Why Your ISO Management Review Procedure Must Drive Results


The Strategic Review · ISO 9001 · 14001 · 45001 · 13485

An ISO management review procedure is the documented method top management uses to judge whether the management system is genuinely working — and done well, it turns a once-a-year compliance meeting into the most strategic conversation leadership has all year. Most organizations treat the review as a box to tick. The ones that build a deliberate ISO management review procedure use the same hour to find risks early, redirect resources, and prove to auditors that leadership is actually steering the system.

Direct Answer

An ISO management review procedure is a documented, repeatable process by which top management evaluates the suitability, adequacy, and effectiveness of the management system at planned intervals. ISO 9001 Clause 9.3 — and its equivalents in ISO 14001, ISO 45001, and ISO 13485 — does not require a written procedure, yet a clear one is what separates a system that drives results from one that merely survives the audit. This guide gives you the proven 15-step framework to build it.

What you will learn in this guide:

  • The 15-step framework for a review process that works in practice, not just on paper
  • Exactly what ISO 9001 Clause 9.3 asks you to review, and how to gather data that drives decisions
  • What the 2026 wave of standards revisions changes for the review — and what stays the same
  • How the review works in multi-site, multi-standard, and public-sector organizations
  • How to run the meeting so leadership makes real decisions, and how to avoid the six mistakes that hollow it out

ISO management review procedure


The Fundamentals

What Is an ISO Management Review Procedure?

Define. Document. Decide.

Direct Answer

An ISO management review procedure is the formal, scheduled process where top management evaluates the performance, adequacy, and effectiveness of the whole management system — not daily activities. It is a strategic leadership session, and a disciplined ISO management review procedure is what makes that session produce decisions instead of status updates.

A management review procedure describes the formal, scheduled meeting where top management evaluates the performance, adequacy, and effectiveness of the management system. Think of it as a strategic board meeting focused on the system that runs your quality, environmental, safety, or medical-device operations. The review is not about daily activities; it is about whether the system as a whole is still fit for purpose. That distinction is the heart of a strong review process.

Management review versus operational review. A management review assesses your system. An operational review assesses your daily activities. Confusing the two is the single fastest way to turn a leadership conversation into a status meeting. Under ISO terminology, the management review sits at the leadership level and answers one question: is this system delivering what the organization needs?

Other names you will hear. Executive Strategy Session, Leadership Review Meeting, Strategic Review Meeting, Top Management Review Session. Whatever the label, the underlying ISO management review procedure should look the same: defined inputs, defined attendees, defined outputs, and a documented trail of decisions. The name your organization uses matters far less than the discipline behind it, and consistency in that discipline is what auditors and leaders both come to rely on. That is also why the review sits at the center of every integrated management system MSI helps design.


Beyond Compliance

Why Does Your Management Review Procedure Matter Beyond Compliance?

Strategic. Operational. Cultural.

According to the ISO management system standards, the review must evaluate whether the system remains suitable, adequate, and effective. A well-built ISO management review procedure goes further: it converts that requirement into a forum where leadership actually acts. MSI client experience suggests that organizations which treat the review as a working session, rather than a formality, get measurably more value from the same standard.

Strategic benefits of a real review process

  • System performance evaluation: identify what is working and what needs improvement across the whole management system.
  • Risk and opportunity management: address risks before they become problems, in line with ISO 9001 Clause 6.1.
  • Resource optimization: make data-driven decisions about where people, budget, and attention go next.
  • Strategic alignment: ensure the management system supports the business objectives leadership actually cares about.

Operational and cultural gains

Beyond strategy, an effective review surfaces process inefficiencies, tracks customer-satisfaction trends, and gives teams a structured voice in system improvements. Culturally, it embeds quality thinking at the leadership level and holds departments accountable for the metrics they own. Organizations typically report that the discipline of preparing for a serious review improves the data itself, because owners know their numbers will be examined.

The bottom line: organizations that run a rigorous ISO management review procedure do not just keep their certificate. They use the system to outperform, because the review forces leadership to look at evidence and decide. That mindset connects directly to MSI’s broader work on the quality management mindset and the leadership case for ISO certification. Across 28 years and 200+ audits attended, the pattern MSI sees most consistently is that review quality predicts system quality better than any other single indicator.

Leadership team discussing an ISO management review procedure and results


Clause 9.3

What Does ISO 9001 Clause 9.3 Require in a Management Review?

Inputs. Evaluation. Outputs.

Direct Answer

A compliant ISO management review procedure must cover the inputs Clause 9.3 names: status of prior actions, changes in internal and external issues, performance and effectiveness information, adequacy of resources, effectiveness of actions taken on risks and opportunities, and opportunities for improvement. The review then produces outputs — decisions on improvement, changes to the system, and resource needs.

Different standards phrase the inputs slightly differently, so any ISO management review procedure should map directly to the clause your organization is certified against. The framework below works for ISO 9001 , ISO 14001, ISO 45001, and ISO 13485, and it integrates cleanly when you hold one combined review.

ISO 9001 requires reviewing, at minimum:

  • Status of actions from previous reviews
  • Changes in external and internal issues relevant to the management system
  • Customer satisfaction and feedback from interested parties
  • Performance against quality objectives
  • Process performance and conformity of products and services
  • Nonconformities and corrective actions
  • Monitoring and measurement results
  • Internal and external audit results
  • Performance of external providers and suppliers
  • Adequacy of resources
  • Effectiveness of actions taken to address risks and opportunities
  • Opportunities for improvement

An experienced procedure does not stop at listing these inputs. An effective ISO management review procedure assigns each input an owner, a data source, and an analysis expectation, so the meeting reviews insight rather than raw numbers. The list of internal and external issues feeding this review comes straight from your organizational context analysis — a weak context document produces a thin review.

Skip the Blank Page

Twenty-eight years of practice, written down

MSI’s ISO Procedure Templates & Guides cover 15 procedure topics across five standards and combinations, in editable Word — with the judgment calls already made. Management review is one of them, and it arrives already mapped to the clause it has to satisfy.

See the ISO Procedure Templates & Guides →


What's Changing in 2026

How Do the 2026 Standards Revisions Affect Your Management Review?

Climate. Evidence. Currency.

2026 has been the busiest revision year in a decade, and three changes touch the review directly. A procedure written against the 2015-era inputs alone will start to show gaps at surveillance, so build the new expectations into your ISO management review procedure now rather than retrofitting them later.

ISO 9001:2026 — publication is now dated

ISO 9001:2026 publishes on September 16, 2026, with a three-year transition window to follow. The technical content was frozen at the Final Draft International Standard ballot stage, so the direction is known rather than speculative. The most discussed change adds climate-change considerations to the Clause 4.1 context requirement. Because context is a named review input, your ISO management review procedure will need to show that leadership has considered whether climate is a relevant issue for the quality system — and recorded the conclusion either way. MSI’s briefing on the ISO 9001:2026 ethics and culture update and the boardroom view of the revision walk through what executives should expect.

ISO 19011:2026 — how audit results reach the review

ISO 19011:2026, the guidance standard for auditing management systems, published on May 27, 2026 and withdrew the 2018 edition immediately, with no transition period. The seven audit principles are preserved, but the new edition integrates remote and hybrid auditing throughout and treats digital records as primary evidence. Since internal and external audit results are a required review input, the way those findings are gathered and verified now feeds your ISO management review procedure with a stronger evidence trail. See MSI’s coverage of internal audit planning under ISO 19011:2026 and the ISO 19011:2026 internal audit procedure for the upstream detail.

ISO 14001:2026 — the review clause itself moved

ISO 14001:2026 published on April 15, 2026, with ISO 14001:2015 withdrawn and a transition deadline of April 30, 2029. This is the revision that changes the review itself, not just its inputs. The fourth edition splits Clause 9.3 into general requirements, review inputs, and review results, and it names two outputs that the 2015 edition did not: opportunities to improve integration of the environmental management system with other business processes, and any implications for the strategic direction of the organization. It also adds a standalone planning-of-changes clause (6.3) with no 2015 predecessor — the requirement that clause-mapping transitions quietly drop, because there is nothing in the left-hand column to map from.

For any organization holding an environmental certificate, transition status is now a standing review item: where are you in the migration, what remains open, and who owns closing it? A review that ignores an open transition is exactly the kind of finding a registrar writes up. MSI’s complete guide to the ISO 14001:2026 updates, its work on the revised environmental aspects register, and its analysis of ISO 14001 continual improvement cover the downstream detail. If you hold both certificates, the combined ISO 9001 and 14001 transition is meaningfully cheaper run as one project than two.

For EHS Managers on the 2029 Clock

Move Your EMS From 2015 to 2026 in a Week

The ISO 14001:2026 Procedure Templates & Guides are built for an experienced environmental manager who already runs a working system and needs it current — the full procedure library in editable Word, including the restructured management review and the new Clause 6.3 change process, plus the clause-by-clause transition course.

Get the ISO 14001:2026 Templates →


Across Standards

How Does the Review Differ Across ISO 9001, 14001, 45001, and 13485?

Same spine. Different inputs.

Direct Answer

One ISO management review procedure can serve ISO 9001, 14001, 45001, and 13485 because all four ask top management to review the same core: system performance, audit results, actions, and improvement. Each standard simply adds its own emphasis, so a single ISO management review procedure works as long as the agenda carries every standard’s required inputs and traces each to its clause.

ISO 9001, 14001, 45001, and ISO 7101 share the same management-review skeleton because they are all written to the Harmonized Structure — the common clause architecture and core text that lives in Appendix 2 of Annex SL to the ISO/IEC Directives, Part 1. (It was called the High Level Structure until 2021; the annex itself has always been Annex SL.) ISO 13485 is the exception: it keeps its own pre-Annex SL numbering and does not share that architecture at all, though its management-review clause asks for the same discipline. The differences live in the inputs each standard emphasizes, which is why one ISO management review procedure can serve an integrated system as long as it carries every required topic.

ISO 9001 (quality) centers on customer satisfaction, conformity of products and services, process performance, and supplier results. ISO 14001 (environmental) adds compliance obligations, significant environmental aspects, environmental performance against objectives, and communications from interested parties including complaints. ISO 45001 (health and safety) brings in incident and near-miss data, the results of worker participation and consultation, and the effectiveness of hazard controls. ISO 13485 (medical devices) layers in regulatory feedback, complaint handling, reporting to authorities, and post-market surveillance, reflecting the controlled environment device organizations operate in. ISO 7101 (healthcare quality) adds patient safety, workforce wellbeing, and health-outcome measures to the same spine.

When you hold one combined review, the agenda should make the source standard for each input explicit, so an auditor can trace any line back to its clause. MSI client experience suggests that integrated reviews work best when the data owner for each standard presents that standard’s inputs in sequence, rather than blending everything into one undifferentiated summary. For a device-specific walkthrough, see MSI’s guide to a first medical-device management review under ISO 13485.

Leadership Owns This Clause

The management review is top management’s responsibility — and where most systems live or die. MSI’s Inspired Leadership Workshop equips ISO 9001 and 13485 leaders to own their role in the system instead of delegating it.

Explore the Inspired Leadership Workshop →


Scale and Structure

How Does an ISO Management Review Procedure Work Across Multiple Sites and Standards?

Sites. Standards. Sequence.

Direct Answer

In a multi-site organization, one ISO management review procedure should define two tiers: local reviews that examine site-level performance, and a central review where top management sees the aggregate and decides. The central review is the one the certificate depends on, so the procedure must state what each site sends upward, in what format, and by when — otherwise the central meeting becomes a reading exercise instead of a decision-making one.

Most published guidance on management review implicitly assumes a single company at a single address with one certificate. A great many certified organizations are nothing of the sort: they are networks, agencies, hospital systems, and multi-country operations holding several standards across many locations. The clause does not change for them. The logistics change enormously, and the ISO management review procedure is where those logistics have to be settled in writing.

Two tiers: what rolls up and what stays local

Site-level reviews handle what site leadership can act on: local objectives, local nonconformities, local audit findings, local resources. The central review handles what only top management can act on: system-wide trends, cross-site patterns, resource reallocation, changes to policy and strategic direction. A workable ISO management review procedure names the split explicitly and gives each site a standard reporting template, so twelve sites do not arrive with twelve formats.

The failure mode here is predictable: sites report activity, headquarters receives volume, and nobody sees the pattern. The fix is to require analysis at the site level and comparison at the central level. A nonconformity trend that appears at three sites independently is a system issue; the same trend at one site is a site issue. Only a structured roll-up makes that distinction visible. MSI’s work on connected quality management across multi-site networks develops this architecture in detail.

Public-sector and mission-driven organizations: the review without a sales number

Government agencies, public institutions, and international organizations certify to ISO standards at scale, and the review looks different when there is no revenue line to anchor the conversation. ISO 14001 was originally devised for the private sector but is now widely used in the public one: the United Nations Global Service Centre earned ISO 14001 certification for its operations in Brindisi and Valencia following a system-wide commitment to implement environmental management systems, and other UN entities have since certified and recertified. The U.S. Environmental Protection Agency publishes similar guidance for public bodies running an EMS.

For these organizations the ISO management review procedure has to substitute mission metrics for commercial ones. “Customer satisfaction” becomes beneficiary, constituent, or patient feedback. “Interested parties” includes oversight bodies, donors, member states, and the communities an operation sits inside. Resource adequacy is a budget-cycle conversation with a different rhythm than a corporate one, which usually means the review calendar has to be pinned to the funding calendar rather than to the audit calendar. None of this is a departure from the clause. It is the clause, read honestly against a different kind of organization — the same discipline MSI applies across manufacturing, technology, medical device, government, and healthcare work.

Transition status belongs on the standing agenda

Two clocks are running simultaneously: ISO 14001:2026 with an April 30, 2029 deadline, and ISO 9001:2026 publishing September 16, 2026 with its own three-year window. According to the ISO Survey, there are well over two million valid certificates to those two standards worldwide, every one of them currently against a 2015 edition. A single-site organization transitions one certificate through one audit cycle. A thirty-site network transitions thirty, through a finite pool of auditors who must be re-accredited themselves first.

That arithmetic is why transition status earns a permanent line on the ISO management review procedure agenda for the next three years, rather than an occasional update. The review is also where the evidence gets made: a registrar generally wants to see a revised system actually run — generating records, driving controls, getting sampled in an internal audit, and reaching a management review — before transitioning the certificate. Working backward from that requirement rather than from the deadline is what separates organizations that transition calmly from those that do it twice. A self-scored ISO 14001 readiness assessment is a reasonable place to start the standing report.


The Framework

How Do You Build an ISO Management Review Procedure? The 15-Step Process

Plan. Build. Sustain.

This is the core of the guide: a proven 15-step ISO management review procedure that works across ISO 9001, ISO 14001, ISO 45001, and other management-system standards. Build the ISO management review procedure once, and the same structure carries every review you run.

Step 1: Start From Your Controlled Procedure Template

Begin your ISO management review procedure in the organization’s standard document format so it slots into existing document control. Include a header with document-control information, a purpose and scope section, roles and responsibilities, the process flow, and a records-and-references list. Consistency with the rest of your ISO consulting documentation matters more than elegance, and the same logic applies to the manual that sits above it.

Step 2: Identify the Process Owner

Assign one role to own the ISO management review procedure, typically the Quality Manager, Environmental Manager, or whoever owns the system. The owner schedules and coordinates reviews, gathers data from departments, prepares the agenda, documents decisions and action items, and tracks follow-up between meetings.

Step 3: Map the Standard’s Requirements

Study your applicable standard and list every required input. Anchor the ISO management review procedure to the exact clause, because that mapping is what an auditor will trace. For combined systems, build one table that shows which input satisfies which standard’s clause — and check it against the current edition, not the one you implemented against.

Step 4: Expand the Scope to Cover Leadership Clauses

A well-designed ISO management review procedure can efficiently address several leadership requirements in one document:

  • Roles, responsibilities, and authorities (Clause 5.3)
  • Communication requirements (Clause 7.4)
  • Quality or environmental policy (Clause 5.2)
  • Objectives and planning (Clause 6.2)
  • Planning of changes (Clause 6.3)
  • Resource management (Clause 7.1)
  • Risk and opportunity management (Clause 6.1)
  • Monitoring and measurement (Clause 9.1)

Step 5: Assign Data Requirements to Department Owners

Every required input needs a named owner responsible for collecting, analyzing, and presenting it. Spell out who owns what:

Data Requirement Owner Source Analysis Required
Customer feedback Customer Service Manager CRM, complaint logs Trends, satisfaction scores
Nonconformities Quality Manager CAPA system Types, frequency, root causes
Audit results Quality Manager Audit reports Findings, action status
Process performance Operations Manager KPI dashboards Metrics vs. targets
Supplier performance Procurement Manager Supplier scorecards Quality, delivery ratings
Compliance obligations EHS Manager Permits, legal register Status, evaluation results
Training effectiveness HR Manager Training records Completion, competency gaps

Direct each owner to pull data from the past six months (or since implementation for new systems), show trends graphically, compare actual performance to targets, reference open corrective actions, and be ready to explain results. That preparation is where the review earns its keep.

Step 6: Define Required Attendees and Quorum

Specify attendees by role, not by name, so the procedure survives staff turnover and keeps the ISO management review procedure intact. Typical required roles include the CEO or General Manager and the Quality Manager, with Operations, Sales or Customer Service, Production, and HR represented. A workable quorum is the CEO plus the Quality Manager plus at least half of department heads.

Step 7: Set the Review Interval

MSI recommendation: for most organizations, a six-month (bi-annual) cadence works best. Six months is long enough to see trends, aligns with typical surveillance-audit cycles, and is frequent enough to act proactively. Organizations undergoing rapid change may move to quarterly; very stable, mature systems may use annual reviews as the minimum the standard allows.

Step 8: Schedule Reviews Strategically

Do not leave timing to chance. Build the review into the corporate calendar: schedule two to three months before surveillance audits, allow time for internal audits to cover the review process itself, avoid busy-season conflicts, and block two to four hours depending on organization size. Pre-setting the dates protects executive attendance.

Step 9: Create Controlled Agenda and Presentation Formats

Standardized templates keep the ISO management review procedure consistent. A complete agenda covers, in order: previous action items, changes affecting the system, customer-satisfaction data, objectives performance, process metrics, nonconformities and corrective actions, internal and external audit results, supplier performance, resource adequacy, risk and opportunity updates, improvement opportunities, and decisions. Distribute the agenda one week in advance and require attendees to come prepared.

Step 10: Document Training Requirements

Specify how personnel are trained on the ISO management review procedure: purpose and importance, roles and responsibilities, data-collection and analysis expectations, how to present, and how to contribute. Provide initial training for new managers, an annual refresher, and one-on-one coaching for presenters. Structured internal auditor training and the ISO Internal Auditor Workshop reinforce the same discipline.

Step 11: Define Process KPIs

Measure whether the ISO management review procedure itself is effective. Useful KPIs include:

  • Percentage of action items completed on time
  • Number of improvement opportunities identified
  • Attendance rate (target 90 percent or higher)
  • On-time review completion (target 100 percent)
  • Audit findings related to management review (target zero)
  • Number of strategic decisions made per review

Step 12: Plan Employee Communication

Decide which outputs get shared organization-wide: overall performance trends, major achievements, strategic-direction changes, planned resource investments, and recognition of department successes. Keep confidential strategy, personnel issues, sensitive financials, and competitive intelligence out of the general communication. Channels include town halls, internal newsletters, department meetings, and the intranet.

Step 13: Establish the Minutes Process

Clear minutes are the evidence trail of any ISO management review procedure. Assign a dedicated note-taker who is not presenting, record the meeting where permitted, and consolidate action items in a trackable format that captures decision, owner, due date, and status. Finalize minutes within one week and distribute to attendees and relevant stakeholders. Maintain a master action log reviewed at the start of every review.

Step 14: List Associated Records and Documents

Document the records and reference documents tied to the ISO management review procedure: agendas, minutes, presentation and data packages, action-item logs, and attendance sheets, plus related documents such as the policy, context analysis, risk and opportunity register, strategic plan, and prior audit reports. A clean reference list makes the procedure auditable at a glance.

Step 15: Review, Approve, and Publish the Procedure

Before finalizing, compare it against the standard’s requirements, review it with key stakeholders, and pilot the format with one practice review. Submit it to top management for approval, keep a record of that approval, publish it in an uneditable format on the organization network, assign a version number and date, and schedule periodic review. This closes the loop that document control expects.

MSI Management Review Tool Kit supporting an ISO management review procedure


Execution

How Do You Conduct an Effective Management Review?

Prepare. Probe. Pursue.

Having a procedure is one thing; executing it well is another. The difference between a review that works in practice and one that fails in practice is whether leadership engages with evidence and commits to action. Use these habits to keep the meeting delivering.

Before the meeting

  • Distribute materials one week early so attendees can read them.
  • Set the expectation that this is strategic discussion, not information sharing.
  • Coach presenters on analysis, not data dumps.
  • Plan to remove distractions so the room stays focused.

During the meeting

  • Start on time and follow the agenda, allowing room for important discussion.
  • Ask probing questions: why did this happen, what is the root cause, what is the impact if we do not act?
  • Make decisions in the room rather than deferring everything.
  • Assign accountability: every action gets an owner and a due date.
  • Draw out quiet voices and manage dominant ones.

After the meeting

Finalize minutes within one week, communicate decisions promptly, track action items monthly rather than waiting six months, update documentation if the process changed, and inform employees of outcomes that affect them. This rhythm is what turns a static ISO management review procedure into a living management practice. The quality management mindset treats the review as a continuous state, not a calendar event.


What To Avoid

What Are the Most Common Management Review Mistakes?

Spot. Stop. Strengthen.

Even a documented ISO management review procedure can fail in practice. These six patterns are the ones MSI sees most often across 200+ audits attended, and each has a straightforward fix.

Mistake 1: Treating it as audit prep

Running the review only just before an external audit reduces it to a checkbox. The fix: schedule reviews on a consistent cadence regardless of audit timing, and use the review for business improvement, not last-minute preparation.

Mistake 2: Data dump without analysis

Presenters show raw numbers with no interpretation. The fix: require owners to analyze trends, compare to targets, identify root causes, and propose actions. The review should answer “what does this mean?” not “here are the numbers.”

Mistake 3: No follow-through on actions

Decisions are made, then nothing happens before the next review. The fix: a robust action-tracking system reviewed monthly, with owners held accountable and delays escalated. Disciplined internal audit follow-up often surfaces these stalled actions first.

Mistake 4: Wrong people in the room

Sending delegates instead of decision-makers strips the meeting of authority. The fix: make attendance mandatory for top management, include cross-functional representation, and ensure attendees can actually decide.

Mistake 5: Wrong frequency

Annual reviews miss issues; monthly reviews do not give trends time to form. The fix: a six-month cadence for most organizations, adjusted to your rate of change. Build the interval into the ISO management review procedure so it is not negotiable.

Mistake 6: Poor documentation

Weak minutes make it impossible to track decisions or demonstrate conformity. The fix: a dedicated note-taker, templates, recordings where possible, and prompt distribution. A disciplined records habit keeps the ISO management review procedure defensible.


The Evidence Trail

What Do Auditors Actually Look For in a Management Review?

Inputs. Decisions. Outputs.

Direct Answer

Auditors checking an ISO management review procedure look for four things: every clause-required input present with data behind it, top management actually in the room, documented decisions with owners and dates, and closed-loop follow-through on prior actions. An ISO management review procedure that runs well produces all four as a natural byproduct.

A registrar is not grading the polish of your slides. They are confirming that the review covered every required input, that top management was genuinely engaged, and that the meeting produced decisions and actions the organization then followed through on. An ISO management review procedure that works in practice produces that evidence naturally; one that exists only on paper leaves visible holes.

In line with the principles in ISO 19011:2026, auditors typically trace four things:

  • Completeness of inputs. Every clause-required input is present in the minutes, with data behind it, not just a heading.
  • Top-management presence. Attendance records show decision-makers in the room, not delegates standing in.
  • Documented outputs. The review produced decisions on improvement, system changes, and resource needs, each with an owner and date.
  • Closed-loop follow-through. Actions from the previous review were tracked, and their status is reviewed at the start of the next one.

Accreditation is now coordinated through Global ACI, the single body that unified the former International Accreditation Forum and International Laboratory Accreditation Cooperation on January 1, 2026, working alongside national accreditation bodies such as ANAB. Registrars are held to consistent expectations, so the same evidence trail satisfies reviews wherever you are certified. Internal teams preparing this evidence often lean on guidance from the Institute of Internal Auditors, the American Society for Quality, and a Baldrige-style performance lens to pressure-test how decisions are made. Build the ISO management review procedure so that completeness, engagement, decisions, and follow-through are produced as a byproduct of running it well, and the audit takes care of itself. When you want that verified before the registrar sees it, MSI’s internal audit services do exactly that.


Build It Faster

Management Review Toolkits: Your ISO Management Review Procedure, Ready to Customize

Template. Tailor. Transform.

Building an ISO management review procedure from scratch takes real time and expertise. MSI’s Management Review Toolkits give you the finished procedure for your standard, plus agenda and presentation formats that cover every required input, department data-collection worksheets, minutes templates with action-item tracking, training materials, example KPIs, and communication templates. MSI client experience suggests the structure alone removes the guesswork that causes missed inputs — which is the most common management review finding of all.

Choose the Toolkit That Matches Your Standard

One page, every version: ISO 9001, ISO 13485, ISO 14001, ISO 45001, and combined systems. Each toolkit contains the procedure, the agenda, the presentation deck, sample minutes, and the data worksheets — already mapped to the clause your registrar will trace.

Browse the ISO Management Review Toolkits →

Already know you need the quality version? Go straight to the ISO 9001 Management Review Tool Kit.


Questions Answered

Frequently Asked Questions About the ISO Management Review Procedure

Ask. Answer. Apply.

Do I really need a written ISO management review procedure?

Direct Answer: ISO standards do not explicitly require a documented ISO management review procedure, but it is strongly recommended. A written procedure ensures consistency, prevents missing required inputs, protects continuity when personnel change, guides new managers, and gives auditors clear evidence of a systematic approach.

How long should a management review take?

Direct Answer: A typical review under a complete ISO management review procedure runs two to four hours, depending on organization size and complexity. If reviews consistently exceed four hours, the agenda is covering operational detail rather than strategic trends.

Can we combine reviews for multiple ISO standards?

Direct Answer: Yes, and it is recommended. One integrated ISO management review procedure covering ISO 9001, ISO 14001, and ISO 45001 saves leadership time, gives a holistic view, and reveals how the systems interact. Use a combined agenda mapped to each standard’s clause so an auditor can trace every line.

How does the review work across multiple sites?

Direct Answer: Use two tiers. Site reviews handle local objectives, findings, and resources; a central review handles system-wide trends, cross-site patterns, and decisions only top management can make. The ISO management review procedure should state what each site reports upward, in what template, and by when, so the central meeting compares rather than reads.

What changed for management review in ISO 14001:2026?

Direct Answer: The fourth edition restructures Clause 9.3 into general requirements, inputs, and results, and names two review outputs the 2015 edition did not: opportunities to improve integration of the environmental management system with other business processes, and any implications for the strategic direction of the organization. Your ISO management review procedure should add both, plus the new Clause 6.3 planning-of-changes requirement, before your first transition audit.

What is the difference between a management review and an operational review?

Direct Answer: A management review is strategic: top management evaluates system effectiveness and direction every six to twelve months under a defined ISO management review procedure. An operational review is tactical: department managers handle daily-to-monthly process metrics and immediate corrective actions.

How do I get top management to take reviews seriously?

Direct Answer: Frame the review as a business tool, not compliance. Bring meaningful, actionable data, keep the agenda efficient, demonstrate value by tracking outcomes from previous reviews, ensure the meeting produces concrete decisions, and link system performance to the objectives leadership already cares about. A well-run ISO management review procedure earns its place on the calendar.

Should pre-certification organizations run management reviews?

Direct Answer: Yes. Even before certification, running the ISO management review procedure builds leadership habits, identifies readiness items before the certification audit, creates documentation that demonstrates maturity, and establishes routines that serve the organization long after the certificate arrives.

Can management reviews be conducted virtually?

Direct Answer: Yes. Virtual reviews are acceptable and common, especially for multi-site and multi-country organizations. ISO 19011:2026 treats remote and hybrid methods as mainstream, so a remote review works best with video on, materials shared in advance, screen sharing for data, a recorded session where consent allows, and collaborative action-tracking tools.


Take Action

Turning Your ISO Management Review Procedure Into Results

Decide. Deploy. Deliver.

A well-designed ISO management review procedure is not about satisfying a clause. It is about creating a discipline of strategic reflection that drives continual improvement — the same principle that runs through every proven ISO 9001 system. When executed properly, the review becomes the control room where leadership makes informed decisions about the organization’s future. The 15-step framework gives you the blueprint; your commitment gives it momentum.

Your action plan: build the ISO management review procedure from the 15 steps above, customize the templates to your structure and standards, train your team on the process and their roles, schedule your first review, and refine it after each cycle. If you want hands-on help standing it up, MSI consultants can guide the build and prepare your team through SurePath, and the same discipline carries forward into ongoing maintenance through SureResults, which keeps the management system audit-ready year-round.

The long-term payoff compounds. The first cycle establishes the rhythm; by the third or fourth, the data improves because owners know it will be examined, decisions land faster because leadership trusts the format, and improvement actions stop slipping because tracking is built in. Organizations typically report that the review shifts from an obligation that consumes a morning to a meeting leadership protects on the calendar, because it is where they get the clearest, most honest read on how the operation is actually performing. That is the difference between a procedure that satisfies a clause and one that quietly becomes a competitive advantage.

Want a Procedure That Drives Improvement?

Start with the Management Review Toolkit for your standard, or widen out to the full ISO Procedure Templates & Guides library. To talk it through with a consultant first, call MSI at 760-434-9141 and book a planning session.

Browse the Management Review Toolkits →

See All ISO Procedure Templates & Guides →

Across 28 years of ISO consulting, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries — the experience encoded into every template in the toolkits. To talk through your review with a consultant, call 760-434-9141.


Keep Reading

Related MSI Guides on Management Reviews and Audits

Internal Audit Planning: Why Proven Methods Always Win

How audit results — a required review input — are planned and sequenced under ISO 19011:2026.

Internal Audit Follow-Up

Where audit findings go after the report closes — and how that feeds the next review.

ISO 9001 and 14001 Transition: Why One Plan Wins

Running both 2026 transitions as one project, including the restructured management review clause.

Connected Quality Management: The Proven Multi-Site Model

How multi-site networks roll site data up into one review leadership can actually act on.

First Medical-Device Management Review Under ISO 13485

The device-specific inputs that make a 13485 review different from a 9001 one.

ISO 9001:2026 Update: Ethics and Culture

What the September 16, 2026 revision adds to context, leadership, and the review.

MSI Internal Audit Services

When you want an experienced auditor to validate the system before the registrar does.

References and Authoritative Sources


About Management Systems International (MSI)

Management Systems International (MSI) is a veteran-owned, female-owned ISO consulting firm founded in 1998. With 28 years of experience including extensive AS9100 work in MSI’s early years, MSI’s track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries.

Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality. msi-international.com · 760-434-9141


Share this post:
post by:
Picture of Diana Lynn

Diana Lynn

Founder and Principal of Management Systems International (MSI), a veteran-owned, female-owned ISO consulting firm she founded in 1998. Diana implements management systems, conducts audits, and develops MSI's entire training curriculum — 80+ organizations certified, 200+ audits, and 600+ professionals trained across manufacturing, technology, aerospace, medical device, government, healthcare, defense, and other regulated industries.
In This Guide
Stay Informed

Join our early-access list for ISO 14001:2026 briefings.

Trusted by Global Leaders

Don't miss our latest news!

Get on our Email list. MSI emails new offers, training dates, and ISO updates to our list before anyone else.

Twenty-eight years of practice, written down.
New: complete ISO procedure templates and guides. 15 procedure topics, five standards and combos, editable Word — with the judgment calls already made.
See the templates →

Buy any Template Packages and the price is credited 100% to ISO Consulting Projects, SurePath or SureResults Online or Traditional. Terms apply