Management Review — Procedure & Record Template
Satisfies ISO/IEC 27001:2022 clause 9.3. No management review has been held yet. This document defines the procedure and provides a fillable record template for when the first one happens — it does not report on a review that already occurred.
What "management review" means here
ISO 27001 describes management review as top management periodically evaluating the ISMS's continuing suitability, adequacy, and effectiveness. At most companies that means a board or leadership-team meeting with a formal agenda. At Stratify's current size, it plainly does not — the people who would be "top management" are Toby (ISMS Owner) and, for anything touching privacy or the regulatory workstream, Antonios (DPO / Privacy Owner). Philipp is not part of this, since he holds no ISMS role.
A realistic management review at this stage is a structured conversation between Toby and Antonios — working through the inputs below, making decisions, and writing them down — not a formal governance ritual. This document describes it that plainly on purpose, rather than dressing it up as something more elaborate than it is. As the team grows, the same procedure scales up naturally; nothing here needs to be rewritten to accommodate that, only attended by more people.
Inputs
Each review works through the following, pulling current numbers rather than relying on memory of the last review:
- Internal audit results — findings from the most recent GOV-11
cycle, if one has run. For the first review, likely "no audit has run yet" — itself a fact worth recording and acting on.
- Risk register changes — new, closed, or re-scored entries in
register/risks.yamlsince the
last review. As of 1 August 2026 there are 9 seeded risks (RISK-001 through RISK-009), 8 open and 1 accepted (RISK-007, single-host redundancy).
- Security objective progress — status of each objective in
GOV-08 against its stated target date.
- Nonconformities — open and closed entries in
GOV-13, and whether corrective actions are actually landing on schedule.
- Supplier / DPA review status — whether the sub-processor list (
register/suppliers.yaml)
and the DPA tracking in docs/compliance/dsgvo-data-flow.md §10 are current. RISK-009 already flags that this review is overdue relative to the Hetzner cutover and SES migration.
- Prior-review action-item follow-up — for every review after the first, whether the action
items from the previous review's record were actually completed.
Outputs
A review should produce explicit decisions, not just a discussion record:
- Resource needs — does anything on the objectives or risk list need time, money, or a hire
that isn't currently allocated (e.g. the ISO 27001/27002 text purchase noted in PLAN.md §6, or the €25k pentest budget already earmarked in pentest-rfp.md)?
- Objective changes — should any GOV-08 objective be added, dropped, re-scoped, or re-dated?
- Risk-treatment changes — should any
register/risks.yamlentry move betweenaccept/
mitigate / transfer / avoid, or get a new owner or review date?
Record template
Copy this section for each actual review meeting and fill it in.
Review date: Attendees: Period covered since last review:
| Input | Reviewed? | Summary / key finding |
|---|---|---|
| Internal audit results (GOV-11) | ||
| Risk register changes (risks.yaml) | ||
| Security objective progress (GOV-08) | ||
| Nonconformities (GOV-13) | ||
| Supplier / DPA review status | ||
| Prior action-item follow-up |
Decisions
| # | Decision | Rationale |
|---|---|---|
Action items
| # | Action | Owner | Due date | Status |
|---|---|---|---|---|
Next review scheduled for:
Cadence
No fixed cadence has been exercised yet, since no review has been held. Recommendation: schedule the first review once the Tier 0 governance documents (GOV-01 through GOV-13) reach approved status — reviewing an ISMS built entirely of drafts mostly just produces "approve the drafts" as the output, which is a fine first review but not a meaningful evaluation of effectiveness. After that, annual is the default per register/schema.md's general review-cadence convention, with the option to hold one sooner if a significant event (a real incident, a completed pentest, a new hire) makes waiting a full year impractical.