Onwyn › Standards › ISO 22301:2019
Certifiable standard · 2019ISO 22301:2019
ISO 22301 is the international standard for a business continuity management system (BCMS): a disciplined way of working out which of your activities the business cannot afford to lose, how fast they must be back, what it would take to get them there, and whether the plans actually work when tested. It follows the same management-system structure as ISO 27001 — clauses 4 to 10 — with a distinctive operational core in clause 8: business impact analysis, risk assessment, continuity strategies, documented plans, and an exercise programme. Companies pursue it when customers, insurers, or tenders demand proof of resilience, when a regulator expects continuity evidence, or after an outage made the gap obvious. It is a common second certificate for a mid-market company that already holds ISO 27001, and much of the groundwork — scope, leadership, competence, internal audit, management review — carries over directly.
What this standard asks for
Every requirement in ISO 22301:2019, grouped the way the standard groups them. In the Compliance Engine each one carries what to do, how to evidence it, what auditors commonly reject, and a button to bring in a consultant if you would rather not work it out alone.
Context of the organization
5 requirements
- 4.1Understanding the organization and its context
- 4.2.1Needs and expectations of interested parties
- 4.2.2Legal, regulatory and contractual requirements
- 4.3Scope of the BCMS
- 4.4The business continuity management system itself
Leadership
3 requirements
- 5.1Leadership and commitment
- 5.2Business continuity policy
- 5.3Roles, responsibilities and authorities
Planning
3 requirements
- 6.1Actions to address risks and opportunities to the BCMS
- 6.2Business continuity objectives
- 6.3Planning of changes to the BCMS
Support
5 requirements
- 7.1Resources
- 7.2Competence
- 7.3Awareness
- 7.4Communication
- 7.5Documented information
Business impact analysis & risk assessment
4 requirements
- 8.1Operational planning and control
- 8.2.1A documented process for impact analysis and risk assessment
- 8.2.2Business impact analysis
- 8.2.3Risk assessment of disruption
Continuity strategies & solutions
4 requirements
- 8.3.2Identifying continuity strategies and solutions
- 8.3.3Selecting strategies and solutions
- 8.3.4Resource requirements for the chosen solutions
- 8.3.5Implementing the solutions
Response structure & continuity plans
5 requirements
- 8.4.1Establishing plans and procedures for disruption
- 8.4.2Incident response structure
- 8.4.3Warning and communication during a disruption
- 8.4.4Business continuity plans
- 8.4.5Recovery and return to normal operations
Exercising & evaluation of capability
3 requirements
- 8.5Exercise programme
- 8.5 (technical tests)Testing recovery arrangements technically
- 8.6Evaluation of continuity documentation and capabilities
Performance evaluation
4 requirements
- 9.1.1Monitoring, measurement, analysis and evaluation
- 9.1.2Evaluation of business continuity procedures and capabilities
- 9.2Internal audit
- 9.3Management review
Improvement
2 requirements
- 10.1Nonconformity and corrective action
- 10.2Continual improvement
The documents you will end up with
The recommended document set for ISO 22301:2019 — 22 in total. The engine tracks which you have, which are missing, and which of your existing documents already cover a requirement.
Which products, services, sites and people the continuity programme covers, and what is deliberately left out.
The continuity-related obligations that bind you — laws, regulator expectations and contract clauses — and who keeps the list current.
How the continuity management system itself works: its processes, how they connect, and how the operational work is planned and controlled.
Top management's statement of what the organisation commits to on continuity and what it expects from everyone.
Who is on the incident team, who can declare an incident, and who deputises when they are unreachable.
The risks to the continuity programme itself — not to the business — and what you are doing about them.
The measurable targets the programme is aiming at, consistent with the recovery times the business has agreed.
How continuity documents are approved, versioned and distributed — including how people reach them when systems are down.
Who needs continuity training, what they get, and how everyone else knows what to do if the lights go out.
Who gets told what during a disruption, through which channel, and what to do when the usual channels are the thing that failed.
The agreed method for judging how badly a disruption hurts and how likely it is, so results from different teams can be compared.
For each activity: how quickly it must be back, what it depends on, and what the damage looks like over time.
What could realistically interrupt the activities the impact analysis flagged, and how likely each scenario is.
The options you considered for meeting your recovery targets, the ones you picked, what they cost in people and kit, and how they were implemented.
The first hour: how a disruption is detected and declared, who assembles, and how you get back to normal afterwards.
The per-activity playbooks people actually pick up during a disruption — steps, contacts, workarounds and dependencies.
The schedule of drills and technical recovery tests, what each one is meant to prove, and what was learned.
How you periodically check that the plans and the documentation still match the business they describe.
What you track about continuity performance and who reviews the numbers.
How the continuity system is audited internally, on what cycle, and by whom.
What leadership reviews about continuity, how often, and what has to be decided.
How gaps found in exercises, audits and real incidents get fixed at root and closed out.
Work that counts twice
ISO 22301:2019 overlaps with 4 other frameworks in the engine. When you start one of these, the requirements you have already settled here are carried across as suggestions for you to confirm — you review them, we never mark them done on your behalf.
Start ISO 22301:2019 today
Every live framework is included in one subscription — no per-framework pricing. Your first 30 days are free, we ask for no card, and there is nothing to cancel. On any requirement you can bring in a senior consultant for a review, a call, or done-for-you implementation.