ISO 22301 tabletop exercises that actually build resilience
Most business continuity exercises are a waste of time—theatrical performances designed to appease an auditor rather than improve resilience. To meet the rigorous requirements of ISO 22301 Clause 8.5, you must move beyond the 'fire drill' and into scenarios that genuinely threaten your ability to deliver.
Michael McCarroll— Founder · 20+ yrs GRC, ISO 27001 lead implementer 16 min read Updated June 2026
Designing Scenarios That Actually Bite
The biggest mistake in BCMS planning is aiming for 'success' in an exercise. If your tabletop goes perfectly, your scenario wasn't hard enough. In a real ISO 22301 environment, the goal of an exercise is to find where your Business Impact Analysis (BIA) assumptions fail, such as discovering that a 'critical' vendor actually has an eight-hour response time when you assumed two.
Start by defining your scope based on Clause 8.2 of the standard. You shouldn't be testing the whole company at once; instead, pick a single critical product or service identified in your BIA. This allows for a deep dive into the specific dependencies—people, tech, and third parties—that actually keep the lights on for that revenue stream.
The Art of the 'Inject' and Escalation
ISO 22301 requires you to test against your predetermined recovery objectives. A generic 'disaster' scenario is useless; you need specific 'Injects' that mirror contemporary threats to your business model. For a SaaS firm, this might be a total database corruption; for a manufacturer, it’s a breakdown in the just-in-time supply chain.
When crafting the narrative, introduce pressure incrementally. Start with a minor anomaly and escalate it into an existential crisis over the course of two hours. This tests the team's ability to escalate according to your Incident Response and Crisis Management plans, rather than just solving the technical problem in isolation.
Loss of Access: Physical site is unavailable (fire, flood, police cordon).
Loss of People: A flu outbreak or mass resignation affecting key skill sets.
Loss of Technology: Ransomware or a major cloud provider region outage.
Loss of Third Parties: A critical SaaS provider or logistics firm goes bust.
Who Belongs in the Room?
Selecting the right participants is the difference between a productive session and a chat in the boardroom. You need the people who will actually make the calls during a crisis, not their deputies. This includes representatives from Legal and PR, as the reputational impact of a disruption often outlasts the operational one.
Avoid the 'hero culture' during the exercise. If the CTO is the only one who knows how to failover a database, remove them from the scenario early on (an 'inject' saying they are on a flight). This forces the rest of the team to rely on documentation and process, which is exactly what ISO 22301 Clause 8.4 is testing.
The Facilitator: Keeps the pace and introduces injects (usually the Head of Compliance).
The Players: The actual decision-makers (Head of Ops, CTO, HR, Legal).
The Scribe: Records every decision, the time it was made, and the rationale.
The Observer: An objective party who watches for friction or communication breakdowns.
The After Action Report: Evidence of Improvement
An exercise is only as good as its documentation. In the eyes of an ISO 22301 auditor, if it isn't documented, it didn't happen. The After Action Report (AAR) must be produced within 72 hours of the exercise while the gaps are fresh in everyone's minds. This report should link every identified failure directly to an improvement action.
A high-quality AAR should be brutally honest. It should highlight where the Business Continuity Plan (BCP) was too vague, where the Recovery Time Objectives (RTOs) were unrealistic, and where communication channels broke down. This document then feeds directly into your Management Review (Clause 9.3), closing the loop on the Plan-Do-Check-Act cycle.
Closing the Gap Between Policy and Reality
The ultimate goal of exercising under ISO 22301 is ensuring your Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are grounded in reality. During the tabletop, you should be timing tasks. If your plan says 'Restore from backup in 2 hours' but the team admits it takes 6 hours to even verify the backup, your BIA is flawed and must be updated.
Your exercise schedule should be a rolling 3-year plan. Year one might be a simple tabletop, year two a more complex 'functional' drill involving actual technical failover, and year three a full-scale simulation. This progressive complexity demonstrates to clients and auditors that your resilience is maturing, not just stagnating in a annual 'tick-box' meeting.
Validate RTOs: Do the times recorded match the BIA requirements?
Test Communication: Did the 'emergency notification' system actually work?
Update PDAs: Are the 'Primary, Delegate, Alternate' contact lists current?
Identify Single Points of Failure: Did the scenario stall because one person was missing?
Stop practicing for the audit—start practicing for the crisis.
Our platform turns ISO 22301 from a dusty manual into a living shield. Centralise your BIA, automate exercise scheduling, and provide the evidence of resilience that wins high-value enterprise contracts. Prove you are ready for anything.
ISO-STANDARD.app ships a ready-to-adopt ISO 22301 workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.
Frequently asked questions
How often should we realistically run tabletop exercises?
ISO 22301 (Clause 8.5) requires exercises to be held at planned intervals and when there are significant changes. For most high-growth firms, an annual full-scale tabletop supplemented by quarterly departmental 'micro-drills' is the gold standard for maintaining operational readiness.
What specific evidence do ISO 22301 auditors look for?
Documentation is everything for Clause 8.5. You need an exercise plan (objectives/scope), a record of the scenario, an attendance log, and—most importantly—an After Action Report (AAR) that tracks corrective actions through to completion.
How do we measure if an exercise was successful?
Focus on 'Maximum Tolerable Period of Disruption' (MTPD) for your critical services. If your MTPD is 4 hours and your tabletop reveals a 12-hour recovery time, you haven't failed the exercise—you've successfully identified a critical gap that needs investment.
What are 'Injects' and why are they necessary?
The 'Inject' is the primary tool. These are mid-exercise updates that change the landscape, such as 'The backup site is also offline' or 'The lead engineer is unreachable.' These force the team to pivot and prevent the scenario from following a predictable, easy path.
Action checklist PDF
Mirrors this guide with owners, artefacts & a 30/60/90-day plan.