Skip to content

Evidence request lists

ISO 22316

Evidence request list. 33 controls, 33 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Application

ISO22316-A.1
Stakeholder Engagement and Trust

Engage stakeholders and build trust through transparent communication, consultation, and commitment to shared outcomes.

Artefacts an auditor will ask for
  • Stakeholder engagement plan
  • Trust or reputation survey results
  • Records of stakeholder consultations on resilience
Where this commonly fails
  • Engagement reactive not planned
  • Trust not measured
  • Communications one way only

Attribute 1

ISO22316-5.1
Shared Vision and Clarity of Purpose

Establish a clearly articulated vision, purpose, and values that align the organization and provide direction during disruption.

Artefacts an auditor will ask for
  • Published vision and purpose statement
  • Values handbook or intranet page
  • Employee survey results on clarity of purpose
Where this commonly fails
  • Vision not referenced in resilience policy
  • No measurement of staff understanding
  • Disconnect between stated values and resilience decisions

Attribute 2

ISO22316-5.2
Understanding and Influencing Context

Maintain awareness of the operating environment and influence factors that affect resilience outcomes.

Artefacts an auditor will ask for
  • Horizon scan reports (quarterly)
  • Regulatory and threat watch logs
  • Trade body or policy engagement records
Where this commonly fails
  • No horizon scanning function
  • Context inputs not feeding risk register
  • Influence activity not documented

Attribute 3

ISO22316-5.3
Effective and Empowered Leadership

Leaders provide direction, allocate resources, and empower decision making across the organization to support resilience.

Artefacts an auditor will ask for
  • Resilience steering committee charter
  • Delegation of authority matrix
  • Crisis decision logs with named decision makers
Where this commonly fails
  • Decision authority unclear in crisis
  • Steering committee meets less than quarterly
  • No leadership development for resilience

Attribute 4

ISO22316-5.4
Culture Supportive of Organizational Resilience

Foster a culture where staff at all levels recognize their role in resilience and behave consistently with shared values.

Artefacts an auditor will ask for
  • Culture survey results
  • Behavioural competency framework
  • Recognition or reward program tied to resilience behaviours
Where this commonly fails
  • Culture measured but not acted on
  • No link between performance reviews and resilience behaviour
  • Recognition limited to incident response heroics

Attribute 5

ISO22316-5.5
Shared Information and Knowledge

Ensure information and lessons are captured, shared, and accessible across functions to support informed decisions.

Artefacts an auditor will ask for
  • Knowledge base or wiki
  • Lessons learned register
  • Cross functional information sharing protocols
Where this commonly fails
  • Lessons captured but not actioned
  • Knowledge siloed in teams
  • No retention policy for incident knowledge

Attribute 6

ISO22316-5.6
Availability of Resources

Identify and provide the resources, including people, finance, technology, and infrastructure, needed for resilience.

Artefacts an auditor will ask for
  • Resilience capability inventory
  • Annual resilience budget
  • Resource gap analysis with mitigation plans
Where this commonly fails
  • Resilience budget not ring fenced
  • Critical skills concentrated in few individuals
  • No succession plan for resilience leads

Attribute 7

ISO22316-5.7
Coordinated Management Disciplines

Integrate risk, security, business continuity, crisis, safety, and related disciplines to deliver coherent resilience outcomes.

Artefacts an auditor will ask for
  • Integrated management system map
  • Joint risk and BCM committee minutes
  • Multi discipline exercise reports
Where this commonly fails
  • Disciplines operate in silos
  • No common taxonomy across teams
  • Exercises test only one discipline at a time

Attribute 8

ISO22316-5.8
Supporting Continual Improvement

Apply continual improvement processes to learn from events, exercises, audits, and reviews and to mature resilience capability.

Artefacts an auditor will ask for
  • Resilience maturity assessment results
  • Improvement action register with owners
  • Audit and exercise follow up tracker
Where this commonly fails
  • Maturity assessed once and not repeated
  • Improvement actions overdue
  • No closure verification on lessons

Attribute 9

ISO22316-5.9
Ability to Anticipate and Manage Change

Anticipate, respond to, and manage internal and external change to sustain resilience over time.

Artefacts an auditor will ask for
  • Change impact assessment templates
  • Scenario planning outputs
  • Adaptation roadmaps tied to strategic plan
Where this commonly fails
  • Change management focused on IT only
  • Scenarios not refreshed annually
  • No link between change pipeline and resilience risk

Evaluation

ISO22316-6.1
Evaluation of Organizational Resilience

Evaluate the effectiveness of resilience attributes through measurement, review, and assurance activities.

Artefacts an auditor will ask for
  • Resilience KPI dashboard
  • Internal audit reports
  • Annual management review minutes
Where this commonly fails
  • KPIs measure activity not outcomes
  • Management review skipped or delegated
  • No independent assurance on resilience
ISO22316-6.2
Integration with Strategic Planning

Integrate resilience evaluation outputs into strategic planning, investment decisions, and risk appetite reviews.

Artefacts an auditor will ask for
  • Strategic plan referencing resilience evaluation
  • Investment business cases citing resilience evidence
  • Risk appetite statement reviewed against resilience posture
Where this commonly fails
  • Resilience evaluation not seen by board
  • Strategy refresh ignores resilience inputs
  • Risk appetite static for multiple years

Foundation

ISO22316-4
Context and Scope of Organizational Resilience

Define the internal and external context, stakeholders, and scope within which organizational resilience is developed and applied.

Artefacts an auditor will ask for
  • Context document (PESTLE/SWOT)
  • Resilience scope statement signed by exec sponsor
  • Stakeholder map with influence and interest ratings
Where this commonly fails
  • Resilience treated as BCM only
  • No external context refresh cadence
  • Stakeholder map missing regulators or supply partners

ISO 22316: BCM Program Management

ISO22316-01
Organizational resilience and security - business continuity policy for building security and resilience

Business continuity policy. Control from ISO 22316 framework, domain: ISO 22316: BCM Program Management.

Artefacts an auditor will ask for
  • resilience policy
  • BIA report
  • continuity strategy document
Where this commonly fails
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-02
BCM program scope and objectives

BCM program scope and objectives. Control from ISO 22316 framework, domain: ISO 22316: BCM Program Management.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
  • BIA report
Where this commonly fails
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
ISO22316-03
Resource allocation for BCM

Resource allocation for BCM. Control from ISO 22316 framework, domain: ISO 22316: BCM Program Management.

Artefacts an auditor will ask for
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
Where this commonly fails
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-04
BCM roles and responsibilities

BCM roles and responsibilities. Control from ISO 22316 framework, domain: ISO 22316: BCM Program Management.

Artefacts an auditor will ask for
  • leadership commitment statement
  • resilience policy
  • BIA report
  • continuity strategy document
Where this commonly fails
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
ISO22316-05
Management commitment to BCM

Management commitment to BCM. Control from ISO 22316 framework, domain: ISO 22316: BCM Program Management.

Artefacts an auditor will ask for
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping

ISO 22316: BCM Testing & Exercising

ISO22316-16
Exercise program development

Exercise program development. Control from ISO 22316 framework, domain: ISO 22316: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • missing leadership engagement
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
ISO22316-17
Tabletop and simulation exercises

Tabletop and simulation exercises. Control from ISO 22316 framework, domain: ISO 22316: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • BIA report
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
Where this commonly fails
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping
ISO22316-18
Full-scale testing procedures

Full-scale testing procedures. Control from ISO 22316 framework, domain: ISO 22316: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
  • BIA report
  • continuity strategy document
Where this commonly fails
  • missing leadership engagement
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
ISO22316-19
Post-exercise review and improvement

Post-exercise review and improvement. Control from ISO 22316 framework, domain: ISO 22316: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • leadership commitment statement
  • resilience policy
  • BIA report
Where this commonly fails
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-20
Plan maintenance and update

Plan maintenance and update. Control from ISO 22316 framework, domain: ISO 22316: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping

ISO 22316: Business Continuity Strategy

ISO22316-11
Continuity strategy development

Continuity strategy development. Control from ISO 22316 framework, domain: ISO 22316: Business Continuity Strategy.

Artefacts an auditor will ask for
  • BIA report
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping
  • insufficient exercise scope
ISO22316-12
Recovery strategy for critical activities

Recovery strategy for critical activities. Control from ISO 22316 framework, domain: ISO 22316: Business Continuity Strategy.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
Where this commonly fails
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
ISO22316-13
Alternate site and resource planning

Alternate site and resource planning. Control from ISO 22316 framework, domain: ISO 22316: Business Continuity Strategy.

Artefacts an auditor will ask for
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
  • BIA report
  • continuity strategy document
Where this commonly fails
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-14
Supply chain continuity

Supply chain continuity. Control from ISO 22316 framework, domain: ISO 22316: Business Continuity Strategy.

Artefacts an auditor will ask for
  • BIA report
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-15
Communication strategy during disruption

Communication strategy during disruption. Control from ISO 22316 framework, domain: ISO 22316: Business Continuity Strategy.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
Where this commonly fails
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping

ISO 22316: Business Impact Analysis

ISO22316-06
Business impact analysis methodology

Business impact analysis methodology. Control from ISO 22316 framework, domain: ISO 22316: Business Impact Analysis.

Artefacts an auditor will ask for
  • continuity strategy document
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
Where this commonly fails
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-07
Critical activity identification

Critical activity identification. Control from ISO 22316 framework, domain: ISO 22316: Business Impact Analysis.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
  • BIA report
Where this commonly fails
  • weak interdependency mapping
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
ISO22316-08
Recovery time and point objectives

Recovery time and point objectives. Control from ISO 22316 framework, domain: ISO 22316: Business Impact Analysis.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
  • BIA report
Where this commonly fails
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping
ISO22316-09
Resource requirements assessment

Resource requirements assessment. Control from ISO 22316 framework, domain: ISO 22316: Business Impact Analysis.

Artefacts an auditor will ask for
  • exercise schedule
  • plan maintenance log
  • leadership commitment statement
  • resilience policy
Where this commonly fails
  • insufficient exercise scope
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
ISO22316-10
Interdependency mapping

Interdependency mapping. Control from ISO 22316 framework, domain: ISO 22316: Business Impact Analysis.

Artefacts an auditor will ask for
  • resilience policy
  • BIA report
  • continuity strategy document
Where this commonly fails
  • gaps in continual improvement
  • unclear resilience attributes
  • missing leadership engagement
  • weak interdependency mapping
  • insufficient exercise scope
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22316 framework page.