Strategy & Ambition
Legal & Compliance
IT Infrastructure X-Ray
Risk & Opportunities
Improvements
Policies & Procedures
Measures & Controls
Operations
Leadership & Management
Compliance
Progress Overview
Audit View
Logging and Monitoring Information
External Audit ISO 27001
MS365 Integration Supporting Documentation
Management Review

Several compliance frameworks require Management Review as part of their governance and continuous improvement processes. These reviews ensure that senior leadership evaluates the effectiveness of policies, controls, and risk management strategies to maintain compliance and drive organizational improvements.
Key Frameworks That Require Management Review:
- ISO 27001 and ISO 27701: Requires periodic management reviews to assess the effectiveness of the ISMS, including audit results, security incidents, and risk management updates.
- NIST 2: Encourages organizations to conduct management reviews to evaluate cybersecurity posture, risk mitigation, and ongoing compliance efforts.
- SOC 2: Management must review security, availability, confidentiality, processing integrity, and privacy controls as part of the compliance cycle.
- GDPR (General Data Protection Regulation): While not explicitly requiring formal management reviews, GDPR mandates that organizations continuously assess and document their compliance efforts, which often involves senior management oversight.
- ISO 9001: Requires top management to review quality objectives, audit findings, customer feedback, and process improvements regularly.
- ISO 13485: Requires a structured management review process to ensure compliance with medical device regulations and ongoing quality improvements.
- HIPAA (Health Insurance Portability and Accountability Act): While not explicitly requiring management review, HIPAA compliance involves ongoing executive oversight of risk assessments and security measures.
To run an effective management review process, it’s important to follow a structured approach to ensure thorough evaluation and continuous improvement. Below are the general steps to guide you through the management review process, followed by more detailed instructions on how to leverage the ‘Management Review Section’ to generate a report. These steps also include tips and the key topics to cover during the review.
General Process for Management Review:
Step 1 Schedule the Review: Conduct the management review at least annually, ideally 1-2 months before the external audit and preferably before the internal audit to ensure all findings are addressed.
Step 2: Assign a Responsible Person: Designate a lead reviewer who will oversee the process and generate the Management Review Report via the ‘Management Review Section.’
Step 3 Draft & Review Findings: Once the initial draft is prepared, identify suggested improvements based on findings, audit results, and compliance performance.
Step 4 Management Discussion: Schedule a Management Team and/or CEO meeting to review all key topics, findings, and proposed improvements.
Step 5 Approval & Finalization: The Managment reviews, approves, and finalizes the Management Review Report, ensuring it is ready to be presented as evidence during the external audit.
Step 6 Create Improvements: Ensure that all approved improvements are documented and added as new improvements in Compleye Online.
Getting Started with the Management Review:
We have developed an automated process to simplify the generation of the Management Review Report. Follow these steps to ensure a structured and effective review process.
Step 1: To begin, review the ‘Closed Improvements Section’. Within these improvements, you will find fields labeled ‘Management Review Topic’ and ‘Text for the Management Review’, as shown below. Use this information to form the core content of your management review concept.

Step 2: The creation of the management review report begins in the ‘Closed Improvement’ section. To start, click the “Management Review Report” button. A window will appear displaying all the closed improvements, which you can then use to build your report.

Step 3: Select the improvements you wish to include in your management review report. From the selected improvements, only the content entered in the evaluation field related to the management review will be pre-populated in the generated report.

Step 4: When you’re ready, select “Start the Management Review Report”. You will be redirected to the management review subsection. Please note that, from this point onward, you will no longer be able to add additional content from improvements to the draft you are creating. However, you can still attach relevant documents to the management review report.

Step 5: Enter the title, the person responsible for reviewing the management review report, and the date of creation of the report. The topics will be pre-filled from the selected improvements, but you can add or review the content as needed. Be sure to include suggestions for improvement on each topic and indicate when management accepts these suggested improvements.
There are two topics that must be filled in manually, as they are not part of the closed improvements card:
- Effectiveness of the entire ISMS
- Compliance Objectives for the upcoming year.

Step 6: Evaluate and document the effectiveness of the entire framework in the open text field of the section. Be sure to highlight any suggested improvements and specify when management accepts these suggested improvements. This evaluation will help in understanding the overall performance of the ISMS and guide future enhancements.
Step 7: Update the topic ‘Compliance Objectives’ for the upcoming year. Review last year’s objectives by clicking on the suggested link and determine whether those objectives have been met. Be sure to note any suggestions for improvement and incorporate them into this year’s objectives.
Step 8: After the management review meeting, where the content is reviewed, adjusted, and approved by the management team, you can finalize the report by clicking the ‘Finalize the Report’ button. Alternatively, you can save the report and continue working on it later.
Step 9: A preview of the management review report will be generated. You can either approve the report or save it for later. When the report is ready for approval, enter the name of the person approving the report in the pop-up window.
Step 10: Once the report is finalized and approved, it can be downloaded. Please note that after finalizing the report, attachments can no longer be deleted, but they can still be downloaded if needed.
Tips for Writing the Mandatory Topics in the Management Review:
Writing the mandatory topics for the management review can seem like a challenging task, but with a structured approach, it becomes easier and more manageable. Some helpful tips to guide you through the process:
Double-Check Improvement Evaluations: Make it a habit to double-check whether the evaluation of each closed improvement you want to add has included content specific to the management review. This will help ensure that the relevant information is properly captured.
Use Compleye Online for Additional Input: In addition to the closed improvements, make sure to check other sections of Compleye Online for input that could contribute to your management review. These additional insights will enrich the report and provide a more comprehensive review.
Key Topics to Include:
When preparing the management review, you need to cover several important topics to ensure a comprehensive evaluation. Below are the key topics to include in your management review.
Periodic Assessment Policy: Check whether you’ve updated any Policies & Procedures or created new documentation. Make sure to include any relevant changes or updates in this section.
Supplier Assessment Outcome: Review the ‘Supplier Assessment Section’ to determine if any new high-risk suppliers have been identified. Also, mention any significant changes related to suppliers, such as contract terminations, security incidents, service modifications, or SLA changes.
Status of Actions from Previous Management Reviews: Look at last year’s management review to confirm if all improvements were addressed and closed. If this is your first year, indicate ‘Not Applicable.’
Changes in External and Internal Topics: Evaluate whether there have been any changes within your organization, products, services, or stakeholders that could impact security and/or privacy. If you’ve entered new markets or countries, check the ‘Global Impact Section’ for relevant updates.
Feedback and Trends on Incidents: Analyze security metrics to see if any incidents have occurred or if you can identify trends in security, privacy, or quality incidents.
Feedback and Trends on Measures & Controls: Review the performance of your ‘Operational & Planning Control’. Were they carried out on time? Were there any modifications? Assess the results to identify areas for improvement.
Feedback and Trends on Audit Results (Internal/External): Examine the findings and improvements from internal and external audits. Are there recurring issues, or have you made significant progress?
Feedback on Threat Intelligence: Refer to several critical threats that were identified through key intelligence sources, including commercial threat feeds, government alerts, and internal monitoring systems. Highlight these risks, particularly those with high potential impact, so that C-level management understands and prioritizes mitigation actions to safeguard your organization’s infrastructure and reputation.
Feedback from Interested Parties: Include any relevant feedback received from stakeholders, as well changes to interested parties, including customers, employees, suppliers, and regulatory bodies. This feedback can cover various aspects such as the availability, integrity, and confidentiality of information, as well as overall satisfaction with security measures.
Feedback and Trends in Meeting Compliance Objectives: Review the ‘Compliance Objectives Section’. Have the objectives been monitored and achieved? If yes, explain how. If not, identify why they weren’t met and suggest adjustments, such as making them smarter or more measurable.
Feedback from Stakeholders: Stakeholders are not just customers, but also employees and other interested parties. Gather feedback regarding the availability, integrity, and transmission of information. If necessary, plan for customer satisfaction reviews or employee surveys.
Results of the Risk Assessment and Status of the Risk Treatment Plan: Ensure that all findings from the risk assessment have been addressed as improvements. This section should reflect any changes or progress made in treating identified risks.
Opportunities for Continuous Improvement: Look for improvements you’ve identified during the year, beyond audits and assessments. Reflect on leadership, communication, resources, and processes. You may uncover small but impactful improvements that have occurred throughout the year.
Effectiveness of the Framework: In this section, evaluate the overall effectiveness of your framework. Discuss contributions from previous improvements, such as enhanced documentation, training, awareness, or technical upgrades.
Compliance Objectives for the Next Year: Define the new Compliance Objectives for the upcoming year. These should align with your business’s overall strategy and the compliance goals you’ve set. Make sure these objectives are documented under the ‘Complicate Objectives Section’.
Finalizing the Report: After gathering input for all the topics and discussing them with your Compliance Team, it’s time for final approval. Someone from C-Level management should approve the document, ideally with a date and signature. Lastly, ensure that all new improvements accepted during the management review are transferred to new improvement cards. This is crucial for tracking progress and ensuring continuous improvement.
Acknowledging the Effort: Although it may feel like a lot of work – and yes, it is – this process showcases how your organization’s efforts over the past year have contributed to a more mature and professional security posture. You can be proud of the progress you’ve made, and it may even serve as a selling point when engaging with potential clients or stakeholders.

