ISO 22317
Evidence request list. 36 controls, 36 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Analysis
Identify the activities that deliver products and services, and assess their relative priority based on impact over time.
- Process or activity catalog
- Impact over time curves per activity
- Prioritized activities list signed by business owners
- Activity inventory incomplete
- Prioritization done by IT not business
- Impact assessed at single point in time only
Define impact categories such as financial, regulatory, reputational, safety, and operational, with tolerance thresholds.
- Impact category matrix
- Tolerance thresholds approved by exec
- Calibration workshop notes
- Only financial impact considered
- Thresholds not approved at exec level
- No reputational or regulatory tolerances
Assurance
Assess the quality and effectiveness of the BIA programme through internal audit, peer review, or independent assurance.
- Internal audit reports on BIA
- Peer review or external assurance reports
- Improvement action log
- BIA never audited
- Findings open beyond target dates
- No independent assurance
Dependencies
Identify internal and external interdependencies and any single points of failure that could undermine recovery objectives.
- Dependency matrix
- Single point of failure register
- Mitigation plans per SPOF
- Dependencies mapped one level only
- SPOFs identified but not tracked
- No owner for SPOF mitigation
Execution
Collect BIA data through interviews, workshops, questionnaires, or document review with adequate coverage and quality.
- Workshop and interview schedule
- Completed BIA questionnaires
- Quality review notes by BIA lead
- Coverage gaps in regions or subsidiaries
- Self assessment without challenge
- Low response rates
Validate BIA findings with activity owners and obtain formal sign off prior to use in continuity strategy decisions.
- Validation workshop minutes
- BIA sign off form per business unit
- Change log of accepted amendments
- BIA never formally signed off
- Validation skipped under time pressure
- No change log maintained
Foundation
Establish a Business Impact Analysis programme with defined objectives, scope, and governance aligned to the BCMS.
- BIA programme document approved by management
- BIA scope inclusion and exclusion list
- Steering committee terms of reference
- BIA treated as one off project
- Scope unclear on inclusion of third parties
- No exec sponsor named
ISO 22317: BCM Program Management
Business continuity policy. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.
- RTO and RPO worksheets
- resource dependency map
- BIA report
- exercise scenario library
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
BCM program scope and objectives. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
Resource allocation for BCM. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
BCM roles and responsibilities. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
Management commitment to BCM. Control from ISO 22317 framework, domain: ISO 22317: BCM Program Management.
- exercise scenario library
- BIA methodology document
- critical activity register
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
ISO 22317: BCM Testing & Exercising
Exercise program development. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.
- resource dependency map
- BIA report
- exercise scenario library
- BIA methodology document
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
Tabletop and simulation exercises. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.
- resource dependency map
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
Full-scale testing procedures. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.
- RTO and RPO worksheets
- resource dependency map
- BIA report
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
Post-exercise review and improvement. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
Plan maintenance and update. Control from ISO 22317 framework, domain: ISO 22317: BCM Testing & Exercising.
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
ISO 22317: Business Continuity Strategy
Continuity strategy development. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- BIA report
- exercise scenario library
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
Recovery strategy for critical activities. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
Alternate site and resource planning. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.
- resource dependency map
- BIA report
- exercise scenario library
- BIA methodology document
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
Supply chain continuity. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.
- resource dependency map
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
Communication strategy during disruption. Control from ISO 22317 framework, domain: ISO 22317: Business Continuity Strategy.
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- BIA report
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
ISO 22317: Business Impact Analysis
Business impact analysis methodology. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
- weak interdependency capture
Critical activity identification. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.
- resource dependency map
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
Recovery time and point objectives. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
Resource requirements assessment. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.
- BIA methodology document
- critical activity register
- RTO and RPO worksheets
- resource dependency map
- BIA report
- exercise scenario library
- weak interdependency capture
- insufficient stakeholder validation
- gaps in BIA refresh cadence
- inconsistent BIA methodology
- missing critical activity ranking
Interdependency mapping. Control from ISO 22317 framework, domain: ISO 22317: Business Impact Analysis.
- BIA report
- exercise scenario library
- BIA methodology document
- critical activity register
- missing critical activity ranking
- weak interdependency capture
- insufficient stakeholder validation
Linkage
Use BIA outputs as the foundation for continuity strategy and solution selection.
- Strategy selection memos citing BIA
- Traceability matrix BIA to strategy to plan
- Cost benefit analysis for strategy options
- Strategy chosen without BIA input
- Traceability absent
- No cost benefit documented
Maintenance
Maintain and refresh the BIA on a defined cycle and after significant change to ensure continued accuracy.
- BIA refresh schedule
- Change trigger criteria
- BIA version history
- BIA older than two years
- No trigger based refresh
- Change history not maintained
Methodology
Define a documented BIA methodology, including data collection methods, impact categories, and analysis techniques.
- Documented BIA methodology
- BIA questionnaire and interview templates
- BIA assessor training records
- Methodology inconsistent across business units
- Templates outdated
- Assessors lack training
Reporting
Produce BIA reports that summarize prioritized activities, RTO, RPO, MBCO, dependencies, and recommendations for management.
- Standard BIA report template
- Executive BIA summary
- Distribution and acknowledgement log
- Reports too detailed for exec
- No exec summary
- Distribution limited to BCM team
Resources
Identify the resources required to deliver prioritized activities at MBCO within RTO, including people, technology, facilities, suppliers, and information.
- Resource requirements per activity
- Dependency map covering people, IT, facilities, suppliers
- Minimum staffing model with skills
- Resource list focuses on IT only
- Supplier dependencies missing
- Skill requirements not captured
Timing Parameters
Determine the MTPD beyond which the viability of the organization is unacceptably threatened for each activity.
- MTPD per prioritized activity
- Sign off by activity owner and exec
- Rationale for each MTPD value
- MTPD set arbitrarily
- No rationale documented
- Exec not aware of MTPD implications
Establish RTO for each prioritized activity, ensuring recovery within the MTPD with sufficient buffer.
- RTO per activity within MTPD
- Validation through exercises
- Reconciliation of RTO with recovery capability
- RTO exceeds MTPD
- RTO not validated by exercise
- IT RTO inconsistent with business RTO
Define the maximum tolerable data loss per activity, informing backup and replication strategies.
- RPO per activity and data set
- Backup and replication configuration matching RPO
- Restore test reports
- RPO not aligned with backup frequency
- No restore tests
- RPO undocumented for non IT data
Define the minimum level of service or production that must be achieved during disruption for the organization to remain viable.
- MBCO per product or service
- Stakeholder and regulator alignment records
- Measurement plan for MBCO during incidents
- MBCO confused with normal service level
- No stakeholder validation
- Measurement plan absent
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 22317 framework page.