Under ISO/IEC 27001:2022, how do internal audit and management review show continual improvement, and what does a certification auditor expect to see?
answer
- the check in plan-do-check-act
- planned programme, impartial auditors
- top management reviews inputs
- decisions and changes as outputs
- findings closed by corrective action
basics
~20 sInternal audit checks at planned intervals, by objective auditors, that the ISMS conforms and works; management review has top management weigh performance, audit results, risks and changes and decide improvements. Auditors expect programmes, records, decisions and closed corrective actions.
solid answer
~50 sBoth are Performance evaluation requirements of ISO/IEC 27001:2022. **Internal audit** needs a planned audit programme covering the ISMS over time, defined criteria and scope for each audit, auditors chosen for objectivity and impartiality (they do not audit their own work), and results reported to management. **Management review** is held by top management at planned intervals. Its inputs include the status of earlier actions, changes in internal and external issues and in interested parties' needs, performance feedback (nonconformities, measurement results, audit results, objectives), risk assessment results and treatment status, and improvement opportunities. Its outputs are decisions on improvements and changes to the ISMS. Continual improvement shows up as a chain: audit finding, corrective action with root cause, verified closure, and management review decisions that change the ISMS. A certification auditor looks for that chain in the records, not for a clean audit report.
go deeper
Recall that internal audit and management review sit in Performance evaluation, and that auditors must be impartial and management review is held by top management.
Explain the management review inputs and outputs and how a correction differs from a corrective action.
Show how you would build an audit programme and review cadence that produce the finding-to-improvement evidence chain a certification auditor follows.
Discuss how to make management review a real decision forum that integrates with existing executive governance rather than a compliance ritual.
## Why these two matter most to a certification auditor A certificate asserts that the ISMS **evaluates and corrects itself**. Internal audit and management review are the two mechanisms in the Performance evaluation clause that make that true, and the Improvement clause turns their outputs into action. If they are missing or hollow, the auditor has no basis to trust the ISMS between visits. ## Internal audit ISO/IEC 27001 requires internal audits at **planned intervals** to establish whether the ISMS conforms to the organization's own requirements and to the standard, and whether it is effectively implemented and maintained. - **Audit programme** — frequency, methods, responsibilities and reporting, taking account of the importance of processes and results of previous audits. Over a cycle, the whole ISMS is covered. - **Criteria and scope** defined for each audit. - **Objectivity and impartiality** — auditors must not audit their own work. A small company often uses a competent external contractor or cross-team auditors. - **Reporting** — results go to relevant management, and **documented information** is kept as evidence of the programme and results. ## Management review Top management reviews the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. | Inputs | Outputs | |---|---| | Status of actions from previous reviews | Decisions on continual improvement opportunities | | Changes in external and internal issues | Any needed changes to the ISMS | | Changes in interested parties' needs and expectations | (Resources, objectives and scope follow from these decisions) | | Feedback on performance: nonconformities and corrective actions, monitoring and measurement results, audit results, fulfilment of objectives | | | Feedback from interested parties | | | Risk assessment results and status of the risk treatment plan | | | Opportunities for continual improvement | | The review must be attended by people with authority to decide; a slide deck circulated by email to executives who never discuss it is weak evidence. ## How continual improvement is demonstrated The Improvement clause requires the organization to react to nonconformities, evaluate the need to eliminate their **causes**, implement actions, review their effectiveness, and continually improve the ISMS. The auditor follows the chain: 1. The internal audit finds that access reviews for production were skipped for two quarters. 2. A **nonconformity** is raised; the owner corrects it by running the reviews. 3. **Root cause** analysis finds no reminder or owner after a reorganisation. 4. **Corrective action**: named owner, automated reminder, review added to a quarterly calendar. 5. **Effectiveness check** next quarter confirms reviews ran. 6. **Management review** sees the finding, approves a change to how control ownership is reassigned in reorganisations. ## What a certification auditor expects at a 250-person SaaS company - A written audit programme and at least one completed internal audit before stage 2. - Internal audit reports with real findings; an internal audit with zero findings for a first-year ISMS invites scepticism. - Management review minutes showing each input was covered, who attended and what was decided. - Corrective actions with root causes and verification, not just "fixed". - Evidence that review decisions changed something: objectives, resources, scope or controls. ## Weak patterns - The ISMS owner auditing the processes they run. - Management review held once, just before the certification audit, then forgotten. - Corrective actions that treat the symptom (re-run the review) and never the cause. - Findings closed without any check that the action worked.
- Can the security team that runs the ISMS also perform its internal audit?Only for parts it does not operate. ISO/IEC 27001 requires auditors selected so the audit is objective and impartial, which in practice means nobody audits their own work. Small organizations often use a competent external contractor, or have people from another team audit the security team's processes, while security staff audit processes owned elsewhere.
- What is the difference between a correction and a corrective action?A correction fixes the specific instance: run the missed access review, remove the stale account. A corrective action removes the cause so it does not recur: assign ownership, automate the reminder, change the process. ISO/IEC 27001's Improvement clause asks for both where needed, plus a review of whether the corrective action was effective.
saying these in an interview costs you the question
- A clean internal audit with zero findings is the best evidence for certification.
- The ISMS owner can audit the processes they run.
- Management review is a report the security team sends to executives.
- Once a nonconformity is fixed, root cause analysis is optional.
- Internal audit must cover the entire ISMS every single year.