Management review under ISO 9001: what clause 9.3 requires, and why it need not be a meeting
In most organizations the management review has a fixed slot. November, two hours, forty slides, minutes filed away and produced for the auditor in spring. The effort is considerable, the insight modest, and internally the whole thing is understood as an obligation owed to the certificate.
Which is odd, because ISO 9001 never asks for a meeting. What it asks for is something else — and harder.
The review is not a meeting
Start with the point that separates the standard from almost every description of it.
ISO/TC 176 maintains, jointly with the International Accreditation Forum, a working group of standards specialists and auditors called the ISO 9001 Auditing Practices Group. It publishes freely available papers on how individual requirements of ISO 9001 should be looked at in an audit. Its paper on policy, objectives and management review puts it without hedging: the review could be carried out at a separate meeting, but this is not a requirement of the standard. It then names alternatives explicitly — top management receiving and reviewing a report generated by the management representative or other personnel, electronic communication, or handling the review as part of regular management meetings where budgets and targets are discussed anyway [2].
The same paper goes further. An overall management review, it says, is a complex process carried out at various levels in the organization, and it will always be a two-way process: generated by top management, with inputs from all levels. Those activities can range from daily, weekly or monthly unit meetings down to simple discussions or reports [2].
One qualification, because it matters for how much weight to give this. The APG papers are not requirements. Each carries an explicit disclaimer that it has not been through an endorsement process at ISO, ISO/TC 176 or IAF, and that the content is provided for educational and communication purposes [2]. What they are is the reading of the people who write and audit the standard for a living — considerably closer to the source than any consultancy page.
The practical consequence is not permission to do less. It is permission to stop staging. An organization that already reviews its quality performance in a monthly operations meeting, a quarterly board report and an annual planning cycle does not need to reconstruct all of that as a single event. It needs to make those activities evidenced.
What 9.3.1 actually asks
Clause 9.3.1 requires top management to review the quality management system at planned intervals, to ensure its continuing suitability, adequacy and effectiveness, and its alignment with the strategic direction of the organization [1].
That is four judgements, and they are not interchangeable:
- Suitability — does the system still fit what the organization does? After an acquisition, a new product line or a relocated site, that question stops being rhetorical.
- Adequacy — is it sufficient without being oversized? A system designed around 40 people and now carrying 300 tends to fail here first.
- Effectiveness — does it achieve the planned results? This is the only one of the four that cannot be answered without data.
- Alignment with strategic direction — does the system point where the business is going?
The practical value of separating them is that they give the review its structure. Walk through the inputs of 9.3.2 in order and you produce a report. Arrange the same material under the four judgements of 9.3.1 and you produce a review. The standard asks for the second.
On frequency, only this much, because it is covered in detail elsewhere: “at planned intervals” is not “annually”. The words annual and annually do not appear anywhere in ISO 9001:2015. The calendar habit is inherited from the certification side, where ISO/IEC 17021-1 requires a surveillance audit in each calendar year [4]. The evidence is set out in ISO 9001 explained.
The inputs of 9.3.2, read as a data requirement
Clause 9.3.2 lists what has to feed the review [1]. The list is interesting because it splits cleanly into items that can be answered from memory and items that presuppose a maintained data set.
| Input under 9.3.2 | Where the answer comes from |
|---|---|
| a) Status of actions from previous management reviews | Your own action stock — needs tracking across review cycles |
| b) Changes in external and internal issues relevant to the quality management system | The context analysis under 4.1/4.2, maintained rather than written once |
| c) Information on the performance and effectiveness of the system, including trends in customer satisfaction and feedback from interested parties, the extent to which objectives have been met, process performance and conformity of products and services, nonconformities and corrective actions, monitoring and measurement results, audit results, and the performance of external providers | Seven separate data sources — by far the heaviest item on the list |
| d) Adequacy of resources | A judgement rather than a measurement, but it rests on the results from c) |
| e) Effectiveness of actions taken to address risks and opportunities | Presupposes that those actions were tracked as such and then evaluated |
| f) Opportunities for improvement | An output of the analysis, not an input to it |
Item c) is where ambition and reality part company. The standard does not ask for numbers there; it asks for trends. A trend is a comparison over time, and a comparison over time requires the same quantity to have been captured on the same basis across several periods. An organization that rewords its question catalogue every year, or categorises findings freely, can report figures but cannot report trends. Where that is decided — at capture, not at reporting — is the subject of from audit to management review.
Three misconceptions about the inputs
They do not have to be worked through point by point. The APG guidance states that ISO 9001 specifies a number of inputs and that these topics need to be addressed, but that it is also acceptable not to address them individually or simultaneously, and instead as part of an overall review of the business [2]. The familiar “a) through f)” slide structure is therefore one option, not an instruction — and often the weaker one, because it invites recitation instead of judgement.
The list is not exhaustive. The same paper is explicit that these are not the only subjects that can be included in a review [2]. An imminent system migration, the loss of a major customer or a regulatory change belongs in the review whether or not 9.3.2 names it.
The inputs need no common format. The guidance notes that auditors should be aware that inputs may come in many forms — reports, trend charts and so on [2]. A tidy KPI table is not itself a mark of quality.
What 9.3.3 requires as an output
Here the standard tightens. Clause 9.3.3 requires the outputs of the management review to include decisions and actions related to opportunities for improvement, any need for changes to the quality management system, and resource needs — and requires documented information to be retained as evidence of those results [1].
The APG guidance sets out what an auditor expects to see at this point: evidence of decisions regarding changes to the quality policy and objectives, plans and possible actions for improvement, changes of resources, revised business plans and budgets. It adds that outputs need not be confined to improvements or changes, and may include decisions on other significant matters, such as plans to introduce new products [2].
On format: documented information on management reviews is required, but its form is not specified. Minutes are the most common type; electronic records, statistical charts and presentations are acceptable too [2].
Assessment: the weak point is almost always here rather than in the inputs. A record that walks through the year’s figures and closes with an acknowledgement satisfies 9.3.2 and misses 9.3.3 entirely. The quickest test before an audit is to ask whether at least one decision per output category can be named from the document, with an owner and a date. If not, the output side is missing.
The item that most often has no evidence behind it
One input in the list is routinely unsupported: the effectiveness of actions taken to address risks and opportunities [1].
The APG guidance is unusually direct about it. Organizations, it says, need to be able to demonstrate that they have evaluated the effectiveness of actions taken to address risks and opportunities during management review — and consequently auditors will be able to obtain objective evidence on the use of this approach [2].
The reason the evidence goes missing is structural. Risks and opportunities are determined once under clause 6.1 and usually kept in a register of their own. The actions arising from them migrate into projects, capital spend or process changes and lose the link back to their origin along the way. A year later the register has been updated, but nobody can say whether last year’s action actually reduced the risk. Evaluating effectiveness requires the action to have stayed attached to the risk, with a criterion agreed when the action was decided rather than hunted for when it was closed. The same pattern governs corrective actions, covered in detail in audit findings and the effectiveness record.
The forthcoming edition looks set to raise the stakes: on what national standards bodies have published about the non-public FDIS, ISO 9001:2026 separates actions to address risks from actions to address opportunities into distinct clauses. What that means for question catalogues and clause mapping is set out in the changes in ISO 9001:2026.
What changes with ISO 9001:2026
ISO/TC 176/SC 2 announced on 7 August 2026 that ISO/FDIS 9001 had been approved with overwhelming international support, and that the sixth edition is scheduled for publication on 16 September 2026 [3]. The announcement says nothing about a transition period, and no competent body has published one to date.
Assessment on clause 9: on the strength of what national standards bodies have published about the non-public FDIS, the core performance-evaluation requirements survive the revision, with the emphasis shifting towards genuine use of data for trends and improvement. For management review that means no structural change, but a harder look at whether the inputs came out of a maintained data set or were assembled the week before. Every clause reference here will be checked against the published text once it appears; the overview sits on the ISO 9001:2026 standard page.
What a tool has to do here
The seven data sources behind 9.3.2 c) are the real cost of a management review — not the reviewing. Assemble them by hand before each cycle, out of audit reports, action lists, complaint data and supplier scorecards, and what gets reviewed is a snapshot nobody can reproduce.
qportal works at the end where that data originates: audit programmes, question catalogues, findings and actions are held as one connected record with clause references and a status history, so audit results, nonconformities and corrective actions can be analysed without reconstruction. The audit side is described on the audit management page and action tracking on the actions and CAPA page.
Roadmap note: a dedicated evaluation layer — indicators and management review as a maintained process rather than an annual assembly job — is on the roadmap and is not shipped. The order is deliberate, and it is the point of this article: the data behind a management review is created during audits and in the processes that follow them. Capture it loosely there and no amount of reporting will recover it later.
Conclusion
Management review is the most laborious obligation in many quality calendars, and it is the requirement about which the standard is least prescriptive. No meeting, no minutes format, no fixed sequence, no annual cadence.
What it does require is a judgement about suitability, adequacy, effectiveness and strategic alignment, supported by trends drawn from seven data sources, and decisions that follow from that judgement with owners attached.
If you change one thing, change this: structure the agenda around the four judgements in 9.3.1 rather than the input list in 9.3.2, and file the inputs underneath them as evidence. The effort stays the same and the output stops being a report.
Sources
- ISO 9001:2015, Quality management systems — Requirements. International Organization for Standardization, Geneva; consulted in the bilingual edition DIN EN ISO 9001:2015-11, Beuth Verlag, Berlin. (Clauses 4.1, 4.2, 6.1, 9.1, 9.2.2, 9.3.1, 9.3.2, 9.3.3, 10.2)
- ISO 9001 Auditing Practices Group: Guidance on: Policy, Objectives and Management Review. Edition 1, 2016-01-13, issued by ISO/TC 176 together with the International Accreditation Forum. The paper carries an explicit disclaimer that it has not been subject to an endorsement process by ISO, ISO/TC 176 or IAF. https://committee.iso.org/home/tc176/iso-9001-auditing-practices-group.html (accessed 2026-09-02)
- ISO/TC 176/SC 2: ISO 9001 revision update. Announcement of 2026-08-07 on the approval of ISO/FDIS 9001 and the publication date of the sixth edition on 2026-09-16. https://committee.iso.org/sites/tc176sc2/home/news/content-left-area/news-and-updates/news-1.html (accessed 2026-09-02)
- ISO/IEC 17021-1:2015, Conformity assessment — Requirements for bodies providing audit and certification of management systems — Part 1: Requirements. Edition 1, 2015-06, ISO/CASCO. Consulted on the surveillance rhythm in certification. https://www.iso.org/obp/ui/en/#!iso:std:iso-iec:17021:-1:ed-1:v1:en (accessed 2026-09-02)
The International Accreditation Forum, joint publisher of the APG papers with ISO/TC 176, ceased operations on 2026-01-01 and was folded together with ILAC into Global ACI. The papers remain available through ISO/TC 176.
Consultancy, certification-body and content-marketing pages are not cited. Normative text is copyrighted; requirements are paraphrased here with a clause reference. Where this text goes beyond the sourced evidence, it is marked as an assessment.
Frequently asked questions
- Does ISO 9001 require management review to be a meeting?
- No. The ISO 9001 Auditing Practices Group — the joint working group of ISO/TC 176 and the International Accreditation Forum — states that the review could be carried out at a separate meeting but that this is not a requirement of the standard. It lists as equally valid routes top management receiving and reviewing a report prepared by others, electronic communication, or coverage as part of regular management meetings.
- How often must management review be carried out?
- As often as the organization has planned and can justify. ISO 9001:2015 says 'at planned intervals' in 9.3.1, and the words annual and annually appear nowhere in the standard. The common yearly rhythm comes from the certification side, where ISO/IEC 17021-1 requires a surveillance audit in each calendar year, not from ISO 9001 itself.
- Do all the inputs in 9.3.2 have to be addressed one by one?
- No. The topics have to be addressed, but the APG guidance makes clear it is acceptable not to address them individually or simultaneously, and instead to cover them as part of an overall review of the business. The list is also not exhaustive — other subjects may be brought into the review.
- What documented information does ISO 9001 require for management review?
- Clause 9.3.3 requires retained documented information as evidence of the results of management review. No format is specified. Minutes are the most common form, but electronic records, statistical charts and presentations are equally acceptable, provided the decisions and actions taken are visible in them.
- What is the most common weakness in a management review?
- Assessment from practice: not the missing review but the missing decision. Clause 9.3.3 requires decisions and actions relating to improvement opportunities, any need for change to the quality management system, and resource needs. A record that recites the year's figures and ends in acknowledgement satisfies the input side and fails the output side.