ISO 22301 is the standard for business continuity management. A good BCMS doesn’t only help you recover quickly after a disruption — it makes your organisation and processes more resilient in the first place: disruptions become less likely, hit you less hard and are brought under control faster. In the audit I look at both sides — resilience in normal operation and the ability to recover when it matters.
Resilience, not just recovery
Resilience means anticipating disruptions, withstanding them, adapting and emerging stronger. A mature BCMS increases the robustness of your critical processes, reduces single points of failure, strengthens supply-chain and IT resilience and embeds responsiveness and adaptability in the organisation — long before a crisis occurs. Recoverability is an important building block, but only one of several.
What the audit covers
The focus is on the business impact analysis (BIA), the risk assessment, your strategies for maintaining and resuming operations, and the emergency plans. I check whether recovery time objectives (RTO) and tolerable data loss (RPO) are properly derived, whether the strategies fit the prioritised activities — and whether they actually make the processes more robust.
Exercised, not just documented
A BCMS is only as good as its tests. Exercises sharpen responsiveness and reveal weaknesses before they become real. I place particular value on exercises actually having taken place, lessons learned flowing back into the plans and processes, and responsibilities and alerting paths being robust under stress.
Areas we focus on
- Robustness and redundancy of critical processes, fewer single points of failure
- Supply-chain and IT resilience
- Organisational adaptability and responsiveness
- Business impact analysis and prioritisation of critical activities
- Recovery time objectives (RTO) and data-loss tolerance (RPO)
- Strategies for maintaining and resuming operations
- Emergency, crisis and communication plans
- Exercises, tests and evaluation (lessons learned)
- Links with information security (ISO 27001) and IT