Skip to content
Reviewed Jul 2026Knowledge base

Management review procedure

Adherence evidenced by 3 mapped controls

A quarterly, dated, written record that the security program's evidence was examined and what was decided, committed to the repository for a tamper-evident timestamp. The first review completed on 26 July 2026 — the ISMS go-live date.

Group
Governance
Owner
Founder
Last reviewed
26 July 2026

Request the full policy

What this policy commits us to

  • Quarterly cadence — deliberately more frequent than the ISO annual minimum — plus a review after any significant incident or material change.
  • 'A measure not taken is a finding' is an explicit rule of the standing agenda.
  • A standing item verifies the automated controls actually executed recently, added after a silent CI outage was discovered.
  • Honest limitation stated: a sole-operator review provides discipline and a verifiable record, not independence.

Controls mapped to this policy

Mapping controls to the policy is how we check adherence. A green dot marks a control that is operating and traceable to evidence; an amber dot marks one that is documented and scheduled but has not run yet.

Standards mappings

Through its controls, this policy maps to the following standards and frameworks. Each entry states our real relationship with the standard.

ISO/IEC 27001:2022InfoSec complianceSelf-assessed

A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.

  • 9.3Management review
  • 10.2Nonconformity and corrective action
  • 7.5Documented information
  • 9.1Monitoring, measurement, analysis, evaluation

Everything mapped to this standard

Need the detail behind this page?

Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.