This version of ISO 27001 Clause 9.3 is applicable to ISO 27001:2013.
The purpose of the management review is ensure that the ISMS is suitable, effective and adequate to support information security. A management review consists of the status of actions from the previous management reviews, any changes in the internal or external issues that are relevant to the ISMS. It also includes the management feedback related to information security performance including trends in nonconformities and corrective actions, monitoring and measurement results, audit results and fulfilment of information security objectives. The review includes feedback from the interested parties and the results from the risk assessment process and risk treatment process.
Management reviews are one of the key elements of the ISMS because of the top management role in the organisation. So, for instance, if information security needs more budget urgently due to an unplanned risk, the top management can make this possible.