ISO 22301 - Business Continuity Management
ISO 22301 is the international standard for business continuity. We help you build a BCMS that keeps critical operations running - or gets them back up fast - after a disruption.
What is ISO 22301?
ISO 22301 sets out how to plan for, respond to and recover from disruptive incidents, from a cyber-attack to a natural disaster or supplier failure, so critical business functions keep running or resume within an agreed timeframe.
A certified Business Continuity Management System (BCMS) demonstrates to customers, regulators and insurers that disruption has been planned for, not just hoped against.
What's included
Business Impact Analysis
Business Impact Analysis (BIA) to identify critical processes and recovery time objectives.
Continuity Risk Assessment
Business continuity risk assessment.
BC/DR Plans
Business continuity and disaster recovery plans.
Tabletop Exercises
Tabletop exercises and simulation testing.
BCMS Documentation
BCMS documentation and certification audit readiness.
Ongoing Plan Maintenance
Ongoing plan maintenance and review.
Our approach - Plan, Do, Check, Act
The same continuous-improvement cycle behind every compliance programme we run.
Plan
Identify objectives, secure management support, define the scope and method of risk assessment, and inventory the assets that need protecting.
Do
Manage risk with a treatment plan, implement the required controls and policies, and train staff to follow them.
Check
Monitor how the management system is actually running, and prepare the organisation for its certification or attestation audit.
Act
Run the audit, then keep improving through continual, corrective and preventive action.
Other compliance frameworks
Questions we get asked first
How is ISO 22301 different from a disaster recovery plan?
A DR plan usually covers IT systems recovery; ISO 22301 covers the whole business - people, premises, suppliers and processes - with a management system that keeps the plan current and tested.
Do we need to test the plan?
Yes - ISO 22301 requires periodic exercising of the continuity plan, from tabletop walkthroughs to full simulations, and we help design and run those exercises.
Can this run alongside ISO 27001?
Yes, and it often should - the risk assessment and management-system structure of ISO 27001 and ISO 22301 overlap significantly, so implementing them together reduces duplicate work.
Ready to get audit-ready for ISO 22301?
Tell us where you're starting from and we'll come back with a scoped proposal within two working days.
