ISO 22301:2019
Evidence request list. 57 controls, 57 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Context of the organization, ISO 22301:2019
Identify the external and internal issues bearing on the organization's purpose that could stop its business continuity management system from delivering the outcomes it is meant to deliver, taking account of its objectives, its products and services and the amount and type of risk it is prepared to carry.
- Documented context analysis naming external and internal issues
- Link from each issue to the BCMS outcome it threatens
- Evidence the analysis was reviewed when the organization or its market changed
- Statement of the risk appetite the analysis was judged against
- Context recorded once at certification and never revisited after reorganisation, acquisition or a change of product mix
- Issues listed generically (economic conditions, cyber threat) with no traceable effect on a BCMS outcome
- Internal issues omitted entirely, so the analysis reads as an external threat scan
Establish who holds a stake in the organization's continuity and what each of them requires of it, covering both stated expectations and the legal and regulatory obligations attached to the continuity of its products and services.
- Interested party register with the requirement recorded against each party
- Register of applicable continuity related legal and regulatory obligations
- Evidence both registers are maintained rather than one time artefacts
- A stakeholder list with no requirement recorded against any entry
- Legal obligations treated as a compliance department concern and never connected to continuity planning
- Regulators, customers under contractual continuity terms or emergency services left off the register
When establishing the BCMS, name the interested parties that are relevant to it and record what each of those parties requires.
- Interested party register, dated and owned
- The specific requirement captured for each listed party
- Method note showing how relevance to the BCMS was decided
- Relevance never argued, so the register is either everyone or only customers
- Requirements captured as categories rather than as something testable
- Register not revisited when new contracts or dependencies are taken on
Run and maintain a process that finds, obtains access to and assesses the legal and regulatory requirements applying to the continuity of the organization's products, services, activities and resources, ensure those requirements are reflected in how the BCMS is built and run, and keep that information documented and current.
- Documented process for identifying and assessing continuity related legal and regulatory requirements
- Current obligations register with source, applicability and assessment date
- Traceability from an obligation to the BCMS element that satisfies it
- Evidence of horizon scanning or subscription to a legal update source
- Obligations register held by legal and never reconciled against the BCMS
- No assessment step, so the register lists laws without saying what they demand of continuity
- Regime changes in new operating jurisdictions missed because the process has no trigger
Fix and document the boundaries of the BCMS, deciding which parts of the organization and which products and services fall inside it and justifying whatever is left outside.
- Approved scope statement held as documented information
- Rationale for the boundary drawn
- Documented exclusions with justification
- Scope written to fit the audit rather than the business, excluding the activities most likely to fail
- Scope statement with no version or approval trail
- Boundary silent on outsourced or shared service functions
Determine the boundaries and applicability of the BCMS from the context issues, the interested party requirements and the organization's own mission, goals and internal and external obligations, and hold the resulting scope as documented information.
- Scope document referencing the context issues and party requirements it was derived from
- Evidence of management approval of the scope
- Version history showing the scope has been maintained
- Scope asserted without any traceable derivation from context or obligations
- Mission and external obligations ignored, so scope is drawn on organizational convenience
- Scope never re-derived after the context analysis changed
State which parts of the organization are inside the BCMS having regard to location, size, nature and complexity, identify the products and services covered, and document and explain every exclusion so that no exclusion undercuts the organization's ability or responsibility to deliver continuity as established by the business impact analysis, the risk assessment and applicable law.
- List of in scope sites, entities and functions
- List of in scope products and services
- Exclusion log with the explanation for each exclusion
- Cross check that no exclusion contradicts the business impact analysis or a legal obligation
- Exclusions recorded with no explanation, or explained only as out of scope
- A site or entity excluded that the business impact analysis shows supports a prioritized activity
- Products and services described at brand level so the actual delivery chain is untested
Establish, implement, maintain and continually improve a business continuity management system, including the processes it needs and the way those processes interact, to the requirements of the standard.
- BCMS manual or equivalent showing the constituent processes and their interactions
- Process owners named for each BCMS process
- Evidence of operation across a full cycle rather than at implementation only
- A documented system that exists on paper with no evidence any process actually ran
- Process interactions undocumented, so handoffs between impact analysis, strategy and planning are invisible
- Continual improvement asserted but not evidenced anywhere in the BCMS
Improvement, ISO 22301:2019
Determine opportunities for improvement and implement the actions needed to achieve the intended BCMS outcomes; when a nonconformity occurs, react to it and deal with its consequences, evaluate whether action is needed to eliminate the cause by reviewing the nonconformity, determining its causes and checking whether similar ones exist or could occur, implement whatever action is needed, review the effectiveness of the corrective action, and change the BCMS if necessary, with corrective action proportionate to the effects encountered and documented evidence retained of the nature of the nonconformities, the actions taken and the results.
- Nonconformity register with source, description and immediate correction
- Root cause analysis records
- Extent of condition check for similar nonconformities elsewhere
- Corrective action records with an effectiveness review
- Evidence of any resulting BCMS change
- Correction recorded as corrective action, with the cause never examined
- Root cause stated as human error, which stops the analysis rather than completing it
- No extent of condition check, so the same failure recurs in a sister site
- Effectiveness review missing, so recurrence is the only test the action ever gets
- Action disproportionate to effect in either direction, over engineered or nominal
Continually improve the suitability, adequacy and effectiveness of the BCMS using qualitative and quantitative measures, considering the results of analysis and evaluation and the outputs of management review to determine whether there are needs or opportunities relating to the business or to the BCMS that must be addressed as part of improvement.
- Improvement register or backlog with items traceable to analysis, evaluation or management review
- Both qualitative and quantitative measures in use
- Evidence of improvements delivered over successive cycles
- Link from business change into the improvement determination
- Improvement evidenced only by corrective actions, so nothing improves that was not first broken
- Quantitative measures only, missing qualitative signals from exercises and near misses
- Improvement register that accumulates items and closes none
- Business needs never considered, so the BCMS improves against itself rather than against the organization
Leadership, ISO 22301:2019
Top management must personally own the BCMS: aligning the continuity policy and objectives with the strategic direction, integrating BCMS requirements into business processes, making resources available, communicating why effective continuity and conformity matter, holding the BCMS to its intended outcomes, directing and supporting the people who deliver it, promoting continual improvement, and backing other managers to lead continuity in their own areas.
- Minutes showing top management setting or approving continuity policy and objectives
- Evidence of BCMS requirements embedded in business process documentation
- Approved budget or resource allocation traceable to the BCMS
- Internal communications from top management about continuity
- Evidence of managers below top level held accountable for continuity in their areas
- Commitment evidenced only by a signature on the policy
- Continuity funded from a residual budget with no top management decision behind it
- Continuity treated as a specialist function that no line manager is answerable for
- No link demonstrable between continuity objectives and strategic direction
Maintain a business continuity policy that top management has set and that reaches the people inside the organization and the interested parties outside it who need to see it.
- Current approved business continuity policy
- Distribution and communication records
- Evidence the policy is obtainable by interested parties where appropriate
- Policy approved once and left unreviewed through several reorganisations
- Policy published on an intranet nobody is directed to
- No decision recorded about which interested parties should receive it
Top management must set a business continuity policy that suits the organization's purpose, gives a frame for setting continuity objectives, and commits the organization to satisfying applicable requirements and to continually improving the BCMS.
- Approved policy carrying an explicit commitment to applicable requirements and to improvement
- Approval record naming the top management body and the date
- Traceability from the policy to the continuity objectives set under it
- Generic policy text lifted from a template that says nothing about this organization's purpose
- Commitments to requirements or improvement missing or implied only
- Objectives set with no reference back to the policy framework
Hold the business continuity policy as documented information, communicate it within the organization, and make it available to interested parties where that is appropriate.
- Controlled copy of the policy with version and date
- Records of communication to staff, including new starters
- Evidence of external availability where appropriate, and the decision on which parties get it
- Policy communicated at launch and never to anyone hired since
- External availability neither provided nor consciously declined
- Uncontrolled copies in circulation alongside the current one
Top management must assign and communicate the responsibilities and authorities for the roles the BCMS depends on, and must specifically assign responsibility and authority for ensuring the BCMS conforms to the standard and for reporting BCMS performance back to top management.
- Role descriptions or a responsibility matrix covering BCMS roles
- Named individual accountable for BCMS conformity
- Named reporting line and evidence of performance reporting to top management
- Evidence the assignments were communicated
- Roles assigned in a matrix that the holders have never seen
- Conformity accountability and performance reporting rolled into one unfunded part time role
- Deputies undefined, so the BCMS has a single point of failure in its own governance
Operation, ISO 22301:2019
Plan, implement and control the processes needed to meet BCMS requirements and to carry out the actions determined under risks and opportunities, by establishing process criteria, controlling the processes against those criteria and keeping enough documented information to be confident the processes ran as planned; control planned changes and review the consequences of unintended ones, taking mitigating action, and ensure outsourced processes and the supply chain are controlled.
- Documented process criteria for BCMS operational processes
- Records showing processes ran to those criteria
- Change records covering planned changes and reviews of unintended change
- Evidence of control over outsourced processes and the supply chain
- Supply chain control asserted through contract clauses with no verification behind them
- Criteria absent, so control of a process cannot be demonstrated
- Unintended changes never reviewed because nothing detects them
- Outsourced processes treated as the provider's problem
Run and maintain the processes that establish what disruption would cost the organization over time and what could cause it, and refresh both whenever the organization or its operating context changes significantly.
- Documented BIA and risk assessment processes
- Current outputs of both
- Review triggers and evidence of review after significant change
- Both performed once at implementation and treated as permanent
- No defined trigger for refresh, so significant change passes unnoticed
- Risk assessment run without reference to the BIA outputs it should be scoped by
Implement and maintain systematic processes for analysing the business impact of disruption and for assessing disruption risk, and review the outputs of both at planned intervals and whenever there is significant change within the organization or in the context in which it operates.
- Written method for each process showing it is systematic and repeatable
- Planned review interval with evidence reviews occurred
- Change triggered reviews evidenced against actual organizational changes
- Method exists as a spreadsheet convention rather than a documented process
- Planned interval set at annual and then missed without escalation
- Significant change defined nowhere, so the change trigger never fires
Use the impact analysis process to set continuity priorities and requirements: define the impact types and criteria relevant to the organization's context, identify the activities supporting delivery of products and services, assess impacts over time from disrupting those activities, fix the point at which non resumption becomes unacceptable, set prioritized time frames within that point for resuming activities at a specified minimum acceptable capacity, identify the prioritized activities, and determine the resources, dependencies and interdependencies they rely on including partners and suppliers.
- Defined impact types and criteria approved for this organization
- Activity inventory mapped to products and services
- Impact over time analysis per activity
- Maximum tolerable period of disruption and resumption time frames with minimum acceptable capacity, approved by management
- Prioritized activity list with resource, dependency and interdependency mapping
- Recovery time frames set by aspiration and never reconciled to the impact analysis that should produce them
- Minimum acceptable capacity omitted, so a plan can claim recovery at any level of service
- Dependencies mapped one level deep, missing the supplier behind the supplier
- Impact criteria copied from a template rather than defined for this organization's context
Implement and maintain a risk assessment process that identifies the risks of disruption to the organization's prioritized activities and the resources they require, analyses and evaluates those risks, and determines which of them require treatment.
- Documented risk assessment process
- Risk register scoped to prioritized activities and their required resources
- Analysis and evaluation records with the criteria applied
- Treatment decisions recorded with rationale, including acceptance
- Risk register covering the enterprise generally rather than the prioritized activities specifically
- Evaluation criteria undefined, so treatment decisions are unreviewable
- Resource level risks such as single site or single supplier concentration not surfaced
- Accepted risks recorded without an acceptance authority
Choose continuity strategies from the impact and risk findings, select the solutions that deliver them, determine the resources they need and put them into effect.
- Strategy document traceable to BIA and risk assessment outputs
- Selection rationale for the chosen solutions
- Evidence solutions are implemented and maintained
- Strategy chosen before the impact analysis, then justified after the fact
- Solutions procured but never maintained to a state where they could be activated
- Resource requirements of the chosen solutions never worked out
On the basis of the business impact analysis and risk assessment outputs, identify and select business continuity strategies that consider options for before, during and after a disruption, each strategy comprising one or more solutions.
- Traceability from BIA and risk assessment outputs into the strategy options considered
- Options covering the before, during and after phases
- Record of which solutions make up each selected strategy
- Only during disruption options considered, with nothing done to reduce likelihood beforehand
- Strategy stated at a level too high to name any actual solution
- Options never documented, so only the chosen one is visible
Identify candidate strategies and solutions by the extent to which they meet the requirement to continue and recover prioritized activities within the identified time frames and agreed capacity, protect those activities, reduce the likelihood of disruption, shorten its duration, limit its impact on products and services, and provide for adequate resources.
- Option analysis scoring candidates against each identification factor
- Evidence time frame and capacity requirements came from the BIA
- Coverage of likelihood reduction options, not recovery options alone
- Candidates assessed on cost alone at the identification stage, collapsing identification into selection
- Likelihood reduction and duration shortening factors ignored
- Capacity requirement dropped, so options are judged on time only
Select from the identified candidates on the extent to which they meet the required time frames and agreed capacity, fit the amount and type of risk the organization is prepared to take, and stand up on associated costs and benefits.
- Selection decision record naming the three selection factors
- Statement of the risk the organization is prepared to take that the decision was judged against
- Cost and benefit analysis behind the chosen solution
- Approval by the authority able to accept the residual exposure
- Selection made on cost with time frames and risk appetite unexamined
- Risk appetite never articulated, so fit to appetite cannot be judged
- Residual gap between what the solution delivers and what the BIA requires left unrecorded and unaccepted
Determine the resources needed to implement the selected continuity solutions, considering at least people, information and data, physical infrastructure such as buildings, workplaces and facilities with their utilities, equipment and consumables, information and communication technology systems, transport and logistics, finance, and partners and suppliers.
- Resource requirement schedule per solution covering each required resource type
- Evidence the resource is available or contracted at the required quantity and time
- Reconciliation between required resources and the dependencies identified in the BIA
- Resource analysis covering ICT only, with people, finance and logistics unexamined
- Requirements stated without quantity or time to availability
- Partner and supplier resources assumed available with no contractual basis
- Consumables and utilities omitted, so a recovery site cannot actually operate
Implement and maintain the selected business continuity solutions so that they can be activated when they are needed.
- Implementation records per selected solution
- Maintenance regime keeping the solution in an activatable state
- Readiness evidence such as a successful activation test or standby verification
- Solution implemented then left to decay as systems, sites and contracts change around it
- Activation never verified, so readiness is an assumption
- Maintenance responsibility unassigned after the implementation project closed
Maintain a response structure and a set of plans and procedures that let the organization warn and communicate, respond in a structured way, continue prioritized activities and return to normal operation.
- Current plan set covering response structure, warning and communication, plans and recovery
- Evidence the plan set derives from the selected strategies and solutions
- Distribution evidence showing plans are where responders are
- Plan set that documents response but stops short of return to normal operations
- Plans not derived from the selected solutions, so they assume capability that was never built
- Plans available only in one location or one format
Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.
- Documented response structure
- Procedures stating immediate steps and the roles that take them
- Traceability from selected strategies and solutions to the documented plans
- Evidence procedures accommodate changing conditions rather than a single scenario
- Procedures written for one rehearsed scenario, brittle against anything else
- Immediate steps missing, so the first hour is left to judgement under pressure
- Roles assigned to job titles that no longer exist
- Plans not traceable to any strategy, so their assumptions are untested
Implement and maintain a structure of one or more teams responsible for responding to disruptions, with roles, responsibilities and inter team relationships clearly stated, collectively competent to assess a disruption and its impact against pre defined thresholds justifying a formal response, activate the response and the continuity solutions, plan actions, set priorities with life safety first, monitor the disruption and the response, and communicate with interested parties, authorities and the media; each team must have identified personnel and alternates with the necessary responsibility, authority and competence, and documented procedures for activation, operation, coordination and communication.
- Team structure chart with roles, responsibilities and inter team relationships
- Pre defined activation thresholds and the authority to invoke them
- Named team members and alternates with competence evidence
- Documented team procedures for activation, operation, coordination and communication
- Exercise evidence that the teams performed the listed competences
- Alternates named on paper but never included in an exercise
- Activation thresholds undefined, so invocation waits on consensus
- Life safety priority stated in policy but absent from the team procedures
- Media and authority communication left to a role with no delegated authority to speak
Document and maintain procedures for communicating internally and externally with relevant interested parties covering what, when, with whom and how, for receiving, documenting and responding to communications including from national or regional risk advisory systems, for keeping the means of communication available during a disruption, for structured communication with emergency responders, for the organization's media response and communications strategy, and for recording the disruption, the actions taken and the decisions made; where applicable also alert parties potentially impacted by an actual or impending disruption and ensure coordination between multiple responding organizations, and exercise these procedures within the exercise programme.
- Communication procedures covering internal, external, responder and media routes
- Verified alternate communication means that survive loss of primary systems
- Incident log template and completed logs from exercises or real events
- Contact data with evidence it is maintained
- Exercise records covering the warning and communication procedures specifically
- Communication cascade depends on the corporate email and telephony that the disruption removes
- Contact lists stale, with departed staff and superseded numbers
- No decision log kept, so the response cannot be reconstructed or defended afterwards
- Inbound communication ignored, with procedures written for broadcast only
- Media response procedure exists but has never been exercised
Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand do
- Plan set with each plan carrying every required element
- Activation criteria and thresholds stated in the plan itself
- Interdependency and resource sections reconciled to the BIA
- Stand down process defined
- Evidence of availability at the point of use, including offline copies
- Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
- Agreed capacity omitted, so continuing an activity at any level counts as success
- Welfare and environmental consequences unaddressed
- Plans held only in a document management system that the disruption may take out
- Interdependencies listed inside the plan that contradict the BIA
Maintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.
- Documented restoration and return to normal processes
- Criteria for deciding that temporary measures can be withdrawn
- Evidence of use, from exercises or real events, including backlog clearance
- Recovery treated as implicit once the incident is closed, with no process behind it
- No criteria for withdrawing temporary measures, so workarounds become permanent
- Backlog and data reconciliation built up during the workaround never planned for
Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.
- Exercise programme showing scope, scenario and interval coverage over time
- Exercise aims and objectives defined before each exercise
- Formal post exercise reports with outcomes, recommendations and actions
- Action tracking to closure with evidence of the resulting change
- Coverage analysis showing the programme validates every strategy and solution over its cycle
- The same comfortable scenario rehearsed annually, so rare failure modes are never stressed
- Exercises run without defined aims, so they cannot pass or fail
- Post exercise findings recorded and never actioned
- Programme covers ICT recovery only, leaving people, premises and supplier scenarios untested
- No coverage analysis, so gaps in what has been validated go unnoticed
Evaluate whether the business impact analysis, risk assessment, strategies, solutions, plans and procedures remain suitable, adequate and effective, carrying out those evaluations through reviews, analysis, exercises, tests, post incident reports and performance evaluations, evaluating the continuity capabilities of relevant partners and suppliers, evaluating compliance with applicable legal and regulatory requirements and industry practice and conformity with the organization's own policy and objectives, and updating documentation and procedures promptly; conduct these evaluations at planned intervals, after an incident or activation, and when significant change occurs.
- Evaluation records covering each element of the BCMS documentation set
- Partner and supplier continuity capability assessments with evidence behind them
- Compliance and conformity evaluation results
- Post incident and post activation evaluations
- Documentation update records traceable to evaluation findings
- Supplier continuity accepted on a self assessment questionnaire with nothing verified
- Evaluation performed only on the anniversary, never after an actual activation
- Findings raised but documentation not updated, so the next responder uses the superseded version
- Legal and regulatory compliance evaluation omitted from the continuity evaluation entirely
Performance evaluation, ISO 22301:2019
Determine what needs monitoring and measuring, the methods that will produce valid results, and when and by whom measurement is performed and when and by whom the results are analysed and evaluated; retain the results as documented evidence and use them to evaluate BCMS performance and effectiveness.
- Defined measurement set with method, frequency and responsible person for measurement and for analysis
- Retained measurement results
- Evaluation of BCMS performance and effectiveness drawn from those results
- Justification that the methods produce valid, comparable results
- Activity counted rather than effectiveness measured, so the metrics cannot show whether the BCMS works
- Measurement performed but never analysed, with results filed unread
- Different methods used across periods, making the trend meaningless
- Analysis responsibility unassigned, so measurement stops at collection
Audit the BCMS internally on a planned basis, and run the audit programme that makes those audits objective, competent and consequential.
- Audit programme and completed audit reports
- Auditor independence evidence
- Findings tracked to closure
- Audits performed by the people who run the BCMS
- Programme planned but not completed, with deferrals unescalated
- Findings closed on assertion rather than on verified action
Conduct internal audits at planned intervals to provide information on whether the BCMS conforms both to the organization's own requirements for it and to the requirements of the standard, and whether it is effectively implemented and maintained.
- Audit schedule with planned intervals and evidence of adherence
- Audit reports addressing conformity to internal requirements, to the standard, and to effective implementation
- Coverage map showing the whole BCMS is audited across a cycle
- Audits test conformity to the standard only and never to the organization's own BCMS requirements
- Effectiveness untested, with audit limited to documentation existence
- Coverage concentrated on easy areas, leaving parts of the BCMS unaudited for years
Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and the results of previous audits; define the criteria and scope of each audit, select auditors and conduct audits so the process is objective and impartial, report results to relevant managers, retain documented evidence of the programme and the audit results, ensure necessary corrective actions are taken without undue delay to eliminate detected nonconformities and their causes, and ensure follow up actions verify what was done and report the verification results.
- Documented audit programme with frequency, method and responsibility, risk weighted
- Per audit criteria and scope statements
- Auditor selection records evidencing objectivity and impartiality
- Management reporting records
- Corrective action records with timeliness evidence and verification of the actions taken
- Programme frequency uniform across all processes, ignoring importance and prior audit results
- Auditors selected for availability, auditing their own work
- Corrective actions raised without a due date, so undue delay cannot be detected
- Follow up confirms an action was recorded rather than verifying it worked
Top management must review the BCMS on a planned basis against a defined set of inputs, and must record and act on the decisions the review produces.
- Scheduled review with attendance evidencing top management
- Inputs presented and outputs recorded
- Actions arising tracked to closure
- Review delegated to the BCMS manager and the management team merely noted
- Inputs incomplete, so decisions rest on partial information
- Decisions recorded but never converted into tracked actions
Top management must review the organization's BCMS at planned intervals to ensure it remains suitable, adequate and effective.
- Review schedule and completed review records at the planned interval
- Attendance list showing top management participation
- Explicit conclusion on continuing suitability, adequacy and effectiveness
- Interval slips repeatedly without escalation
- Reviews held but reaching no stated conclusion on suitability, adequacy and effectiveness
- Top management represented by a delegate with no decision authority
The review must consider the status of actions from previous reviews, changes in external and internal issues relevant to the BCMS, BCMS performance information including trends in nonconformities and corrective actions, monitoring and measurement results and audit results, feedback from interested parties, the need for changes including to policy and objectives, procedures and resources that could improve performance and effectiveness, information from the business impact analysis and risk assessment, the output of the evaluation of continuity documentation and capabilities, risks or issues not adequately addressed in any previous risk assessment, lessons learned and actions arising from near misses and disruptions, and opportunities for continual improvement.
- Review pack demonstrably covering every required input
- Trend data rather than point in time figures for nonconformities, measurement and audits
- Near miss and disruption lessons presented with the actions arising
- Interested party feedback captured and presented
- Evidence that previously unaddressed risks were surfaced rather than dropped
- Input pack covering audit results and little else
- Near misses never captured, so the richest source of learning is absent
- Trends replaced by the current month, hiding deterioration
- Risks judged out of scope in an earlier assessment quietly disappear rather than being re presented
The review must produce decisions on continual improvement opportunities and on any changes needed to improve BCMS efficiency and effectiveness, covering variations to scope, updates to the business impact analysis, risk assessment, strategies, solutions and plans, modification of procedures and controls to respond to internal or external issues, and how control effectiveness will be measured; retain documented evidence of the results, communicate them to relevant interested parties and take appropriate action on them.
- Minutes recording decisions against each required output area
- Actions with owners and dates traceable from the decisions
- Communication records to relevant interested parties
- Evidence of the resulting change in the BCMS artefacts
- Minutes that record discussion but no decisions
- Decisions on how control effectiveness will be measured omitted, so measurement never improves
- Results not communicated beyond the review attendees
- Actions raised and then closed administratively at the next review without evidence
Planning, ISO 22301:2019
Work out what could help or hinder the management system itself and plan what to do about it, keeping this separate from the disruption risks handled under business impact analysis and risk assessment.
- Register of risks and opportunities relating to BCMS effectiveness
- Planned actions with owners and integration points into BCMS processes
- Evidence that BCMS risk is kept distinct from operational disruption risk
- BCMS risk conflated with disruption risk, so management system weaknesses are never surfaced
- Opportunities omitted entirely, leaving a one sided risk register
- Actions planned but never integrated into a BCMS process or evaluated
Taking the context issues and interested party requirements already identified, determine which risks and opportunities must be addressed so the BCMS achieves its intended outcomes, prevents or reduces undesired effects, and continues to improve.
- Risk and opportunity register traceable to specific context issues and party requirements
- Statement of the intended BCMS outcomes the register is judged against
- Review record showing the register is maintained
- Register produced independently of the context analysis, so the two never agree
- Only threats recorded, with continual improvement opportunities absent
- No stated BCMS outcome, so nothing anchors what counts as a risk
Plan the actions that will address those risks and opportunities, and plan how each action will be integrated into and implemented within BCMS processes and how its effectiveness will subsequently be evaluated.
- Action plan naming owner, target date and the BCMS process the action lands in
- Evidence of implementation within that process
- Effectiveness evaluation carried out through performance evaluation
- Actions closed on completion with no evaluation of whether they worked
- Actions held in a standalone tracker that never touches a BCMS process
- No effectiveness criterion set, so evaluation has nothing to test against
Set business continuity objectives and plan concretely how each of them will be achieved.
- Documented objectives with the plan attached to each
- Evidence objectives are monitored and reported
- Evidence the objective set is updated as the organization changes
- Objectives stated as aspirations with no plan behind them
- Objectives never measured, so achievement is asserted rather than shown
- Objective set unchanged over years despite material change in the business
Establish business continuity objectives at the relevant functions and levels; each must be consistent with the continuity policy, measurable where practicable, informed by applicable requirements, and monitored, communicated and updated as appropriate, with the objectives retained as documented information.
- Retained objective register showing function, level, measure and owner
- Evidence of monitoring against each measure
- Communication records for the objectives
- Update history for the objective set
- Objectives only at corporate level, so no function owns one
- Measurability waived without any judgement recorded on why it was impracticable
- Objectives inconsistent with the policy, most often on recovery ambition
For each objective, determine what will be done, what resources it needs, who is responsible, when it will be completed and how the results will be evaluated.
- Plan per objective covering activity, resource, owner, date and evaluation method
- Evidence the resource named was actually made available
- Evaluation results against the stated method
- Plans that name an owner and a date and nothing else
- Resource requirement omitted, so the objective competes for unallocated effort
- Evaluation method left undefined until after the deadline passes
When change to the BCMS is needed, including change arising from nonconformity and improvement, carry it out in a planned way that considers the purpose and potential consequences of the change, the integrity of the BCMS, the availability of resources, and how responsibilities and authorities are allocated or reallocated.
- Change records for BCMS changes showing purpose and consequence analysis
- Assessment of the effect on BCMS integrity
- Resource and accountability reallocation recorded with the change
- BCMS changes made informally, visible only as an unexplained document version bump
- Consequence analysis skipped for changes that originated as corrective actions
- Responsibilities left with departed staff after a reorganisation
Support, ISO 22301:2019
Determine and provide the resources needed to establish, implement, maintain and continually improve the BCMS.
- Documented determination of the resources the BCMS requires
- Evidence of provision, such as budget allocation, headcount or contracted capacity
- Evidence resourcing is revisited as the BCMS matures
- Resource need never determined, so provision is whatever was left over
- Provision covers implementation only and lapses at maintenance
- Resource shortfalls known to the BCMS owner but never escalated to top management
Determine the competence needed by people whose work under the organization's control affects business continuity performance, ensure they hold it on the basis of education, training or experience, take and evaluate action where competence is missing, and retain documented evidence of competence.
- Competence requirements defined per continuity role
- Training records, qualifications or experience evidence per person
- Gap actions with an evaluation of whether the action closed the gap
- Retained competence records
- Attendance registers filed as though attendance proved competence
- Competence defined for the continuity team only, ignoring response team members and contractors
- Actions taken to build competence never evaluated for effectiveness
People doing work under the organization's control must be aware of the business continuity policy, of how they contribute to BCMS effectiveness and what better continuity performance delivers, of the implications of not conforming, and of their own role and responsibilities before, during and after a disruption.
- Awareness material covering all four required points
- Delivery records covering staff, contractors and new starters
- A test of awareness, such as a spot check or survey, rather than delivery evidence alone
- Awareness content covering the policy only, silent on individual roles during a disruption
- Contractors and temporary staff excluded despite working under the organization's control
- No verification, so awareness is evidenced by attendance rather than by knowledge
Determine the internal and external communications the BCMS requires, settling what will be communicated, when, with whom, how, and by whom.
- Communication plan addressing each of the five determinations
- Named communicators with authority to speak externally
- Evidence the plan has been used, not merely written
- Plan covers what and when but never says who is authorised to communicate
- External communication deferred entirely to corporate affairs with no continuity input
- Plan untested, so channel assumptions fail on first use
Hold the documented information the BCMS depends on, create and update it to a defined standard, and control it throughout its life.
- Document register covering BCMS documentation
- Defined creation, update and approval route
- Access, retention and disposition rules in force
- Register incomplete, so documents exist that nothing controls
- External origin documents excluded from control
- Retention rules stated but never applied
The BCMS must include both the documented information the standard requires and whatever further documented information the organization itself judges necessary for the BCMS to be effective.
- Mapping from each documentation requirement of the standard to the document that satisfies it
- Rationale for additional documentation the organization chose to hold
- Evidence the set is proportionate to the size and complexity of the organization
- Documentation assembled to a template with no mapping back to requirements
- Organization specific documentation absent, leaving gaps the standard does not name explicitly
- Volume mistaken for effectiveness, with documents nobody uses
When creating or updating documented information, ensure appropriate identification and description, an appropriate format and medium, and review and approval for suitability and adequacy.
- Documents carrying title, date, author or reference and version
- Review and approval records showing who approved and when
- Format and media choices suited to how the document is used in a disruption
- Approval evidenced by a name in a footer with no date or record
- Format unsuited to use, such as plans available only on the systems a disruption takes out
- Updates issued without re-approval
Control the documented information the BCMS and the standard require so it is available and suitable for use where and when needed and adequately protected, addressing distribution, access, retrieval and use, storage and preservation including legibility, change control, and retention and disposition; documented information of external origin that the BCMS depends on must also be identified and controlled.
- Access and distribution controls with evidence of enforcement
- Storage and preservation arrangements including offline or alternate site availability
- Version control history and retention and disposition schedule
- Register of controlled external origin documents
- Plans stored only on the corporate network, so they are unavailable in the scenario they exist for
- External origin documents such as supplier contracts and regulator guidance left uncontrolled
- Protection considered for confidentiality but not for integrity or loss
- Superseded plans still in circulation at response team locations
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22301:2019 framework page.