MSI site analytics pixel

Management Review Procedure: What ISO 9001:2026 Demands

LEADERSHIP & COMMITMENT

Direct Answer: A management review procedure is the documented method by which top management examines the whole management system at planned intervals, weighs the required inputs, and records decisions on improvement, changes, and resources. ISO 9001:2026, published September 16, 2026, names eight inputs at Clause 9.3.2 where the 2015 edition named six, and asks for trends rather than numbers. Almost every management review procedure still omits at least one required input — not through carelessness, but because the person preparing the review already knows the answer, so it gets covered in conversation and never becomes a produced, dated record. An auditor works from the record. Nothing counts what was only said.

A well-run management review procedure is the single clearest signal of leadership commitment inside an ISO management system, and it is the one procedure that most organizations believe they have already mastered. They hold the meeting. They invite the right people. They talk through performance, complaints, objectives, and audits. Everyone in the room leaves confident the system was reviewed. Then a surveillance assessor asks a plain question — “show me the audit results as a review input” — and the calm disappears, because the findings were discussed, everyone knew them, and no one produced them as a distinct, recorded item.

That gap is not a knowledge gap. It is a structural one, and it repeats across ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101 with a consistency that only ISO consulting practices with hundreds of audits behind them tend to notice. Three 2026 revisions have now landed on top of it. ISO 14001:2026 published April 15, 2026. ISO 19011:2026 published May 27, 2026. ISO 9001:2026 published September 16, 2026. Each one touched the review clause, the audit clause, or both — and each one made a habit-built management review procedure easier to find wanting.

This article does two things. It sets out exactly what the 2026 editions changed about the review clause and what that means for your record. Then it names the specific input each standard’s management review procedure most reliably drops, explains the mechanism that makes it vanish, and shows the one design change that closes it — a named producer and a record that exists before the meeting rather than being spoken into being during it.

Prepare. Produce. Prove.


DEFINITION

What Is a Management Review Procedure?

Inputs. Evaluation. Results.

Direct Answer: A management review procedure defines how, when, and by whom top management reviews the management system’s suitability, adequacy, and effectiveness. It names the required inputs the review must consider, the evaluation the meeting performs on them, and the results — decisions and actions on improvement, changes to the system, and resource needs — that the review must record. Every ISO management system standard requires one. The differences live in which inputs each names and how the record must be kept, and in the 2026 editions those differences moved.

Management review is not an ISO 9001 idea that other standards borrowed. It is a requirement in its own clause in ISO 9001 (Clause 9.3), ISO 13485 (Clause 5.6), ISO 14001 (Clause 9.3), ISO 45001 (Clause 9.3), and ISO 7101 (Clause 9.3). The shared logic is Plan-Do-Check-Act: the review is the “Check” step at the leadership level, where accumulated evidence is turned into direction. A management review procedure exists to make that step repeatable — so the review does not depend on who happened to prepare the slides that year.

Three parts define any compliant management review procedure. The inputs are the specific evidence categories the standard names as mandatory — performance data, audit results, interested-party needs, the status of prior actions, and more. The evaluation is what leadership actually does with those inputs in the room: judges whether the system is still suitable for the organization’s purpose, adequate for its scale, and effective at achieving intended results. Under ISO 9001:2026 that judgment carries a fourth test the environmental standard does not impose — continuing alignment with the strategic direction of the organization. The results are the recorded decisions: what will change, what will improve, and what resources that requires. A management review procedure that captures inputs and results but skips genuine evaluation produces minutes that read like a status report and satisfy no clause fully.

One piece of vocabulary changed in 2026 and it is worth adopting deliberately, because it will appear in audit language before it appears in your document. Both ISO 9001:2026 and ISO 14001:2026 now split the review clause into three subclauses — 9.3.1 General, 9.3.2 Management review inputs, 9.3.3 Management review results. The word “outputs” is gone. A management review procedure that still says “management review outputs” is not non-conforming for that reason alone, but it signals a document written to a superseded edition, and assessors read those signals.

The value of a strong management review procedure runs well past the certificate. As MSI’s work on continual improvement under ISO 9001 lays out, Clause 9.3 is the recurring leadership forum where analysis (Clause 9.1) is weighed and where the decisions that feed corrective action (Clause 10.2) are made. It is also, done well, the difference between a system that manages crises one at a time and a system that lets leadership evaluate the organization as a whole — a shift MSI’s guide to ISO 9001 change management describes as the moment leadership first feels the system working for them. For a walkthrough of building the document itself, MSI’s step-by-step guide to the ISO management review procedure covers structure, attendees, and cadence in detail. This article does something narrower and more useful: it isolates what 2026 changed, and the one input that even a well-built procedure tends to lose.


THE 2026 RESET

What ISO 9001:2026 Changed About the Management Review Procedure

Eight inputs. Two splits. One word.

Direct Answer: ISO 9001:2026 changed five things a management review procedure has to carry. Clause 9.3.2 now names eight inputs instead of six. Changes in the needs and expectations of interested parties became an input in its own right. Risks and opportunities split into two separate inputs, each testing the effectiveness of the actions taken. Performance items are expressed as trends rather than results. And Clause 9.2.2 a) now requires each internal audit to define objectives — which changes what the audit-results input is able to report.

ISO 9001:2026 is the sixth edition and it replaces ISO 9001:2015 as the current edition of the standard. For anyone maintaining a management review procedure, the revision is not a formality. Most commentary has fairly described the revision as evolutionary — the framework, the process approach, and the ten-clause structure all carry forward. That framing is accurate at the level of the whole standard and misleading at the level of Clause 9.3, because the review clause is one of the places where the drafting actually moved. Count the named inputs a management review procedure must carry and the change is visible immediately.

ISO 9001 Clause 9.3.2 — what a review must consider

2015 edition — six named inputs. Status of prior actions; changes in external and internal issues; information on QMS performance (seven sub-items); adequacy of resources; effectiveness of actions taken to address risks and opportunities, as one item; opportunities for improvement.

2026 edition — eight named inputs. Status of prior actions; changes in external and internal issues; changes in needs and expectations of interested parties; information on QMS performance including trends in seven sub-items; opportunities for improvement; adequacy of resources; effectiveness of actions taken to address risks; effectiveness of actions taken to address opportunities.

Interested Parties Became an Input in Its Own Right

The 2015 edition asked the review to consider changes in external and internal issues relevant to the quality management system. The 2026 edition keeps that and adds a separate item: changes in the needs and expectations of interested parties relevant to the quality management system. In practice most organizations determined their interested parties once, during implementation, and have not revisited the register since. A management review procedure built on the 2015 list has no line for this, which means the register goes unexamined for as long as the procedure goes unedited. The honest first-year answer is often “no material change,” and that answer is perfectly acceptable — but it has to be reached and recorded, not skipped.

Risks and Opportunities Split Into Two

This is the change most likely to produce a finding, and it runs deeper than the review clause. ISO 9001:2026 separates Clause 6.1.2 (actions to address risks) from Clause 6.1.3 (actions to address opportunities), and Clause 9.3.2 follows suit with two distinct inputs testing the effectiveness of each. The practical consequence is that a review reporting “risks and opportunities were reviewed, no changes” now answers half a requirement. Risk work is usually documented somewhere — a register, a risk assessment, an FMEA. Opportunity work rarely is. Ask most quality managers to produce evidence that an opportunity was identified, acted on, and the action evaluated for effectiveness, and the honest answer is that the opportunity column of the register has been blank since the last recertification. That is the new most-likely-missing input in any management review procedure, and MSI’s analysis of ISO transition planning treats the separation as one of the defining moves of the revision.

“Trends In” Replaced the Snapshot

Clause 9.3.2 d) asks for information on quality management system performance including trends in seven things: nonconformities and corrective actions, monitoring and measurement results, audit results, customer satisfaction and feedback from relevant interested parties, the extent to which quality objectives have been met, process performance and conformity of products and services, and the performance of external providers. The operative words are “trends in.” A single figure for the current period is no longer the shape the clause asks for. A management review procedure that brings one number per input has produced seven inputs of the wrong kind — a failure mode this article returns to at length, because it is the harder of the two ways a review goes wrong.

Audit Objectives Are Now Required — in ISO 9001 Too

ISO 9001:2015 Clause 9.2.2 asked the organization to define the audit criteria and scope for each audit. ISO 9001:2026 asks it to define the audit objectives, criteria and scope for each audit. ISO 14001:2026 made the same move in the same subclause. This is widely reported as an internal-audit change, and it is — but its sharpest consequence lands on the review, because audit results are a mandatory review input and a trend in findings means very little if the audits that produced them had no stated aim. Trending the count of whatever an auditor happened to look at that year is arithmetic, not evaluation. With objectives defined per audit, the input becomes answerable: did the audits achieve what they were sent to achieve? MSI’s coverage of the ISO 19011:2026 changes works through what the refreshed auditing guidance expects of audit programs, and MSI’s guide to internal audit planning covers how objectives get set in the first place.

There is a second-order effect worth naming, because it is the kind of thing that surfaces at the worst possible moment. An audit program owner who never wrote objectives cannot produce them at review time, and nobody in the room will ask — the 2015 habit says criteria and scope are the whole requirement. The gap is invisible from inside the document until an assessor asks what the audit was for. For dual-certified organizations the reach is wider still: run one integrated audit program across quality and environmental scopes and the objectives requirement touches every audit in it, which is exactly the coordination problem MSI works through in its guide to the ISO 9001 and 14001 transition.

The Climate Determination Has to Be Recorded

The 2024 climate change amendment is now folded into the body of both 2026 editions. Clause 4.1 requires the organization to determine whether climate change is a relevant external issue. The requirement is a determination, not an affirmative answer — “not relevant to our management system, for these reasons” is a valid outcome. What is not valid is no determination at all. Because changes in external and internal issues are a named review input, the determination and any change to it belong in the review record. A management review procedure written before the amendment has no place to put it.

When Does This Become Your Problem?

Nothing happened to your certificate on September 16. ISO 9001:2015 certification remains valid through the transition, and certification bodies themselves need time to retrain and requalify before the first 2026 certificates are issued. Certification-body guidance converges on a three-year transition window, which would put the deadline at approximately September 30, 2029, with the binding arrangements to be confirmed by Global Accreditation Cooperation and the accreditation bodies. Treat that date as firm enough to plan against and provisional enough to verify with your registrar.

The environmental side is further along and tighter. ISO 14001:2026 published April 15, 2026, with a transition deadline of April 30, 2029. ISO 19011:2026 is a guidance standard, so it took effect on publication with no transition period at all — the 2018 edition is already withdrawn, and any audit program referencing it is referencing a superseded document. The practical sequencing point is that most organizations will hold two or three more management reviews before their transition audit, and the review is where the transition plan gets owned and resourced. A management review procedure held to the old input list cannot carry the transition. MSI’s work on timing the ISO 9001:2026 transition makes the case for working backward from the recertification date rather than forward from publication.

BUILT FROM THE CLAUSE, NOT FROM LAST YEAR’S AGENDA

Stop Rebuilding Your Agenda Every Time the Standard Moves

Present. Decide. Record.

MSI’s ISO Management Review Toolkits are eleven matched pairs — a PowerPoint deck to present from and a Word minutes form to record into — generated from the same numbered section list, so the presenter and the recorder are never on different items. Every section carries the clause reference printed under its title, and where a section is MSI practice rather than a requirement, it says so. The ISO 9001 and ISO 9001-combination toolkits ship four files instead of two: one pair built to ISO 9001:2015 for the review you hold while that edition is still on your certificate, and a second pair built to ISO 9001:2026 for planning now — with a one-page transition planner worked backward from your surveillance and recertification dates.

Compare all eleven toolkits by standard, sections and price →


THE STRUCTURAL FAILURE

Why a Management Review Procedure Passes in the Room and Fails on the Record

Known. Spoken. Lost.

Direct Answer: A management review procedure fails on the record when a required input is satisfied in conversation instead of as a produced document. The person preparing the review usually already knows the answer to several inputs — they ran the audits, they track the objectives, they field the complaints — so those inputs get “covered” verbally and never become a distinct, dated item. The clause is met in the room and missing from the file. An assessor works from the file.

Here is the mechanism, stated plainly, because blaming carelessness explains nothing and fixes less. In most organizations a single competent person prepares the management review: the quality or EHS manager who also owns the internal audit program, tracks the objectives dashboard, and processes customer feedback. That concentration of knowledge is efficient — and it is exactly why the management review procedure loses inputs. When the preparer already knows what the audits found, the audit-results input never becomes its own artifact. It gets mentioned. It gets nodded at. It does not get produced.

The sharpest instance is audit results as a review input. ISO 9001:2026 lists audit results at Clause 9.3.2 d) 3) — it sat at 9.3.2 c) 6) in the 2015 edition, so a procedure citing the old reference is pointing at a clause number that no longer holds — and it remains the input most reliably absent from the record, precisely because the audit-program owner is typically also the review preparer. They know what the audits found, so the finding never gets carried into the review as a distinct, evaluated input with its own trend and its own decision. As MSI’s analysis of auditing quality culture puts it, the entire discipline is maintaining a system whose normal operation produces the evidence — not performing the evidence for the assessor. The record that already exists is the only thing that counts.

The Input Is Bigger Than Almost Anyone Reports: All Audits, Not Just Internal

This is the single most useful sentence in the 2026 edition for anyone rebuilding a management review procedure, and it sits in Annex A rather than the requirements, so it is easy to miss. Annex A.9.3 states that trends in audit results refer to all audits — first-party, second-party, and third-party audits of the organization’s quality management system. First-party is your internal audit program. Second-party is your customers auditing you, and your audits of your own suppliers. Third-party is your certification body.

Read that against what actually happens in most review meetings and the gap is uncomfortable. The internal audit summary goes in the pack. The registrar’s last surveillance report sits in a folder, its findings closed individually, never trended against prior visits. Customer audit findings are handled by whoever hosted the customer — often sales or operations, not quality — and never reach the review at all. Supplier audit results live in purchasing. Four streams of audit evidence about the same management system, and a management review procedure that carries one of them.

“Everyone knew the audit findings. That is exactly why they never made it into the record — and why the input the whole room understood was the one input the file could not prove.”

The all-audits reading also explains why the audit-objectives requirement matters at review level rather than only at audit level. Three parties auditing the same system will produce findings in different formats against different criteria. Without stated objectives, “trends in audit results” collapses into a count of findings from whoever happened to visit. With objectives, the three streams become comparable: each audit was sent to establish something, and the management review procedure can evaluate whether it did. That is the difference between a tally and an evaluation, and it is the difference an assessor is trained to hear.

This generalizes past audits. Every standard has an equivalent “the preparer already knows it, so it vanishes” input, and the strongest management review procedure is the one that forces each required input to arrive with a named producer and a record dated before the meeting. That is not bureaucracy for its own sake. It is the difference between a review that survives scrutiny and a review whose quality depends on whoever is in the room remembering to say the right thing. MSI’s work on connecting internal audit follow-up to management review makes the same structural point from the audit side: follow-up trends and repeat-finding rates should be standing, produced inputs — not facts that live only in one person’s head.

There is a benefit hiding inside the discipline, and it is worth stating because it reframes the whole exercise away from compliance and toward performance. MSI client experience suggests that organizations which require every review input to be produced as a record before the meeting end up with better data year-round, because owners know their numbers will be examined rather than narrated. The management review procedure stops being a meeting to survive and becomes the mechanism that keeps the underlying system honest. That is the reframe MSI describes in its work on the quality management mindset — turning the review from an annual event into a continuous state where leadership reads evidence rather than reassurance.


THE PER-STANDARD BREAKOUT

The One Input Each Standard’s Management Review Procedure Omits

Five standards. Five blind spots.

Direct Answer: The required inputs a management review procedure must include differ by standard, and each standard has one input that vanishes for a structural reason. ISO 9001 loses audit results and, since 2026, opportunity-action effectiveness; ISO 13485 loses two regulatory items; ISO 14001 loses the trend in meeting compliance obligations; ISO 45001 loses worker consultation; ISO 7101 loses the evaluation of service-user experience. In every case the input is either already known by the preparer, or easy to replace with a number that looks like evidence but is not.

One management review procedure can serve all five standards, because the review clause sits at or near the same place in each. But a procedure built generically will inherit each standard’s specific blind spot unless it names that standard’s most-omitted input explicitly. Here is the one to watch for each, and the toolkit built to the matching clause list.

ISO 9001:2026: Audit Results as a Distinct, Evaluated Input — and Now Opportunity Actions

ISO 9001:2026 Clause 9.3.2 lists the inputs the review “shall include,” and audit results sit at d) 3) as a trend. This is the classic vanishing input: the audit-program owner is almost always the review preparer, so the findings are known and get discussed rather than produced — and, per Annex A.9.3, the input was always broader than the internal program anyway. The fix is to make audit results a standing row in the management review procedure record with its own trend across all three audit parties, owned and dated by the audit-program manager, before the meeting opens.

The 2026 edition adds a second candidate that will catch more organizations than the first in the transition years. Clause 9.3.2 h) asks for the effectiveness of actions taken to address opportunities, as a separate input from the risk equivalent at g). Most risk registers have a well-tended risk column and an empty opportunity column. There is also a new assignment upstream that makes this easier to solve than it looks: Clause 5.3 e) requires top management to assign responsibility and authority for reporting on opportunities for improvement to top management. The standard has, in effect, named the producer for you. MSI’s coverage of the ISO 9001:2026 ethics and culture update and its companion analysis of ISO 9001:2026 for boardrooms work through what the leadership clauses now expect the review to evidence.

Toolkit: the ISO 9001 Management Review Tool Kit is twenty-four numbered sections built to the 2026 edition, and ships both editions — a 2015 pair for the review you hold today and a 2026 pair for the one you are planning. Procedure: the ISO 9001 Leadership and Commitment template in MSI’s ISO procedure templates and guides names audit results as a produced input with an assigned owner.

ISO 13485: The Two Regulatory Inputs That Land in Neither System

ISO 13485 Clause 5.6.2 names twelve required review inputs — more than ISO 9001 names in either edition. Two of them read like regulatory-affairs topics sitting inside a quality clause, and so they land in neither system’s agenda: reporting to regulatory authorities, and applicable new or revised regulatory requirements. Quality assumes regulatory owns them; regulatory assumes the quality management review covers them; the management review procedure records neither. This matters more since February 2, 2026, when the FDA Quality Management System Regulation (QMSR) took effect, incorporating ISO 13485:2016 by reference into 21 CFR Part 820 and retiring the old §820.180(c) exemption that once shielded management review records from routine inspection. Under the QMSR final rule, FDA investigators can now read these records and expect them to show risk-based discussion. Note also that ISO 13485 is not being revised on this timetable — the device certificate does not move, which makes a dual-certified organization’s transition planning asymmetric. MSI’s ISO 13485 management review guide walks the full twelve inputs and the QMSR agenda; MSI’s coverage of medical device cybersecurity as a QMS shift shows how quickly new regulatory inputs now arrive.

Toolkit: the Medical Device ISO 13485 Management Review Tool Kit is twenty-three sections built where the clause actually sits — 5.6, inside Management Responsibility, not 9.3. Already ISO 9001 certified? The combined 9001 + 13485 toolkit resolves the asymmetry both ways. For teams still confirming where they stand, MSI’s ISO 13485 Gap Analysis is the current-state starting point.

ISO 14001:2026: The Trend in Meeting Compliance Obligations

ISO 14001:2026 restructured management review into three subclauses and made the input list more definitive. Clause 9.3.2 d) 3) now asks the review to consider information on environmental performance including trends in meeting its compliance obligations — not merely that a compliance register exists, and not merely a point-in-time compliance status. The register is usually kept immaculately, and it gets mistaken for the requirement, so the management review procedure reports a document instead of a direction of travel. Evaluating the trend is a separate act, and it is the one nobody is assigned. MSI’s work on evaluation of compliance makes the companion point from the Clause 9.1.2 side: an annual tick never proves status.

ISO 14001:2026 also gives the review the richest results clause of the family. Where ISO 9001:2026 asks the results to include decisions on improvement, system changes and resource needs, ISO 14001:2026 Clause 9.3.3 names six required results: conclusions on continuing suitability, adequacy and effectiveness; decisions on continual improvement opportunities; decisions on changes including resources; actions where environmental objectives have not been achieved; opportunities to improve integration of the EMS with other business processes; and any implications for the strategic direction. Those last three have no ISO 9001 equivalent, and a combined review built from the quality agenda will drop all three. With the 36-month transition running to April 30, 2029, organizations rebuilding documents have a natural opening to add the missing inputs while they are already in the files.

FOR EHS MANAGERS ALREADY RUNNING 14001

Close the ISO 14001:2015 to 2026 Documentation Gap in a Week, Not a Quarter

The ISO 14001:2026 Procedure Templates and Guides bundle was built for experienced environmental managers who already know their system and simply need the 2026 documents — the restructured review clause, the new Clause 6.3 planning of changes, the per-audit objectives requirement, and the register updates the edition requires. Editable Word, clause-mapped, with the judgment calls already made. The scoring pass is fast; writing the procedures is where transitions stall. This is the part that stalls, already written.

See the ISO 14001:2026 templates bundle →  ·  Or the ISO 14001:2026 Management Review Tool Kit →

ISO 45001: Consultation and Participation of Workers — Recorded by Level

ISO 45001 names consultation and participation of workers among the management review inputs at Clause 9.3, and Clause 5.4 carries an emphasis the review often misses: the consultation and participation of non-managerial workers specifically. A safety committee of supervisors satisfies the sentence on its face — but the clause asks for the workers closest to the hazards, and the review record should show consultation by level, not just that a committee met. A management review procedure that logs “safety committee input received” without evidencing non-managerial participation has produced a record that reads compliant and is thin where the standard is most specific.

A management review procedure for safety also carries an obligation no other standard imposes: ISO 45001 is the only standard in this family that requires the results of the review to leave the room — top management must communicate the relevant results to workers and their representatives. That makes the review a two-way requirement, and half-satisfying it is easy — input received, nothing returned. Note too that ISO 45001:2018 is not transitioning on the 2026 timetable, so in an integrated system it is the fixed point around which the other two move. MSI’s overview of ISO 45001 workplace safety consulting explains why worker credibility, not managerial sign-off, is the point of the clause, and MSI’s analysis of the ISO 45001 revision covers where the standard is heading next.

Toolkit: the ISO 45001 Management Review Tool Kit is twenty-seven sections and carries a five-column communication log recording what results went to whom, by what means, when, and why anything was judged not relevant. Running safety alongside environmental? The HSE combined toolkit resolves fourteen divergences between the two.

ISO 7101: Service-User Experience, Evaluated — Not Scored

ISO 7101:2023 — the first international consensus standard for healthcare quality management — carries the longest list of mandatory review inputs of any ISO management system standard, and several of them exist in no other: health indicators, patient safety, waste management, internal finances and external funding, accessibility of services, and information owed to stakeholders under agreement. The one that vanishes is the evaluation of service-user experience. A satisfaction percentage is easy to produce and easy to present, so in most every healthcare management review procedure it stands in for the evaluation and the harder question goes unasked: what was the experience of care actually like? A number recording that people were asked is not an evaluation of what their care was. A management review procedure that brings a stable satisfaction score to every meeting has produced an input of the wrong kind. As MSI’s work on ISO standards and integrity notes, in healthcare a record that does not match the reality of care is a patient-safety issue, not a rounding error. MSI’s guides to healthcare quality culture and ISO 7101 documentation cover the wider system the review reports on.

Toolkit: the ISO 7101 Management Review Tool Kit is twenty-six sections, including the six inputs no other standard names.

The Combined Review: Whichever Side Chairs It, Owns the Blind Spot

Organizations running more than one standard often merge the reviews into a single meeting — sensible, and encouraged where the standards share the Harmonized Structure. But a merged management review procedure chaired from one side inherits that side’s blind spots and quietly drops the other standards’ unique inputs: the quality chair forgets worker consultation, the safety chair forgets customer satisfaction, and both forget the compliance-obligations trend. Build a three-standard agenda from ISO 9001 and you drop worker consultation, incidents, and compliance evaluation; build it from the environmental and safety agendas and you drop customer satisfaction, external providers, and risk-action effectiveness. The asymmetry runs in every direction, which is why building the combined agenda from whichever standard you know best is the reliable way to lose requirements.

MSI’s guide to integrated management system implementation makes the design point directly — one review, one document set, but an input checklist that carries every standard’s required items, because ISO 13485 uses an older structure and does not share the ten-clause backbone the others do. A combined management review procedure needs each standard’s most-omitted input written in by name, and it needs a record of which standard governs wherever two requirements differ, so the decision is visible as a decision rather than as an omission.

Toolkits: ISO 9001 + ISO 14001:2026 (thirty-one sections, the most common dual certification in North America) and the IMS toolkit for 9001 + 14001 + 45001 (thirty-five sections, twelve requirements that exist in one standard and not the others). Each combined edition carries an appendix recording every divergence, which standard governs it, and the alternative rejected. Not certified yet and building the discipline first? There is a general-purpose version that records the missing concept as the finding and sets the goal.


TWO WORKED EXAMPLES

Two Management Review Procedures That Looked Fine

Absent. Or hollow.

These two cases are anonymized composites drawn from MSI’s audit-attended experience, chosen because they fail in opposite ways. In the first, a required input is absent because it was assumed. In the second, a required input is present but hollow — the wrong kind of thing wearing the right label. A management review procedure has to defend against both, and the 2026 emphasis on trends makes the second failure far easier for an assessor to name than it used to be.

Example A — Everybody Already Knew (ISO 9001)

A manufacturer with a genuinely well-run quality system holds a diligent annual review. The internal audits were thorough, the findings were closed, and the management review was engaged — leadership discussed the audit outcomes at length. Then the surveillance assessor asks to see audit results as a review input, and there is no record of them as a distinct item. The findings had been discussed; everyone knew them; no one had produced them. This is a low-value case carrying high exposure: nothing was actually unsafe or unmanaged, the system was healthy, but the record understated it because the input existed only in the conversation. The finding writes itself — a required input not evidenced — and it lands on an organization that had done the underlying work.

Under the 2026 edition the same organization now has a second problem it does not know about. Its record would have shown one internal-audit summary, and the input is defined as trends across all audits — including the two customer audits it hosted that year and the registrar’s own findings from the last surveillance visit. The fix handles both at once, and it is a change to the management review procedure rather than to the audit program. Name the audit-program manager as the producer of the audit-results input. Give it a row in the review record that exists before the meeting, with findings summarized by source, the trend against prior periods shown, and a decision field attached. The conversation still happens — but now it evaluates a produced input instead of substituting for one. MSI’s work on government internal audit makes the same move in the public sector, where audits feed management review and leadership decisions only when the findings arrive as evidence rather than recollection.

Example B — The Satisfaction Score That Told Leadership Nothing (ISO 7101)

A healthcare organization brings a stable 94% satisfaction score to every management review. It is presented, noted, and carried forward, meeting after meeting. An accreditation assessor raises a finding — not because the number is bad, but because the evaluation of service-user experience that the review is expected to perform is not happening. A percentage recording that people were asked is not an assessment of what their care was like. The input is present, and it is the wrong shape: a score standing in for an evaluation. This is the opposite failure from Example A. There the input was missing; here it is hollow.

The fix defines an evaluation method — themed analysis of complaints and compliments, care-experience review of specific pathways, structured service-user input — and makes that evaluation, logged and dated, the named review input. The score can stay as one signal among several. But the management review procedure now records a judgment about the experience of care, which is what the standard was reaching for. A single number is comfortable precisely because it asks nothing of leadership; the evaluation is uncomfortable because it does — and that discomfort is the point of the input.

What makes Example B worth re-reading in 2026 is that it stopped being a healthcare-only problem. ISO 9001:2026 asks for trends in customer satisfaction, in objectives attainment, in process performance, in external-provider performance. A single current-period figure for each is the same hollow input in quality clothing — present, labelled correctly, and not the shape the clause asks for. Any organization that has been bringing one number per input to its review for the last decade now has seven instances of Example B sitting in its pack, and a transition window in which to fix them before anyone is scored against the new edition.

FIND YOUR OWN GAP — FREE, FIVE MINUTES

Is your review missing an input — or carrying a hollow one?

The Leadership & Commitment Maturity Check scores eight elements of your review against the clause and flags both failure modes — the input that is absent because it was assumed, and the input that is present but hollow. It tells you which of yours is which before you spend anything.

Score My Management Review →


THE FIX

How to Fix a Management Review Procedure So the Record Carries It

Name. Produce. Date.

Direct Answer: Fix a management review procedure by requiring every mandatory input to arrive with a named producer and a record dated before the meeting. Give each required input its own row in the review record, an assigned owner, a trend against prior periods, and a decision field. Then the meeting evaluates produced inputs instead of manufacturing them in conversation — and the record proves what the room already knew.

The redesign is not a bigger procedure. It is a differently shaped one. Most management review procedures are written as an agenda — a list of topics to discuss, usually assembled from what last year’s review covered, in the order it covered it. That works until the review meets an assessor, because a habit-built agenda cannot surface a requirement the organization has never performed. If interested-party needs were never reported, no line asks for them. If nobody set audit objectives, no section requests them. The gap is invisible from inside the document. Rewrite the management review procedure as an input register instead: a table where each row is a required input, each input has a named owner, and each owner produces and dates their input before the meeting. The agenda then becomes the evaluation layer on top of records that already exist. Three design moves carry most of the value.

1. Give Every Required Input a Named Producer

The single point of failure is one person knowing everything. Break it by assigning each required input to the person who owns the underlying process — audit results to the audit-program manager, customer satisfaction and feedback to the account or quality owner, worker consultation to a named safety representative, the compliance-obligations trend to the environmental lead, the service-user evaluation to a care-experience owner, and opportunity-action effectiveness to whoever ISO 9001:2026 Clause 5.3 e) says is responsible for reporting improvement opportunities to top management. The preparer coordinates; the owners produce. A management review procedure built this way cannot lose an input to “everyone already knew,” because knowing is no longer the same as producing. MSI’s guide to the ISO implementation lead role explains why distributed ownership, not a single heroic manager, is what makes a system durable, and MSI’s work on ISO HR standardization shows what happens when a named role and the actual work drift apart.

2. Require Each Input to Exist as a Dated Record Before the Meeting

An input produced in the meeting is an input that was never really tested, so the management review procedure has to demand it earlier. Require every input to be submitted, dated, and attached to the review pack before the meeting opens. This is the discipline that improves the data itself: owners who know their input will be read as a standing record prepare differently from owners who plan to speak to a slide. It is also the only practical way to satisfy the 2026 emphasis on trends, because a trend cannot be improvised — it needs the prior periods pulled and compared in advance. As MSI’s analysis of auditing quality culture keeps returning to, the strongest evidence is the record that already exists in the normal operation of the system, not the artifact assembled the week before the assessor arrives.

3. Attach a Decision Field to Every Input

Inputs without decisions are a status report, not a review, and a management review procedure that records the first and calls it the second will be read as exactly that. Every input row should force a recorded result: no action needed and why, an action with an owner and a due date, or an escalation. This closes the loop between input and result that the standards require, and it makes the next review’s “status of actions from previous management reviews” input produce itself. ISO 14001:2026 pushes this furthest by naming six things the results must include, so an environmental or integrated review needs decision fields that reach conclusions on suitability, unachieved objectives, integration opportunities, and strategic implications — not just a to-do list. MSI’s work on building a quality improvement culture and on continual improvement both land here: leadership commitment is proven by decisions that carry owners and dates, not by attendance.

One boundary is worth stating plainly, because it is where organizations buy the wrong thing. A management review record and a management review procedure are two different documents, and ISO 13485 Clause 5.6.1 is explicit that it wants both. The deck and the minutes form are the record — what was presented, what was decided, when, by whom. The procedure is the upstream document that determines what arrives at the meeting at all: who produces each required input, on what frequency, and where the record lives before the review opens. Buy a record and you have a better meeting. Write the management review procedure and you have a better system feeding it. Most organizations need both, and MSI’s guide to ISO procedure order explains where management review sits in the build sequence.

THE PROCEDURES BEHIND THE RECORD

Stop Writing Procedures From Scratch. Start Editing Ones That Already Work.

Edit. Approve. Deploy.

MSI’s ISO Procedure Templates and Guides cover thirteen procedure families and 100+ templates across ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101 — written to one architecture so the set interlocks, delivered as editable Word with the clause mapping resolved and the record requirements defined. The Leadership and Commitment procedure is the one your review record depends on: it structures the review as an input register with named producers, dated records and decision fields, and carries each standard’s most-omitted input by name. Twenty-eight years of judgement calls, already made.

Browse the ISO Procedure Templates & Guides library →


FREQUENCY

How Often Should a Management Review Procedure Run?

Interval. Plus trigger.

Direct Answer: A management review procedure must run “at planned intervals” — the standards do not fix a number, and annual is common but not mandated. ISO 9001:2026 Annex A.9.3 is explicit that the interval is the organization’s to determine and can be influenced by risks, opportunities, and changes in external and internal context. The stronger design pairs a planned interval with defined triggers: a significant regulatory change, a major nonconformity, a serious incident, or a strategic shift should convene a review regardless of the calendar.

The clause language — “at planned intervals” — is deliberately open, and the 2026 Annex guidance makes the reasoning visible rather than leaving organizations to infer it. Annual reviews are the default across ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101, and for a stable, mature system that is defensible. But a once-a-year management review procedure treats the review as an event, and the more capable design treats it as a state. MSI’s work on the quality management mindset argues for a continuous review posture: standing inputs updated on their own cadence, a leadership forum that meets more often on a shorter agenda, and the full review as a periodic consolidation rather than the only moment leadership looks.

Triggers are where most procedures are silent and should not be. A management review procedure that only fires annually will, by definition, be up to eleven months behind a regulatory change like the QMSR taking effect, a serious safety incident, or the loss of a major customer. Writing named triggers into the management review procedure — regulatory change, major nonconformity, significant incident, strategic pivot — means the review convenes when the evidence demands it, not only when the calendar does. The publication of a new edition of your own standard is itself a trigger, and organizations that convened a short review in the weeks after September 16 are already a cycle ahead of those waiting for next year’s meeting. For organizations that want the discipline maintained year-round without building the infrastructure themselves, MSI’s SurePath turnkey program and the SureResults ISO maintenance program keep the review cadence and its inputs live between audits.


THE BUSINESS CASE

What Does a Strong Management Review Procedure Give Leadership?

Direction. Not decoration.

The compliance framing undersells what a well-built management review procedure actually does. It is the only recurring forum where leadership sees the entire management system at once — quality, risk, compliance, safety, and customer or patient experience side by side rather than in the separate reports each function files. That single vantage point is where scattered evidence becomes direction: where a rising trend in one area is read against resource constraints in another, and where the organization decides, on the record, what it will improve next. A management review procedure built as an input register rather than an agenda gives leadership evidence to decide from instead of reassurance to nod at.

The 2026 revisions sharpen that argument rather than complicating it. A clause list that asks for trends instead of numbers, for interested-party movement as its own item, and for opportunity actions as a separate test of effectiveness is describing something closer to a board pack than to compliance minutes. A management review procedure that produces a record of genuine discussion of quality culture, ethical concerns raised and resolved, and the leadership behaviours that reinforce or undermine the policy is, in effect, minutes of governance oversight — the evidence an assessor looks for and the evidence that protects leadership after the fact. The practical change is small; the governance change is large.

The benefit compounds. Each review’s recorded decisions become the next review’s “status of actions from previous management reviews” input, so a management review procedure run with discipline begins to produce its own continuity — the system starts to carry its own memory instead of relying on whoever remembers last year’s promises. MSI client experience suggests that organizations which treat the review as evidence-based decision-making, not a certificate ritual, tend to make faster and better-grounded resource calls, because the data arrives already examined. MSI’s analysis of how leading organizations use evidence-based decision making traces that same loop from analysis to review to action.

It is also the clearest proof of leadership commitment an assessor can find. Not a signed policy statement, but a standing record of executives evaluating produced evidence and deciding with owners and dates attached — a management review procedure that shows top management doing the work the standards ask leadership to do. Across 28 years, with 200+ audits attended, 80+ certifications supported, and 600+ professionals trained, MSI’s consistent observation is simple: the organizations whose reviews produce the record, input by input, are the ones for whom certification is a byproduct of a system that already works — not a performance staged for the visit. That is as true of the 2026 editions as it was of the 2015 ones. The clause list got longer. The discipline did not change.


QUESTIONS LEADERS ASK

Management Review Procedure: Frequently Asked Questions

Ask. Answer. Advance.

What changed in Clause 9.3 in ISO 9001:2026?

Five things. Clause 9.3.2 now names eight inputs instead of six. Changes in the needs and expectations of interested parties became a separate input. Risks and opportunities split into two inputs, each testing the effectiveness of actions taken. Performance items are expressed as trends rather than single results. And “management review outputs” was renamed “management review results” at 9.3.3. A management review procedure written to the 2015 list is missing at least two named inputs.

Do audit results as a review input include my certification body’s audits?

Yes. ISO 9001:2026 Annex A.9.3 states that trends in audit results refer to all audits — first-party (your internal program), second-party (customer audits of you and your audits of suppliers), and third-party (your certification body). Most review records carry only the internal audit summary. A management review procedure that trends all three sources is doing what the clause describes; one that trends only internal audits is reporting a quarter of the input.

When do I have to meet the ISO 9001:2026 review requirements?

ISO 9001:2026 published September 16, 2026, and your ISO 9001:2015 certificate remains valid through the transition — but your management review procedure is the document that will be read against the new clause list first. Certification bodies converge on a three-year window, putting the deadline at approximately September 30, 2029, subject to confirmation by Global Accreditation Cooperation and your accreditation body. ISO 14001:2026 carries a firm April 30, 2029 deadline. ISO 19011:2026 is guidance and took effect on publication with no transition period. Confirm your own dates with your registrar.

Is a management review the same as an internal audit?

No — and conflating them is common. An internal audit is a systematic check of whether processes conform and work, conducted by trained auditors under a planned audit program that, since 2026, must state objectives for each audit. A management review is the leadership-level evaluation that consumes audit results as one of several required inputs. Audit results feed the management review procedure; the review does not perform the audit. The most-omitted input problem exists precisely because the same person often owns both.

Can top management delegate the management review?

No. The review is a top-management accountability in every standard — leadership must lead it, not merely receive the minutes. Under the FDA QMSR, that accountability now carries regulatory weight for medical device organizations. Others can prepare and produce inputs, but the evaluation and the decisions are leadership’s to own. A management review procedure that shows the executive team present and deciding is itself evidence of the leadership commitment the standards require.

Is a satisfaction score enough for the ISO 7101 review?

No. ISO 7101:2023 expects an evaluation of service-user experience, not a score that records people were surveyed. A percentage is a signal; the required input is a judgment about what the experience of care actually was. The same logic now reaches quality systems, because ISO 9001:2026 asks for trends in customer satisfaction rather than a current-period figure. A single number is an input of the wrong kind in either setting.

Does ISO 45001 require the review to report back to workers?

Yes — consultation and participation of workers is a two-way requirement, so the loop closes only when relevant review results are communicated back to workers and their representatives, with the non-managerial emphasis of Clause 5.4 respected. ISO 45001 is the only standard in this family whose review results must leave the room. A management review procedure should record both the worker input received and the results returned, by level. Reporting up without reporting back leaves the input half-satisfied.

How is an ISO 13485 management review procedure different from ISO 9001?

ISO 13485 lists twelve required review inputs at Clause 5.6.2 — more than either ISO 9001 edition — and two are explicitly regulatory: reporting to regulatory authorities, and new or revised regulatory requirements. The clause also sits at 5.6, inside Management Responsibility, rather than at 9.3. Since the QMSR took effect on February 2, 2026, those records are inspectable. A device management review procedure must carry all twelve or document why one is not applicable. MSI’s ISO 13485 management review guide walks each input in full.

What is the minimum record a management review procedure must keep?

At minimum: evidence that each required input was considered, the evaluation performed, and the results decided — with owners and due dates. The practical minimum that survives scrutiny is an input register showing each mandatory input as a produced, dated record plus its decision. Attendance minutes alone do not meet it, because they prove a meeting happened, not that the inputs were evaluated.


WHERE TO GO NEXT

Four Moves, In Order

Score. Record. Write. Talk.

1. Score it free, in five minutes. The Leadership & Commitment Maturity Check tells you which required inputs your review is satisfying in conversation rather than on the record — before you spend anything.

2. Fix the record this quarter. The ISO Management Review Toolkits give you a deck and a matching minutes form built from your standard’s clause list, numbered section by numbered section — with both the 2015 and 2026 editions where ISO 9001 is in scope, so you can run this year’s review and plan next year’s transition from the same set.

3. Fix the system feeding it. The ISO Procedure Templates and Guides library is where the Leadership and Commitment procedure lives — the document that decides who produces each input, on what frequency, and where the record sits before the meeting opens. Running ISO 14001? The ISO 14001:2026 bundle is scoped to close the 2015-to-2026 documentation gap in about a week.

4. Talk it through. A planning session at 760-434-9141 maps your current review against the clause list you are actually certified to, and against the one you will be certified to by 2029. New to the standards and still deciding whether to certify at all? Start with the ISO Executive Decision Briefs — short leadership videos you can watch at your desk.

Not sure which toolkit matches your certification scope? Tell MSI what you are certified to and MSI will tell you which one fits. Across 28 years MSI has attended 200+ certification and surveillance audits and watched registrars read management review records for all of it — a short conversation is faster than guessing.


References & Primary Sources

1. ISO — ISO 9001 catalogue entry (sixth edition, published September 2026).

2. ISO — ISO 9001 Quality Management (Clause 9.3 management review; 9.3.2 inputs; 9.3.3 results; Annex A.9.3).

3. ISO — ISO 13485 Medical Devices (Clause 5.6 management review; 5.6.2 twelve inputs).

4. ISO — ISO 14001 Environmental Management (2026 edition, published 15 April 2026; Clauses 9.3.1 / 9.3.2 / 9.3.3).

5. ISO — ISO 45001 Occupational Health & Safety (Clause 9.3 inputs; Clause 5.4 worker consultation).

6. ISO — ISO 7101:2023 Healthcare Organization Management (service-user focus and review inputs).

7. ISO — ISO 19011:2026 Guidelines for auditing management systems (fourth edition, May 2026).

8. CQI / IRCA — ISO 19011:2026 revision briefing, confirming the guidance took effect on publication with no transition period.

9. LRQA — ISO 9001 revision update: publication date confirmed (16 September 2026; three-year transition anticipated).

10. DQS — ISO 9001:2026 transition guidance (2015 certificates expected to remain valid to 30 September 2029, subject to confirmation).

11. Bureau Veritas — ISO 9001:2026 officially published (transition arrangements to be determined by accreditation bodies).

12. U.S. FDA — Quality Management System Regulation (QMSR), effective February 2, 2026.

13. eCFR — 21 CFR Part 820, Quality Management System Regulation.

14. Federal Register — QMSR Final Rule (2024-01709).

15. ASQ — ISO 9001 quality resources.

16. AAMI — Association for the Advancement of Medical Instrumentation.

17. ANAB — ANSI National Accreditation Board.

18. Global Accreditation Cooperation (Global ACI) — the international accreditation authority that succeeded IAF and ILAC, effective January 1, 2026: global-aci.org.

Clause references are provided so you can locate each requirement in your own licensed copy of the standard; the standards themselves are not reproduced. Standards are revised, amended and withdrawn — confirm current status at iso.org before relying on any clause reference.


ABOUT MANAGEMENT SYSTEMS INTERNATIONAL (MSI)

Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a veteran-owned, female-owned consulting firm she founded in 1998. With 28 years of experience, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality.

To pressure-test your organization’s management review procedure against the clause list you are certified to — and the one you will be certified to by 2029 — call 760-434-9141 or visit msi-international.com.


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply