management-review

Generate ISO 27001:2022 Management Review Minutes with inputs, outputs, and action logs.

Updated Apr 28, 2026
One-click install
npx skills add https://github.com/gombing/ISO27001Agent --skill management-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: management-review
Source: https://github.com/gombing/ISO27001Agent/tree/main/management-review
Command: npx skills add https://github.com/gombing/ISO27001Agent --skill management-review

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Streamlines the ISO 27001:2022 Management Review (Clause 9.3) by collecting mandatory inputs, guiding facilitator discussion, and producing auditable minutes that demonstrate management engagement.

Core Features & Use Cases

  • Guides the facilitator through loading prior work and compiling inputs (I1–I10) and outputs (O1–O3) for the management review.
  • Generates Management Review Minutes with attendee lists, decisions, and a signed-off action log suitable for auditor review.
  • Supports audit-readiness workflows by aligning with prior MR artifacts (prior actions, risk status, NCRs, audit findings) and producing traceable documentation.

Quick Start

Run the management-review skill after starting an engagement to generate auditable minutes that capture inputs, decisions, and actions.

Frequently Asked Questions about management-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prepare ISO 27001 management review minutes for Clause 9.3 audit readiness?

ISO 27001 management review minutes must capture mandatory inputs from I1 to I10 and outputs from O1 to O3 to satisfy Clause 9.3 compliance. The process compiles prior audit findings, risk status, and NCRs into a signed-off action log that ensures full audit traceability.

What inputs are required for an ISO 27001 Clause 9.3 management review?

An ISO 27001 Clause 9.3 management review requires mandatory inputs I1 through I10, including prior action logs, risk status, and audit findings. Compiling these inputs ensures the resulting minutes document necessary decisions and produce compliant outputs O1 through O3 for audit readiness.

How do I generate an action log and sign-off section for ISMS management review minutes?

Generating an action log and sign-off section for ISMS management review minutes involves loading prior work artifacts and aligning them with current decisions. This ensures the final document includes attendee lists, documented actions, and sign-offs suitable for auditor review and continual improvement tracking.

Can I automate compiling prior audit findings and NCRs for ISO 27001 continual improvement meetings?

You can automate compiling prior audit findings and NCRs for ISO 27001 continual improvement meetings by loading previous artifacts into a structured workflow. This aligns prior actions and risk statuses to produce traceable management review minutes that satisfy audit requirements.

What is the best way to document management engagement for ISO 27001 internal audits?

The best way to document management engagement for ISO 27001 internal audits is to generate formal management review minutes that record attendee lists, decisions, and a signed-off action log. This demonstrates active management involvement and ensures compliance with Clause 9.3 requirements.

Do I need prior risk management documents to generate ISO 27001 management review minutes?

You need prior risk management documents, including risk statuses and previous nonconformities, to generate compliant ISO 27001 management review minutes. Loading these prior artifacts ensures the review accurately reflects continual improvement and satisfies mandatory Clause 9.3 inputs.