OnwynStandards › ISO 22301:2019

Certifiable standard · 2019

ISO 22301:2019

ISO 22301 is the international standard for a business continuity management system (BCMS): a disciplined way of working out which of your activities the business cannot afford to lose, how fast they must be back, what it would take to get them there, and whether the plans actually work when tested. It follows the same management-system structure as ISO 27001 — clauses 4 to 10 — with a distinctive operational core in clause 8: business impact analysis, risk assessment, continuity strategies, documented plans, and an exercise programme. Companies pursue it when customers, insurers, or tenders demand proof of resilience, when a regulator expects continuity evidence, or after an outage made the gap obvious. It is a common second certificate for a mid-market company that already holds ISO 27001, and much of the groundwork — scope, leadership, competence, internal audit, management review — carries over directly.

38
Requirements
10
Areas
22
Recommended documents
4
Mapped frameworks
Start ISO 22301:2019 free Have us do it instead

What this standard asks for

Every requirement in ISO 22301:2019, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.

Context of the organization

5 requirements

  • 4.1Understanding the organization and its context
  • 4.2.1Needs and expectations of interested parties
  • 4.2.2Legal, regulatory and contractual requirements
  • 4.3Scope of the BCMS
  • 4.4The business continuity management system itself

Leadership

3 requirements

  • 5.1Leadership and commitment
  • 5.2Business continuity policy
  • 5.3Roles, responsibilities and authorities

Planning

3 requirements

  • 6.1Actions to address risks and opportunities to the BCMS
  • 6.2Business continuity objectives
  • 6.3Planning of changes to the BCMS

Support

5 requirements

  • 7.1Resources
  • 7.2Competence
  • 7.3Awareness
  • 7.4Communication
  • 7.5Documented information

Business impact analysis & risk assessment

4 requirements

  • 8.1Operational planning and control
  • 8.2.1A documented process for impact analysis and risk assessment
  • 8.2.2Business impact analysis
  • 8.2.3Risk assessment of disruption

Continuity strategies & solutions

4 requirements

  • 8.3.2Identifying continuity strategies and solutions
  • 8.3.3Selecting strategies and solutions
  • 8.3.4Resource requirements for the chosen solutions
  • 8.3.5Implementing the solutions

Response structure & continuity plans

5 requirements

  • 8.4.1Establishing plans and procedures for disruption
  • 8.4.2Incident response structure
  • 8.4.3Warning and communication during a disruption
  • 8.4.4Business continuity plans
  • 8.4.5Recovery and return to normal operations

Exercising & evaluation of capability

3 requirements

  • 8.5Exercise programme
  • 8.5 (technical tests)Testing recovery arrangements technically
  • 8.6Evaluation of continuity documentation and capabilities

Performance evaluation

4 requirements

  • 9.1.1Monitoring, measurement, analysis and evaluation
  • 9.1.2Evaluation of business continuity procedures and capabilities
  • 9.2Internal audit
  • 9.3Management review

Improvement

2 requirements

  • 10.1Nonconformity and corrective action
  • 10.2Continual improvement

The documents you will end up with

The recommended document set for ISO 22301:2019 — 22 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.

BCMS Scope Statement

Which products, services, sites and people the continuity programme covers, and what is deliberately left out.

Legal and Regulatory Register

The continuity-related obligations that bind you — laws, regulator expectations and contract clauses — and who keeps the list current.

BCMS Manual

How the continuity management system itself works: its processes, how they connect, and how the operational work is planned and controlled.

Business Continuity Policy

Top management's statement of what the organisation commits to on continuity and what it expects from everyone.

Continuity Roles and Responsibilities

Who is on the incident team, who can declare an incident, and who deputises when they are unreachable.

BCMS Risk and Opportunity Register

The risks to the continuity programme itself — not to the business — and what you are doing about them.

Business Continuity Objectives

The measurable targets the programme is aiming at, consistent with the recovery times the business has agreed.

Document and Record Control Procedure

How continuity documents are approved, versioned and distributed — including how people reach them when systems are down.

Competence and Awareness Plan

Who needs continuity training, what they get, and how everyone else knows what to do if the lights go out.

Communication and Warning Plan

Who gets told what during a disruption, through which channel, and what to do when the usual channels are the thing that failed.

Impact Analysis and Risk Assessment Methodology

The agreed method for judging how badly a disruption hurts and how likely it is, so results from different teams can be compared.

Business Impact Analysis

For each activity: how quickly it must be back, what it depends on, and what the damage looks like over time.

Disruption Risk Assessment

What could realistically interrupt the activities the impact analysis flagged, and how likely each scenario is.

Continuity Strategies and Solutions

The options you considered for meeting your recovery targets, the ones you picked, what they cost in people and kit, and how they were implemented.

Incident Response Plan

The first hour: how a disruption is detected and declared, who assembles, and how you get back to normal afterwards.

Business Continuity Plans

The per-activity playbooks people actually pick up during a disruption — steps, contacts, workarounds and dependencies.

Exercise and Test Programme

The schedule of drills and technical recovery tests, what each one is meant to prove, and what was learned.

Capability Evaluation Procedure

How you periodically check that the plans and the documentation still match the business they describe.

Monitoring and Measurement Plan

What you track about continuity performance and who reviews the numbers.

Internal Audit Procedure and Programme

How the continuity system is audited internally, on what cycle, and by whom.

Management Review Procedure

What leadership reviews about continuity, how often, and what has to be decided.

Nonconformity and Corrective Action Procedure

How gaps found in exercises, audits and real incidents get fixed at root and closed out.

Work that counts twice

ISO 22301:2019 overlaps with 4 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.

Start ISO 22301:2019 today

Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.