Skip to content

Management system

A certifiable ISMS is more than a set of controls. ISO 27001 also asks you to run the system: audit it, review it with leadership, fix what’s broken, set measurable objectives, and keep the registers that underpin it. Keel gives each of these its own module, and because they share one graph with your controls, evidence, and risk register, findings and inputs flow between them instead of living in disconnected spreadsheets.

Module Clause Where in Keel
Internal audits ISO 27001 / 9001 Clause 9.2 Internal audits
Audit programme & calendar Clause 9.2.2 Audit programme
Management review ISO 27001 / 9001 Clause 9.3 Management reviews
Nonconformity & corrective action ISO 27001 / 9001 Clause 10 Nonconformities
Objectives & KPIs ISO 27001 Clause 6.2 Objectives & KPIs
Information asset register Annex A 5.9 & 5.12 Information assets
Legal & regulatory register Annex A 5.31 Legal & regulatory
Documented information Clause 7.5 Documented information
Competence matrix ISO 27001 Clause 7.2 Competence

The internal-audit, audit-programme, management-review, and corrective-action modules are written to the clauses ISO 27001 and ISO 9001 hold in common (9.2, 9.2.2, 9.3, and 10). If you run both standards, you work these modules once and they serve each management system, the same way a control crosswalks across frameworks.

  • An internal audit records findings against a clause-by-clause checklist. A nonconformity finding promotes straight into a nonconformity (CAPA) record.
  • Security incidents and control gaps also feed the CAPA register.
  • A management review pulls its agenda inputs — open nonconformities, completed audits, audit findings, and incidents — live from these modules, so the review reflects the real state of the program.