ISO Management Review – Documented Information Requirements

Table of Contents

ISO Management Review Documented Information

ISO Management Review: What Documented Information is actually Required?

 

Management review is intended to be a core governance activity within an ISO-based management system.

Yet it is also an area where certified organisations can face very different expectations from certification body (CAB) auditors.

  • One auditor may accept management review minutes that capture conclusions, decisions and actions, supported by existing management system records.
  • Another may expect a comprehensive “management review pack” demonstrating that every prescribed input has been considered.
  • Some auditors also expect documented trend analysis against management system performance.

 

At DBell Consulting, we have encountered these differences firsthand. We have also disputed findings where we considered an auditor’s expectation for documented information went beyond what the applicable ISO standard actually stipulates.

This creates understandable frustration for certified organisations.

If two auditors interpret the same requirement differently, what does the organisation actually need to document?

Inputs and Results are not the same thing

 

Clause 9.3 provides the requirements for management review.

Specifically, this requires top management to review the organisation’s management system at planned intervals to ensure its continuing suitability, adequacy, effectiveness and alignment with the strategic direction of the organisation.

This clause prescribes information that must be used as inputs into the management review. They also prescribe the results that should come from it. The distinction matters.

ISO’s current Harmonized Structure for Management System Standards (MSS) separates management review into the below sub-clauses:

  • 9.3.1 General
  • 9.3.2 Management review inputs
  • 9.3.3 Management review results

 

Importantly, the common documented information requirement is attached to the results of management reviews, and is consistent across ISO 9001:2015, ISO 14001:2015 and ISO 45001:2018 – specifically “The organization shall retain documented information as evidence of the results of management reviews.“.

This does not specify that documented information must demonstrate consideration of every individual management review input.

The newly issued update to ISO 14001:2026 (Environmental Management Systems) slightly amends this terminology, but we’ll get to that.

When reviewing the inputs to be considered (Clause 9.3.2), some will have their own documented information requirements elsewhere in the applicable standard(s), and subject to inspection by the auditor when determining conformity with those clauses. This can include (depending on which standards your organsation is certified to):

  • The extent to which objectives have been met (Clause 6.2), and monitoring and measuring results (Clause 9.1).
  • Performance of external providers – key to ISO 9001, Clause 8.4.1.
  • Nonconformities and corrective actions – may relate to control of nonconforming outputs (ISO 9001, Clause 8.7), or nonconformity and corrective action (Clause 10.2).
  • Audit results – Clause 9.2.2.

 

But does Clause 9.3 require an organisation to create a separate documented record proving that each input was considered?

That is where interpretations start to differ.

The diagram below illustrates the distinction between management system information used as inputs to management review and the documented information ISO requires as evidence of the results of management review.

ISO Management Review Documented Information Flow

ISO 14001 Guidance provides some useful Clarification


ISO/TC 207/SC 1 is the sub-committee responsible for Environmental Management Systems (EMS) within the International Organization for Standardization (ISO). It operates under the parent technical committee ISO/TC 207 (Environmental Management) and provides guidance for the consistent interpretation of ISO 14001 (Environmental Management Systems).

Its reviewed interpretations for ISO 14001:2015 (released in March 2024) considered whether documented information from management review needed to demonstrate consideration of all the required Clause 9.3 inputs.

Its response was clear:

“Clause 9.3 only requires documentation of the outputs of the management review.”

The interpretation explains that some management review inputs have their own documented information requirements elsewhere within ISO 14001 (as outlined above).

It also recognises that organisations may want to retain additional information such as agendas, presentations, reports or minutes.

That is an important choice of language.

There is a difference between information an organisation may want to retain and information the standard requires it to retain – the choice is with the organisation, not the CAB auditor.

Other useful resources from ISO/TC 207/SC1 are available from their official subcommittee page at this link.

ISO 9001 Auditing Guidance for Management Review


The ISO 9001 Auditing Practices Group (APG) also provides useful guidance with their publication ISO 9001 Auditing Practices Group Guidance on: Policy, Objectives and Management Review (released in January 2016).

Its guidance recognises that management review does not have to be a standalone annual meeting built around an ISO agenda. Management review can form part of normal business management processes, including different meetings, discussions and reports.

It also confirms that documented information about management review is required, while noting that its format is not prescribed.

The guidance then advises auditors to look for evidence that management review inputs and outputs are relevant to the organisation’s size and complexity, and that they are used to improve the business.

This distinction between audit evidence and required documented information is important.

Whilst an auditor needs sufficient objective evidence to determine conformity, that does not automatically mean the organisation must create documentations and records for every piece of evidence an auditor might reasonably examine.

ISO 14001:2026 makes the distinction clearer


ISO 14001:2026 has restructured Clause 9.3 from the 2015 revision, separating this into the 3 sub-clauses under the ISO High Level Structure (HLS).

The requirements are now separated into general requirements (Clause 9.3.1), management review inputs (Clause 9.3.2), and management review results (Clause 9.3.3) – consistent with ISO 9001:2015.

The terminology has also been made more consistent.

Clause 9.3.3 is now specifically concerned with Management review results, and documented information must be available as evidence of those results.

This aligns with ISO’s current Harmonized Structure, and the intent of the publication by ISO/TC 207/SC 1 in its 2024 interpretation, where it clarified that the terminology of “outputs” means the same thing as “results”.

You might therefore expect the revised structure to reduce disagreement about what needs to be documented.

Unfortunately, different interpretations are already emerging.

And this is where the frustration starts


Well-meaning ISO management system authorities and CABs around the world have attempted to put their own spin on the requirements of Clause 9.3 – unfortunately without consistency.

The CQI and IRCA ISO 14001:2026 Briefing Note for Implementers takes a more prescriptive position.

It states that top management is required to ensure documented information generated through management review clearly demonstrates that all specified inputs have been considered and analysed.

This goes further than simply requiring documented evidence of management review results.

To its credit, CQI makes an important qualification. It says that the implementation implications within the briefing are CQI’s interpretations and that the document should not be treated as a definitive reference source. It identifies ISO/TC 207/SC 1 documentation as the authoritative source (so why the inconsistency?).

Other organisations take different approaches.

  • The SGS ISO 14001:2026 readiness checklist separately asks whether management review covers the required inputs and results, and whether documented information is available as evidence of the results.
  • The Institute of Sustainability & Environmental Professionals (ISEP) similarly recognises the revised requirements concerning management review inputs, while describing the documented information requirement in terms of documented results.
  • For ISO 9001, NQA identifies the results of management reviews among the mandatory records required by ISO 9001:2015.

 

So when you dig a little deeper, it isn’t difficult to see how different interpretations can develop.

When Guidance evolves into an audit requirement

This is where certified organisations can get caught in the middle.

There is nothing wrong with maintaining a comprehensive management review pack. For some organisations, this may be their preferred approach. A structured agenda, reports, graphs, dashboards and detailed minutes can provide excellent management information.

The problem arises when good practice becomes an auditor’s expectation, and that expectation then becomes a nonconformity during a certification audit.

At DBell Consulting, we have encountered multiple findings where CAB auditors:

  • Expected documentary evidence showing that every management review input had been considered, or
  • Expected to see a documented trend analysis showing performance of the management system’s various elements.

 

In these cases, we have often disputed those findings because we could not identify the ISO requirement supporting the auditor’s prescribed form of evidence.

This does not mean the organisation can simply say, “we discussed it”. The auditor should prompt for objective evidence that the management review process conforms with Clause 9.3.2 requirements relating to management review inputs.

However, objective evidence can come from several sources, which may not necessary relate to documentation. Existing dashboards, audit results, compliance evaluations, registers, performance information, actions, interviews with management and evidence of resulting decisions may all contribute.

The question is whether the requirement has been met, not whether the organisation has produced the auditor’s preferred document.

What about Trend Analysis?


Trend analysis is a good example of the problem.

Where Clause 9.3 requires performance information, including trends, those trends need to inform management review.

But that does not necessarily create a requirement for a separate documented “trend analysis”.

The trend may already be evident within KPIs, dashboards, audit results, incident statistics, environmental performance data, customer feedback or objectives.

ISO 9001 APG guidance identifies trend charts as one possible management review input. It does not prescribe them as the required method.

Again, the audit question should be:

Was appropriate information about trends available and used during management review?

Not: Where is your management review trend analysis document?

Why Consistency matters


Certification audits should give organisations confidence that they are being assessed against the requirements of the applicable ISO standard.

When different CAB auditors apply materially different expectations to the same requirement, that confidence suffers.

It also creates unnecessary work.

Organisations start building documents for auditors rather than operating management systems for their business.

That outcome conflicts with the process-based approach ISO management system standards are intended to encourage.

The ISO 9001 APG makes a particularly useful observation here, to paraphrase: Management review should not become an exercise conducted solely to satisfy the standard and auditors. It should form an integral part of the organisation’s business management process.

That is a principle worth preserving across ISO 9001, ISO 14001, ISO 45001 and integrated management systems.

A Responsibility for ISO Technical Committees

There is also a responsibility here for the ISO technical committees responsible for ISO 9001, ISO 14001 and ISO 45001.

As three of the world’s most widely adopted management system standards, recurring differences in interpretation should prompt clear and consistent guidance from their respective technical committees.

That guidance could sit within each standard’s informative Annex, formal interpretations, or accessible standalone guidance. Common Harmonized Structure requirements should also receive consistent interpretation across standards.

Organisations should not have to reconcile different technical committee papers, CAB guidance and professional commentary to understand a common Clause 9.3 requirement.

Where ambiguity leads to inconsistent auditing, ISO’s technical committees have a responsibility to address it. A common ISO requirement deserves a clear and consistent ISO interpretation.

For management review, this means clearly distinguishing between required inputs, required results, required documented information, and objective evidence used by auditors to establish conformity.

Greater clarity would help organisations focus on effective management review, rather than anticipating what individual auditors expect to see.

Three Questions worth discussing separately

When assessing management review, three questions should not be confused when approached by the CAB auditor:

1. What must the management review include?

  • The inputs prescribed by the applicable standard.

2. What documented information must the organisation have?

  • The documented information expressly required by the standard, including evidence of management review results and records required under other clauses.

3. What evidence can an auditor examine?

  • Whatever appropriate objective evidence is necessary to determine whether management review conforms and is effective.

These questions overlap, but they are not the same.

  • A CAB auditor should absolutely test whether management review addresses the required inputs.
  • They should also test whether it produces the required results.

 

What deserves greater caution is turning the auditor’s preferred method of demonstrating those things into an additional documented information requirement.

Keep the focus on the Requirement

 

There is nothing wrong with documenting more than the ISO management system standards require.

If additional documentation improves governance, decision-making or accountability, it has value. But certification findings need to trace back to requirements.

Where a finding effectively requires an organisation to produce a particular document, analysis or management review pack, it is reasonable to ask the auditor:

Where does the applicable ISO standard require that documented information?

That question is not about resisting scrutiny – rather, it is about keeping conformity assessment focused on what the standard actually requires.

The be

For organisations operating certified management systems, that distinction matters. And based on our experience supporting clients through certification audits, greater consistency in how Clause 9.3 is interpreted would be welcomed.

Share the Post:
Related Posts