ISO Compliance Governance Risk Management Draft

ISO 27001 Clause 9: Performance Evaluation — Monitoring, Internal Audit, and Management Review

Maciej
ISO 27001 Clause 9: Performance Evaluation — Monitoring, Internal Audit, and Management Review
TL;DR

Clause 9 of ISO 27001:2022 closes the ISMS feedback loop in three parts. 9.1 requires you to decide what to monitor and measure, with methods producing comparable and reproducible results, defined owners and timing, and to evaluate security performance and ISMS effectiveness — retaining the results as evidence. 9.2 requires an internal audit programme: audits at planned intervals checking the ISMS conforms both to ISO 27001 and to your own requirements, with defined criteria and scope per audit, auditors who are objective and impartial (they can't audit their own work), and results reported to relevant management. 9.3 requires management review at planned intervals with explicitly listed inputs — including status of previous actions, changes in context and interested parties (the latter added in 2022), performance trends, audit results, risk assessment status — and outputs recording decisions on improvement and ISMS changes. The certification reality: skipped or last-minute internal audits and thin management review minutes are among the most common ISO 27001 findings anywhere in the standard, and both are fully preventable with a calendar and an agenda.

Everything before Clause 9 builds and runs the ISMS. Clause 9 asks the uncomfortable question: is it working? — and requires you to answer with measurements, an internal audit, and your executives' recorded judgment, not with confidence. It's also, in certification practice, one of the most finding-dense clauses in the entire standard, for a mundane reason: its three mechanisms are exactly the ones startups postpone until the month before the audit. Part six of our clauses 4–10 series (hub, Clause 8 previous).

9.1 — Monitoring, measurement, analysis and evaluation

What it requires: determine what needs to be monitored and measured (including security processes and controls), the methods — which must produce comparable and reproducible results to be considered valid — when monitoring happens, who does it, when the results are analyzed, and who analyzes them. Then evaluate the information security performance and the effectiveness of the ISMS, and keep the results as documented information.

The trap here is measuring what's easy instead of what's informative. Uptime and phishing-simulation click rates are fine, but the standard wants measurements that tell you whether the ISMS is effective — which usually means tying metrics to your Clause 6.2 objectives and to your riskiest controls. Practical startup-scale examples: percentage of access reviews completed on schedule, median time to revoke access after offboarding, vulnerability remediation times against your own SLA, incident detection-to-response intervals, policy acknowledgment coverage. Five to ten metrics with named owners and a defined cadence beat a dashboard of thirty that nobody reads. (This is the same discipline as year-round SOC 2 monitoring — one operational habit feeding both frameworks.)

Evidence in practice: the metric definitions (what, how, who, when — a table satisfies it), and the recorded results with signs of analysis: a trend noted, a threshold breached and acted on. Metrics collected but never evaluated fail the clause's second half.

9.2 — Internal audit

What it requires: conduct internal audits at planned intervals to check the ISMS conforms to both ISO 27001's requirements and your organization's own requirements, and is effectively implemented and maintained. That double target matters: auditing yourself against your own policies is where most real findings come from. The programme requirements: plan an audit programme (frequency, methods, responsibilities, planning requirements, reporting) that considers the importance of the processes and results of previous audits; define criteria and scope for each audit; select auditors ensuring objectivity and impartiality; report results to relevant management; and keep documented information of the programme and results.

Three practical implications for small companies:

  • Impartiality without headcount. Nobody may audit their own work. In a 20-person company that usually means the audit is split (an ops person audits engineering controls and vice versa), or you bring in an external contractor to run the internal audit — fully permitted and common. What fails is the ISMS owner auditing the ISMS they built.
  • Risk-weighted, not uniform. "Considers the importance of the processes" is permission to audit your critical areas annually and lighter areas on rotation — documented as a multi-year programme rather than a single heroic audit-everything event.
  • It must precede certification. The certification body expects at least one full internal audit cycle (plus a management review) completed before stage 2. Discovering this five weeks out is a rite of passage we'd rather you skip.

We've published a step-by-step ISO 27001 internal audit guide covering planning, execution, and reporting in detail — consider it the companion piece to this section.

9.3 — Management review

What it requires: top management shall review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. The standard prescribes the inputs: status of actions from previous reviews; changes in external and internal issues relevant to the ISMS; changes in needs and expectations of interested parties (an input added explicitly in the 2022 revision); feedback on security performance — trends in nonconformities and corrective actions, monitoring and measurement results, audit results, fulfilment of security objectives; feedback from interested parties; results of risk assessment and status of the risk treatment plan; and opportunities for continual improvement. The outputs must record decisions on continual improvement and any needed ISMS changes — kept as documented information.

Treat that input list as your literal agenda: walking through it takes 60–90 minutes once or twice a year and produces exactly the minutes the auditor wants. Notice how the inputs summon the rest of the standard into the room — Clause 4's context changes, Clause 6's risks and objectives, 9.1's metrics, 9.2's audit results, Clause 10's corrective actions. That's the design: management review is where the whole loop closes in front of the people who own it — which is why executive attendance here is also the visible proof of Clause 5 leadership.

Evidence in practice: minutes that map to the required inputs, with decisions and assigned actions — not "reviewed ISMS, all good." Thin minutes are the most common 9.3 finding; the fix costs one honest agenda template.

Common Clause 9 nonconformities

  • The eve-of-audit internal audit — one rushed audit days before certification, no programme, no consideration of previous results.
  • Self-audit — the person who built the control auditing the control; impartiality fails regardless of good faith.
  • Metrics without evaluation — data collected, never analyzed, no evidence anyone drew a conclusion.
  • Management review without management — or minutes so generic they'd fit any company in any year, missing required inputs like interested-party changes.
  • Actions that evaporate — review outputs assigned to nobody, with "status of previous actions" showing the same items unresolved review after review.

Ready to Streamline Your Compliance?

Discover how AuditBadger can simplify your compliance management process.

The bottom line

Clause 9 is a calendar problem disguised as a compliance problem: put the metrics review, the internal audit programme, and two management reviews on the calendar now, and the clause largely takes care of itself. Skip them until audit season and you'll manufacture in one panicked month what the standard wanted spread over twelve. Next and last in the series: Clause 10, Improvement — nonconformities and corrective action, the clause startups most often fake and auditors most easily catch.

FAQ

Frequently asked questions

Can we do our own ISO 27001 internal audit? +

Yes — internal audits can be performed by your own staff, but Clause 9.2 requires auditor selection to ensure objectivity and impartiality, which means nobody may audit their own work. In a small company that's usually solved one of two ways: split the audit so people cross-audit areas they don't operate (an ops person audits engineering controls and vice versa), or hire an external contractor to perform the internal audit on your behalf — fully permitted, common, and often cheaper than it sounds. What fails is the ISMS owner auditing the ISMS they built. Auditors also check the internal auditor's competence specifically, so document the basis (training, experience, or the contractor's credentials) against a defined requirement.

What inputs are required for an ISO 27001 management review? +

Clause 9.3.2 prescribes the list, which works as a literal agenda: status of actions from previous management reviews; changes in external and internal issues relevant to the ISMS; changes in needs and expectations of interested parties (an input added explicitly in the 2022 revision); feedback on information security performance — including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of security objectives; feedback from interested parties; results of risk assessment and status of the risk treatment plan; and opportunities for continual improvement. The outputs (9.3.3) must record decisions on continual improvement and any needed ISMS changes, retained as documented information. Minutes that map to these inputs with assigned actions are exactly what the auditor wants; "reviewed ISMS, all good" is the most common 9.3 finding.

Do we need an internal audit before ISO 27001 certification? +

Yes. Certification bodies expect at least one full internal audit cycle and at least one management review to be completed before your stage 2 (certification) audit — stage 1 checks that these mechanisms exist and have run. This requirement sets the minimum realistic timeline to certification more often than any control does: however fast you implement Annex A, you still need time to plan an internal audit programme, execute the audit impartially, process its findings through corrective action, and hold a management review that considers the results. Discovering this five weeks before a booked stage 2 is a common and avoidable scramble — put the internal audit and management review on the calendar as soon as the certification date exists.

Keep reading

More implementation notes and operator context from the same topic area.

Next step

Ready to replace scattered compliance work?

See how AuditBadger turns policies, evidence, risks, and audit prep into one operating system for lean teams.

Start Subscription