Stratify
Legal and compliance

Management Review — Procedure & Record Template

docs/compliance/isms/governance/GOV-12-management-review.md

Source updated 03. Aug. 2026

Management Review — Procedure & Record Template

Satisfies ISO/IEC 27001:2022 clause 9.3. No management review has been held yet. This document defines the procedure and provides a fillable record template for when the first one happens — it does not report on a review that already occurred.

What "management review" means here

ISO 27001 describes management review as top management periodically evaluating the ISMS's continuing suitability, adequacy, and effectiveness. At most companies that means a board or leadership-team meeting with a formal agenda. At Stratify's current size, it plainly does not — the people who would be "top management" are Toby (ISMS Owner) and, for anything touching privacy or the regulatory workstream, Antonios (DPO / Privacy Owner). Philipp is not part of this, since he holds no ISMS role.

A realistic management review at this stage is a structured conversation between Toby and Antonios — working through the inputs below, making decisions, and writing them down — not a formal governance ritual. This document describes it that plainly on purpose, rather than dressing it up as something more elaborate than it is. As the team grows, the same procedure scales up naturally; nothing here needs to be rewritten to accommodate that, only attended by more people.

Inputs

Each review works through the following, pulling current numbers rather than relying on memory of the last review:

  1. Internal audit results — findings from the most recent GOV-11

cycle, if one has run. For the first review, likely "no audit has run yet" — itself a fact worth recording and acting on.

  1. Risk register changes — new, closed, or re-scored entries in register/risks.yaml since the

last review. As of 1 August 2026 there are 9 seeded risks (RISK-001 through RISK-009), 8 open and 1 accepted (RISK-007, single-host redundancy).

  1. Security objective progress — status of each objective in

GOV-08 against its stated target date.

  1. Nonconformities — open and closed entries in

GOV-13, and whether corrective actions are actually landing on schedule.

  1. Supplier / DPA review status — whether the sub-processor list (register/suppliers.yaml)

and the DPA tracking in docs/compliance/dsgvo-data-flow.md §10 are current. RISK-009 already flags that this review is overdue relative to the Hetzner cutover and SES migration.

  1. Prior-review action-item follow-up — for every review after the first, whether the action

items from the previous review's record were actually completed.

Outputs

A review should produce explicit decisions, not just a discussion record:

  • Resource needs — does anything on the objectives or risk list need time, money, or a hire

that isn't currently allocated (e.g. the ISO 27001/27002 text purchase noted in PLAN.md §6, or the €25k pentest budget already earmarked in pentest-rfp.md)?

  • Objective changes — should any GOV-08 objective be added, dropped, re-scoped, or re-dated?
  • Risk-treatment changes — should any register/risks.yaml entry move between accept /

mitigate / transfer / avoid, or get a new owner or review date?

Record template

Copy this section for each actual review meeting and fill it in.


Review date: Attendees: Period covered since last review:

InputReviewed?Summary / key finding
Internal audit results (GOV-11)
Risk register changes (risks.yaml)
Security objective progress (GOV-08)
Nonconformities (GOV-13)
Supplier / DPA review status
Prior action-item follow-up

Decisions

#DecisionRationale

Action items

#ActionOwnerDue dateStatus

Next review scheduled for:


Cadence

No fixed cadence has been exercised yet, since no review has been held. Recommendation: schedule the first review once the Tier 0 governance documents (GOV-01 through GOV-13) reach approved status — reviewing an ISMS built entirely of drafts mostly just produces "approve the drafts" as the output, which is a fine first review but not a meaningful evaluation of effectiveness. After that, annual is the default per register/schema.md's general review-cadence convention, with the option to hold one sooner if a significant event (a real incident, a completed pentest, a new hire) makes waiting a full year impractical.