Skip to content

The annual review cycle

How Certaria prompts you to review a document, and why approving it again is the record that the review happened.

Audience: ISMS Admin.

Where: the Certaria app. The Monday prompt arrives by email.

A document does not need changing to need reviewing. ISO 27001 Clause 7.5 expects you to be able to show that controlled documents are reviewed at a planned interval, whether or not the review changes anything.

%%{init: {"theme":"base","themeVariables":{
  "fontFamily":"Space Grotesk, system-ui, sans-serif","fontSize":"14px",
  "background":"#ffffff","mainBkg":"#f0fafa","primaryColor":"#f0fafa",
  "primaryTextColor":"#1a2b32","primaryBorderColor":"#0d7377",
  "secondaryColor":"#f2f4f5","tertiaryColor":"#ffffff",
  "textColor":"#1a2b32","nodeTextColor":"#1a2b32","lineColor":"#5b6f76",
  "clusterBkg":"#fbfcfc","clusterBorder":"#9ecfd0","titleColor":"#0a5c5f",
  "edgeLabelBackground":"#ffffff","labelBackground":"#ffffff",
  "labelBoxBkgColor":"#ffffff","labelTextColor":"#1a2b32"
}} }%%
flowchart TD
  APPROVED["<b>Approved</b><br/><i>in force, on the site</i>"]
  TASK["Policy review task<br/><i>plus a Monday email</i>"]
  UNDER["<b>Under Review</b><br/><i>STILL in force for staff</i>"]
  WORK["ISMS Working<br/><i>revise the copy here</i>"]
  GONE["<b>Superseded or Archived</b><br/><i>removed from the site</i>"]

  APPROVED -.->|"review date due<br/>within 30 days"| TASK
  TASK -->|"YOU: set Under Review"| UNDER
  UNDER -->|"YOU: copy to revise"| WORK
  WORK -->|"YOU: replace the published file,<br/>bump the version"| UNDER
  UNDER -->|"YOU: approve again.<br/>Closes the task, moves<br/>the date on a year"| APPROVED
  APPROVED -->|"YOU: withdraw"| GONE

  classDef you fill:#0d7377,stroke:#0a5c5f,color:#ffffff
  classDef auto fill:#f0fafa,stroke:#0d7377,color:#1a2b32
  class APPROVED,UNDER,WORK,GONE you
  class TASK auto

How Certaria prompts you. Every Monday morning, ISMS Policy Review Date Alert emails the ISMS administrator a list of every document whose Next Review Date falls within the next 30 days. That email is the prompt. Nothing else chases it.

What to do when a document comes up.

  • If the document still stands unchanged, set the status to Under Review and straight back to Approved. That records a fresh Approved Date and moves the review date on another year. This is the record that the review happened, and it is what your auditor will look for. Leave the version alone, so nobody is asked to re-acknowledge a document that has not changed.
  • If it needs revising, follow Revising a document that is already in force above, and bump the version.

Review and acknowledgement are two separate clocks. Reviewing a document does not by itself ask anyone to re-acknowledge it. People are asked again either when the version changes, or when their own acknowledgement passes its expiry, whichever comes first. So a yearly review that changes nothing does not generate work for your whole organisation.

Changing the interval. The Document Review Months setting controls how far ahead the Next Review Date is set, and defaults to 12. Some certification bodies expect a shorter cycle for the top level Information Security Policy. Changing it applies to documents approved after the change, not to review dates already set.