They will specifically ask: how does this metric tell you whether the control is working? An inability to answer is a Clause 9.1 finding.

Why Surveillance Audits Expose What Certification Concealed

Certification audits operate under commercial and time pressures that limit the depth of performance evaluation testing. A Stage 1 audit confirms documentation. A Stage 2 audit samples implementation evidence. The question of whether the performance evaluation system is genuinely functional — whether it is producing insight the organisation acts on — is the question that surveillance audits are designed to test.

At surveillance, the auditor can compare the current state against the certification baseline. They can ask: what has changed, what was the evidence that produced that change, and what does the management review record show? An ISMS that has not demonstrably improved, adapted, or evolved since certification — that is running the same metrics, the same audit programme, and producing the same management review outputs twelve months later — is an ISMS that has stopped. Clause 9 requires a performance system. What surveillance finds, too often, is a performance ritual.

The SGRII Position

The Systems pillar in the SGRII framework requires that performance evaluation operates as a connected system, not a collection of compliance activities. THE SGRII ISO 27001:2022 ISMS FRAMEWORK addresses Clause 9 with an integrated performance architecture. The ISMS Measurement Framework distinguishes effectiveness metrics from activity metrics for each principal control area, with data collection requirements, analysis responsibilities, and reporting cycles built in.

The Internal Audit Programme template covers all ISMS clauses and all four Annex A control themes across the audit cycle, with auditor independence and competence records as mandatory components. The Management Review Record is structured as a decision forum: mandatory inputs are listed with evidence fields, and mandatory outputs include governance decisions with owners, timelines, and traceability to subsequent ISMS actions. Every management review output is tagged to either Clause 10 (improvement) or Clause 6 (planning) — creating the evidential chain that connects performance evaluation to system change.

SGRII ISO 27001:2022 ISMS FRAMEWORK

Two tiers. One framework. Choose the depth your organisation needs.

Professional

$149

Modules 01–06  ·  Self-implementing SME

✓

ISMS Effectiveness Measurement Framework (outcome vs activity metrics)

✓

Internal Audit Programme (all clauses + all 4 Annex A control themes)

✓

Internal auditor competence records as mandatory programme component

✓

Management Review Decision Record (governance decisions required, not summaries)

✓

Output traceability tags linking review decisions to Clause 10 & Clause 6

GET PROFESSIONAL ›
MOST COMPLETE

Premium

$349

11 deliverables  ·  Compliance Manager & Consultant

✓

Everything in Professional (Modules 01–06)

✓

E3: ISMS Compliance Checklist — 22/22 clause requirements verified including Clause 9 measurement & review obligations

✓

E2: Risk & Opportunity Register — 10 KPI linkages pre-built for management review performance reporting

✓

E1: DI Register — 16/16 mandatory documented information items with Clause 9 evidence requirements mapped

✓

O7: Annex A Implementation Guide — monitoring & measurement controls (A.8.16) fully evidenced

GET PREMIUM ›

Both tiers include immediate download  ·  Lifetime access  ·  Designed for Stage 2 audit readiness

Join the Conversation

At your last surveillance audit, what question was most difficult to answer — and why? If it was a Clause 9 question about what the ISMS has improved since certification, what did that reveal about how the performance evaluation system was functioning?

ISMS Managers preparing for first surveillance, internal auditors who have assessed ISMS effectiveness, and certification auditors who have raised Clause 9 findings are particularly welcome. The SGRII team responds to every substantive contribution.

Build it, don’t just read about it

SGRII ISO/IEC 27001:2022 ISMS Framework

All 93 Annex A controls, Statement of Applicability, risk register and audit pack — built for certification readiness.

View the Framework → Get the newsletter

Coverage is not compliance. SGRII frameworks provide structured coverage, templates and guidance. They are designed for audit defensibility and structured for certification readiness; they do not certify you, do not guarantee a successful audit, and are not legal advice. The official ISO standard remains the only authoritative source of requirements.

Leave a Reply

Discover more from SGRII Performance & Digital Solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading