Back to Hub
Governance

How often should you review your management system? A practical schedule

Published 31 July 2026
  • management systems
  • governance
  • internal audit
  • ISO 9001
  • audit readiness

Most businesses either never formally review their management system or only do it the week before an audit. Here is the cadence that actually keeps a system live between certifications.

A management system reviewed only once a year, right before recertification, is not being managed - it is being audited. The practical cadence that keeps a system live is layered: informal checks monthly, internal audit sampling quarterly, and a full management review annually, with the annual review feeding directly off the other two rather than starting from scratch.

What does "reviewing the management system" actually mean?

It means checking three things on a regular rhythm: whether the system's processes are still being followed, whether they are still effective, and whether anything in the business has changed enough that the system needs to change with it (new sites, new plant, new regulatory requirements, growth in headcount or project scale). A review that only checks "is the paperwork current" is not a management system review - it is a filing check.

What should get checked monthly?

Monthly checks are informal and fast - usually under an hour for a 10-250 staff operation - and they are what stops small issues from becoming the pattern an auditor finds in twelve months' time.

  • Open corrective actions. Are they closing out, or accumulating?
  • Incident and near-miss log. Is anything being reported at all, and does it match what you know is actually happening on site?
  • Overdue actions from the last internal audit or management review. Nothing kills system credibility faster than a leadership team that sets actions and never checks whether they happened.

What should get checked quarterly?

Quarterly is where a genuine internal audit sample belongs - not the full system every time, but a rotating sample of processes and sites so that everything gets covered across a year or two.

  • Internal audit of a sampled process or site. Rotate through the system so every area gets audited on a reasonable cycle (see the table below).
  • Trend review of non-conformances and corrective actions. One NCR is an event; three NCRs on the same root cause across a quarter is a pattern that management review needs to see, not just the audit log.
  • Objective tracking. If the system set measurable objectives at the last management review, a quarterly checkpoint is what stops them from being forgotten until the next annual review.

What should get checked annually?

The formal management review - the one ISO standards actually name - happens annually at minimum, chaired by leadership, and it should walk in already informed by twelve months of monthly and quarterly data rather than starting cold.

Review layerFrequencyWho owns itWhat it checks
Informal checkMonthlyHSEQ/quality leadOpen corrective actions, incident log, overdue items
Internal audit sampleQuarterlyHSEQ/quality lead, trained internal auditorsRotating process/site sample, NCR trends, objective tracking
Formal management reviewAnnually (minimum)Senior leadership, chaired by the most senior operational leaderAudit results, incident trends, resourcing, objectives, risk, whether the system still fits the business
Full system/certification cycleEvery 3 yearsLeadership + certification bodyFull recertification audit against the standard

Businesses in higher-risk categories, or those going through rapid growth (new sites, new plant, a step-change in project scale), often tighten this to a six-monthly formal review rather than waiting the full year - the standard sets a minimum, not a ceiling.

The layered review cadence Monthly - informal check (open actions, incident log, overdue items) Quarterly - internal audit sample + NCR trend review Annually (minimum) - formal management review Each layer feeds the one above it

What actually goes wrong when review cadence is too thin?

The most common failure mode is not a missing document - it is a system that looks compliant in the file but has stopped reflecting how the business actually runs. Corrective actions get logged and never closed. The same non-conformance recurs three audits in a row because nobody connected the pattern. Objectives set at last year's management review are quietly forgotten until this year's review reminds everyone they existed. None of that shows up as a finding until an external auditor - or a regulator, after an incident - samples the system and finds the gap between the paper and the practice.

FAQ

How often does ISO actually require a management review? ISO 9001, 14001 and 45001 all require a formal management review "at planned intervals" - the standard does not mandate a specific frequency. In practice, annual is the minimum that satisfies certification bodies, but annual-only reviews are also the most common reason systems drift into paper exercises between audits.

What is the difference between an internal audit and a management review? An internal audit checks whether the system is being followed and whether it is effective at the process level - it is detailed and sampling-based. A management review is a leadership-level check-in that looks at internal audit results, incidents, corrective actions and objectives, and decides whether the system needs to change. Internal audits feed management review; they are not the same activity.

Who should own the management system review schedule? Day-to-day monitoring usually sits with whoever holds the quality/HSEQ function - often a single person in a 10-250 staff business. Formal management review is a leadership-team activity chaired by the most senior operational leader, because its outputs (resourcing, objective changes, risk acceptance) need leadership authority to act on.

What happens if you only review the system once a year, before the audit? The system tends to become a paper exercise for eleven months and a scramble for one. Corrective actions pile up rather than closing out as they arise, hazard and non-conformance trends go unnoticed until they are already a pattern, and the annual review becomes a compliance event rather than a genuine check on whether the business is being run well.

Does a smaller business need the same review cadence as a larger one? The cadence scales with risk and complexity, not headcount alone. A 15-person business running high-risk plant on a single site may need tighter monthly checks than a 100-person office-based operation. The schedule above is a starting point to adjust to your actual risk profile, not a fixed rule.


Jemma Kennedy - Lead Auditor, 15+ years in civil, mining and infrastructure.

Not sure where your system sits against this schedule? The Audit Readiness Check is free and flags whether your review cadence would hold up under external scrutiny.

Want plain feedback on your governance?

30 minutes. No pitch.

Jemma Kennedy

Founder, Hillview Business Services. 15+ years inside civil construction, mining and infrastructure businesses.

Frequently asked questions

Find out where you stand.

Free, thirty minutes, no pitch.