Management review of your AI management system: inputs, outputs and frequency (ISO 42001 clause 9.3)

Compliance9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

The management review is the part of ISO 42001 that most organisations throw together at the last minute. An hour in the calendar, a slide deck with some numbers, minutes written afterwards. Auditors see through that quickly, because clause 9.3 is fairly precise about what has to be on the table and what has to come out of it. This article walks through the three sub-clauses and describes what you actually need.

What clause 9.3 asks of you

The standard splits the management review into three parts. Clause 9.3.1 says top management reviews the AI management system at planned intervals for continuing suitability, adequacy and effectiveness. Clause 9.3.2 sets out the topics that have to be considered. Clause 9.3.3 covers what has to come out: decisions and actions on improvement, on changes to the AIMS including resource needs, and on updated risk assessments.

Those three words in 9.3.1 form the frame for the review. Suitability is about whether the AIMS still fits what the organisation does with AI. Adequacy is about resources, people and competencies: is there enough to keep the system running? Effectiveness is about whether the AIMS achieves its purpose, which for ISO 42001 means AI systems that are developed and used responsibly. A review that only walks through compliance status touches at most one of the three.

Frequency and triggers

The standard sets no fixed interval. In practice almost everyone runs a full review at least annually, and that is what certification bodies expect. For organisations where AI moves fast, once a year is thin. A quarterly cycle with limited scope plus one full annual review tends to work better, because a resource decision does not have to wait eleven months.

There should also be events that trigger an extra review. A serious AI incident, a large-scale rollout of a new system, an acquisition, a regulatory change. Write down which events those are. An organisation that waits for the annual review after an incident with a discriminatory model is showing that its steering does not work.

Who sits at the table

Clause 9.3.1 refers to top management, and that is where a common nonconformity sits. The review gets delegated to the compliance manager, the CISO or the AI governance lead, and the board receives a summary afterwards. Formally that does not meet the requirement, and substantively it does not work: decisions on budget, capacity and risk appetite belong with the people who can make them.

Keep attendance records. An auditor who doubts whether top management was really involved looks at the minutes: are there decisions in there that only top management can take, or only observations?

The inputs the standard expects

Clause 9.3.2 sets out what has to be considered. Translated into a practical input set, these are the topics.

The status of actions from previous reviews, with clear progress per action. This is the quickest way for an auditor to see whether the review is an instrument or a ritual.

Changes in external and internal issues affecting the AIMS. New or tightened AI regulation, shifting expectations from customers and regulators, and internally: new AI systems, reorganisations, changes in available expertise.

Information on AIMS performance and effectiveness, including trends in nonconformities and corrective actions. Alongside that: monitoring and measurement results from clause 9.1, internal and external audit results, and the extent to which the AI objectives from clause 6.2 were met.

Feedback from interested parties. For AI that means not only customers and regulators, but also the people affected by an AI system's output. Complaints, objections and requests for human review belong here.

The results of the risk assessment and the status of the risk treatment plan, including residual risk, plus improvement opportunities identified during the period.

In practice the best approach is to bundle these inputs into one input package that is circulated in advance, dated and retained. Then nobody has to improvise in the meeting, and you have the evidence ready for the audit.

What is AI-specific about the inputs

The difference from an ISO 27001 management review lies in the nature of the measurement data. Beyond availability and incidents you want figures on how the models themselves behave: performance indicators such as accuracy and error margins, drift signals in data or model behaviour, results of bias or fairness measurements across the groups you defined, and how often a human overrode an outcome.

That last number is surprisingly informative. If human oversight is in place but nobody intervened once in twelve months, the oversight exists on paper. If interventions happen in thirty percent of cases, something is wrong with the model or with where it is deployed.

The outcomes of AI system impact assessments (clause 6.1.4) also belong in the input package. They often get produced and then never reach a board again.

What has to come out of the review

Clause 9.3.3 asks for decisions and actions. Concretely: improvement actions with an owner, a deadline and a criterion that tells you when they are done. Decisions on changes to the AIMS, such as a revised AI policy, an adjusted scope or a modified procedure. Decisions on resources: budget for tooling, capacity for AI governance, training. And updated risk assessments, because the information from the review often changes the risk picture.

Minutes with the sentence "agreed to maintain focus on AI governance" are not an output. The difference between a good and a poor management review is almost always visible in how concrete the actions are.

The actions go into an action register and come back as input at the next review. Without that loop the review is a snapshot.

Common nonconformities

Our internal audits keep surfacing the same points. The review does not happen at planned intervals and gets postponed repeatedly. Top management is absent. There is no structured input package, so the review runs on verbal updates. The status of earlier actions is not tracked. AI-specific measurement data is missing and the review covers compliance status only. Decisions are too vague to follow up. And, strikingly often: records of earlier reviews were not retained, so the organisation cannot show what was decided before.

Documents an auditor will ask for

A procedure or description covering frequency, participants and method. The schedule or calendar invitations. The input package from the last review, dated. Attendance records. Minutes with decisions, actions, owners and deadlines. The action register with progress. And evidence that decisions were actually carried out: a revised policy, an approved budget, an updated risk assessment.

How we approach it

The internal audit module in our platform holds, per ISO 42001 norm element, the criterion, the interview questions we ask, a description of a well-implemented situation, the common nonconformities and the documents to expect. For clause 9.3 that means you can see in advance which evidence an auditor will request and set the review up accordingly, instead of reconstructing it afterwards. Get in touch if you want the management review of your AIMS assessed or set up.

Frequently asked questions

How often should the AIMS management review take place?+

ISO 42001 prescribes no fixed interval; it refers to planned intervals. In practice at least one full review per year is the norm, with additional reviews after events such as a serious AI incident, a major rollout or a regulatory change. Organisations with heavy AI activity often use a quarterly cycle with limited scope.

Who has to take part in the management review?+

The standard places responsibility with top management. Delegating to the compliance manager or AI governance lead does not meet the requirement, because decisions on budget, capacity and risk appetite belong at executive level. Record attendance, because auditors check this.

Which inputs must the management review consider?+

Among others: the status of actions from previous reviews, changes in external and internal issues, AIMS performance and effectiveness including trends in nonconformities and corrective actions, monitoring and measurement results, audit results, the extent to which AI objectives were met, feedback from interested parties, risk assessment results and risk treatment plan status, and improvement opportunities.

How does this differ from an ISO 27001 management review?+

The structure is largely the same, since both standards follow the same HLS layout. The difference is in the measurement data: ISO 42001 adds model performance and drift indicators, bias or fairness measurement results, the number of human interventions, and the outcomes of AI system impact assessments.

What has to be in the minutes of the management review?+

Decisions and actions with an owner, a deadline and a completion criterion. Plus decisions on changes to the AIMS, on resources such as budget and capacity, and on updated risk assessments. General observations without action do not satisfy clause 9.3.3.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us