Skip to main content

Certification you can stand behind.

ISO 22301:2019

ISO 22301 Business Continuity Management Systems

When disruption hits, run the plan instead of improvising.

Business continuity
  1. Normal operations

    Steady state

    Prepare

  2. BIA and RTOs

    Priorities set early

  3. Disruption

    Impact begins

    Impact

  4. Continuity controls

    Plans invoked

  5. Recovery proven

    Exercised to RTO

    Within RTO

    Exercise returns to Continuity controls

  6. Service continuity

    Verified recovery

SYS/06 · Continuity timeline

Disruption interrupts operations; controls arrest the fall and tested recovery climbs back to service continuity.

What ISO 22301 is

ISO 22301 specifies a management system for business continuity: impact analysis, risk assessment, continuity strategies, documented plans and an exercise programme that proves they work. Certification to it demonstrates that an independent body has tested the capability, not just read the plan.

CORE audits ISO 22301 along the chain the standard builds, and each link is tested against the one before it. Your auditor asks whether the prioritized activities and recovery time objectives follow from impact data, whether the chosen strategies are capable of meeting those objectives, and whether the plans and exercises would hold under a disruption the organization could plausibly face. Exercise reports, incident and invocation logs, contact and call-out records, supplier continuity arrangements and the resources the strategies assume are examined as evidence. The findings raised most often concern recovery time objectives set without impact analysis behind them, plans naming people who have left, and exercises that validate the document rather than the capability.

Who it is for

  • Organizations whose customers or regulators require a certificate of registration to ISO 22301
  • Operations dependent on critical sites, systems or single-source suppliers where continuity is written into contracts
  • Technology and financial-services firms with recovery-time obligations they must evidence to a third party
  • Certified organizations transferring an active ISO 22301 certificate from another certification body

Business outcomes

What leadership should expect the system to change, in operational terms.

Known priorities

Business impact analysis defines what must recover first, and how fast, before an incident forces the choice.

Tested capability

Exercised plans and trained teams, with findings fed back into improvement.

Customer assurance

Continuity questionnaires and contract clauses answered with a certificate of registration rather than a statement of intent.

Reduced downtime cost

Faster, ordered recovery directly reduces the financial impact of disruption.

Benefits beyond the certificate

  • Clarity in crisis

    Defined incident structure, roles and communication remove hesitation when minutes matter.

  • Supplier resilience

    Continuity requirements pushed into critical supplier relationships.

  • Insurance and finance posture

    Demonstrated resilience supports insurance, credit and due-diligence conversations.

  • Pairing with security

    Complements ISO 27001, sharing risk method and covering availability in depth, and the two can be audited together under one scope.

  • Regulatory alignment

    Supports operational-resilience expectations in regulated sectors.

Steel arch bridge with light trails at blue hour
ISO 22301 in the field

The main requirements

The themes your auditor will examine, in plain language. The full clause detail is worked through at Stage 2.

01

Context and scope (Clause 4)

Products, services, sites and interested parties inside the BCMS boundary.

02

Leadership and policy (Clause 5)

Continuity policy, roles and management commitment.

03

Planning (Clause 6)

Risks, opportunities and measurable continuity objectives.

04

Business impact analysis and risk assessment (Clause 8.2)

Impact over time, prioritized activities, recovery time objectives and disruption risks.

05

Strategies, plans and exercises (Clauses 8.3 to 8.5)

Continuity strategies and solutions, documented response structure and plans, and a testing programme.

06

Evaluation and improvement (Clauses 9 and 10)

Performance monitoring, internal audit, management review and post-incident learning.

What each requirement buys you

Select a requirement theme to see the business outcomes it chiefly drives. The mapping reflects where audit sampling concentrates, not a normative ISO table.

Requirement themes

Context and scope (Clause 4) chiefly drives 2 of 4 ISO 22301 outcomes.

Outcomes it drives

Known priorities

Business impact analysis defines what must recover first, and how fast, before an incident forces the choice.

Tested capability

Exercised plans and trained teams, with findings fed back into improvement.

Customer assurance

Continuity questionnaires and contract clauses answered with a certificate of registration rather than a statement of intent.

Reduced downtime cost

Faster, ordered recovery directly reduces the financial impact of disruption.

How CORE audits ISO 22301

Step 1

Stage 1 reviews scope, impact analysis and plans

Your auditor confirms the continuity scope names the products and services you are asking to have certified, reads the business impact analysis, the risk assessment, the continuity strategies and the plans, and checks that internal audit, management review and at least one exercise have taken place. Findings here are raised as improvement requests, not nonconformities.

Step 2

Stage 2 examines capability rather than documents

The audit follows the chain from impact to recovery: whether prioritized activities and recovery time objectives are supported by impact data, whether the strategies can meet those objectives with the resources actually available, whether response structure and plans are usable by the people named in them, and whether exercise reports show weaknesses found and acted on. Dependencies on suppliers, sites and technology are sampled against the arrangements claimed for them.

Step 3

Surveillance samples exercises, incidents and change

Year 1 and Year 2 audits sample exercises run since the last visit, any real disruption and the post-incident review that followed, changes to sites, systems, suppliers or key people, the currency of the impact analysis and contact information, progress against continuity objectives, and the closure of previous findings.

Step 4

Recertification revisits the whole cycle

In Year 3 the audit reviews continuity capability across the full three years: whether the impact analysis has been maintained against how the business now operates, whether recovery objectives have ever been met in an exercise or a real event, whether the exercise programme has progressed beyond walkthroughs, and whether the scope still matches the services you deliver.

What your auditor expects to see

Before Stage 2 can proceed, the system needs to have run long enough to have produced its own evidence.

  1. 01Exercise programme completed

    At least one completed exercise cycle covering the strategies and plans in scope, with the report, the weaknesses identified and the improvements made available to your auditor.

  2. 02Internal audit completed

    A full internal audit of the BCMS against ISO 22301:2019, including plan quality and exercise follow-up, run by auditors independent of the arrangements they audit.

  3. 03Management review held

    A minuted management review covering the Clause 9.3 inputs, including the currency of the impact analysis, exercise and incident results, and decisions on resources, with owners named.

  4. 04Scope defined and records available

    A written scope naming the products, services and sites inside the BCMS boundary, consistent with the impact analysis, plus records covering long enough a period to show the system operating: exercises, invocations, supplier reviews and corrective actions closed.

  5. Certification decision

    With that evidence in place, Stage 1 and Stage 2 can run. The decision that follows is taken by a reviewer who was not on your audit team.

CORE is the certification body. We assess and certify management systems. We do not build them — that separation is what makes the certificate worth holding. We do not design, document or implement the systems we audit, and we do not run your internal audits. If you need that work done, our directory of independent consultants is a starting point, and engaging one has no bearing on the decision. More on how we keep the audit and the decision separate.

The optional pre-assessment

Before Stage 1 you can ask for an optional pre-assessment: an audit-style review of your business impact analysis, risk assessment, continuity strategies, plans and exercise history against ISO 22301:2019. It samples in the same way a certification audit does and returns a written report of findings, separating gaps in documentation from gaps in capability.

The report states where the evidence would not yet satisfy an auditor. It does not run your impact analysis, design your strategies, write your plans or facilitate your exercises: producing that work would make CORE the author of a system it must later audit, which ISO/IEC 17021-1 prohibits. Organizations that want help acting on the report can use the directory of independent consultants at /resources/find-a-consultant, and engaging one has no bearing on the certification decision.

What you receive

  • Findings against each clause of the standard
  • Where the evidence is missing or incomplete
  • Whether Stage 2 could proceed on today's records
  • The same sampling method a certification audit uses
How the pre-assessment works

Training for ISO 22301

Courses that teach how the standard is written and how it is audited.

All courses

ISO 22301 questions, answered straight

Ready to certify to ISO 22301?

Tell us your standards, scope, effective headcount and sites. You will get a scope statement and a fixed quotation, with audit duration calculated from the accreditation body's mandatory formula.