Skip to content

Evidence request lists

ISO 22313:2020 - Guidance on Business Continuity Management Systems

Evidence request list. 47 controls, 47 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Clause 10: Improvement

ISO-22313-10.1
Nonconformity and corrective action

Guidance on reacting to nonconformities, evaluating the need for corrective action, and implementing changes.

Artefacts an auditor will ask for
  • Updated process documentation
  • Innovation maturity reassessment
  • Root cause analysis records
Where this commonly fails
  • Feedback loops from operations back to strategy missing
  • Lessons learned stored but never reused
  • Corrective actions closed without verifying effectiveness
  • Root cause analysis stops at symptom level
  • Maturity reassessment skipped year over year
ISO-22313-10.2
Continual improvement

Guidance on continually improving the suitability, adequacy, and effectiveness of the BCMS.

Artefacts an auditor will ask for
  • Root cause analysis records
  • Retrospective and post-mortem notes
  • Lessons learned reports
  • Process improvement proposals tracker
  • Updated process documentation
  • Continual improvement register
Where this commonly fails
  • Corrective actions closed without verifying effectiveness
  • Root cause analysis stops at symptom level
  • Lessons learned stored but never reused
  • Improvement register stale, items older than 12 months unactioned

Clause 4: Context of the Organization

ISO-22313-4.1
Understanding the organization and its context

Guidance on reviewing strategic objectives, internal and external issues, and their relevance to business continuity.

Artefacts an auditor will ask for
  • Competitor innovation benchmark
  • IMS scope statement signed by leadership
  • Market and technology radar
Where this commonly fails
  • Internal capability gaps not assessed against strategy
  • Stakeholder map omits external innovation partners (universities, startups)
  • Context analysis treated as one-off, not refreshed annually
  • Trend scanning is ad hoc and undocumented
  • Innovation maturity baseline never established
ISO-22313-4.2
Understanding the needs and expectations of interested parties

Guidance on identifying stakeholders and understanding their requirements related to business continuity.

Artefacts an auditor will ask for
  • Innovation context register
  • PESTEL/SWOT analysis covering innovation landscape
  • Trend and foresight scan report
  • IMS scope statement signed by leadership
Where this commonly fails
  • Stakeholder map omits external innovation partners (universities, startups)
  • Innovation maturity baseline never established
  • Internal capability gaps not assessed against strategy
  • Trend scanning is ad hoc and undocumented
  • Strategic intelligence not feeding into innovation decisions
ISO-22313-4.3
Determining the scope of the BCMS

Guidance on defining the boundaries and applicability of the business continuity management system.

Artefacts an auditor will ask for
  • Innovation maturity baseline assessment
  • Strategic intelligence brief
  • Interested-party requirements log
  • Stakeholder map with innovation interests
  • PESTEL/SWOT analysis covering innovation landscape
Where this commonly fails
  • IMS scope undefined or inconsistent across business units
  • Stakeholder map omits external innovation partners (universities, startups)
  • Trend scanning is ad hoc and undocumented
ISO-22313-4.4
Business continuity management system

Guidance on establishing, implementing, maintaining, and continually improving a BCMS in accordance with ISO 22301.

Artefacts an auditor will ask for
  • Strategic intelligence brief
  • IMS scope statement signed by leadership
  • Innovation maturity baseline assessment
  • PESTEL/SWOT analysis covering innovation landscape
  • Market and technology radar
Where this commonly fails
  • Stakeholder map omits external innovation partners (universities, startups)
  • IMS scope undefined or inconsistent across business units
  • Strategic intelligence not feeding into innovation decisions
  • Context analysis treated as one-off, not refreshed annually
  • Trend scanning is ad hoc and undocumented

Clause 5: Leadership

ISO-22313-5.1
Leadership and commitment

Guidance on how top management should demonstrate leadership and commitment to the BCMS.

Artefacts an auditor will ask for
  • Board minutes referencing innovation strategy
  • Leadership innovation commitments register
  • Strategic alignment matrix linking innovation to business goals
  • Innovation council terms of reference
  • RACI for innovation roles
  • Innovation vision and strategy document
Where this commonly fails
  • Innovation strategy disconnected from corporate strategy
  • Roles and responsibilities for innovation undefined
  • Culture barriers to risk-taking not addressed by leadership
  • Executive sponsorship limited to lip service, no time committed
ISO-22313-5.2
Policy

Guidance on establishing a business continuity policy that is appropriate to the organization's purpose.

Artefacts an auditor will ask for
  • Strategic alignment matrix linking innovation to business goals
  • Board minutes referencing innovation strategy
  • Approved innovation policy
  • Innovation vision and strategy document
  • Executive innovation charter
Where this commonly fails
  • Roles and responsibilities for innovation undefined
  • No clear accountability for innovation outcomes
  • Executive sponsorship limited to lip service, no time committed
ISO-22313-5.3
Organizational roles, responsibilities and authorities

Guidance on assigning and communicating management roles and responsibilities within the BCMS.

Artefacts an auditor will ask for
  • RACI for innovation roles
  • Innovation governance framework
  • Strategic alignment matrix linking innovation to business goals
  • Leadership innovation commitments register
  • Executive innovation charter
Where this commonly fails
  • Executive sponsorship limited to lip service, no time committed
  • No clear accountability for innovation outcomes
  • Innovation strategy disconnected from corporate strategy
  • Governance forum lacks decision-making authority

Clause 6: Planning

ISO-22313-6.1
Actions to address risks and opportunities

Guidance on determining risks and opportunities that need to be addressed to ensure the BCMS can achieve its intended outcomes.

Artefacts an auditor will ask for
  • Innovation objectives with measurable targets
  • Change management plan for innovation initiatives
  • Innovation portfolio dashboard
  • Resource allocation plan
  • Portfolio balancing model (horizons 1/2/3)
  • Innovation roadmap
Where this commonly fails
  • Risk treatment plans absent for high-uncertainty bets
  • Initiative prioritisation done by HiPPO not criteria
  • Roadmap not updated when strategy changes
  • Innovation objectives lack measurable targets
ISO-22313-6.2
Business continuity objectives and plans to achieve them

Guidance on setting measurable BC objectives and establishing plans with responsibilities, timeframes, and resources.

Artefacts an auditor will ask for
  • Innovation portfolio dashboard
  • Opportunity and risk register
  • Initiative prioritisation scorecard
  • Innovation roadmap
Where this commonly fails
  • Risk treatment plans absent for high-uncertainty bets
  • Opportunities and risks tracked separately with no link to objectives
  • No resource plan tied to portfolio priorities
  • Innovation objectives lack measurable targets
ISO-22313-6.3
Planning changes to the BCMS

Guidance on managing changes to the business continuity management system in a planned manner.

Artefacts an auditor will ask for
  • Opportunity and risk register
  • Resource allocation plan
  • Portfolio balancing model (horizons 1/2/3)
  • Innovation roadmap
Where this commonly fails
  • Opportunities and risks tracked separately with no link to objectives
  • No resource plan tied to portfolio priorities
  • Portfolio biased toward horizon 1 incremental projects
  • Roadmap not updated when strategy changes

Clause 7: Support

ISO-22313-7.1
Resources

Guidance on determining and providing resources needed for the establishment, implementation, and improvement of the BCMS.

Artefacts an auditor will ask for
  • Resource and budget plan for innovation
  • Communication plan (internal/external)
  • Competence matrix for innovation roles
  • IP register and assignment agreements
  • Training records and learning paths
  • Innovation tools and methods catalogue
Where this commonly fails
  • Innovation budget not ring-fenced from operating budget
  • Competence requirements for innovation roles not defined
  • Strategic intelligence siloed in one team
  • Tools and methods inconsistent across teams
  • Knowledge from past projects not captured or reused
ISO-22313-7.2
Competence

Guidance on ensuring personnel performing BC functions have the necessary competence through education, training, or experience.

Artefacts an auditor will ask for
  • Strategic intelligence repository
  • Training records and learning paths
  • Communication plan (internal/external)
  • IP register and assignment agreements
  • Time-allocation policy (e.g., 10% innovation time)
Where this commonly fails
  • Strategic intelligence siloed in one team
  • Knowledge from past projects not captured or reused
  • Competence requirements for innovation roles not defined
ISO-22313-7.3
Awareness

Guidance on ensuring personnel are aware of the BC policy, their contribution to the BCMS, and implications of non-conformance.

Artefacts an auditor will ask for
  • Training records and learning paths
  • IP register and assignment agreements
  • Document control register for IMS
  • Partnership and collaboration agreements
Where this commonly fails
  • IP register incomplete, ownership disputes likely
  • Knowledge from past projects not captured or reused
  • Strategic intelligence siloed in one team
ISO-22313-7.4
Communication

Guidance on determining internal and external communication requirements related to the BCMS.

Artefacts an auditor will ask for
  • Training records and learning paths
  • Document control register for IMS
  • IP register and assignment agreements
  • Partnership and collaboration agreements
  • Innovation infrastructure inventory
  • Time-allocation policy (e.g., 10% innovation time)
Where this commonly fails
  • Partnership agreements lack IP and confidentiality clauses
  • Strategic intelligence siloed in one team
  • IP register incomplete, ownership disputes likely
  • Tools and methods inconsistent across teams
  • Innovation budget not ring-fenced from operating budget
ISO-22313-7.5
Documented information

Guidance on the creation, updating, and control of documented information required by the BCMS.

Artefacts an auditor will ask for
  • Partnership and collaboration agreements
  • Time-allocation policy (e.g., 10% innovation time)
  • Knowledge repository / lessons learned database
  • Innovation infrastructure inventory
  • Document control register for IMS
Where this commonly fails
  • Innovation budget not ring-fenced from operating budget
  • Competence requirements for innovation roles not defined
  • Tools and methods inconsistent across teams
  • Knowledge from past projects not captured or reused
  • Time allocation for innovation crowded out by BAU

Clause 8: Operation

ISO-22313-8.1
Operational planning and control

Guidance on planning, implementing, and controlling the processes needed to meet BCMS requirements.

Artefacts an auditor will ask for
  • Maintenance plan tied to energy performance
  • Operating procedures for each SEU
  • Shift handover logs covering energy
  • Setpoint and operating window register
  • Change management records affecting energy
Where this commonly fails
  • Maintenance focused on uptime not energy
  • Change management bypasses energy review
  • Operating criteria not documented for SEUs
  • Outsourced providers have no energy obligations
  • Setpoints drift between shifts
ISO-22313-8.2
Business impact analysis and risk assessment

Guidance on conducting business impact analysis and assessing risks of disruption to prioritized activities.

Artefacts an auditor will ask for
  • Design brief template with energy criteria
  • Design review minutes covering energy
  • Capex business case template requiring EnPI impact
  • Commissioning records validating energy performance
  • Life cycle cost or energy assessment records
  • Specification checklist for energy efficient equipment
Where this commonly fails
  • Energy considered only after design freeze
  • No life cycle cost analysis
  • Commissioning does not verify energy performance
  • Design briefs silent on energy
ISO-22313-8.3
Business continuity strategies and solutions

Guidance on determining and selecting appropriate strategies and solutions for continuing prioritized activities.

Artefacts an auditor will ask for
  • Specification template for energy using equipment
  • Purchase order checklist for energy criteria
  • Contractor briefs referencing the energy policy
Where this commonly fails
  • Renewable or low carbon options not evaluated
  • Energy specifications not communicated to suppliers
  • Suppliers not assessed against energy criteria
  • Procurement decisions based on capex only
ISO-22313-8.4
Business continuity plans and procedures

Guidance on establishing and implementing documented plans and procedures for responding to disruptions.

Artefacts an auditor will ask for
  • EnMS clause mapping to the control
  • Records demonstrating top management oversight
  • Management review minutes covering energy performance
  • Action plan aligned with clause 6.2
Where this commonly fails
  • Top management oversight not evidenced
  • Control implemented without explicit link to the EnMS
  • Continual improvement not demonstrated through EnPIs
ISO-22313-8.5
Exercise programme

Guidance on establishing an exercise and testing programme to validate the effectiveness of BC strategies and plans.

Artefacts an auditor will ask for
  • Internal audit results for the EnMS
  • Records demonstrating top management oversight
  • Evidence pack referencing energy review and EnPIs
  • Action plan aligned with clause 6.2
  • Management review minutes covering energy performance
Where this commonly fails
  • Records dispersed and not centrally managed
  • Energy performance impact not assessed
  • Continual improvement not demonstrated through EnPIs

Clause 9: Performance Evaluation

ISO-22313-9.1
Monitoring, measurement, analysis and evaluation

Guidance on determining what needs to be monitored and measured to evaluate BCMS performance and effectiveness.

Artefacts an auditor will ask for
  • Performance evaluation criteria document
  • Balanced scorecard for innovation
  • Internal audit programme and reports
  • Customer and partner feedback summary
  • Benchmarking study results
  • Measurement and evaluation procedure
Where this commonly fails
  • Benchmarking against peers absent
  • Management reviews skip innovation as an agenda item
  • KPIs measure activity (idea count) not outcomes (revenue, adoption)
  • Lagging indicators only, no leading indicators
ISO-22313-9.2
Internal audit

Guidance on conducting internal audits at planned intervals to verify BCMS conformance and effectiveness.

Artefacts an auditor will ask for
  • Audit nonconformity log
  • Measurement and evaluation procedure
  • Internal audit programme and reports
Where this commonly fails
  • Benchmarking against peers absent
  • Evaluation criteria differ across portfolio without rationale
  • Management reviews skip innovation as an agenda item
  • KPIs measure activity (idea count) not outcomes (revenue, adoption)
  • Lagging indicators only, no leading indicators
ISO-22313-9.3
Management review

Guidance on top management review of the BCMS to ensure its continuing suitability, adequacy, and effectiveness.

Artefacts an auditor will ask for
  • Innovation KPI dashboard
  • Customer and partner feedback summary
  • Balanced scorecard for innovation
  • Management review minutes and actions
  • Innovation analytics report
Where this commonly fails
  • Evaluation criteria differ across portfolio without rationale
  • Customer feedback not systematically captured
  • Lagging indicators only, no leading indicators
  • Internal audits of IMS not scheduled

Context

ISO22313-4.1
Guidance on understanding context

Use guidance to determine internal and external issues that shape BCMS direction including dependencies.

Artefacts an auditor will ask for
  • Context analysis
  • Dependency map
  • PESTLE
Where this commonly fails
  • Dependencies not mapped
  • Context generic
ISO22313-4.2
Guidance on interested parties

Identify and prioritise interested parties whose needs influence BCMS outcomes including regulators and supply chain.

Artefacts an auditor will ask for
  • Stakeholder register
  • Prioritisation
  • Supplier list
Where this commonly fails
  • Supply chain stakeholders absent
  • Priority not set
ISO22313-4.3
Guidance on BCMS scope

Apply guidance to set a meaningful BCMS scope including critical activities, products, services, and exclusions.

Artefacts an auditor will ask for
  • Scope statement
  • Critical activity list
  • Exclusion rationale
Where this commonly fails
  • Critical activities undefined
  • Scope cosmetic

Evaluation

ISO22313-9.1
Guidance on monitoring and evaluation

Monitor BCMS performance using leading and lagging indicators and evaluate effectiveness.

Artefacts an auditor will ask for
  • KPI dashboard
  • Indicator definitions
  • Reports
Where this commonly fails
  • Only lagging KPIs
  • No effectiveness measure
ISO22313-9.2
Guidance on internal audit

Plan and conduct internal audits using a risk-based approach with independent auditors.

Artefacts an auditor will ask for
  • Audit plan
  • Reports
  • Auditor independence statement
Where this commonly fails
  • Auditors not independent
  • No risk basis
ISO22313-9.3
Guidance on management review

Conduct management review with inputs covering performance, audits, exercises, and improvement opportunities.

Artefacts an auditor will ask for
  • Review pack
  • Minutes
  • Decisions log
Where this commonly fails
  • Inputs thin
  • Decisions not actioned

Improvement

ISO22313-10.1
Guidance on nonconformity and corrective action

Use guidance to identify nonconformities, apply root cause analysis, and verify corrective action effectiveness.

Artefacts an auditor will ask for
  • NC log
  • RCA records
  • Verification evidence
Where this commonly fails
  • No verification step
  • RCA shallow
ISO22313-10.2
Guidance on continual improvement

Drive continual improvement through learning from exercises, incidents, audits, and reviews.

Artefacts an auditor will ask for
  • Improvement log
  • Lessons learned
  • Maturity assessments
Where this commonly fails
  • No maturity model
  • Lessons not actioned

Leadership

ISO22313-5.1
Guidance on leadership and commitment

Guidance to embed leadership commitment, sponsorship, and visible support for the BCMS at executive level.

Artefacts an auditor will ask for
  • Sponsor charter
  • Exec briefings
  • Visibility plan
Where this commonly fails
  • No exec sponsor
  • BC invisible to staff
ISO22313-5.2
Guidance on BC policy

Develop a meaningful BC policy supported by guidance on content, communication, and review.

Artefacts an auditor will ask for
  • BC policy
  • Comms records
  • Review log
Where this commonly fails
  • Generic policy
  • No staff awareness
ISO22313-5.3
Guidance on roles and authorities

Guidance to assign BC roles including BCM coordinator, response teams, and recovery owners.

Artefacts an auditor will ask for
  • RACI
  • Team charters
  • Role descriptions
Where this commonly fails
  • No team charters
  • Recovery owners absent

Operation

ISO22313-8.1
Guidance on operational planning and control

Plan operational processes for BC including outsourced processes and change management.

Artefacts an auditor will ask for
  • Process map
  • Outsourced register
  • Change log
Where this commonly fails
  • Outsourced not in BC scope
  • Changes not BC-reviewed
ISO22313-8.2
Guidance on BIA and risk assessment

Apply BIA and risk assessment guidance to determine recovery priorities, RTOs, RPOs, and MTPDs.

Artefacts an auditor will ask for
  • BIA report
  • RTO/RPO register
  • MTPD log
Where this commonly fails
  • RTOs not validated
  • MTPD undefined
ISO22313-8.3
Guidance on BC strategies and solutions

Select BC strategies and solutions for people, premises, technology, information, and supplies.

Artefacts an auditor will ask for
  • Strategy paper
  • Resource plan
  • Supplier resilience plan
Where this commonly fails
  • No supplier resilience
  • Strategy ignores people
ISO22313-8.4
Guidance on BC plans and procedures

Develop BC plans, incident response procedures, and recovery procedures with clear activation criteria.

Artefacts an auditor will ask for
  • BC plans
  • IR procedures
  • Activation criteria
Where this commonly fails
  • No activation criteria
  • Plans not site-specific
ISO22313-8.5
Guidance on exercising and testing

Design an exercise programme covering tabletop, simulation, live, and full failover with progression.

Artefacts an auditor will ask for
  • Exercise schedule
  • Scenarios
  • After-action reports
Where this commonly fails
  • Tabletop only
  • No progression
ISO22313-8.6
Guidance on evaluation of BC documentation and capability

Evaluate documentation, plans, and capabilities periodically and after disruption events.

Artefacts an auditor will ask for
  • Evaluation reports
  • Post-incident reviews
  • Capability assessment
Where this commonly fails
  • No post-incident reviews
  • Capability not assessed

Planning

ISO22313-6.1
Guidance on risks and opportunities

Use guidance to identify BCMS risks and opportunities and integrate treatment into planning.

Artefacts an auditor will ask for
  • Risk register
  • Opportunity log
  • Treatment plan
Where this commonly fails
  • Opportunities ignored
  • Risk not BC-specific
ISO22313-6.2
Guidance on BC objectives

Set SMART BC objectives with guidance on alignment to policy and measurable targets.

Artefacts an auditor will ask for
  • Objectives register
  • Targets
  • Alignment map
Where this commonly fails
  • Targets missing
  • No alignment map

Support

ISO22313-7.2
Guidance on competence

Build BC competence through training, exercises, and experience guided by role-based requirements.

Artefacts an auditor will ask for
  • Competency matrix
  • Training plan
  • Exercise records
Where this commonly fails
  • No role-based training
  • Exercises rare
ISO22313-7.4
Guidance on communication

Plan internal and external communication including incident and stakeholder communication with templates.

Artefacts an auditor will ask for
  • Comms plan
  • Templates
  • Notification list
Where this commonly fails
  • Templates outdated
  • Notification list stale
ISO22313-7.5
Guidance on documented information

Maintain BCMS documentation aligned to guidance on creation, control, and accessibility during disruption.

Artefacts an auditor will ask for
  • Doc procedure
  • DMS
  • Offline copies
Where this commonly fails
  • No offline copies
  • DMS depends on systems being up
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.