Skip to content

Evidence request lists

BS 65000:2014 - Guidance on Organizational Resilience

Evidence request list. 26 controls, 26 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Context

BS65000-4.1
Context of the Organization

Understand the internal and external context within which the organization operates including stakeholder expectations relevant to resilience.

Artefacts an auditor will ask for
  • Context analysis
  • Stakeholder map
  • PESTLE analysis
Where this commonly fails
  • No stakeholder map
  • Context not refreshed annually

Culture

BS65000-5.2
Resilience Culture

Develop a culture supportive of resilience characterised by shared values, learning behaviours, and recognition of resilience contributions.

Artefacts an auditor will ask for
  • Culture survey results
  • Recognition programme
  • Lessons learned register
Where this commonly fails
  • No culture measurement
  • Blame culture in incident response

Governance

BS65000-5.3
Governance and Accountability

Establish governance arrangements assigning accountability for resilience across the organization with defined escalation paths.

Artefacts an auditor will ask for
  • RACI for resilience
  • Resilience committee terms of reference
  • Escalation procedure
Where this commonly fails
  • No accountable executive
  • Escalation paths untested

Improvement

BS65000-10.1
Continual Improvement

Continually improve resilience capability based on monitoring, audit, exercises, incidents, and changing context.

Artefacts an auditor will ask for
  • Improvement register
  • Closed action evidence
  • Annual maturity assessment
Where this commonly fails
  • Actions raised never closed
  • No maturity model used
BS65000-10.2
Learning from Incidents and Near Misses

Capture learning from incidents and near misses across the organization and apply structurally to prevent recurrence.

Artefacts an auditor will ask for
  • Incident register
  • Near miss log
  • Root cause analyses
Where this commonly fails
  • Near misses not reported
  • RCA superficial

Leadership

BS65000-4.2
Resilience Vision and Objectives

Define a resilience vision and measurable objectives aligned to the strategic intent of the organization.

Artefacts an auditor will ask for
  • Resilience policy
  • Resilience objectives with KPIs
  • Strategy alignment matrix
Where this commonly fails
  • Objectives generic not measurable
  • Not linked to strategic plan
BS65000-5.1
Leadership Commitment

Top management visibly commits to organizational resilience by providing resources, communicating importance, and integrating resilience into business processes.

Artefacts an auditor will ask for
  • Board approval of resilience programme
  • Resourcing record
  • Internal communications
Where this commonly fails
  • Resilience seen as IT or BCM only
  • No board visibility

Operations

BS65000-8.1
Strategic Resilience

Integrate resilience into strategic planning, investment decisions, and major change programmes.

Artefacts an auditor will ask for
  • Strategic plan with resilience criteria
  • Investment appraisal templates
  • Change impact assessment
Where this commonly fails
  • Strategy decoupled from resilience
  • Change not assessed for resilience impact
BS65000-8.2
Operational Resilience

Embed resilience in day to day operations through standardised processes, control of critical activities, and continuity planning.

Artefacts an auditor will ask for
  • Business impact analysis
  • Continuity plans
  • Critical process map
Where this commonly fails
  • BIA out of date
  • Critical activities undefined
BS65000-8.3
People Resilience

Develop people resilience through succession planning, wellbeing support, and skills redundancy across critical roles.

Artefacts an auditor will ask for
  • Succession plan
  • Wellbeing programme
  • Skills matrix with redundancy
Where this commonly fails
  • Single points of knowledge
  • No succession for critical roles
BS65000-8.4
Supply Chain Resilience

Map critical suppliers, assess concentration risk, and require contractual resilience obligations from key suppliers.

Artefacts an auditor will ask for
  • Supplier map with criticality
  • Concentration risk analysis
  • Resilience clauses in contracts
Where this commonly fails
  • No tier 2 supplier visibility
  • No concentration analysis
BS65000-8.5
Technology and Information Resilience

Ensure resilience of technology platforms and information assets supporting critical activities including recovery objectives.

Artefacts an auditor will ask for
  • IT disaster recovery plan
  • RTO and RPO definitions
  • Information classification scheme
Where this commonly fails
  • RTOs not validated
  • Critical data not classified
BS65000-8.6
Physical and Site Resilience

Protect physical sites and infrastructure through security, environmental controls, and alternative location arrangements.

Artefacts an auditor will ask for
  • Site risk assessment
  • Alternative site agreements
  • Physical security review
Where this commonly fails
  • Alternative site untested
  • No site risk assessment
BS65000-8.7
Incident and Crisis Management

Establish incident and crisis management arrangements with trained teams and rehearsed plans.

Artefacts an auditor will ask for
  • Crisis management plan
  • Team rotation roster
  • Exercise programme
Where this commonly fails
  • Plan never exercised
  • No 24x7 contact
BS65000-8.8
Adaptive Capacity

Develop adaptive capacity through innovation, learning, and the ability to make decisions under uncertainty.

Artefacts an auditor will ask for
  • Innovation pipeline
  • Decision under uncertainty training
  • Post incident reviews
Where this commonly fails
  • No formal learning programme
  • Decisions deferred upward

Performance

BS65000-9.1
Monitoring and Measurement

Define resilience indicators and monitor performance against objectives with reporting to senior management.

Artefacts an auditor will ask for
  • Resilience scorecard
  • KPI dashboards
  • Board reporting pack
Where this commonly fails
  • No KPIs defined
  • Reporting ad hoc
BS65000-9.2
Exercises and Testing

Conduct exercises and tests of resilience arrangements at intervals appropriate to the risk and operating environment.

Artefacts an auditor will ask for
  • Exercise programme
  • Exercise reports
  • Improvement plans
Where this commonly fails
  • Tabletop only never live
  • No multi function exercises
BS65000-9.3
Internal Audit and Review

Audit the resilience programme and conduct management reviews at planned intervals to ensure suitability and effectiveness.

Artefacts an auditor will ask for
  • Audit schedule
  • Audit reports
  • Management review minutes
Where this commonly fails
  • No internal audit of resilience
  • Management reviews infrequent

Resilience Model

BS65000-RM-01
Resilience Journey

Four stages of organisational resilience maturity: preventative control (compliance), mindful action (enterprise risk management), performance optimisation (strategic resilience), and adaptive innovation.

Artefacts an auditor will ask for
  • maturity assessment
  • Roadmap
  • milestone tracker
  • executive review
Where this commonly fails
  • no maturity assessment
  • weak roadmap
  • stale review
BS65000-RM-02
Integrated Approach

Integrate business continuity, risk management, crisis management, security, and emergency management into a unified resilience framework. Break silos between disciplines.

Artefacts an auditor will ask for
  • integration mapping
  • governance charter
  • cross-functional minutes
  • reporting cadence
Where this commonly fails
  • siloed resilience
  • weak integration
  • poor reporting
BS65000-RM-03
Leadership and Culture

Board-level ownership of resilience. Culture of awareness, learning, and adaptation. Employee empowerment to identify and escalate risks. Investment in resilience capabilities.

Artefacts an auditor will ask for
  • leadership commitment letter
  • culture survey
  • training records
  • executive sponsor record
Where this commonly fails
  • weak commitment
  • no culture survey
  • missing training

Risk

BS65000-6.1
Risk and Opportunity Identification

Identify and assess risks and opportunities affecting the organization across strategic, operational, financial, and reputational dimensions.

Artefacts an auditor will ask for
  • Strategic risk register
  • Operational risk register
  • Horizon scanning reports
Where this commonly fails
  • Strategic risks not separated from operational
  • No horizon scanning
BS65000-6.2
Scenario Planning

Use scenario planning techniques to anticipate disruption and stress test resilience arrangements.

Artefacts an auditor will ask for
  • Scenario library
  • Workshop outputs
  • Stress test reports
Where this commonly fails
  • No formal scenarios
  • Scenarios optimistic by default

Support

BS65000-7.1
Resources for Resilience

Determine and provide resources required for the resilience programme including financial, human, technological, and physical.

Artefacts an auditor will ask for
  • Resilience budget
  • Team headcount plan
  • Tool licensing
Where this commonly fails
  • No dedicated budget
  • Resilience an additional duty
BS65000-7.2
Competence and Awareness

Ensure personnel involved in resilience activities are competent through training, education, and experience, with general awareness across all staff.

Artefacts an auditor will ask for
  • Competence framework
  • Training records
  • Awareness campaign materials
Where this commonly fails
  • No competence framework
  • Awareness limited to BCM team
BS65000-7.4
Communication

Establish internal and external communication arrangements relevant to organizational resilience including during disruption.

Artefacts an auditor will ask for
  • Communication plan
  • Stakeholder contact list
  • Pre approved holding statements
Where this commonly fails
  • No pre approved statements
  • Contact list outdated
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.