Knowledge base
ISO 22301:2019: Documentation and Compliance Requirements
ISO 22301:2019 explains what an organisation needs to have in place to manage business continuity and prepare for disruptions.
Prem Kumar Dvivedi · 12 September 2026
Below is a clause-by-clause explanation of what the standard requires and what an auditor may ask for as evidence.
The focus is not simply on whether you have a document. The important question is whether the required arrangements are actually implemented and working.
________________________________________
4. Understanding the Organisation and Possible Disruptions
Clauses 4.1, 4.2, 4.3 and 4.4
Understand external issues
You should identify external factors that could affect your business, such as:
• Supplier problems
• Power or utility failures
• Extreme weather
• Cyberattacks
• Transport problems
• Changes in laws and regulations
Evidence: A documented list of these issues and a record showing when it was last reviewed.
Understand internal issues
You should also identify internal factors that could create problems, such as:
• Dependence on key employees
• Having only one operating location
• Old or unsupported systems
• Dependence on a single critical supplier
Evidence: A documented list of internal issues.
Identify interested parties
You should identify people and organisations that may be affected by a disruption, such as:
• Customers
• Employees
• Suppliers
• Regulators
• Insurance companies
• Emergency services
Evidence: A list of interested parties and their relevant requirements during a disruption.
Understand customer commitments
You should know what your contracts or service agreements promise customers regarding business continuity.
For example:
• Service availability
• Recovery time
• Service levels
• Penalties for service failure
Evidence: Relevant contract or service agreement requirements.
Identify legal and regulatory requirements
You should know which laws and regulations related to business continuity apply to your organisation.
Evidence: A legal and regulatory requirements register.
Define the scope of the BCMS
You should clearly define what your Business Continuity Management System (BCMS) covers.
This could include:
• Products
• Services
• Locations
• Business activities
Evidence: A documented scope statement.
If something is excluded from the scope, you should be able to explain why it does not affect the products or services covered by the BCMS.
Evidence: Documented justification for the exclusion.
Understand key processes
You should identify your main business processes and understand how they are connected.
Evidence: Process map or a list of processes with responsible owners.
________________________________________
5. Leadership
Clauses 5.1, 5.2 and 5.3
Management involvement
Top management should actively participate in business continuity decisions.
Evidence may include:
• Management review records
• Approved budgets
• Investment in backup systems or standby facilities
• Decisions related to business continuity
An auditor may also ask senior management directly about their involvement.
Management participation in exercises
Senior management should participate in business continuity exercises or actual incident responses.
Evidence: Exercise records showing management participation.
Business continuity policy
The organisation must have a documented Business Continuity Policy.
It should:
• Be approved and dated
• Commit to meeting applicable requirements
• Commit to continual improvement
Evidence: Approved Business Continuity Policy.
Communicating the policy
Employees should know about the policy and understand its importance.
Evidence: Communication records, training or awareness activities.
Roles and responsibilities
It should be clear who is responsible for what during an incident.
This should include:
• Who can declare an incident
• Who can activate the continuity plan
• Who takes responsibility if the main person is unavailable
Evidence: Organisation chart, responsibility matrix and nominated deputies.
Emergency authority
It should also be clear:
• Who can approve emergency spending
• Who communicates with customers
• Who communicates with the media
Evidence: Delegated authority and nominated spokesperson details.
________________________________________
6. Planning
Clauses 6.1, 6.2 and 6.3
Risks and opportunities
You should identify risks that could affect the BCMS itself, as well as opportunities to improve it.
Evidence: Risk and opportunity register for the BCMS.
This should be different from the risk assessment for specific business disruptions.
Business continuity objectives
You should establish measurable continuity objectives.
For example:
• Maximum acceptable downtime
• Target recovery time
• Minimum level of service during a disruption
Evidence: Documented objectives with measurable targets.
Action plans
For every objective, it should be clear:
• What needs to be done
• Who will do it
• When it will be completed
• What resources are required
• How success will be measured
Evidence: Documented action plan.
Managing changes
Important changes should be planned rather than handled informally.
Examples include:
• New locations
• New IT systems
• New products
• New suppliers
• Organisational restructuring
Evidence: Change management records.
________________________________________
7. Support – People, Communication and Documents
Clauses 7.1, 7.2, 7.3, 7.4 and 7.5
Provide necessary resources
The organisation should provide the people, money, equipment and other resources needed for business continuity.
Evidence:
• Budget
• Staffing arrangements
• Backup or standby resources
Competence and training
People involved in incident or crisis management should know their responsibilities and be trained.
Evidence:
• Competence requirements
• Training records
• Emergency or scenario-based training
People conducting the Business Impact Analysis (BIA) and risk assessment should also have suitable knowledge and experience.
Evidence: Training certificates, qualifications or relevant experience.
Employee awareness
Employees should understand:
• The business continuity policy
• Their responsibilities
• What they should do during an incident
• Who they should contact
Evidence: Induction and refresher training records.
An auditor may ask employees what they would do during an emergency.
Communication arrangements
You should decide:
• What information needs to be communicated
• Who needs to receive it
• How it will be communicated
This should cover relevant stakeholders such as:
• Employees
• Customers
• Suppliers
• Authorities
• Media
Evidence: Business continuity communication plan.
Emergency contact information
Contact details should remain available even if normal IT systems are unavailable.
Evidence: Updated offline or alternative contact lists.
These contact details should also be tested regularly.
Testing communication methods
Alternative communication methods should be tested.
Evidence: Call-tree, messaging or communication test records.
Pre-prepared communication
You should have ready-to-use messages for customers and media where appropriate.
Evidence: Pre-approved statements and details of who is authorised to issue them.
Documented information
You should maintain the documents and records required by ISO 22301.
Evidence: Document and record control list.
Documents should be reviewed and approved before they are used.
Evidence: Approval and revision records.
Access to plans
Business continuity plans should be accessible even if:
• The office is unavailable
• The network is down
• The main IT system fails
• A supplier becomes unavailable
Evidence: Offline, off-site or independently stored copies of plans.
A common weakness is keeping the only copy of the continuity plan on the system that has failed.
________________________________________
8. Business Impact, Risk and Continuity Arrangements
Clauses 8.1, 8.2.2, 8.2.3, 8.3.2–8.3.5, 8.4.2–8.4.5, 8.5 and 8.6
Plan and implement continuity processes
The organisation should establish the processes needed to meet its continuity requirements.
Evidence: Documented processes and records showing that they are actually followed.
Control suppliers and outsourced services
If business continuity depends on suppliers or outsourced services, their continuity capability should also be considered.
Evidence:
• Contractual continuity requirements
• Supplier assessments
• Evidence of supplier continuity capability
Conduct a Business Impact Analysis
You should identify which activities are most important to the organisation and understand what happens if they stop.
Evidence: Business Impact Analysis showing the impact of disruption over time.
Define recovery requirements
For each important activity, you should determine:
• How long the organisation can survive without it
• How quickly it needs to be restored
The recovery target should be shorter than the maximum acceptable disruption period.
Evidence:
• Maximum Tolerable Period of Disruption (MTPD)
• Recovery Time Objective (RTO)
Define data recovery requirements
You should determine how much data the organisation can afford to lose.
Evidence: Recovery Point Objectives (RPOs) for relevant systems and data.
Identify required resources
For every critical activity, identify what is required to continue operating, such as:
• People
• Skills
• Information
• Premises
• IT systems
• Equipment
• Suppliers
These requirements should reflect the minimum level needed to continue operations during a disruption, not necessarily normal business capacity.
Evidence: Documented resource requirements for each priority activity.
Identify dependencies
You should understand how activities depend on each other and identify single points of failure.
Evidence: Dependency maps and documented single points of failure.
Assess disruption risks
You should assess what could disrupt critical activities and the resources they depend on.
Evidence: Business continuity risk assessment and risk treatment actions.
Identify continuity options
You should consider different ways of continuing operations, such as:
• Alternate offices
• Remote working
• Alternate suppliers
• Manual processes
• Additional stock
• Backup systems
Evidence: Documented options considered for each important activity.
Select suitable solutions
You should select the appropriate continuity solution and demonstrate that it can meet the required recovery time.
Evidence:
• Selected strategy
• Reason for selection
• Evidence that the solution can achieve the required recovery time
Identify requirements for the solution
Each continuity solution may itself require resources such as:
• Premises
• Licences
• Employees
• Equipment
• IT systems
Evidence: Documented requirements for implementing the solution.
Put solutions into practice
Continuity arrangements should not exist only on paper. They should actually be available and operational.
Evidence may include:
• Contracts for alternate premises
• Tested IT recovery times
• Actual emergency stock
• Signed standby supplier agreements
This is often where organisations discover a difference between what is written in the plan and what actually exists.
Establish an incident response structure
There should be a clear structure for responding to incidents.
It should identify:
• Roles
• Responsibilities
• Deputies
• Call-out arrangements
• Alternate meeting locations
Evidence: Incident and crisis management structure and call-out arrangements.
Define incident activation criteria
It should be clear when an incident becomes serious enough to activate the continuity plan.
Evidence: Documented triggers and escalation criteria.
Warning and communication
You should have arrangements for informing employees and external stakeholders during an incident.
Evidence: Emergency communication and notification arrangements.
Business continuity plans
Plans should clearly explain:
• Purpose
• When to activate
• Who is responsible
• What needs to be done
• In what order
• What resources are required
• Dependencies
• Communication requirements
• When the plan can be closed
Evidence: Documented and usable continuity plans.
Test whether others can use the plan
The plan should be understandable to someone other than the person who created it.
Evidence: A deputy or another employee successfully testing the plan.
Recovery and return to normal
Business continuity does not end when the immediate emergency is over.
Plans should also cover:
• Restoring normal operations
• Clearing backlogs
• Reconciling data
• Returning to the main site
• Deciding when the incident is officially closed
Evidence: Recovery and restoration arrangements.
Conduct exercises
The organisation should regularly test its continuity arrangements.
Exercises should cover different scenarios and become more challenging over time.
Evidence:
• Exercise programme
• Exercise objectives
• Exercise reports
• Results and recovery times
• Lessons learned
Follow up exercise findings
Actions identified during exercises should be assigned, tracked and closed.
Evidence: Corrective action or exercise action log showing:
• Action owner
• Target date
• Completion status
Review and update the system
The BIA, risk assessments, strategies and plans should be reviewed after:
• Exercises
• Real incidents
• Major organisational changes
Evidence: Review records showing that the documents were actually updated where necessary.
________________________________________
9. Monitoring and Reviewing Performance
Clauses 9.1, 9.2 and 9.3
Decide what to measure
You should identify what aspects of business continuity will be monitored and how often.
Examples include:
• Exercise performance
• Recovery times
• Plan updates
• Contact information accuracy
• Training completion
• Backup performance
Evidence: Monitoring and measurement plan.
Review results
You should analyse the results and take action where necessary.
Evidence: Performance analysis and action records.
Internal audits
The BCMS should be internally audited over time to ensure that all relevant requirements are being addressed.
Evidence:
• Internal audit programme
• Audit reports
• Audit findings
Auditors should be competent and independent from the activities they audit.
Evidence: Auditor qualifications/training and audit assignments.
Management review
Top management should review the BCMS at planned intervals.
The review should consider:
• Previous actions
• Changes affecting the organisation
• Performance results
• Nonconformities
• Monitoring results
• Internal audit results
• Exercise results
• Risks
• Improvement opportunities
Evidence: Management review agenda and records.
The review should result in actual decisions and actions.
Evidence: Action list showing responsibilities and target dates.
________________________________________
10. Corrective Action and Continual Improvement
Clauses 10.1 and 10.2
Correct problems
When something goes wrong, including an actual business disruption, the organisation should:
• Address the problem
• Identify the cause
• Take corrective action
Evidence: Nonconformity and incident records, including root-cause analysis.
Check for similar problems
You should check whether the same problem could exist somewhere else in the organisation.
You should also verify later that the corrective action actually worked.
Evidence:
• Wider review
• Follow-up records
• Effectiveness verification
Learn from real incidents
Lessons from actual incidents should be used to improve:
• Business Impact Analysis
• Risk assessments
• Continuity strategies
• Business continuity plans
Evidence: Updated documents following an actual incident.
Demonstrate improvement
The organisation should be able to demonstrate that its business continuity arrangements are improving over time.
Examples include:
• Better exercise results
• Improved recovery times
• Previously missed targets being achieved
• Corrective actions being closed
• Improvement decisions recorded in management reviews
________________________________________
How to Use These Requirements
ISO 22301 does not simply require an organisation to create a large manual or a collection of templates.
The main requirement is that the organisation has made the right business continuity decisions, implemented them, tested them and can demonstrate evidence that they work.
More documents do not automatically mean better compliance.
A long procedure that nobody follows can actually create a bigger problem during an audit because the auditor may find a difference between what the document says and what employees actually do.
The key question is:
Can the people responsible for the work recognise their actual roles and activities in the documented system?
A practical ISO 22301 system should therefore be clear, relevant, implemented, tested and continuously improved — not simply a collection of documents created for the audit.
What this covers
See how this looks as a working system
Reading about a requirement and seeing the documentation that satisfies it are different things. In a short demo we open the actual manual, procedures and records set for ISO 22301, show you how each clause is answered and where your existing way of working already fits. You will know what implementation involves before you commit to it.
More reading
- Automotive Suppliers Face Stricter Cybersecurity Assessments
Cybersecurity is becoming a key part of supplier evaluations in the automotive industry. Vehicle manufacturers now check how suppliers protect data and systems alongside quality, cost, and delivery.
13 September 2026
- Automotive OEM Vendor Cybersecurity Assessment: Controls, Scoring and ISO Standards Mapping
What does an automotive vendor cybersecurity assessment cover?
13 September 2026
- Inside an Automotive OEM Vendor Cybersecurity Assessment: The 19 Control Families and What They Actually Ask For
The nineteen control families in an automotive vendor cybersecurity assessment, where the structure came from, and why good controls still score zero.
13 September 2026
