10.3 Management Review, Nonconformity & Corrective Action

Key Takeaways

  • ISO 22301:2019 Clause 9.3 mandates that top management review the organization's BCMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.
  • Management reviews must address all mandatory inputs specified in Clause 9.3.2 (status of previous actions, context changes, BCMS performance/KPIs, audit results, exercise outcomes, lessons learned) and generate actionable outputs under Clause 9.3.3 (continual improvement decisions, resource allocations, policy updates).
  • Clause 10.1 establishes a strict two-stage requirement for nonconformities: immediate reaction/containment (correction) followed by systematic root cause elimination (corrective action) to prevent recurrence.
  • Root Cause Analysis (RCA) techniques such as the 5 Whys and Ishikawa (Fishbone) diagrams must be employed to uncover systemic failures rather than attributing nonconformities solely to human error.
  • Continual improvement under Clause 10.2 requires organizations to continually enhance the suitability, adequacy, and effectiveness of the BCMS through lessons learned, corrective action outcomes, and strategic management reviews.
Last updated: August 2026

Management Review, Nonconformity & Corrective Action

A Business Continuity Management System (BCMS) is not a static repository of emergency manuals; it is an active, evolving organizational governance framework. To maintain strategic alignment with business priorities and protect against emerging disruption threats, executive leadership must systematically evaluate system performance and enforce accountability for correcting deficiencies. ISO 22301:2019 Clause 9.3 (Management review), Clause 10.1 (Nonconformity and corrective action), and Clause 10.2 (Continual improvement) complete the "Act" phase of the PDCA cycle, ensuring that executive decisions translate into operational resilience.


1. Management Review Governance: Suitability, Adequacy & Effectiveness

Clause 9.3 mandates that top management shall review the organization's BCMS, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.

                                ┌─────────────────────────────────────────┐
                                │     The Triad of Management Review      │
                                │              (Clause 9.3)               │
                                └────────────────────┬────────────────────┘
                                                     │
                     ┌───────────────────────────────┼───────────────────────────────┐
                     ▼                               ▼                               ▼
      ┌─────────────────────────────┐ ┌─────────────────────────────┐ ┌─────────────────────────────┐
      │         SUITABILITY         │ │          ADEQUACY           │ │        EFFECTIVENESS        │
      ├─────────────────────────────┤ ├─────────────────────────────┤ ├─────────────────────────────┤
      │ • Strategic Alignment       │ │ • Resource Sufficiency      │ │ • Goal Achievement          │
      │ • Does the BCMS fit the     │ │ • Are budget, staff, tools, │ │ • Are RTOs, RPOs, and MBCOs │
      │   organization's context,   │ │   and infrastructure        │ │   actually achieved during  │
      │   culture, and mission?     │ │   sufficient to operate?    │ │   exercises and incidents?  │
      └─────────────────────────────┘ └─────────────────────────────┘ └─────────────────────────────┘

Definitions and Strategic Distinctions

  1. Suitability: Reflects how the BCMS aligns with the organization's overarching vision, culture, operational environment, and strategic objectives. If the company pivots from on-premise operations to a fully decentralized cloud model, a BCMS anchored to physical facility recovery is no longer suitable.
  2. Adequacy: Reflects whether the BCMS is equipped with sufficient resources, funding, personnel, technical capabilities, and executive authority to fulfill its mandate.
  3. Effectiveness: Reflects the degree to which planned business continuity activities are realized and planned recovery results are achieved (e.g., meeting RTOs, containing cyber incidents, maintaining critical customer operations).

Frequency and Operational Governance

  • Planned Intervals: Management reviews must occur at planned intervals defined in the BCMS governance manual (typically annually for comprehensive executive reviews, or quarterly in high-velocity sectors like finance and healthcare).
  • Triggered Reviews: Top management must also convene ad-hoc reviews following catastrophic real-world disruptions, major organizational restructuring, or significant corporate acquisitions.
  • Executive Participation: The review must be chaired or actively attended by Top Management (e.g., CEO, COO, CIO, Chief Risk Officer). Delegating the management review exclusively to junior continuity planners violates Clause 5.1 and Clause 9.3.

2. Mandatory Management Review Inputs (Clause 9.3.2)

Clause 9.3.2 establishes an explicit, non-negotiable list of mandatory inputs that must be presented and evaluated during the management review. Omitting any mandatory input represents an audit nonconformity.

  ┌───────────────────────────────────────────────────────────────────────────────────────────┐
  │                       MANDATORY MANAGEMENT REVIEW INPUTS (CLAUSE 9.3.2)                   │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 1. Status of Actions from Previous Reviews: Tracking prior executive action items.        │
  │ 2. Context Changes: Shifts in external/internal issues, legal/regulatory mandates.         │
  │ 3. BCMS Performance & Effectiveness:                                                      │
  │    • Trends in nonconformities and corrective actions (CAP velocity);                     │
  │    • Monitoring and measurement results (Clause 9.1 KPI/KRI dashboard);                   │
  │    • Internal and external audit findings (Clause 9.2);                                   │
  │    • Exercise and testing results (Clause 8.5 After-Action Reports).                      │
  │ 4. Feedback from Interested Parties: Customer audit inquiries, regulator feedback.        │
  │ 5. Results of BIA and Risk Assessment: Updated MTPDs, RTOs, emerging threat profiles.     │
  │ 6. Lessons Learned from Disruptions: Post-incident reviews of actual disruptive events.    │
  │ 7. Opportunities for Continual Improvement: Proposals for technological/process upgrades. │
  └───────────────────────────────────────────────────────────────────────────────────────────┘

Detailed Breakdown of Mandatory Inputs

Input CategoryOperational Source DocumentsCritical Information Examined by Top Management
Status of Prior ActionsAction Item Tracker from previous Management ReviewEvaluation of whether previously authorized investments, staffing approvals, and policy updates were completed.
Internal/External ChangesContext Register (4.1), Regulatory Compliance Matrix (4.2)New statutory continuity requirements (e.g., DORA, NIS 2), geopolitical unrest, M&A activity, new SaaS dependencies.
Performance & MetricsClause 9.1 Evaluation DossierBCP freshness percentages, training completion rates, critical vendor SLA compliance, RTO achievement rates.
Audit FindingsInternal & External Audit Reports (9.2)Volume and severity of Major/Minor Nonconformities, systemic audit trends, status of open corrective actions.
Exercise OutcomesAfter-Action Reports (AARs) & CAPs (8.5)Success/failure rates of simulated failovers, command center response times, operational gaps uncovered under simulated stress.
Disruption LessonsPost-Incident Review Reports (8.4.5)Actual downtime, financial losses, operational bottlenecks, and crisis communication performance during live disruptions.
BIA & Risk AssessmentUpdated BIA Worksheets & Risk Registers (8.2)Identification of new critical activities, changes in maximum tolerable periods of disruption (MTPD), new risk vectors.
Improvement ProposalsContinual Improvement Register (10.2)Business cases for automated notification tools, secondary cloud zone deployments, expanded staff training.

3. Mandatory Management Review Outputs (Clause 9.3.3)

The management review must not be a passive briefing; it must generate concrete, documented decisions and actions signed off by executive leadership.

Required Review Outputs

  1. Decisions Related to Continual Improvement Opportunities: Authorizing enhancements to BCMS processes, updating methodologies, or streamlining response workflows.
  2. Decisions Related to Any Need for Changes to the BCMS: Formal updates to the Business Continuity Policy, adjustments to BCMS scope, modifications to continuity objectives, or revisions to recovery strategies.
  3. Resource Allocations: Executive authorization of capital expenditures, operational budgets, personnel hiring, specialist training, or technical infrastructure investments.
  4. Documented Information Mandate: The organization must retain comprehensive documented information (formal Management Review Minutes, Signed Executive Action Matrix) as evidence of review results.

Comprehensive Inputs vs. Outputs Mapping Matrix

Management Review Input (Clause 9.3.2)Executive Evaluation & DeliberationMandatory Output Decision / Action (Clause 9.3.3)Documented Evidence Artifact
Exercise AAR: Secondary data center failover took 75 minutes against a 60-minute RTO.Leadership evaluates whether to relax the RTO or invest in automated database orchestration tools.Executive decision to allocate $120,000 for automated cloud failover software to achieve RTO $\le 30\text{ min}$.Management Review Minutes; Approved Budget Requisition.
Audit Finding: Multiple departments failed to maintain trained secondary deputies.Leadership reviews operational staffing constraints and single points of failure (SPOFs).Policy change mandating dual-deputy training with mandatory attendance KPIs tied to manager performance bonuses.Updated BC Policy; Executive Action Matrix.
Context Change: New financial regulatory mandate requiring operational resilience testing.Leadership assesses current exercise scope against new statutory obligations.Decision to expand BCMS scope and approve two additional multi-vector supply chain exercises in Year 2.Updated Scope Document; Approved Exercise Programme.
Post-Incident Review: Supply chain disruption caused by sole-source packaging vendor insolvency.Leadership reviews tier-1 supplier continuity risks and inventory buffer levels.Directive to establish dual-sourcing contracts and increase safety stock to 4 weeks of MBCO demand.Strategic Procurement Directive; Updated BCP.

4. Nonconformity Handling & Corrective Action (Clause 10.1)

When a nonconformity occurs—whether identified through an internal audit, metric breach, exercise failure, or actual disruption—the organization must execute a structured, two-phase response under Clause 10.1.

                               ┌─────────────────────────────────────────┐
                               │    THE TWO-PHASE CLAUSE 10.1 RESPONSE   │
                               └────────────────────┬────────────────────┘
                                                    │
                     ┌──────────────────────────────┴──────────────────────────────┐
                     ▼                                                             ▼
      ┌─────────────────────────────┐                               ┌─────────────────────────────┐
      │     PHASE 1: CORRECTION     │                               │  PHASE 2: CORRECTIVE ACTION │
      │     (Immediate Containment) │                               │   (Root Cause Elimination)  │
      ├─────────────────────────────┤                               ├─────────────────────────────┤
      │ • React immediately         │                               │ • Conduct Root Cause        │
      │ • Control and contain       │                               │   Analysis (5 Whys/Ishikawa)│
      │ • Deal with consequences    │                               │ • Implement systemic change │
      │ • "Put out the fire"        │                               │ • Prevent recurrence        │
      └─────────────────────────────┘                               └─────────────────────────────┘

4.1 Correction (Containment) vs. Corrective Action

Understanding this distinction is one of the most frequently tested concepts on the PECB ISO 22301 Lead Implementer exam:

  • Correction (Immediate Action / Containment): Action taken to eliminate an identified nonconformity and mitigate its immediate consequences. It addresses the symptom (e.g., manually updating a corrupted contact list, manually restoring a dropped database connection, issuing a missing document signature).
  • Corrective Action (Systemic Prevention): Action taken to eliminate the underlying root cause of an identified nonconformity to prevent its recurrence or occurrence elsewhere. It addresses the systemic flaw (e.g., implementing automated HR-to-BCMS directory synchronization so contact records can never become outdated again).

4.2 The Clause 10.1 Step-by-Step Workflow

  ┌──────────────────────────────────────────────────────────────────────────────────┐
  │                  CLAUSE 10.1 CORRECTIVE ACTION LIFECYCLE                         │
  ├──────────────────────────────────────────────────────────────────────────────────┤
  │ Step 1: React to the Nonconformity                                               │
  │         • Take immediate action to control and correct it;                       │
  │         • Deal with any operational consequences.                                │
  │ Step 2: Evaluate Need for Action to Eliminate Causes                             │
  │         • Review and analyze the nonconformity;                                  │
  │         • Determine the fundamental root causes;                                 │
  │         • Determine if similar nonconformities exist or could occur elsewhere.   │
  │ Step 3: Implement Corrective Actions                                             │
  │         • Design systemic process, technology, or governance changes;            │
  │         • Assign action owners and strict completion milestones.                 │
  │ Step 4: Review Effectiveness of Corrective Actions                               │
  │         • Evaluate post-implementation performance after sufficient time;        │
  │         • Verify that the root cause was eliminated and nonconformity is gone.   │
  │ Step 5: Update Risks and Opportunities & BCMS Documentation                      │
  │         • Update Risk Assessment register if new risk vectors were uncovered;   │
  │         • Make necessary changes to BCMS policies, procedures, and plans.        │
  │ Step 6: Retain Documented Information                                            │
  │         • Retain evidence of nonconformity details, actions taken, and results.  │
  └──────────────────────────────────────────────────────────────────────────────────┘

5. Root Cause Analysis (RCA) Methodologies for BCMS

Superficial investigations produce recurring failures. Lead Implementers must apply rigorous Root Cause Analysis methodologies to isolate the true systemic breakdown.

5.1 The "5 Whys" Methodology (Worked Example)

Incident: During an unannounced workplace denial exercise, the Crisis Management Team failed to broadcast an emergency evacuation alert to 400 building occupants within the mandatory 10-minute window (actual time: 48 minutes).

  Problem Statement: Emergency mass notification alert delayed by 38 minutes.
  │
  ├── Why? (1) The Crisis Communications Officer could not log into the alert platform.
  │   └── Why? (2) The officer's single sign-on (SSO) security token had expired.
  │       └── Why? (3) The alert platform was configured to require hardware tokens stored
  │                    inside the denied physical office building.
  │           └── Why? (4) The system architecture was never designed with an out-of-band,
  │                        cloud-native multi-factor authentication (MFA) fallback.
  │               └── Why? (5) [ROOT CAUSE] The BCMS technical requirements for out-of-band
  │                            emergency tools were never integrated into the corporate IT
  │                            Identity & Access Management (IAM) engineering architecture.
  • Correction: Reset the officer's security token and send the delayed broadcast.
  • Corrective Action: Reconfigure the mass notification platform with cloud-native, out-of-band biometric MFA accessible from any mobile device, and update the IT Architecture Standard to require out-of-band redundancy for all crisis tools.

5.2 Ishikawa (Fishbone / Cause-and-Effect) Diagram

When investigating complex, multi-variable continuity failures, the Fishbone diagram categorizes potential root causes across six dimensions:

                       ISHIKAWA (FISHBONE) DIAGRAM FOR BCMS FAILURE

     PEOPLE                          PROCESS                         TECHNOLOGY
  Inadequate Deputy ──┐           Outdated BCP ──┐             Single Point of ──┐
  Training            │           Checklist      │             Network Failure   │
                      │                          │                               │
  High Staff ─────────┼──┐        Ambiguous ─────┼──┐          Unpatched ────────┼──┐
  Turnover            │  │        Escalation     │  │          Failover Script   │  │
                      │  │        Criteria       │  │                            │  │
  ────────────────────┴──┴───────────────────────┴──┴────────────────────────────┴──┴──► [ PROBLEM: ]
                      │  │                       │  │                            │  │    [ RTO BREACH ]
  Severe Weather ─────┼──┘        Insufficient ──┼──┘          Vendor SLA ───────┼──┘
  Access Denial       │           Budget/Staff   │             Not Enforced      │
                      │                          │                               │
  Building Power ─────┘           No Management ─┘             Third-Party ──────┘
  Grid Outage                     Review Cadence               Cloud Outage
   ENVIRONMENT                     MANAGEMENT / GOVERNANCE       SUPPLIERS / 3RD PARTIES

[!IMPORTANT] The Fallacy of "Human Error" In ISO 22301 Lead Implementer audits, citing "human error" as the root cause is unacceptable. Human error is a symptom of deeper systemic failures, such as ambiguous procedures, poor interface design, cognitive fatigue, lack of training, or absence of procedural verification checks. Corrective actions that state only "retrained the employee" will be rejected by certification auditors.


6. Verifying Corrective Action Effectiveness & Continual Improvement (Clause 10.2)

Implementing a corrective action is not the final step. Under Clause 10.1(d), the organization must review the effectiveness of any corrective action taken.

  ┌───────────────────────────────────────────────────────────────────────────────────────────┐
  │                     CORRECTIVE ACTION EFFECTIVENESS VERIFICATION                          │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 1. Time Horizon: Allow sufficient operational time (30, 60, or 90 days) for the new       │
  │    process or technical control to operate in the production environment.                 │
  │ 2. Re-Testing / Re-Auditing: Execute a focused drill, component test, or targeted audit  │
  │    specifically designed to stress-test the remediated vulnerability.                     │
  │ 3. Objective Evidence Verification: Confirm zero recurrence of the original failure mode  │
  │    under operational stress.                                                              │
  │ 4. Formal Closure: If effective, formally close the Nonconformity in the CAP log.         │
  │    If ineffective, re-open the RCA investigation and formulate an escalated action plan.   │
  └───────────────────────────────────────────────────────────────────────────────────────────┘

Continual Improvement Mechanisms (Clause 10.2)

Clause 10.2 mandates that the organization shall continually improve the suitability, adequacy, and effectiveness of the BCMS. Continual improvement is achieved through:

  • Iterative PDCA Cycles: Using metrics, audit findings, exercise results, and management reviews to drive progressive capability enhancements year over year.
  • Benchmarking & Horizon Scanning: Incorporating emerging threat intelligence, industry standards, and best practices into the BCMS.
  • Automation & Modernization: Transitioning from manual, error-prone recovery workarounds to automated, resilient cloud-native architectures.

7. Worked Implementation Scenario: Core Banking Exercise Outage & Corrective Action

Context

Global Retail Bank conducted an operations-based functional exercise simulating a primary mainframe data center power failure. The business continuity objective mandated an RTO of $\le 2\text{ hours}$ for core customer account ledger services.

The Incident & Discovery

  • Exercise Result: Secondary ledger failover took $4\text{ hours and } 15\text{ minutes}$, breaching the RTO by over two hours.
  • Phase 1 (Correction): The database engineering team manually restarted the replication daemon and synchronized the database replica.
  • Phase 2 (Evaluation & RCA): The Lead Implementer convened an RCA working group utilizing the 5 Whys. The investigation discovered that the automated failover script crashed because the database storage volumes on the secondary storage array had reached $98%$ capacity due to uncompressed historical backup logs that were never purged.
  • Systemic Root Cause: The Storage Management policy lacked an automated log rotation and disk threshold monitoring alerting rule for disaster recovery standby volumes.
  • Corrective Action Plan (CAP):
    1. Implement automated disk quota alerting (triggers at $75%$ capacity) across all standby DR arrays (Completed in 7 days).
    2. Reconfigure log compression daemons with daily automated purge scripts (Completed in 14 days).
    3. Update the Infrastructure Disaster Recovery Procedure (Clause 8.4) with pre-failover storage health checks (Completed in 21 days).
  • Effectiveness Verification: Sixty days later, the Lead Implementer and IT team conducted an unannounced component drill simulating a forced database failover. The automated failover completed cleanly in $38\text{ minutes}$ with storage utilization at $42%$, confirming that the corrective action eliminated the root cause.

8. PECB Exam Warning Traps & Implementation Pitfalls

[!CAUTION] Critical Exam Traps for Section 10.3

  1. Trap: Confusing Correction with Corrective Action: On the exam, when asked how an organization must respond to a nonconformity, remember that Correction is the immediate containment/patch (dealing with consequences), while Corrective Action is the systemic elimination of the root cause to prevent recurrence.
  2. Trap: Missing Mandatory Management Review Inputs: If an exam question describes a management review where top management reviewed only financial budgets and IT uptime metrics—ignoring BIA results, exercise reports, audit findings, or previous review action items—it represents an audit Nonconformity under Clause 9.3.2.
  3. Trap: Immediate CAP Closure Without Effectiveness Verification: Closing a corrective action ticket immediately upon deploying a software patch or publishing a new policy violates Clause 10.1(d). A corrective action can only be closed after an effectiveness verification confirms that the root cause has been permanently eliminated.
  4. Trap: Delegating Management Review Away from Top Management: If an exam scenario depicts the BCMS Lead Implementer conducting and signing off on the Management Review alone without executive leadership participation, this violates Clause 5.1 and Clause 9.3.
Loading diagram...
ISO 22301 Clause 10.1 Nonconformity & Corrective Action Closed-Loop Lifecycle
Test Your Knowledge

Following a major power outage exercise, an organization discovers that its secondary emergency generator failed to start because the starter battery was completely discharged. The Facilities Manager immediately replaces the dead battery with a newly charged battery and tests that the generator turns on. How should this response be characterized under ISO 22301:2019 Clause 10.1?

A
B
C
D
Test Your Knowledge

Top management at a healthcare provider convenes to conduct the annual ISO 22301 Management Review. The executive team reviews the status of previous review action items, external regulatory changes, customer feedback, and internal audit reports. However, the Lead Implementer omits the results of recent disaster recovery exercises and the latest Business Impact Analysis (BIA) updates from the agenda. What is the compliance status of this management review under ISO 22301:2019 Clause 9.3?

A
B
C
D
Test Your Knowledge

An organization experiences a nonconformity during a functional continuity exercise. The Lead Implementer conducts a 5 Whys root cause analysis, identifies a systemic procedural flaw in the call tree escalation protocol, updates the standard operating procedure, and conducts staff training on the new process. According to ISO 22301 Clause 10.1, what is the mandatory next step before this corrective action can be formally closed in the BCMS registry?

A
B
C
D