BUSINESS CONTINUITY

ISO 22301, Run As A Programme

Most continuity plans are written once and never tested. ISO 22301 exists because that is not continuity, it is paperwork. The standard asks you to work out what would actually hurt and how fast, choose your response from that analysis rather than from what you already own, and then prove it works by exercising it.

What This Is, And What It Is Not

Not a certification body

Auditara prepares you. A separate accredited certification body audits and issues the certificate. Their fees are always separate and we will tell you what to expect.

Not a disaster recovery plan

IT disaster recovery is one part of continuity, not the whole of it. The standard covers people, premises, suppliers, information and finance as well as technology, and a programme that only addresses IT will not certify.

Exercising is not optional

The standard requires an exercise programme with post exercise reports containing outcomes and recommendations. A plan that has never been tested is an untested assumption, and auditors ask about your last exercise first.

Works alongside your other standards

ISO 22301 shares its management clauses with ISO 27001, ISO 9001, ISO 14001 and ISO 45001. If you already hold one, a substantial part of the structure is done. Run them in the same workspace and the shared evidence serves each.

What The Programme Covers

Forty six clause requirements assessed one at a time, each with a question you can answer honestly about how your organisation would actually cope.

Context And Dependencies

What your organisation depends on, what could realistically disrupt it, and who depends on you continuing to operate.

Scope And Exclusions

Which products and services the certificate covers, with any exclusion explained. Leaving out the part hardest to recover is the first thing an auditor tests.

Business Impact Analysis

The analytical heart of the standard. What each activity does for the business, how quickly it must resume, the minimum acceptable level of delivery, and the resources each one needs.

Disruption Risk Assessment

What could disrupt the activities the impact analysis identified as prioritised, assessed with a defined method rather than a general risk register.

Strategies And Solutions

Options identified, compared and selected against the recovery timeframes your analysis produced, then actually implemented. Solutions chosen but never contracted is the most common finding at certification.

Response Structure And Plans

Who responds, what triggers activation, who has authority to invoke a plan, and who deputises. Plus plans someone could follow under pressure who did not write them.

Warning, Communication And Recovery

Communication that works when the normal channels are the thing that failed, and a plan for returning to normal rather than only for keeping going.

Exercising And Evaluation

An exercise programme with post exercise reports and tracked actions, plus periodic evaluation of whether the plans still fit the business.

How The Programme Runs

The same guided journey as every framework in Auditara. The content changes; the method does not.

Step 1

Book the call

Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. Your operations, your dependencies, what would hurt if it stopped, and what is driving the deadline.

Step 2

Answer the intake

Plain English questions about your activities, your contractual recovery commitments, the disruptions credible for you, and when you last tested anything.

Step 3

Run the impact analysis

Activity by activity: the impact over time of not resuming, the recovery timeframe, the minimum acceptable level of delivery, and the resources and dependencies each one needs. Everything downstream rests on this.

Step 4

Assess every clause

Forty six requirements, one at a time, with guidance written for people who have never done this before and a question describing situations you can recognise.

Step 5

Choose and implement

Strategy options compared against your recovery timeframes, the selection reasoning recorded, and the arrangements actually put in place with contracts or provisioned capacity.

Step 6

Exercise it

Test the plans, write up what happened honestly, and fix what you found. This is where certification most often falls down.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

How is this different from our IT disaster recovery plan?

Disaster recovery covers restoring technology. Business continuity covers keeping the organisation delivering while the technology is down, and covers people, premises, suppliers and finance as well. A strong DR plan is useful input but it is not a continuity management system.

What is a business impact analysis and why does it matter so much?

It works out what each activity does for the business, how quickly it must resume, and what it needs to run. Every strategy decision that follows depends on those figures. A continuity arrangement chosen without one is a guess, and auditors can see the difference immediately.

Do we really have to run exercises?

Yes. The standard requires an exercise programme validating the strategies and plans over time, with post exercise reports containing outcomes and recommendations. Exercising is the single most common gap we see, and it is not one you can paper over.

What counts as an exercise?

Anything from a desktop walkthrough with the response team to a full simulation, provided the scenario suits the scope, the aims are defined, and you write up honestly what worked and what did not. Starting with a desktop exercise is entirely acceptable.

We are a small organisation. Is this proportionate?

The requirements scale to the size and complexity of the organisation. A small company still needs to know what would hurt if it stopped, what it would do about it, and whether that works. The documentation supporting that can be brief.

We already hold ISO 27001. How much of this is new?

The management clauses overlap substantially: context, leadership, competence, documented information, internal audit, management review and improvement. What is new is the business impact analysis, the strategy selection, the response structure and the exercise programme.

Ready To Get Started?

Book the call. Fifteen minutes, no obligation, and you leave with a route.

See all frameworks