Knowledge base

ISO 22301:2019: Documentation and Compliance Requirements

ISO 22301:2019 explains what an organisation needs to have in place to manage business continuity and prepare for disruptions.

Prem Kumar Dvivedi · 2026 оны есдүгээр сарын 12

Below is a clause-by-clause explanation of what the standard requires and what an auditor may ask for as evidence.

The focus is not simply on whether you have a document. The important question is whether the required arrangements are actually implemented and working.

________________________________________

4. Understanding the Organisation and Possible Disruptions

Clauses 4.1, 4.2, 4.3 and 4.4

Understand external issues

You should identify external factors that could affect your business, such as:

• Supplier problems

• Power or utility failures

• Extreme weather

• Cyberattacks

• Transport problems

• Changes in laws and regulations

Evidence: A documented list of these issues and a record showing when it was last reviewed.

Understand internal issues

You should also identify internal factors that could create problems, such as:

• Dependence on key employees

• Having only one operating location

• Old or unsupported systems

• Dependence on a single critical supplier

Evidence: A documented list of internal issues.

Identify interested parties

You should identify people and organisations that may be affected by a disruption, such as:

• Customers

• Employees

• Suppliers

• Regulators

• Insurance companies

• Emergency services

Evidence: A list of interested parties and their relevant requirements during a disruption.

Understand customer commitments

You should know what your contracts or service agreements promise customers regarding business continuity.

For example:

• Service availability

• Recovery time

• Service levels

• Penalties for service failure

Evidence: Relevant contract or service agreement requirements.

Identify legal and regulatory requirements

You should know which laws and regulations related to business continuity apply to your organisation.

Evidence: A legal and regulatory requirements register.

Define the scope of the BCMS

You should clearly define what your Business Continuity Management System (BCMS) covers.

This could include:

• Products

• Services

• Locations

• Business activities

Evidence: A documented scope statement.

If something is excluded from the scope, you should be able to explain why it does not affect the products or services covered by the BCMS.

Evidence: Documented justification for the exclusion.

Understand key processes

You should identify your main business processes and understand how they are connected.

Evidence: Process map or a list of processes with responsible owners.

________________________________________

5. Leadership

Clauses 5.1, 5.2 and 5.3

Management involvement

Top management should actively participate in business continuity decisions.

Evidence may include:

• Management review records

• Approved budgets

• Investment in backup systems or standby facilities

• Decisions related to business continuity

An auditor may also ask senior management directly about their involvement.

Management participation in exercises

Senior management should participate in business continuity exercises or actual incident responses.

Evidence: Exercise records showing management participation.

Business continuity policy

The organisation must have a documented Business Continuity Policy.

It should:

• Be approved and dated

• Commit to meeting applicable requirements

• Commit to continual improvement

Evidence: Approved Business Continuity Policy.

Communicating the policy

Employees should know about the policy and understand its importance.

Evidence: Communication records, training or awareness activities.

Roles and responsibilities

It should be clear who is responsible for what during an incident.

This should include:

• Who can declare an incident

• Who can activate the continuity plan

• Who takes responsibility if the main person is unavailable

Evidence: Organisation chart, responsibility matrix and nominated deputies.

Emergency authority

It should also be clear:

• Who can approve emergency spending

• Who communicates with customers

• Who communicates with the media

Evidence: Delegated authority and nominated spokesperson details.

________________________________________

6. Planning

Clauses 6.1, 6.2 and 6.3

Risks and opportunities

You should identify risks that could affect the BCMS itself, as well as opportunities to improve it.

Evidence: Risk and opportunity register for the BCMS.

This should be different from the risk assessment for specific business disruptions.

Business continuity objectives

You should establish measurable continuity objectives.

For example:

• Maximum acceptable downtime

• Target recovery time

• Minimum level of service during a disruption

Evidence: Documented objectives with measurable targets.

Action plans

For every objective, it should be clear:

• What needs to be done

• Who will do it

• When it will be completed

• What resources are required

• How success will be measured

Evidence: Documented action plan.

Managing changes

Important changes should be planned rather than handled informally.

Examples include:

• New locations

• New IT systems

• New products

• New suppliers

• Organisational restructuring

Evidence: Change management records.

________________________________________

7. Support – People, Communication and Documents

Clauses 7.1, 7.2, 7.3, 7.4 and 7.5

Provide necessary resources

The organisation should provide the people, money, equipment and other resources needed for business continuity.

Evidence:

• Budget

• Staffing arrangements

• Backup or standby resources

Competence and training

People involved in incident or crisis management should know their responsibilities and be trained.

Evidence:

• Competence requirements

• Training records

• Emergency or scenario-based training

People conducting the Business Impact Analysis (BIA) and risk assessment should also have suitable knowledge and experience.

Evidence: Training certificates, qualifications or relevant experience.

Employee awareness

Employees should understand:

• The business continuity policy

• Their responsibilities

• What they should do during an incident

• Who they should contact

Evidence: Induction and refresher training records.

An auditor may ask employees what they would do during an emergency.

Communication arrangements

You should decide:

• What information needs to be communicated

• Who needs to receive it

• How it will be communicated

This should cover relevant stakeholders such as:

• Employees

• Customers

• Suppliers

• Authorities

• Media

Evidence: Business continuity communication plan.

Emergency contact information

Contact details should remain available even if normal IT systems are unavailable.

Evidence: Updated offline or alternative contact lists.

These contact details should also be tested regularly.

Testing communication methods

Alternative communication methods should be tested.

Evidence: Call-tree, messaging or communication test records.

Pre-prepared communication

You should have ready-to-use messages for customers and media where appropriate.

Evidence: Pre-approved statements and details of who is authorised to issue them.

Documented information

You should maintain the documents and records required by ISO 22301.

Evidence: Document and record control list.

Documents should be reviewed and approved before they are used.

Evidence: Approval and revision records.

Access to plans

Business continuity plans should be accessible even if:

• The office is unavailable

• The network is down

• The main IT system fails

• A supplier becomes unavailable

Evidence: Offline, off-site or independently stored copies of plans.

A common weakness is keeping the only copy of the continuity plan on the system that has failed.

________________________________________

8. Business Impact, Risk and Continuity Arrangements

Clauses 8.1, 8.2.2, 8.2.3, 8.3.2–8.3.5, 8.4.2–8.4.5, 8.5 and 8.6

Plan and implement continuity processes

The organisation should establish the processes needed to meet its continuity requirements.

Evidence: Documented processes and records showing that they are actually followed.

Control suppliers and outsourced services

If business continuity depends on suppliers or outsourced services, their continuity capability should also be considered.

Evidence:

• Contractual continuity requirements

• Supplier assessments

• Evidence of supplier continuity capability

Conduct a Business Impact Analysis

You should identify which activities are most important to the organisation and understand what happens if they stop.

Evidence: Business Impact Analysis showing the impact of disruption over time.

Define recovery requirements

For each important activity, you should determine:

• How long the organisation can survive without it

• How quickly it needs to be restored

The recovery target should be shorter than the maximum acceptable disruption period.

Evidence:

• Maximum Tolerable Period of Disruption (MTPD)

• Recovery Time Objective (RTO)

Define data recovery requirements

You should determine how much data the organisation can afford to lose.

Evidence: Recovery Point Objectives (RPOs) for relevant systems and data.

Identify required resources

For every critical activity, identify what is required to continue operating, such as:

• People

• Skills

• Information

• Premises

• IT systems

• Equipment

• Suppliers

These requirements should reflect the minimum level needed to continue operations during a disruption, not necessarily normal business capacity.

Evidence: Documented resource requirements for each priority activity.

Identify dependencies

You should understand how activities depend on each other and identify single points of failure.

Evidence: Dependency maps and documented single points of failure.

Assess disruption risks

You should assess what could disrupt critical activities and the resources they depend on.

Evidence: Business continuity risk assessment and risk treatment actions.

Identify continuity options

You should consider different ways of continuing operations, such as:

• Alternate offices

• Remote working

• Alternate suppliers

• Manual processes

• Additional stock

• Backup systems

Evidence: Documented options considered for each important activity.

Select suitable solutions

You should select the appropriate continuity solution and demonstrate that it can meet the required recovery time.

Evidence:

• Selected strategy

• Reason for selection

• Evidence that the solution can achieve the required recovery time

Identify requirements for the solution

Each continuity solution may itself require resources such as:

• Premises

• Licences

• Employees

• Equipment

• IT systems

Evidence: Documented requirements for implementing the solution.

Put solutions into practice

Continuity arrangements should not exist only on paper. They should actually be available and operational.

Evidence may include:

• Contracts for alternate premises

• Tested IT recovery times

• Actual emergency stock

• Signed standby supplier agreements

This is often where organisations discover a difference between what is written in the plan and what actually exists.

Establish an incident response structure

There should be a clear structure for responding to incidents.

It should identify:

• Roles

• Responsibilities

• Deputies

• Call-out arrangements

• Alternate meeting locations

Evidence: Incident and crisis management structure and call-out arrangements.

Define incident activation criteria

It should be clear when an incident becomes serious enough to activate the continuity plan.

Evidence: Documented triggers and escalation criteria.

Warning and communication

You should have arrangements for informing employees and external stakeholders during an incident.

Evidence: Emergency communication and notification arrangements.

Business continuity plans

Plans should clearly explain:

• Purpose

• When to activate

• Who is responsible

• What needs to be done

• In what order

• What resources are required

• Dependencies

• Communication requirements

• When the plan can be closed

Evidence: Documented and usable continuity plans.

Test whether others can use the plan

The plan should be understandable to someone other than the person who created it.

Evidence: A deputy or another employee successfully testing the plan.

Recovery and return to normal

Business continuity does not end when the immediate emergency is over.

Plans should also cover:

• Restoring normal operations

• Clearing backlogs

• Reconciling data

• Returning to the main site

• Deciding when the incident is officially closed

Evidence: Recovery and restoration arrangements.

Conduct exercises

The organisation should regularly test its continuity arrangements.

Exercises should cover different scenarios and become more challenging over time.

Evidence:

• Exercise programme

• Exercise objectives

• Exercise reports

• Results and recovery times

• Lessons learned

Follow up exercise findings

Actions identified during exercises should be assigned, tracked and closed.

Evidence: Corrective action or exercise action log showing:

• Action owner

• Target date

• Completion status

Review and update the system

The BIA, risk assessments, strategies and plans should be reviewed after:

• Exercises

• Real incidents

• Major organisational changes

Evidence: Review records showing that the documents were actually updated where necessary.

________________________________________

9. Monitoring and Reviewing Performance

Clauses 9.1, 9.2 and 9.3

Decide what to measure

You should identify what aspects of business continuity will be monitored and how often.

Examples include:

• Exercise performance

• Recovery times

• Plan updates

• Contact information accuracy

• Training completion

• Backup performance

Evidence: Monitoring and measurement plan.

Review results

You should analyse the results and take action where necessary.

Evidence: Performance analysis and action records.

Internal audits

The BCMS should be internally audited over time to ensure that all relevant requirements are being addressed.

Evidence:

• Internal audit programme

• Audit reports

• Audit findings

Auditors should be competent and independent from the activities they audit.

Evidence: Auditor qualifications/training and audit assignments.

Management review

Top management should review the BCMS at planned intervals.

The review should consider:

• Previous actions

• Changes affecting the organisation

• Performance results

• Nonconformities

• Monitoring results

• Internal audit results

• Exercise results

• Risks

• Improvement opportunities

Evidence: Management review agenda and records.

The review should result in actual decisions and actions.

Evidence: Action list showing responsibilities and target dates.

________________________________________

10. Corrective Action and Continual Improvement

Clauses 10.1 and 10.2

Correct problems

When something goes wrong, including an actual business disruption, the organisation should:

• Address the problem

• Identify the cause

• Take corrective action

Evidence: Nonconformity and incident records, including root-cause analysis.

Check for similar problems

You should check whether the same problem could exist somewhere else in the organisation.

You should also verify later that the corrective action actually worked.

Evidence:

• Wider review

• Follow-up records

• Effectiveness verification

Learn from real incidents

Lessons from actual incidents should be used to improve:

• Business Impact Analysis

• Risk assessments

• Continuity strategies

• Business continuity plans

Evidence: Updated documents following an actual incident.

Demonstrate improvement

The organisation should be able to demonstrate that its business continuity arrangements are improving over time.

Examples include:

• Better exercise results

• Improved recovery times

• Previously missed targets being achieved

• Corrective actions being closed

• Improvement decisions recorded in management reviews

________________________________________

How to Use These Requirements

ISO 22301 does not simply require an organisation to create a large manual or a collection of templates.

The main requirement is that the organisation has made the right business continuity decisions, implemented them, tested them and can demonstrate evidence that they work.

More documents do not automatically mean better compliance.

A long procedure that nobody follows can actually create a bigger problem during an audit because the auditor may find a difference between what the document says and what employees actually do.

The key question is:

Can the people responsible for the work recognise their actual roles and activities in the documented system?

A practical ISO 22301 system should therefore be clear, relevant, implemented, tested and continuously improved — not simply a collection of documents created for the audit.


What this covers

See how this looks as a working system

Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 22301, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.

Ask us about this

Tell us what is being asked of you and by whom.

What are you looking for?

We reply within one working day. Your details stay with our consultants.

More reading

All articles