ISO/IEC 27031:2011
Evidence request list. 27 controls, 27 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Annexes: Supporting Guidance
Informative annex on IRBC milestones and timeframes during a disruption event
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Informative annex on high availability embedded system considerations
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Informative annex on methods for assessing failure scenarios
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Informative annex on developing ICT performance criteria for business continuity
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Clause 4-5: Overview and IRBC Concepts
Overview of information and communication technology readiness for business continuity concepts and principles
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Framework of methods and processes to identify and specify all aspects of improving ICT readiness
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Establish, document and approve an ICT readiness for business continuity policy that defines scope, objectives and authority.
- approved IRBC policy document
- policy review schedule
- signed acknowledgements from accountable executives
- policy conflates IT disaster recovery with IRBC
- no defined review cadence
Identifying critical ICT services and infrastructure that support business continuity
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Clause 6: IRBC Relationship to BCM
Identify ICT services, their criticality, dependencies and the business processes they support to scope IRBC requirements.
- ICT service catalogue with criticality ratings
- dependency maps to business processes
- upstream and downstream supplier dependencies
- service catalogue exists but lacks criticality tiers
- no mapping of shadow IT dependencies
Conduct a BIA focused on ICT services to determine recovery time objectives, recovery point objectives and minimum business continuity objectives.
- BIA reports per critical service
- approved RTO and RPO values
- MBCO definitions signed by business owners
- RTO set by IT without business validation
- BIA never refreshed after service changes
Assess threats and vulnerabilities affecting ICT continuity, including environmental, technical, supplier and human factors.
- ICT continuity risk register
- threat catalogue with likelihood and impact ratings
- treatment plans for top risks
- risk assessment focused on cyber threats only ignoring physical and supplier risks
- no link from risks to recovery strategies
Clause 7: IRBC Planning and Objectives
Define an IRBC strategy that selects appropriate continuity options for each critical ICT service based on BIA, risk and cost.
- IRBC strategy document covering people, processes, technology and suppliers
- options appraisal with cost benefit analysis
- executive approval records
- strategy defaults to backup and restore without alternative options considered
- no supplier dimension in strategy
Determine and provision the people, facilities, technology, information and suppliers needed to execute the IRBC strategy.
- resource requirements matrix
- evidence of standby contracts and warm or hot sites
- skills matrix for recovery teams
- recovery dependent on individual staff with no backup
- facilities contracts expired without renewal
Clause 8: IRBC Implementation
Exercise and test IRBC plans regularly using a programme that progressively increases complexity and scope.
- multi-year exercise programme
- exercise scenarios and scripts
- after-action reports with findings and actions
- only tabletop exercises performed
- findings logged but not actioned
Maintain IRBC arrangements through change management, regular reviews and updates triggered by significant changes.
- IRBC change triggers list
- review records following major changes
- annual maintenance report
- IRBC excluded from change management process
- no triggers defined for unscheduled reviews
Content requirements for IRBC plan documents including roles, responsibilities, and procedures
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Awareness, competency, and training programs for ICT readiness personnel
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Clause 9: Monitor and Review
Measure and monitor IRBC performance against objectives using defined metrics and indicators.
- IRBC KPI dashboard
- monthly performance reports
- trend analysis showing improvement
- metrics measure activity not capability
- no benchmarking against industry
Conduct internal audits of IRBC arrangements at planned intervals to verify conformance and effectiveness.
- IRBC internal audit plan
- audit reports with findings
- management responses and closure evidence
- IRBC audit rolled into general IT audit with insufficient depth
- audit findings without owner or due date
Top management reviews the IRBC programme at planned intervals to ensure suitability, adequacy and effectiveness.
- management review meeting minutes
- input pack including audit findings exercise results and metrics
- approved actions and decisions
- reviews scheduled but cancelled or deferred
- no decisions or actions captured
Reviewing and improving IRBC based on test results, incidents, and changing requirements
- IRBC plan
- ICT continuity playbook
- Recovery time objectives
- Training records
- IRBC scope narrow
- RTO/RPO not tested
- Plans untested
- Training irregular
Implement
Establish communication procedures for ICT incidents covering internal teams, business stakeholders, suppliers and external parties.
- incident communications plan
- pre-approved message templates
- alternate communication channels tested
- communications plan relies on systems that may fail in the incident
- no out-of-band channels tested
Establish an incident response structure for ICT incidents covering roles, escalation and decision authority.
- incident response team charter
- escalation matrix with named alternates
- decision authority thresholds
- no named alternates for key roles
- decision thresholds undefined leading to delayed escalation
Develop, document and maintain IRBC plans containing procedures to recover ICT services within agreed objectives.
- IRBC plans per critical service with step-by-step recovery procedures
- version control records
- plan distribution and access controls
- plans not updated after infrastructure changes
- plans stored only on systems that may be unavailable in a disaster
Build IRBC awareness across the organisation and provide role-specific training for those with recovery responsibilities.
- training plan and attendance records
- awareness campaign materials
- competency assessments for recovery team members
- training delivered once at onboarding only
- no competency validation
Improve
Continually improve the suitability, adequacy and effectiveness of the IRBC programme through corrective actions and enhancements.
- corrective action register
- root cause analyses for IRBC failures
- trend showing closure rates
- corrective actions closed administratively without verification of effectiveness
- no root cause analysis
Strategy
Include critical ICT suppliers and cloud providers in IRBC scope with contractual continuity obligations and verification.
- supplier criticality assessments
- contractual continuity clauses and SLAs
- supplier exercise participation records
- cloud providers excluded from IRBC scope
- contracts lack measurable continuity commitments
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.