ISO 27001 · Step-by-step series · Article 6 of 7
ISO 27001 Clause 9: Performance Evaluation of the ISMS
Clause 9 of ISO 27001:2022 is where an information security management system (ISMS) proves it actually works. It is not enough to design controls and write policies — the standard requires you to systematically check whether the ISMS is achieving its intended outcomes, through monitoring and measurement, internal audits, and management review. This guide breaks down each subclause with practical guidance on how to build a performance evaluation programme that stands up to certification audits.
Internal audit and management review findings are consistently among the top sources of nonconformities in ISO 27001 certification audits
Certification bodies routinely report that organizations struggle most with demonstrating that internal audits are genuinely independent, that audit findings are tracked to closure, and that management review actually drives decisions rather than being a box-ticking meeting with no documented outputs.
Structure of clause 9: three complementary checks
Clause 9 is organized into three subclauses that operate at different levels and frequencies:
- 9.1 Monitoring, measurement, analysis and evaluation: the continuous, often automated layer — tracking whether controls are operating as intended and whether the ISMS is achieving its objectives.
- 9.2 Internal audit: a periodic, planned, independent examination of the ISMS against ISO 27001 requirements and the organization's own documented processes.
- 9.3 Management review: a periodic, top-management-led review that uses the outputs of 9.1 and 9.2 (plus other inputs) to decide whether the ISMS needs to change.
These three layers feed each other: monitoring data informs what internal audits should focus on, and both monitoring results and audit findings are mandatory inputs into management review. If any one layer is weak or missing, the whole performance evaluation chain breaks down — which is exactly what auditors look for.
9.1 Monitoring, measurement, analysis and evaluation: knowing if it's working
Clause 9.1 requires the organization to determine what needs to be monitored and measured, including information security processes and controls, the methods used, when monitoring and measuring will take place, who will do it, when results will be analyzed and evaluated, and who will analyze and evaluate them. The output must be retained as documented information as evidence of the results.
In practice, this means defining a set of ISMS metrics before you can claim compliance with 9.1. A well-built metrics programme typically covers:
- Control effectiveness metrics: percentage of critical patches applied within the defined SLA, number of privileged accounts reviewed on schedule, percentage of endpoints with active EDR coverage.
- Incident-related metrics: number of security incidents by severity, mean time to detect, mean time to contain, number of incidents caused by the same root cause recurring.
- Awareness and behavior metrics: phishing simulation click rates, percentage of staff completing mandatory security training, number of policy exceptions requested.
- Risk treatment metrics: percentage of Statement of Applicability controls implemented, number of overdue risk treatment actions, number of risks accepted above the defined risk appetite.
Practical tip
Do not confuse activity metrics with performance metrics. Counting "how many vulnerability scans we ran" tells an auditor nothing about whether the ISMS is effective. What matters is outcome-based evidence: how many critical vulnerabilities remained open past the remediation deadline, and what the trend looks like quarter over quarter. Auditors specifically probe whether metrics are tied back to the information security objectives defined under clause 6.2 — pick metrics that let you demonstrate that link directly.
9.2 Internal audit: the independent health check
Clause 9.2 is split into two subclauses covering the audit programme (9.2.1) and the execution requirements (9.2.2). Together they require the organization to conduct internal audits at planned intervals to provide information on whether the ISMS conforms to the organization's own requirements and to the requirements of ISO 27001, and whether it is effectively implemented and maintained.
The mandatory elements of an ISO 27001 internal audit programme are:
1. Planning the programme (9.2.1)
The audit programme must consider the importance of the processes concerned and the results of previous audits. In practice this means high-risk areas — access control, third-party supplier security, incident response — get audited more frequently than lower-risk administrative processes. A typical approach is a rolling 12-month audit plan that covers the full scope of the ISMS at least once per certification cycle, with critical Annex A control areas revisited annually.
2. Defining criteria and scope (9.2.2)
For each audit, the organization must define the audit criteria and scope. The criteria are typically the relevant ISO 27001 clauses, the applicable Annex A controls per the Statement of Applicability, and the organization's own internal policies and procedures. The scope defines which department, process, system or location is being examined in that particular audit cycle.
3. Selecting objective and impartial auditors (9.2.2)
This is the requirement most frequently flagged in audits. Clause 9.2.2 requires that auditors be selected and that audits be conducted in a manner that ensures objectivity and impartiality of the audit process — in practice, nobody audits their own work. A small IT team without independent staff can satisfy this by using a peer from another department trained as an internal auditor, rotating auditors between areas, or engaging an external internal-audit contractor. Without evidence of this independence check, certification bodies will raise a nonconformity even if the audit itself was thorough.
4. Reporting to relevant management and retaining evidence (9.2.2)
The results of each audit must be reported to relevant management, and documented information must be retained as evidence of the audit programme and the audit results. This means an audit report with findings, evidence sampled, nonconformities raised (if any), and observations, distributed to the process owners and top management — not just filed away.
9.3 Management review: closing the loop at the top
Clause 9.3 requires top management to review the organization's ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. This is split into three parts: general requirements (9.3.1), the mandatory inputs (9.3.2), and the mandatory outputs (9.3.3).
The inputs that management review must consider include:
- The status of actions from previous management reviews.
- Changes in external and internal issues relevant to the ISMS (linking back to clause 4.1).
- Changes in needs and expectations of interested parties relevant to the ISMS (clause 4.2).
- Feedback on the information security performance, including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfillment of information security objectives.
- Feedback from interested parties.
- Results of risk assessment and status of the risk treatment plan.
- Opportunities for continual improvement.
The mandatory outputs of management review must include decisions related to continual improvement opportunities and any need for changes to the ISMS. As with 9.1 and 9.2, documented information must be retained as evidence of the results.
A common weakness auditors identify is a management review meeting that produces minutes listing what was discussed, but no explicit decisions. To satisfy 9.3.3, the output has to be actionable: "approved additional budget for MFA rollout to legacy systems by Q4" is a valid output; "discussed MFA coverage gaps" is not.
Common audit errors in clause 9
Across ISO 27001 certification and surveillance audits, these are the recurring nonconformities and observations linked to clause 9:
- 9.1 — Metrics not linked to information security objectives: organizations track generic IT metrics (tickets closed, uptime) without connecting any of them back to the objectives set under clause 6.2.
- 9.1 — No defined analysis or evaluation step: data is collected but nobody is assigned to interpret it, and there is no record of when or how it was evaluated.
- 9.2 — Auditor independence not evidenced: the same person who manages IT operations conducts the internal audit of IT operations, with no documented justification of impartiality.
- 9.2 — Audit programme not risk-based: every area gets audited on the same fixed schedule regardless of criticality, with no rationale linking audit frequency to risk.
- 9.3 — Management review inputs incomplete: the meeting happens, but agenda items skip mandatory inputs like interested party feedback or risk treatment plan status.
- 9.3 — No traceable outputs: minutes describe discussion but contain no explicit decisions, owners, or deadlines that can be traced in the next review cycle.
| Subclause | Mandatory evidence | Typical frequency | Owner |
|---|---|---|---|
| 9.1 Monitoring & measurement | Documented metrics with method, timing, analysis and evaluation results | Monthly / quarterly dashboards | CISO / Security lead |
| 9.2.1 Audit programme | Risk-based multi-year audit plan covering full ISMS scope | Reviewed annually | ISMS manager |
| 9.2.2 Audit execution | Audit report with criteria, scope, findings, independence statement | Per planned audit (e.g. quarterly) | Internal auditor |
| 9.3 Management review | Minutes covering all mandatory inputs and explicit, actionable outputs | At least annually | Top management |
// Demo IgeraIndustria — ISMS performance evaluation query
ISMS Manager: Which internal audit actions from last quarter are still open?
IgeraIndustria: Internal audit IA-2026-Q2 (scope: Annex A.8 asset management, A.5.15 access control). 2 findings open. Finding IA-2026-Q2-01: privileged access review not evidenced for 3 of 12 sampled admin accounts, owner IT Operations, due 15/08/2026. Finding IA-2026-Q2-02: asset inventory missing 4 cloud storage instances identified during audit, owner Cloud Team, due 01/08/2026. Both findings scheduled for verification in follow-up review IA-2026-Q3.
Auditor: Show me the last management review outputs related to the risk treatment plan.
IgeraIndustria: Management review MR-2026-01, held 14/03/2026. Input reviewed: risk treatment plan status — 27 of 31 planned controls implemented, 4 overdue relating to third-party supplier security assessments. Decision recorded: approved extension of Q2 budget to complete supplier security assessments for 4 critical vendors, action owner Procurement & Security, deadline 30/06/2026. Status: closed, verified during IA-2026-Q3.
Frequently asked questions about ISO 27001 clause 9
How often does ISO 27001 require internal audits and management review?
ISO 27001 does not fix an exact frequency — it requires both to happen at "planned intervals" appropriate to the organization. In practice, most certified organizations run management review at least once a year (often aligned with the certification or surveillance audit cycle), and structure internal audits so that the full ISMS scope is covered at least once within each three-year certification cycle, with higher-risk areas audited more frequently, for example quarterly or semi-annually.
Can the same person who manages information security also perform the internal audit?
Not for the areas they are directly responsible for. Clause 9.2.2 requires objectivity and impartiality, which generally means auditors cannot audit their own work. A security manager can conduct internal audits of areas outside their direct operational responsibility, or organizations can rotate auditors across departments, train a peer from a different function, or bring in an external internal-audit resource for smaller teams without enough internal separation.
What documented evidence do auditors expect for clause 9.1 monitoring?
Auditors typically expect to see a defined list of what is monitored and measured, the method used for each metric, who is responsible for collection, the frequency, and — critically — evidence that results were actually analyzed and evaluated against defined criteria, not just collected. Dashboards or reports alone are insufficient if there is no record of who reviewed them and what conclusion was drawn.
What happens if an internal audit finds a nonconformity?
A nonconformity found during an internal audit is handled the same way as one found in an external audit: it feeds into clause 10.1 (nonconformity and corrective action). The organization must react to the nonconformity, evaluate the need for action to eliminate the root cause, implement any action needed, and review the effectiveness of the corrective action taken. This should be tracked to closure and verified, typically in the following internal audit cycle or at management review.
Does management review have to be a single meeting?
No. ISO 27001 does not require management review to be one formal meeting on one date. Some organizations spread it across several shorter sessions, or combine it with existing governance meetings, as long as all the mandatory inputs from 9.3.2 are addressed and the mandatory outputs from 9.3.3 are documented within the review period. What matters is that top management is genuinely involved and that the decisions are recorded, not the meeting format.
How does clause 9 relate to clause 6.2 information security objectives?
Clause 6.2 requires the organization to set measurable information security objectives. Clause 9.1 is where you demonstrate whether those objectives are actually being met, by defining metrics that map directly to them. Clause 9.3 then requires management review to explicitly consider "the extent to which information security objectives have been met" as one of its mandatory inputs. Without a clear link from objectives (6.2) to metrics (9.1) to review (9.3), auditors will flag the ISMS as having a disconnected performance evaluation loop.
Struggling to keep internal audit findings and management review actions from falling through the cracks?
IgeraIndustria centralizes ISMS metrics, internal audit programmes and management review records for clause 9 — with real-time status on every open finding, no spreadsheets required.
See the ISO 27001 solutionExpert ISO 27001 · Updated 2026-07-31 · ISO 27001 step-by-step series: Article 5 — Clause 8 · Article 7 — Clause 10