ISO 22301:2019
ISO 22301 Business Continuity Management Systems
When disruption hits, run the plan instead of improvising.
Normal operations
Steady state
Prepare
BIA and RTOs
Priorities set early
Disruption
Impact begins
Impact
Continuity controls
Plans invoked
Recovery proven
Exercised to RTO
Within RTO
Exercise returns to Continuity controls
Service continuity
Verified recovery
SYS/06 · Continuity timeline
Disruption interrupts operations; controls arrest the fall and tested recovery climbs back to service continuity.
What ISO 22301 is
ISO 22301 specifies a management system for business continuity: impact analysis, risk assessment, continuity strategies, documented plans and an exercise programme that proves they work. Certification to it demonstrates that an independent body has tested the capability, not just read the plan.
CORE audits ISO 22301 along the chain the standard builds, and each link is tested against the one before it. Your auditor asks whether the prioritized activities and recovery time objectives follow from impact data, whether the chosen strategies are capable of meeting those objectives, and whether the plans and exercises would hold under a disruption the organization could plausibly face. Exercise reports, incident and invocation logs, contact and call-out records, supplier continuity arrangements and the resources the strategies assume are examined as evidence. The findings raised most often concern recovery time objectives set without impact analysis behind them, plans naming people who have left, and exercises that validate the document rather than the capability.
Who it is for
- Organizations whose customers or regulators require a certificate of registration to ISO 22301
- Operations dependent on critical sites, systems or single-source suppliers where continuity is written into contracts
- Technology and financial-services firms with recovery-time obligations they must evidence to a third party
- Certified organizations transferring an active ISO 22301 certificate from another certification body
Business outcomes
What leadership should expect the system to change, in operational terms.
Known priorities
Business impact analysis defines what must recover first, and how fast, before an incident forces the choice.
Tested capability
Exercised plans and trained teams, with findings fed back into improvement.
Customer assurance
Continuity questionnaires and contract clauses answered with a certificate of registration rather than a statement of intent.
Reduced downtime cost
Faster, ordered recovery directly reduces the financial impact of disruption.
Benefits beyond the certificate
Clarity in crisis
Defined incident structure, roles and communication remove hesitation when minutes matter.
Supplier resilience
Continuity requirements pushed into critical supplier relationships.
Insurance and finance posture
Demonstrated resilience supports insurance, credit and due-diligence conversations.
Pairing with security
Complements ISO 27001, sharing risk method and covering availability in depth, and the two can be audited together under one scope.
Regulatory alignment
Supports operational-resilience expectations in regulated sectors.

The main requirements
The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.
01
Context and scope (Clause 4)
Products, services, sites and interested parties inside the BCMS boundary.
02
Leadership and policy (Clause 5)
Continuity policy, roles and management commitment.
03
Planning (Clause 6)
Risks, opportunities and measurable continuity objectives.
04
Business impact analysis and risk assessment (Clause 8.2)
Impact over time, prioritized activities, recovery time objectives and disruption risks.
05
Strategies, plans and exercises (Clauses 8.3 to 8.5)
Continuity strategies and solutions, documented response structure and plans, and a testing programme.
06
Evaluation and improvement (Clauses 9 and 10)
Performance monitoring, internal audit, management review and post-incident learning.
What each requirement buys you
Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.
Requirement themes
Context and scope (Clause 4) chiefly drives 2 of 4 ISO 22301 outcomes.
Outcomes it drives
Known priorities
Business impact analysis defines what must recover first, and how fast, before an incident forces the choice.
Tested capability
Exercised plans and trained teams, with findings fed back into improvement.
Customer assurance
Continuity questionnaires and contract clauses answered with a certificate of registration rather than a statement of intent.
Reduced downtime cost
Faster, ordered recovery directly reduces the financial impact of disruption.
How CORE audits ISO 22301
Step 1
Stage 1 reviews scope, impact analysis and plans
Your auditor confirms the continuity scope names the products and services you are asking to have certified, reads the business impact analysis, the risk assessment, the continuity strategies and the plans, and checks that internal audit, management review and at least one exercise have taken place. Findings here are raised as improvement requests, not nonconformities.
Step 2
Stage 2 examines capability rather than documents
The audit follows the chain from impact to recovery: whether prioritized activities and recovery time objectives are supported by impact data, whether the strategies can meet those objectives with the resources actually available, whether response structure and plans are usable by the people named in them, and whether exercise reports show weaknesses found and acted on. Dependencies on suppliers, sites and technology are sampled against the arrangements claimed for them.
Step 3
Surveillance samples exercises, incidents and change
Year 1 and Year 2 audits sample exercises run since the last visit, any real disruption and the post-incident review that followed, changes to sites, systems, suppliers or key people, the currency of the impact analysis and contact information, progress against continuity objectives, and the closure of previous findings.
Step 4
Recertification revisits the whole cycle
In Year 3 the audit reviews continuity capability across the full three years: whether the impact analysis has been maintained against how the business now operates, whether recovery objectives have ever been met in an exercise or a real event, whether the exercise programme has progressed beyond walkthroughs, and whether the scope still matches the services you deliver.
What your auditor expects to see
Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.
01Exercise programme completed
At least one completed exercise cycle covering the strategies and plans in scope, with the report, the weaknesses identified and the improvements made available to your auditor.
02Internal audit completed
A full internal audit of the BCMS against ISO 22301:2019, including plan quality and exercise follow-up, run by auditors independent of the arrangements they audit.
03Management review held
A minuted management review covering the Clause 9.3 inputs, including the currency of the impact analysis, exercise and incident results, and decisions on resources, with owners named.
04Scope defined and records available
A written scope naming the products, services and sites inside the BCMS boundary, consistent with the impact analysis, plus records covering long enough a period to show the system operating: exercises, invocations, supplier reviews and corrective actions closed.
Certification decision
With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.
CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.
The optional pre-assessment
Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your business impact analysis, risk assessment, continuity strategies, plans and exercise history against ISO 22301:2019. It samples in the same way a certification audit does and returns a written report of findings, separating gaps in documentation from gaps in capability.
The report states where the evidence would not yet satisfy an auditor. It does not run your impact analysis, design your strategies, write your plans or facilitate your exercises: producing that work would make CORE the author of a system it must later audit, which ISO/IEC 17021-1 prohibits. Organizations that want help acting on the report can use the directory of independent consultants at /resources/find-a-consultant, and engaging one has no bearing on the certification decision.
What you receive
- Findings against each clause of the standard
- Where the evidence is missing or incomplete
- Whether Stage 2 could proceed on today's records
- The same sampling method a certification audit uses
Training for ISO 22301
Courses that teach how the standard is written and how it is audited.
ISO 22301 questions, answered straight
Related standards
Ready to certify to ISO 22301?
Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.
