← All services ISO 22301

ISO 22301 Audit – Business Continuity Management

Audit of your business continuity management system (BCMS) to ISO 22301 — for stronger organisational and process resilience, not just recovery after an incident.

ISO 22301 is the standard for business continuity management. A good BCMS doesn’t only help you recover quickly after a disruption — it makes your organisation and processes more resilient in the first place: disruptions become less likely, hit you less hard and are brought under control faster. In the audit I look at both sides — resilience in normal operation and the ability to recover when it matters.

Resilience, not just recovery

Resilience means anticipating disruptions, withstanding them, adapting and emerging stronger. A mature BCMS increases the robustness of your critical processes, reduces single points of failure, strengthens supply-chain and IT resilience and embeds responsiveness and adaptability in the organisation — long before a crisis occurs. Recoverability is an important building block, but only one of several.

What the audit covers

The focus is on the business impact analysis (BIA), the risk assessment, your strategies for maintaining and resuming operations, and the emergency plans. I check whether recovery time objectives (RTO) and tolerable data loss (RPO) are properly derived, whether the strategies fit the prioritised activities — and whether they actually make the processes more robust.

Exercised, not just documented

A BCMS is only as good as its tests. Exercises sharpen responsiveness and reveal weaknesses before they become real. I place particular value on exercises actually having taken place, lessons learned flowing back into the plans and processes, and responsibilities and alerting paths being robust under stress.

Areas we focus on

  • Robustness and redundancy of critical processes, fewer single points of failure
  • Supply-chain and IT resilience
  • Organisational adaptability and responsiveness
  • Business impact analysis and prioritisation of critical activities
  • Recovery time objectives (RTO) and data-loss tolerance (RPO)
  • Strategies for maintaining and resuming operations
  • Emergency, crisis and communication plans
  • Exercises, tests and evaluation (lessons learned)
  • Links with information security (ISO 27001) and IT
Contact

Let’s talk about your audit.

Send an informal enquiry or arrange a slot directly — I reply to every e-mail.