Knowledge base
ISO 22301:2019: documentation and compliance requirements
Everything ISO 22301:2019 requires you to document, clause by clause, with what an auditor asks to see for each. Written as requirements rather than as a checklist.
Prem Kumar Dvivedi · 12 September 2026
This is what ISO 22301:2019 requires you to have, clause by clause, and what an auditor will ask to see for each of it. It covers 61 requirements across 7 areas.
It is deliberately not a checklist. A checklist asks whether you have something; this says what is required and what counts as evidence, which is the question that matters when you are building a system rather than testing one. If you would rather find out where you stand first, the same ground is covered by our free ISO 22301:2019 readiness assessment, which scores you out of 100.
4 Your organisation and what could disrupt it
Clauses 4.1, 4.2, 4.3, 4.4.
You must have written down the outside things that could disrupt you — suppliers, utilities, weather, cyber attack, transport, laws.
Evidence: A short list of these issues, with a note of when you last looked at it.
You must have written down the inside things — key people, single sites, ageing systems, one supplier for a critical part.
Evidence: The same list, covering internal issues.
You must have listed the people and bodies with an interest — customers, staff, suppliers, regulators, insurers, emergency services.
Evidence: A list of these groups and what each needs from you if something goes wrong.
You must know what you have promised customers about recovery, in contracts or service agreements.
Evidence: Contract clauses on availability, recovery times or penalties. These often do not match your own internal recovery targets, and nobody has noticed.
You must know which laws and regulations apply to you on continuity.
Evidence: A register of legal and regulatory duties on continuity and resilience.
You must have written down what the continuity system covers — which products and services, sites and activities.
Evidence: A scope statement naming the products and services covered.
If you have left something out, you must be able to show it cannot affect the products and services in scope.
Evidence: The reasoning behind the exclusion.
You must know what your main processes are and how they fit together.
Evidence: A process map or a list with owners.
5 Leadership
Clauses 5.1, 5.2, 5.3.
Senior management must be able to point to continuity decisions they made in the last year.
Evidence: Management review notes. Money approved for standby capacity or systems. Ask them directly.
You must be able to answer: Has senior management taken part in an exercise or a real incident?
Evidence: Exercise records showing who took part.
You must have a written business continuity policy.
Evidence: The policy, signed and dated, promising to meet requirements and to keep improving.
It must be shared with your people.
Evidence: Where it is displayed. Ask staff.
It must be clear who is responsible for what — including who can declare an incident and start the plan.
Evidence: Organisation chart. A named person with the authority to invoke, plus deputies.
It must be clear who can spend money during an incident, and who speaks to the press.
Evidence: Delegated spending authority for emergencies. Named spokespeople.
6 Planning
Clauses 6.1, 6.2, 6.3.
You must have worked out what could stop the continuity system working, and what opportunities there are.
Evidence: A risk and opportunity list at system level, kept separate from the disruption risk assessment.
You must have set continuity objectives, and they must be able to be measured.
Evidence: Objectives with targets. The minimum level of service you would accept during a disruption, stated clearly.
For each objective, it must be clear what will be done, by whom, by when, with what, and how you will judge it.
Evidence: An action plan covering all five points.
When something significant changes, you must plan the change rather than absorbing it.
Evidence: Change records covering new sites, systems, products, suppliers or restructures.
7 Support — people, communication and documents
Clauses 7.1, 7.2, 7.3, 7.4, 7.5.
You must provide the people, money and equipment the continuity system needs.
Evidence: Budget. Staffing. Standby arrangements paid for.
The people must with a role in an incident know what to do, and they must have been trained for it.
Evidence: Competence criteria for incident and crisis roles. Training records. Scenario training.
The people who did the impact analysis and risk assessment must be competent to have done it.
Evidence: Their training or experience.
Your people must know the policy, their part in it, and what to do if something happens.
Evidence: Induction and refresher records. Ask staff where they would go and who they would call.
You must have decided what to communicate during a disruption, to whom and how.
Evidence: A communication plan covering staff, customers, suppliers, authorities and the press.
You must have contact details that work when your normal systems are down.
Evidence: Contact lists held off the main system and kept up to date. Evidence they were checked recently.
You must have tested the alternative ways of contacting people.
Evidence: Call cascade or messaging test records.
You must have holding statements ready for customers and the press.
Evidence: Pre-drafted statements. Who is allowed to use them.
You must have the documents and records the standard asks for.
Evidence: A list of documents and records held.
When a document is created or changed, it must be checked and approved before use.
Evidence: Approval on the document.
People must be able to reach the plans when the building, the network or the supplier is unavailable.
Evidence: Plans held offline, off-site or on separate devices. This is the failure most often missed — plans saved only on the system that has just gone down.
8 Working out what matters and being ready
Clauses 8.1, 8.2.2, 8.2.3, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.2, 8.4.3, 8.4.4, 8.4.5, 8.5, 8.6.
You must have planned and put in place the processes needed to meet the continuity requirements.
Evidence: Documented processes and evidence they are followed.
You must control suppliers and outsourced work that your continuity depends on.
Evidence: Continuity terms in contracts. Evidence you checked their own continuity capability rather than taking their word for it.
You must have worked out which activities matter most, and how quickly the harm builds if they stop.
Evidence: A business impact analysis showing the effects over time for each activity.
You must have set the longest you could survive without each activity, and a recovery time shorter than that.
Evidence: Maximum tolerable period of disruption and a recovery time objective for each priority activity. The recovery time must be shorter than the maximum tolerable period.
You must have set how much data you could afford to lose.
Evidence: Recovery point objectives for each system or data set.
For each priority activity, you must know what it needs to run — people, skills, information, premises, systems, equipment, suppliers.
Evidence: Resource requirements per activity, set at the reduced level you would run at, not business as usual.
You must know which activities depend on each other, and where the single points of failure are.
Evidence: Dependencies mapped. Single points of failure listed.
You must have assessed what could disrupt those priority activities and their resources.
Evidence: A risk assessment covering disruption, with treatments to make it less likely or shorter.
You must have looked at the options for keeping going — another site, working from home, another supplier, doing it manually, holding stock, standby systems.
Evidence: The options considered for each priority activity and resource.
You must have chosen an option for each, and you must be able to show it will actually meet the recovery time.
Evidence: The chosen solution with the reasoning, and evidence it can meet the recovery time rather than an assumption that it will.
You must know what each chosen solution needs in order to work.
Evidence: Resource requirements for the solution itself — space, licences, people, equipment.
The solutions must be actually in place, rather than named in a plan.
Evidence: Contracts for standby premises with their access terms. Tested recovery times for systems. Stocks actually held. Standby supplier agreements signed. This is where the gap between plan and reality is usually found.
There must be a team structure to respond to an incident, with roles, deputies and a way to call people in.
Evidence: The incident and crisis structure. Call-out arrangements. Where the team would meet if the main site were unavailable.
It must be clear at what point you declare an incident and start the plan.
Evidence: Written triggers and escalation criteria.
You must have a way of warning and informing people during an incident, including those outside.
Evidence: Warning and communication arrangements. Who tells customers, staff, authorities and the press.
The plans must say who does what, in what order, with what, and when to stop.
Evidence: Plans covering purpose, when to activate, roles, tasks in order, resources, dependencies, communication and stand-down.
You must be able to answer: Could someone other than the author follow the plan under pressure?
Evidence: Plans written for a deputy. Evidence they were tested by someone who did not write them.
You must have arrangements for getting back to normal afterwards — not just for the first few hours.
Evidence: Recovery arrangements: restoring normal operation, clearing the backlog, reconciling data, returning to the main site, and deciding when the incident is over.
You must exercise the arrangements, and do the exercises get harder over time.
Evidence: An exercise programme covering different scenarios and different plans. Exercise plans with objectives. Reports saying what worked and what did not, with the times taken.
The actions from exercises must be followed up and closed.
Evidence: A post-exercise action log with owners, dates and closure.
You must review the impact analysis, the strategies and the plans after an exercise, an incident or a change.
Evidence: Review records with the trigger. Evidence the impact analysis is refreshed rather than rolled forward unchanged.
9 Checking how you are doing
Clauses 9.1, 9.2, 9.3.
You must have decided what you will measure about continuity, and how often.
Evidence: A monitoring plan. Measures such as exercise results against recovery times, plan currency, contact data accuracy, training completion, backup success.
You must look at the results and act on them.
Evidence: Analysis and actions taken.
You must audit the continuity system, covering the whole standard over time.
Evidence: An audit programme. Audit reports and findings.
The auditors must be independent of the work they audit, and competent.
Evidence: Auditor training. Who audited what.
Senior management must review the system at planned intervals.
Evidence: Review dates and attendance.
The review must cover everything the standard asks for.
Evidence: An agenda covering: previous actions, changes, performance, nonconformities, monitoring and audit results, exercise and evaluation outcomes, risks not properly dealt with, opportunities.
The review must produce decisions and actions, not just minutes.
Evidence: Decisions and an action list with owners and dates.
10 Putting things right and getting better
Clauses 10.1, 10.2.
It must be defined when something goes wrong, or a real disruption happens, you must deal with it and work out why.
Evidence: Nonconformity and post-incident records with root cause.
You must check whether the same weakness exists elsewhere, and check later that your fix worked.
Evidence: Evidence you looked wider. A follow-up record with a date.
You must be able to answer: Do lessons from real incidents feed back into the impact analysis and the plans?
Evidence: Plans and analyses revised after an incident.
You must be able to show the continuity arrangements are better than last year.
Evidence: Exercise results improving. Recovery times met that were previously missed. Actions closed. Management review conclusions.
Using this document
Nothing above asks for a manual, a template pack, or a filing system. It asks for decisions that have been taken deliberately and can be shown to have been taken — which is a far smaller job than most organisations expect, and a different one.
Length is not compliance. A procedure nobody follows is worse than no procedure, because an auditor finds the gap between the two. The test we apply is whether the person who has to do the job recognises their own work in what is written down.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 22301, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- South Africa's Information Regulator is issuing notices again
Enforcement notices through 2026, a ransomware finding against SABS, and a R10 million ceiling. POPIA compliance has moved from paper to practice.
12 September 2026
- Information security certification in Nigeria and South Africa
Two regulators, two statutes, one management system. What NDPA and POPIA ask for, and where ISO 27001 and ISO 27701 do the work.
12 September 2026
- Why is ISO Consulting Services Important for Businesses in Bahrain?
ISO consulting services in Bahrain helps organisations improve their processes and meet ISO requirements. They also help businesses build effective management systems that support growth and strengthen market credibility.
24 January 2025
