What this is
What is a management review action log?
What is a management review action log?
It is the register carrying every decision made at management review from the minute it is taken until somebody has verified it happened. Each row holds the originating review, the decision, its type, an owner, a due date and a status. It is maintained between meetings, not a section of the minutes.
How does it differ from the management review record itself?
The management review record captures one meeting: the inputs considered, the discussion and the conclusions reached on that day. The action log is longitudinal. It spans reviews, which is why it carries a Reviews Covered field and a carry-over count. The record answers what was decided; the log answers whether anything happened.
What counts as a closed action?
Closed means the work is done, evidence exists, and somebody other than the owner has confirmed it. The template separates these deliberately into Evidence Of Completion and Verified. An owner marking their own item Complete with no artefact behind it is a self-declaration, and auditors read it as one.
Scope
When is a management review action log required?
This log tracks decisions after the meeting. It is not the meeting record, not the indicator pack that fed the meeting, and not the investigation machinery for things that went wrong. Using it for those produces a register nobody can report closure from.
Use this template when
- A management review has concluded and its decisions need owners, dates and a place to be chased between meetings
- You need to report closure percent, overdue count and carry-over to top management or a certification auditor
- An action has stalled and you need the blocker named on the record rather than discussed informally
- A decision needs verification by someone other than its owner before it can be treated as closed
- You are running the Management System Governance programme and need one register spanning several review cycles
Do not use it for
- Management Review Record, which captures the inputs, discussion and conclusions of a single review meeting rather than what happened afterwards.
- Performance Indicator Report, which supplies the leading and lagging measures that feed into a review and is not a place to track decisions.
- Corrective Action Record, which handles nonconformities requiring root cause analysis; a review decision only becomes CAPA when it is raised as one.
- Management System Objectives, which holds the standing objectives and targets that a review may adjust but does not replace.
- Context and Interested Parties Review, which reassesses external issues and stakeholder expectations rather than tracking commitments.
Compliance mapping
Which ISO 45001 cl.9.3 requirements does this satisfy?
ISO 45001 requires management review to produce outputs and requires those outputs to be retained as documented information. The clause map below shows which part of this form carries each of those requirements.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 45001 cl.9.3 | Management review outputs include decisions on opportunities for continual improvement and any need for changes to the management system | Actions |
| ISO 45001 cl.9.3 | Outputs include decisions on resource needs, recorded here as an explicit yes, partly or no rather than an implied allocation | Actions |
| ISO 45001 cl.5.1 | Top management demonstrates leadership by ensuring resources are available and by being accountable for effectiveness | Summary |
| ISO 45001 cl.10.3 | Continual improvement of the suitability, adequacy and effectiveness of the system is demonstrated by closure and observed impact | Actions |
| ISO 45001 cl.9.1 | Evaluation of performance uses defined measures; closure percent, overdue count and average days to close are the measures for this process | Summary |
| ISO 45001 cl.7.5 | Documented information is identified, reviewed, approved and controlled, satisfied by the log ID, last updated date and dual signature | Header |
What it does not cover
- A minute that lists decisions with no owner, which leaves the requirement for outputs met on paper while nobody is accountable for delivering any of them.
- A spreadsheet updated the week before the next review, which reconstructs a year of progress from memory and cannot show when an action actually moved.
- An action marked Complete by its own owner, which is a claim rather than verified evidence, and is the first thing an auditor will sample.
- A rolling due date with no carry-over count, which reports healthy closure while the same items have survived three review cycles untouched.
- Actions raised with no resource decision, which fails the resource-needs output of the clause and guarantees the blocker surfaces late.
Global
Management Review Action Log requirements by country
ISO 45001 is voluntary, but in several jurisdictions the duty that sits behind this log — reviewing arrangements and releasing the resources to fix them — is statutory, and the log is the evidence that the duty was discharged.
Management of Health and Safety at Work Regulations 1999, reg.5
Employers must make and give effect to arrangements for the effective planning, organisation, control, monitoring and review of preventive and protective measures.
Review is a named statutory step, and giving effect to it is part of the duty. A log showing decisions taken but never delivered evidences the review while undermining the giving effect.
Work Health and Safety Act 2011, s.27
Officers must exercise due diligence, including ensuring the business has and uses appropriate resources and processes to eliminate or minimise risks.
A personal duty on directors and senior officers. A log where Resource Released is repeatedly no, and Escalation Needed yes with nothing following, is a documented record of resources not being made available.
OSHA Recommended Practices for Safety and Health Programs (2016), Program Evaluation and Improvement
Employers are advised to evaluate the programme periodically, correct shortcomings identified, and verify that corrections are effective.
Not enforceable in itself, but it is the framework OSHA uses to judge programme maturity and it names verification explicitly. Verified and Impact Observed map straight onto it.
How to complete it
How to complete a management review action log, step by step
Most of this form fills itself from the review minutes. Four judgements decide whether the finished log will survive scrutiny.
The Summary carries Action Required, Priority and a CAPA ID, and the temptation is to raise CAPA for everything so the log looks responsive. Resist it. CAPA is for nonconformities needing root cause analysis. A resource decision or objective change is a review action and belongs here. Use the CAPA ID only where the review found something that failed, not something that should be better.
The template does not enforce separation between Owner and verifier, so you must. Fix a rule at the outset, usually the compliance lead or the site manager whose signature closes the log, and hold it. If the same person supplies the evidence and confirms it, Verified adds nothing to Evidence Of Completion and an audit treats both as one self-report.
Too early is the right answer for a genuinely recent change and a comfortable place to hide for an ineffective one. Set a point at which it is no longer available, usually one further review cycle, and force a yes or no. An action closed, verified, then observed to have changed nothing is the most useful row this log will produce.
The Summary asks for one main blocker across the whole log: a forcing question, not a statistical mode. Pick the one that, if removed, closes the most rows. If the honest answer is unclear ownership, the score drops to zero, and it should, because that blocker is entirely within the review body's own gift to fix.
What auditors find
Most common management review action log findings
These recur whenever this log is sampled, with what each actually requires.
| Finding | Clause | What fixes it |
|---|---|---|
| Actions recorded with no due date, or with a date in a month that has already passed and no overdue count | ISO 45001 cl.9.3 | Make Due Date mandatory at the point the row is created, and calculate Days Overdue from it rather than entering it by hand. |
| Closure percent reported in the Summary does not reconcile with the statuses in the Actions rows | ISO 45001 cl.9.1 | Derive Actions Open, Actions Closed and Closure Percent from the repeating section rather than typing them, and reconcile before signature. |
| Rows marked Closed where Evidence Of Completion is no or blank | ISO 45001 cl.7.5 | Treat Closed as unavailable until evidence exists; attach or reference the artefact against the row rather than describing it. |
| Verified is yes across every row, signed by the same person who owns the actions | ISO 45001 cl.5.1 | Assign verification to a named role independent of the owner and record who verified, not merely that verification occurred. |
| Carried From Previous Review is zero although the log spans three review cycles | ISO 45001 cl.9.3 | Carry the count forward when a row is rolled, and audit the field against last cycle's log rather than resetting it at the start of a period. |
| Resource Released is no on stalled actions and Escalation Needed remains no | ISO 45001 cl.5.1 | Set a rule that any action blocked on resource for one full cycle escalates automatically, and record the escalation and its outcome. |
Case in point
Case in point: the three items that outlived the manager
A packaging plant certified to ISO 45001 reviewed each March. The 2023 minutes carried eleven decisions. Nine closed. Three did not: a guarding upgrade on two older lines, a permit-to-work rewrite, and supervisor training for the night shift. Each was re-tabled in 2024 with a fresh due date, and again in 2025. The log showed closure at 82 percent every year, because the carry-over field was never populated and rolled items were counted as new.
The surveillance audit sampled the 2025 log against the 2023 minutes and found the same three decisions with three due dates and no carry-over. The nonconformity was written against management review outputs, not guarding. What restored it was honesty in the log: each row re-entered under its original review ID, carry-over of two, Resource Released no, Main Blocker budget. Real closure was 61 percent, and two of the three were funded that quarter, because a number that low reached the board in a form it could not read past.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
3 sections
- Reference
- CMP-015
- Archetype
- Log
- Record ID
- MRAL-2026-000
- Scoring
- Closure percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 45001 cl.9.3
- Links
- Links Management Review, CAPA
- Tags
- Governance, Action
- Sections
- 3
- Fields
- 37
- Follow up fields
- 3
- Repeating sections
- 1
- Links out
- 3
Header
8 fieldsLog ID*
Auto sequence. Format MRA-2026-000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Site*
Site ID*
Format SITE-000.
Links to FDN-001 Site ID
Last Updated*
Maintained By*
Reviews Covered*
The Reason Reviews Get Taken Seriously
If last year's decisions are all still open at this year's meeting, everybody learns that management review actions are optional.
Actions
Repeats12 fieldsReview ID*
Links to CMP-014 Review ID
Decision*
Type*
Owner*
Due Date*
Status*
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Days Overdue
Resource Released*
A decision with no budget and no time allocated is a wish, not an action.
- Yes3 pts
- Partly1 pt
- No0 pts
Blocker
Evidence Of Completion*
- Yes3 pts
- Partly1 pt
- No0 pts
Verified*
- Yes3 pts
- No0 pts
Impact Observed
- Yes3 pts
- Too early1 pt
- No0 pts
Summary
17 fieldsActions Open*
Actions Closed*
Closure Percent*
Overdue Actions*
Carried From Previous Review*
Carried More Than Twice*
Average Days To Close*
Main Blocker*
- None3 pts
- Resource1 pt
- Budget1 pt
- Conflicting priority1 pt
- Unclear ownership0 pts
Escalation Needed*
- No3 pts
- Yes0 pts
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Compliance Lead*
Signature*
Site Manager*
Second Signature*
CMP-015 · record IDs look like MRAL-2026-000 · Links Management Review, CAPA
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The log is easy to write and hard to keep honest between meetings. These are the parts of the work that tend to slip, and the workspaces that carry them.
Holds the log against the management review record, carries carry-over counts forward between cycles, and keeps closure percent, overdue count and average days to close reconciled with the underlying rows.
Routes actions arising from health and safety decisions to the owners who run the controls, and surfaces the ones that have been blocked on resource for a full cycle before they reach a third carry-over.
Links review actions that turn out to be nonconformities into corrective action records with root cause analysis, so the log tracks commitment and CAPA tracks failure without the two being confused.

Coordinates the crew, chases evidence from named owners ahead of each review, drafts the closure summary for the next meeting, and holds every write for your approval before it touches a record.
This template lives in KnowComply — audit and governance. Audit programmes, legal register, management review, risk and certification.
Meet KnowComply→Glossary
Management Review Action Log definitions and key terms
- Closure percent
- Actions closed as a proportion of all actions on the log. The headline score for this template, where high is good.
- Carry-over
- An action rolled from one review cycle into the next. Counted separately so that rolling cannot disguise itself as progress.
- Verification
- Confirmation by someone other than the action owner that the completed work exists and matches what was decided.
- Resource release
- The formal allocation of budget, headcount or protected time to a decision. Recorded as yes, partly or no against each action.
- Review output
- A decision, change or resource commitment produced by management review, which ISO 45001 requires to be retained as documented information.
FAQ
Frequently asked questions about management review action log
How many actions should a review produce?+
Fewer than most reviews generate. A meeting that produces twenty decisions and closes six has a worse record than one producing six and closing all of them. If the log routinely carries more open rows than the organisation can resource in a cycle, the constraint is the review's appetite, not the owners.
Should overdue actions be closed and reopened as new ones?+
No. That resets the history the log exists to hold. Keep the original row and its review ID, increment the carry-over, and move the due date only if the plan changed. Reopening as new is the most effective way to make a stalled system look responsive.
Does every action need a CAPA reference?+
No. CAPA is for nonconformities requiring root cause analysis. Most review actions are improvements, resource decisions or objective changes and are tracked entirely within this log. Raise a CAPA only where something failed, and record its reference so the two records point at each other.
Who signs the log, and how often?+
The compliance lead maintains it and signs, with a second signature from the site manager. Sign at each update that changes the summary figures, and always before the log is presented to the next review. The last updated date should never be older than the most recent status change in the rows.
What if an action is no longer relevant?+
Record it as deferred or closed with the reason written into the decision text, and take it back to the review body rather than deleting the row. A decision withdrawn deliberately is defensible; a row that disappears between two versions of the log is not, and deletion is what an auditor will look for first.
Can one log cover several sites?+
It can, but the header carries one site and site ID, so a multi-site log means that field describes the reviewing entity rather than where the work happens. Workable for a group review, but keep site-specific actions in site-level logs so local owners see their own closure percent, not a group average.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Management System Governance
Legal and Other Requirements Register
Lists every law, regulation, permit and commitment that applies to your operation
Compliance Obligation Assessment
Assesses how each legal requirement applies to you and what you do to meet it
Compliance Evaluation Record
Records the periodic evaluation of whether you actually comply with each obligation
Regulatory Change Record
Records a change in law or regulation and what it means for you
Regulatory Inspection Record
Records a visit by a regulator, including what was inspected, what was said and any orders issued
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
More in Management Review
Management Review Record
Records the periodic review of the management system by senior leadership, covering performance, risks, resources and improvement
Performance Indicator Report
Reports the leading and lagging indicators for the management system over a period
Context and Interested Parties Review
Reviews the internal and external issues affecting the organisation and the expectations of interested parties

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 45001:2018, cl.9.3 Management review; cl.10.3 Continual improvement
- ISO 45001:2018, cl.5.1 Leadership and commitment; cl.7.5 Documented information
- Management of Health and Safety at Work Regulations 1999 (UK), reg.5 Health and safety arrangements
- Work Health and Safety Act 2011 (Australia), s.27 Duty of officers
- OSHA Recommended Practices for Safety and Health Programs (2016), Program Evaluation and Improvement
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.