Why must management review be conducted before a certification audit?
- A.To impress the auditor
- B.It demonstrates top management involvement and ISMS governance, which is a mandatory requirement auditors will verify
- C.It is not required. Annex A control 8.27 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- D.Only for documentation. Clause 8.2 requires this evidence to be retained for the full three-year certification cycle following the surveillance audit.
Why B is correct
Management review is a mandatory ISO 27001 requirement that demonstrates top management engagement. Auditors will verify that reviews have been conducted with appropriate inputs and outputs.
Know someone studying for ISO 27001? Send them this one.