Skip to content

Evidence request lists

ISO/IEC 27031:2011

Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Annexes: Supporting Guidance

27031-A
IRBC milestones during disruption

Informative annex on IRBC milestones and timeframes during a disruption event

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-B
High availability embedded systems

Informative annex on high availability embedded system considerations

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-C
Assessing failure scenarios

Informative annex on methods for assessing failure scenarios

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-D
Developing performance criteria

Informative annex on developing ICT performance criteria for business continuity

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular

Clause 4-5: Overview and IRBC Concepts

27031-4.1
Overview of IRBC

Overview of information and communication technology readiness for business continuity concepts and principles

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-4.2
IRBC framework elements

Framework of methods and processes to identify and specify all aspects of improving ICT readiness

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-5.1
IRBC Policy

Establish, document and approve an ICT readiness for business continuity policy that defines scope, objectives and authority.

Artefacts an auditor will ask for
  • approved IRBC policy document
  • policy review schedule
  • signed acknowledgements from accountable executives
Where this commonly fails
  • policy conflates IT disaster recovery with IRBC
  • no defined review cadence
27031-5.2
ICT services and infrastructure scope

Identifying critical ICT services and infrastructure that support business continuity

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular

Clause 6: IRBC Relationship to BCM

27031-6.1
Understanding the Organisation

Identify ICT services, their criticality, dependencies and the business processes they support to scope IRBC requirements.

Artefacts an auditor will ask for
  • ICT service catalogue with criticality ratings
  • dependency maps to business processes
  • upstream and downstream supplier dependencies
Where this commonly fails
  • service catalogue exists but lacks criticality tiers
  • no mapping of shadow IT dependencies
27031-6.2
Business Impact Analysis for ICT

Conduct a BIA focused on ICT services to determine recovery time objectives, recovery point objectives and minimum business continuity objectives.

Artefacts an auditor will ask for
  • BIA reports per critical service
  • approved RTO and RPO values
  • MBCO definitions signed by business owners
Where this commonly fails
  • RTO set by IT without business validation
  • BIA never refreshed after service changes
27031-6.3
Risk Assessment for ICT Continuity

Assess threats and vulnerabilities affecting ICT continuity, including environmental, technical, supplier and human factors.

Artefacts an auditor will ask for
  • ICT continuity risk register
  • threat catalogue with likelihood and impact ratings
  • treatment plans for top risks
Where this commonly fails
  • risk assessment focused on cyber threats only ignoring physical and supplier risks
  • no link from risks to recovery strategies

Clause 7: IRBC Planning and Objectives

27031-7.1
IRBC Strategy

Define an IRBC strategy that selects appropriate continuity options for each critical ICT service based on BIA, risk and cost.

Artefacts an auditor will ask for
  • IRBC strategy document covering people, processes, technology and suppliers
  • options appraisal with cost benefit analysis
  • executive approval records
Where this commonly fails
  • strategy defaults to backup and restore without alternative options considered
  • no supplier dimension in strategy
27031-7.2
Resource Requirements

Determine and provision the people, facilities, technology, information and suppliers needed to execute the IRBC strategy.

Artefacts an auditor will ask for
  • resource requirements matrix
  • evidence of standby contracts and warm or hot sites
  • skills matrix for recovery teams
Where this commonly fails
  • recovery dependent on individual staff with no backup
  • facilities contracts expired without renewal

Clause 8: IRBC Implementation

27031-8.1
Exercising and Testing

Exercise and test IRBC plans regularly using a programme that progressively increases complexity and scope.

Artefacts an auditor will ask for
  • multi-year exercise programme
  • exercise scenarios and scripts
  • after-action reports with findings and actions
Where this commonly fails
  • only tabletop exercises performed
  • findings logged but not actioned
27031-8.2
Maintaining IRBC

Maintain IRBC arrangements through change management, regular reviews and updates triggered by significant changes.

Artefacts an auditor will ask for
  • IRBC change triggers list
  • review records following major changes
  • annual maintenance report
Where this commonly fails
  • IRBC excluded from change management process
  • no triggers defined for unscheduled reviews
27031-8.3
IRBC plan documents

Content requirements for IRBC plan documents including roles, responsibilities, and procedures

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular
27031-8.4
Awareness, competency and training

Awareness, competency, and training programs for ICT readiness personnel

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular

Clause 9: Monitor and Review

27031-9.1
Performance Measurement

Measure and monitor IRBC performance against objectives using defined metrics and indicators.

Artefacts an auditor will ask for
  • IRBC KPI dashboard
  • monthly performance reports
  • trend analysis showing improvement
Where this commonly fails
  • metrics measure activity not capability
  • no benchmarking against industry
27031-9.2
Internal Audit

Conduct internal audits of IRBC arrangements at planned intervals to verify conformance and effectiveness.

Artefacts an auditor will ask for
  • IRBC internal audit plan
  • audit reports with findings
  • management responses and closure evidence
Where this commonly fails
  • IRBC audit rolled into general IT audit with insufficient depth
  • audit findings without owner or due date
27031-9.3
Management Review

Top management reviews the IRBC programme at planned intervals to ensure suitability, adequacy and effectiveness.

Artefacts an auditor will ask for
  • management review meeting minutes
  • input pack including audit findings exercise results and metrics
  • approved actions and decisions
Where this commonly fails
  • reviews scheduled but cancelled or deferred
  • no decisions or actions captured
27031-9.4
IRBC review and improvement

Reviewing and improving IRBC based on test results, incidents, and changing requirements

Artefacts an auditor will ask for
  • IRBC plan
  • ICT continuity playbook
  • Recovery time objectives
  • Training records
Where this commonly fails
  • IRBC scope narrow
  • RTO/RPO not tested
  • Plans untested
  • Training irregular

Implement

27031-10.3
Communication During Incidents

Establish communication procedures for ICT incidents covering internal teams, business stakeholders, suppliers and external parties.

Artefacts an auditor will ask for
  • incident communications plan
  • pre-approved message templates
  • alternate communication channels tested
Where this commonly fails
  • communications plan relies on systems that may fail in the incident
  • no out-of-band channels tested
27031-7.3
Incident Response Structure

Establish an incident response structure for ICT incidents covering roles, escalation and decision authority.

Artefacts an auditor will ask for
  • incident response team charter
  • escalation matrix with named alternates
  • decision authority thresholds
Where this commonly fails
  • no named alternates for key roles
  • decision thresholds undefined leading to delayed escalation
27031-7.4
IRBC Plans

Develop, document and maintain IRBC plans containing procedures to recover ICT services within agreed objectives.

Artefacts an auditor will ask for
  • IRBC plans per critical service with step-by-step recovery procedures
  • version control records
  • plan distribution and access controls
Where this commonly fails
  • plans not updated after infrastructure changes
  • plans stored only on systems that may be unavailable in a disaster
27031-7.5
Awareness and Training

Build IRBC awareness across the organisation and provide role-specific training for those with recovery responsibilities.

Artefacts an auditor will ask for
  • training plan and attendance records
  • awareness campaign materials
  • competency assessments for recovery team members
Where this commonly fails
  • training delivered once at onboarding only
  • no competency validation

Improve

27031-10.1
Continual Improvement

Continually improve the suitability, adequacy and effectiveness of the IRBC programme through corrective actions and enhancements.

Artefacts an auditor will ask for
  • corrective action register
  • root cause analyses for IRBC failures
  • trend showing closure rates
Where this commonly fails
  • corrective actions closed administratively without verification of effectiveness
  • no root cause analysis

Strategy

27031-10.2
Supplier Continuity Arrangements

Include critical ICT suppliers and cloud providers in IRBC scope with contractual continuity obligations and verification.

Artefacts an auditor will ask for
  • supplier criticality assessments
  • contractual continuity clauses and SLAs
  • supplier exercise participation records
Where this commonly fails
  • cloud providers excluded from IRBC scope
  • contracts lack measurable continuity commitments
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.