Skip to content

Evidence request lists

ISO 22320:2018

Evidence request list. 37 controls, 37 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annexes: Guidance on Incident Management Planning

ISO-22320-A
Annex A: Collaboration and communication guidance

Provides guidance on collaboration, communications, and establishment of communication protocols during an incident.

Artefacts an auditor will ask for
  • role and responsibility matrix
  • resource inventory
  • incident management plan
  • command structure chart
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
ISO-22320-B
Annex B: Incident management plan structure

Provides additional content on structure and content for building an incident management plan and programme.

Artefacts an auditor will ask for
  • role and responsibility matrix
  • resource inventory
  • incident management plan
  • command structure chart
Where this commonly fails
  • weak inter-agency coordination
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
ISO-22320-C
Annex C: Incident management task examples

Provides examples of incident management tasks for plans and checklists during incident management activities.

Artefacts an auditor will ask for
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
  • command structure chart
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination

Clause 4: Principles of Incident Management

ISO-22320-4.1
General

Introduces the overarching principles that should guide all incident management activities.

Artefacts an auditor will ask for
  • incident management plan
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
ISO-22320-4.2
Ethics

Requires managing incidents with integrity and duty of care for human life and dignity.

Artefacts an auditor will ask for
  • command structure chart
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
Where this commonly fails
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
ISO-22320-4.3
Risk-based approach

Requires that incident management be based on risk management principles and preparedness.

Artefacts an auditor will ask for
  • role and responsibility matrix
  • resource inventory
  • incident management plan
  • command structure chart
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
ISO-22320-4.4
Information sharing

Requires sharing of information and perspectives among all parties involved in incident management.

Artefacts an auditor will ask for
  • resource inventory
  • incident management plan
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
ISO-22320-4.5
Safety

Emphasizes the importance of safety for both responders and those impacted by the incident.

Artefacts an auditor will ask for
  • incident management plan
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
ISO-22320-4.6
Flexibility and adaptability

Requires incident management to be flexible, adaptable, and scalable to the nature and scope of the incident.

Artefacts an auditor will ask for
  • resource inventory
  • incident management plan
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
ISO-22320-4.7
Human and cultural factors

Requires consideration of human and cultural factors in incident management decision-making and communication.

Artefacts an auditor will ask for
  • resource inventory
  • incident management plan
  • command structure chart
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
Where this commonly fails
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
ISO-22320-4.8
Continual improvement

Emphasizes continual improvement based on lessons learned from incidents and exercises.

Artefacts an auditor will ask for
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
Where this commonly fails
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy

Clause 5: Basic Components - Process and Structure

ISO-22320-5.1
General process requirements

Defines the basic components of incident management including roles, responsibilities, tasks, and resource management.

Artefacts an auditor will ask for
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
  • insufficient role clarity
ISO-22320-5.2
Incident management process

Describes the incident management process from detection through assessment, response, and recovery.

Artefacts an auditor will ask for
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
Where this commonly fails
  • insufficient role clarity
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
ISO-22320-5.3
Incident management structure (command)

Specifies that all incident management activities should adhere to a command structure with defined leadership and authority.

Artefacts an auditor will ask for
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
Where this commonly fails
  • weak inter-agency coordination
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
ISO-22320-5.4
Roles and responsibilities

Requires clear definition of roles and responsibilities for all personnel involved in incident management.

Artefacts an auditor will ask for
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
  • insufficient role clarity
ISO-22320-5.5
Resource management

Requires effective management and allocation of resources during incident response including personnel, equipment, and facilities.

Artefacts an auditor will ask for
  • resource inventory
  • incident management plan
  • command structure chart
  • communication protocol document
Where this commonly fails
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
  • unclear command structure

Clause 6: Working Together - Joint Direction and Cooperation

ISO-22320-6.1
General cooperation requirements

Requires organizations to work together during incidents based on identified incident risks.

Artefacts an auditor will ask for
  • resource inventory
  • incident management plan
  • command structure chart
  • communication protocol document
Where this commonly fails
  • weak inter-agency coordination
  • missing communication redundancy
  • insufficient role clarity
  • gaps in lessons-learned capture
  • unclear command structure
ISO-22320-6.2
Collaboration and coordination

Requires establishing collaboration protocols across organizations to share resources and information during incidents.

Artefacts an auditor will ask for
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
Where this commonly fails
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
ISO-22320-6.3
Communication protocols

Requires establishment of communication protocols during incidents to ensure timely and accurate information flow.

Artefacts an auditor will ask for
  • command structure chart
  • communication protocol document
  • exercise after-action report
Where this commonly fails
  • unclear command structure
  • weak inter-agency coordination
  • missing communication redundancy
ISO-22320-6.4
Joint direction

Requires mechanisms for joint direction where multiple organizations are involved in managing the same incident.

Artefacts an auditor will ask for
  • communication protocol document
  • exercise after-action report
  • role and responsibility matrix
  • resource inventory
  • incident management plan
  • command structure chart
Where this commonly fails
  • gaps in lessons-learned capture
  • unclear command structure
  • weak inter-agency coordination

Command and Control

ISO22320-5.1
Command Function

Establish a command function with clear unity of command, named commanders, and defined authority to direct response.

Artefacts an auditor will ask for
  • Documented command structure
  • Trained commander register
  • Activation criteria and triggers
Where this commonly fails
  • Multiple commanders without unity
  • No qualifications criteria for commanders
  • Activation triggers undefined
ISO22320-5.2
Control Function

Establish a control function to allocate resources, monitor performance, and adjust the response according to objectives.

Artefacts an auditor will ask for
  • Resource allocation logs
  • Status boards and common operating picture
  • Incident action plans with objectives
Where this commonly fails
  • Objectives not set or reviewed
  • Status board not maintained in real time
  • Resource tracking on paper only

Competence

ISO22320-9.2
Training, Exercising, and Competence

Train and exercise personnel in incident management roles and maintain records of competence and currency.

Artefacts an auditor will ask for
  • Role based training curriculum
  • Annual exercise calendar
  • Competence and currency register
Where this commonly fails
  • Training one off and not refreshed
  • Exercises infrequent
  • No competence currency tracking

Cooperation

ISO22320-8.1
Cooperation with External Agencies

Establish arrangements for cooperation with external agencies, mutual aid partners, and authorities, including pre agreed protocols.

Artefacts an auditor will ask for
  • Memoranda of understanding with agencies
  • Joint response plans
  • Up to date contact lists
Where this commonly fails
  • MOUs absent or expired
  • No joint plans
  • Contacts not refreshed
ISO22320-8.2
Multi Agency Coordination

Coordinate command and control across multiple agencies through unified or joint command structures as appropriate.

Artefacts an auditor will ask for
  • Unified command procedures
  • Multi agency exercise reports
  • Liaison officer assignments
Where this commonly fails
  • Unified command never practiced
  • Liaison roles not staffed
  • Joint exercises rare

Coordination

ISO22320-5.3
Coordination Function

Coordinate across functions, teams, and external agencies to align action, information, and resources during incidents.

Artefacts an auditor will ask for
  • Coordination protocols with internal and external parties
  • Named liaison officers
  • Joint operations centre layout
Where this commonly fails
  • Liaison roles informal
  • No joint protocols with key agencies
  • Coordination breaks down under load

Foundation

ISO22320-4.1
Incident Management Policy

Establish an incident management policy that defines scope, objectives, authorities, and alignment with organizational strategy.

Artefacts an auditor will ask for
  • Approved incident management policy
  • Distribution and acknowledgement records
  • Annual policy review log
Where this commonly fails
  • Policy not approved at executive level
  • Scope unclear on multi site or multi agency
  • No periodic review
ISO22320-4.2
Roles, Responsibilities, and Authorities

Define roles, responsibilities, and decision authorities for incident management, including delegations during escalation.

Artefacts an auditor will ask for
  • Incident management RACI
  • Role specific position descriptions
  • Delegation of authority matrix with escalation
Where this commonly fails
  • Authority unclear when primary unavailable
  • Delegations not documented
  • Role descriptions outdated

ICS

ISO22320-6.1
Incident Command System Structure

Adopt a modular and scalable incident command system structure covering command, operations, planning, logistics, and finance and administration.

Artefacts an auditor will ask for
  • ICS organization chart
  • Module activation guidance
  • Span of control standards (3 to 7)
Where this commonly fails
  • Single chart used regardless of incident scale
  • Modules activated late
  • Span of control exceeded
ISO22320-6.2
Common Terminology and Plain Language

Use common terminology and plain language to support clear communication across teams and agencies.

Artefacts an auditor will ask for
  • Common terminology and code use guide
  • Training records on plain language
  • Post incident communication audits
Where this commonly fails
  • Agency specific codes used in joint response
  • Plain language not enforced
  • No communication audits
ISO22320-6.3
Incident Action Planning

Develop incident action plans for defined operational periods, setting objectives, tactics, assignments, and safety considerations.

Artefacts an auditor will ask for
  • Incident action plan template
  • Documented operational periods
  • Briefing and debriefing records
Where this commonly fails
  • No IAP produced beyond initial response
  • Operational periods not defined
  • Safety messages absent from IAP

Improvement

ISO22320-10.1
Post Incident Review and Lessons Learned

Conduct structured post incident reviews to identify lessons, validate effectiveness, and drive improvement.

Artefacts an auditor will ask for
  • Post incident review procedure
  • Review reports per significant incident
  • Lessons learned action tracker
Where this commonly fails
  • Reviews skipped after smaller incidents
  • Lessons not assigned owners
  • Actions overdue without escalation
ISO22320-10.2
Continual Improvement of Incident Management

Apply continual improvement to incident management capability based on reviews, audits, exercises, and changes in context.

Artefacts an auditor will ask for
  • Incident management maturity assessment
  • Improvement plan with timeline
  • Audit and exercise follow up tracker
Where this commonly fails
  • Maturity never assessed
  • Improvement plan not funded
  • Audit findings open beyond target

Information

ISO22320-7.1
Operational Information Management

Manage operational information to ensure accuracy, timeliness, accessibility, and integrity to support decision making.

Artefacts an auditor will ask for
  • Information management plan
  • Common operating picture or information system
  • Quality and verification checks
Where this commonly fails
  • Information siloed in functional teams
  • No verification step
  • Tools used inconsistently
ISO22320-7.2
Communication Systems and Interoperability

Provide communication systems that are reliable, redundant, and interoperable with external responders and partners.

Artefacts an auditor will ask for
  • Communications architecture diagram
  • Redundant paths and fallback procedures
  • Interoperability test records with partner agencies
Where this commonly fails
  • Single mode communication (radio only or phone only)
  • No interoperability tests
  • Fallback procedures untested
ISO22320-7.3
Situational Awareness and Common Operating Picture

Develop and maintain situational awareness through a common operating picture shared across command, control, and coordination roles.

Artefacts an auditor will ask for
  • Common operating picture standard
  • Physical or digital COP display
  • Documented update cadence
Where this commonly fails
  • COP refreshed irregularly
  • Different teams maintain separate pictures
  • No information validation

People

ISO22320-9.1
Human Factors and Welfare

Address human factors including fatigue, stress, training, and welfare to sustain responder effectiveness during prolonged incidents.

Artefacts an auditor will ask for
  • Responder welfare plan
  • Shift rotation schedules
  • Psychological first aid arrangements
Where this commonly fails
  • No fatigue management
  • Long shifts without relief
  • Psychological support not arranged
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.