BS 65000:2014 - Guidance on Organizational Resilience
Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context
Understand the internal and external context within which the organization operates including stakeholder expectations relevant to resilience.
- Context analysis
- Stakeholder map
- PESTLE analysis
- No stakeholder map
- Context not refreshed annually
Culture
Develop a culture supportive of resilience characterised by shared values, learning behaviours, and recognition of resilience contributions.
- Culture survey results
- Recognition programme
- Lessons learned register
- No culture measurement
- Blame culture in incident response
Governance
Establish governance arrangements assigning accountability for resilience across the organization with defined escalation paths.
- RACI for resilience
- Resilience committee terms of reference
- Escalation procedure
- No accountable executive
- Escalation paths untested
Improvement
Continually improve resilience capability based on monitoring, audit, exercises, incidents, and changing context.
- Improvement register
- Closed action evidence
- Annual maturity assessment
- Actions raised never closed
- No maturity model used
Capture learning from incidents and near misses across the organization and apply structurally to prevent recurrence.
- Incident register
- Near miss log
- Root cause analyses
- Near misses not reported
- RCA superficial
Leadership
Define a resilience vision and measurable objectives aligned to the strategic intent of the organization.
- Resilience policy
- Resilience objectives with KPIs
- Strategy alignment matrix
- Objectives generic not measurable
- Not linked to strategic plan
Top management visibly commits to organizational resilience by providing resources, communicating importance, and integrating resilience into business processes.
- Board approval of resilience programme
- Resourcing record
- Internal communications
- Resilience seen as IT or BCM only
- No board visibility
Operations
Integrate resilience into strategic planning, investment decisions, and major change programmes.
- Strategic plan with resilience criteria
- Investment appraisal templates
- Change impact assessment
- Strategy decoupled from resilience
- Change not assessed for resilience impact
Embed resilience in day to day operations through standardised processes, control of critical activities, and continuity planning.
- Business impact analysis
- Continuity plans
- Critical process map
- BIA out of date
- Critical activities undefined
Develop people resilience through succession planning, wellbeing support, and skills redundancy across critical roles.
- Succession plan
- Wellbeing programme
- Skills matrix with redundancy
- Single points of knowledge
- No succession for critical roles
Map critical suppliers, assess concentration risk, and require contractual resilience obligations from key suppliers.
- Supplier map with criticality
- Concentration risk analysis
- Resilience clauses in contracts
- No tier 2 supplier visibility
- No concentration analysis
Ensure resilience of technology platforms and information assets supporting critical activities including recovery objectives.
- IT disaster recovery plan
- RTO and RPO definitions
- Information classification scheme
- RTOs not validated
- Critical data not classified
Protect physical sites and infrastructure through security, environmental controls, and alternative location arrangements.
- Site risk assessment
- Alternative site agreements
- Physical security review
- Alternative site untested
- No site risk assessment
Establish incident and crisis management arrangements with trained teams and rehearsed plans.
- Crisis management plan
- Team rotation roster
- Exercise programme
- Plan never exercised
- No 24x7 contact
Develop adaptive capacity through innovation, learning, and the ability to make decisions under uncertainty.
- Innovation pipeline
- Decision under uncertainty training
- Post incident reviews
- No formal learning programme
- Decisions deferred upward
Performance
Define resilience indicators and monitor performance against objectives with reporting to senior management.
- Resilience scorecard
- KPI dashboards
- Board reporting pack
- No KPIs defined
- Reporting ad hoc
Conduct exercises and tests of resilience arrangements at intervals appropriate to the risk and operating environment.
- Exercise programme
- Exercise reports
- Improvement plans
- Tabletop only never live
- No multi function exercises
Audit the resilience programme and conduct management reviews at planned intervals to ensure suitability and effectiveness.
- Audit schedule
- Audit reports
- Management review minutes
- No internal audit of resilience
- Management reviews infrequent
Resilience Model
Four stages of organisational resilience maturity: preventative control (compliance), mindful action (enterprise risk management), performance optimisation (strategic resilience), and adaptive innovation.
- maturity assessment
- Roadmap
- milestone tracker
- executive review
- no maturity assessment
- weak roadmap
- stale review
Integrate business continuity, risk management, crisis management, security, and emergency management into a unified resilience framework. Break silos between disciplines.
- integration mapping
- governance charter
- cross-functional minutes
- reporting cadence
- siloed resilience
- weak integration
- poor reporting
Board-level ownership of resilience. Culture of awareness, learning, and adaptation. Employee empowerment to identify and escalate risks. Investment in resilience capabilities.
- leadership commitment letter
- culture survey
- training records
- executive sponsor record
- weak commitment
- no culture survey
- missing training
Risk
Identify and assess risks and opportunities affecting the organization across strategic, operational, financial, and reputational dimensions.
- Strategic risk register
- Operational risk register
- Horizon scanning reports
- Strategic risks not separated from operational
- No horizon scanning
Use scenario planning techniques to anticipate disruption and stress test resilience arrangements.
- Scenario library
- Workshop outputs
- Stress test reports
- No formal scenarios
- Scenarios optimistic by default
Support
Determine and provide resources required for the resilience programme including financial, human, technological, and physical.
- Resilience budget
- Team headcount plan
- Tool licensing
- No dedicated budget
- Resilience an additional duty
Ensure personnel involved in resilience activities are competent through training, education, and experience, with general awareness across all staff.
- Competence framework
- Training records
- Awareness campaign materials
- No competence framework
- Awareness limited to BCM team
Establish internal and external communication arrangements relevant to organizational resilience including during disruption.
- Communication plan
- Stakeholder contact list
- Pre approved holding statements
- No pre approved statements
- Contact list outdated
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.