Skip to content

Evidence request lists

ISO 22317

Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Analysis

ISO22317-5.1
Prioritized Activities Identification

Identify the activities that deliver products and services, and assess their relative priority based on impact over time.

Artefacts an auditor will ask for
  • Process or activity catalog
  • Impact over time curves per activity
  • Prioritized activities list signed by business owners
Where this commonly fails
  • Activity inventory incomplete
  • Prioritization done by IT not business
  • Impact assessed at single point in time only
ISO22317-5.2
Impact Categories and Tolerances

Define impact categories such as financial, regulatory, reputational, safety, and operational, with tolerance thresholds.

Artefacts an auditor will ask for
  • Impact category matrix
  • Tolerance thresholds approved by exec
  • Calibration workshop notes
Where this commonly fails
  • Only financial impact considered
  • Thresholds not approved at exec level
  • No reputational or regulatory tolerances

Assurance

ISO22317-8.2
BIA Programme Assurance

Assess the quality and effectiveness of the BIA programme through internal audit, peer review, or independent assurance.

Artefacts an auditor will ask for
  • Internal audit reports on BIA
  • Peer review or external assurance reports
  • Improvement action log
Where this commonly fails
  • BIA never audited
  • Findings open beyond target dates
  • No independent assurance

Dependencies

ISO22317-5.8
Interdependencies and Single Points of Failure

Identify internal and external interdependencies and any single points of failure that could undermine recovery objectives.

Artefacts an auditor will ask for
  • Dependency matrix
  • Single point of failure register
  • Mitigation plans per SPOF
Where this commonly fails
  • Dependencies mapped one level only
  • SPOFs identified but not tracked
  • No owner for SPOF mitigation

Execution

ISO22317-6.1
BIA Data Collection

Collect BIA data through interviews, workshops, questionnaires, or document review with adequate coverage and quality.

Artefacts an auditor will ask for
  • Workshop and interview schedule
  • Completed BIA questionnaires
  • Quality review notes by BIA lead
Where this commonly fails
  • Coverage gaps in regions or subsidiaries
  • Self assessment without challenge
  • Low response rates
ISO22317-6.2
BIA Validation and Sign Off

Validate BIA findings with activity owners and obtain formal sign off prior to use in continuity strategy decisions.

Artefacts an auditor will ask for
  • Validation workshop minutes
  • BIA sign off form per business unit
  • Change log of accepted amendments
Where this commonly fails
  • BIA never formally signed off
  • Validation skipped under time pressure
  • No change log maintained

Foundation

ISO22317-4.1
BIA Programme Establishment

Establish a Business Impact Analysis programme with defined objectives, scope, and governance aligned to the BCMS.

Artefacts an auditor will ask for
  • BIA programme document approved by management
  • BIA scope inclusion and exclusion list
  • Steering committee terms of reference
Where this commonly fails
  • BIA treated as one off project
  • Scope unclear on inclusion of third parties
  • No exec sponsor named

ISO 22317: BCM Program Management

ISO22317-01
Business continuity policy

Business continuity policy. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.

Artefacts an auditor will ask for
  • RTO and RPO worksheets
  • resource dependency map
  • BIA report
  • exercise scenario library
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
ISO22317-02
BCM program scope and objectives

BCM program scope and objectives. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.

Artefacts an auditor will ask for
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
Where this commonly fails
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
ISO22317-03
Resource allocation for BCM

Resource allocation for BCM. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.

Artefacts an auditor will ask for
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture
ISO22317-04
BCM roles and responsibilities

BCM roles and responsibilities. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.

Artefacts an auditor will ask for
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
ISO22317-05
Management commitment to BCM

Management commitment to BCM. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.

Artefacts an auditor will ask for
  • exercise scenario library
  • BIA methodology document
  • critical activity register
Where this commonly fails
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture

ISO 22317: BCM Testing & Exercising

ISO22317-16
Exercise program development

Exercise program development. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • resource dependency map
  • BIA report
  • exercise scenario library
  • BIA methodology document
Where this commonly fails
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
ISO22317-17
Tabletop and simulation exercises

Tabletop and simulation exercises. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • resource dependency map
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
ISO22317-18
Full-scale testing procedures

Full-scale testing procedures. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • RTO and RPO worksheets
  • resource dependency map
  • BIA report
Where this commonly fails
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
ISO22317-19
Post-exercise review and improvement

Post-exercise review and improvement. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture
ISO22317-20
Plan maintenance and update

Plan maintenance and update. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.

Artefacts an auditor will ask for
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology

ISO 22317: Business Continuity Strategy

ISO22317-11
Continuity strategy development

Continuity strategy development. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.

Artefacts an auditor will ask for
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
  • BIA report
  • exercise scenario library
Where this commonly fails
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
ISO22317-12
Recovery strategy for critical activities

Recovery strategy for critical activities. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.

Artefacts an auditor will ask for
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
ISO22317-13
Alternate site and resource planning

Alternate site and resource planning. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.

Artefacts an auditor will ask for
  • resource dependency map
  • BIA report
  • exercise scenario library
  • BIA methodology document
Where this commonly fails
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
ISO22317-14
Supply chain continuity

Supply chain continuity. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.

Artefacts an auditor will ask for
  • resource dependency map
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
Where this commonly fails
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
ISO22317-15
Communication strategy during disruption

Communication strategy during disruption. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.

Artefacts an auditor will ask for
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
  • BIA report
Where this commonly fails
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture

ISO 22317: Business Impact Analysis

ISO22317-06
Business impact analysis methodology

Business impact analysis methodology. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

Artefacts an auditor will ask for
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
  • weak interdependency capture
ISO22317-07
Critical activity identification

Critical activity identification. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

Artefacts an auditor will ask for
  • resource dependency map
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
Where this commonly fails
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
ISO22317-08
Recovery time and point objectives

Recovery time and point objectives. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

Artefacts an auditor will ask for
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
Where this commonly fails
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
ISO22317-09
Resource requirements assessment

Resource requirements assessment. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

Artefacts an auditor will ask for
  • BIA methodology document
  • critical activity register
  • RTO and RPO worksheets
  • resource dependency map
  • BIA report
  • exercise scenario library
Where this commonly fails
  • weak interdependency capture
  • insufficient stakeholder validation
  • gaps in BIA refresh cadence
  • inconsistent BIA methodology
  • missing critical activity ranking
ISO22317-10
Interdependency mapping

Interdependency mapping. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.

Artefacts an auditor will ask for
  • BIA report
  • exercise scenario library
  • BIA methodology document
  • critical activity register
Where this commonly fails
  • missing critical activity ranking
  • weak interdependency capture
  • insufficient stakeholder validation

Linkage

ISO22317-7.2
Linking BIA to Continuity Strategy

Use BIA outputs as the foundation for continuity strategy and solution selection.

Artefacts an auditor will ask for
  • Strategy selection memos citing BIA
  • Traceability matrix BIA to strategy to plan
  • Cost benefit analysis for strategy options
Where this commonly fails
  • Strategy chosen without BIA input
  • Traceability absent
  • No cost benefit documented

Maintenance

ISO22317-8.1
BIA Maintenance and Refresh

Maintain and refresh the BIA on a defined cycle and after significant change to ensure continued accuracy.

Artefacts an auditor will ask for
  • BIA refresh schedule
  • Change trigger criteria
  • BIA version history
Where this commonly fails
  • BIA older than two years
  • No trigger based refresh
  • Change history not maintained

Methodology

ISO22317-4.2
BIA Methodology and Approach

Define a documented BIA methodology, including data collection methods, impact categories, and analysis techniques.

Artefacts an auditor will ask for
  • Documented BIA methodology
  • BIA questionnaire and interview templates
  • BIA assessor training records
Where this commonly fails
  • Methodology inconsistent across business units
  • Templates outdated
  • Assessors lack training

Reporting

ISO22317-7.1
BIA Outputs Reporting

Produce BIA reports that summarize prioritized activities, RTO, RPO, MBCO, dependencies, and recommendations for management.

Artefacts an auditor will ask for
  • Standard BIA report template
  • Executive BIA summary
  • Distribution and acknowledgement log
Where this commonly fails
  • Reports too detailed for exec
  • No exec summary
  • Distribution limited to BCM team

Resources

ISO22317-5.7
Resource Requirements Analysis

Identify the resources required to deliver prioritized activities at MBCO within RTO, including people, technology, facilities, suppliers, and information.

Artefacts an auditor will ask for
  • Resource requirements per activity
  • Dependency map covering people, IT, facilities, suppliers
  • Minimum staffing model with skills
Where this commonly fails
  • Resource list focuses on IT only
  • Supplier dependencies missing
  • Skill requirements not captured

Timing Parameters

ISO22317-5.3
Maximum Tolerable Period of Disruption (MTPD)

Determine the MTPD beyond which the viability of the organization is unacceptably threatened for each activity.

Artefacts an auditor will ask for
  • MTPD per prioritized activity
  • Sign off by activity owner and exec
  • Rationale for each MTPD value
Where this commonly fails
  • MTPD set arbitrarily
  • No rationale documented
  • Exec not aware of MTPD implications
ISO22317-5.4
Recovery Time Objective (RTO)

Establish RTO for each prioritized activity, ensuring recovery within the MTPD with sufficient buffer.

Artefacts an auditor will ask for
  • RTO per activity within MTPD
  • Validation through exercises
  • Reconciliation of RTO with recovery capability
Where this commonly fails
  • RTO exceeds MTPD
  • RTO not validated by exercise
  • IT RTO inconsistent with business RTO
ISO22317-5.5
Recovery Point Objective (RPO)

Define the maximum tolerable data loss per activity, informing backup and replication strategies.

Artefacts an auditor will ask for
  • RPO per activity and data set
  • Backup and replication configuration matching RPO
  • Restore test reports
Where this commonly fails
  • RPO not aligned with backup frequency
  • No restore tests
  • RPO undocumented for non IT data
ISO22317-5.6
Minimum Business Continuity Objective (MBCO)

Define the minimum level of service or production that must be achieved during disruption for the organization to remain viable.

Artefacts an auditor will ask for
  • MBCO per product or service
  • Stakeholder and regulator alignment records
  • Measurement plan for MBCO during incidents
Where this commonly fails
  • MBCO confused with normal service level
  • No stakeholder validation
  • Measurement plan absent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22317 framework page.