ISO 22301

ISO 22301 is the international standard for Business Continuity Management Systems (BCMS). It gives you a structured way to prepare for, respond to and recover from disruptive incidents.

Who it applies to

Any organisation needing formal business continuity management — commonly financial services, healthcare, critical infrastructure, essential suppliers.

How ISO-STANDARD.app helps with ISO 22301

Pre-loaded ISO 22301 control mapping crosswalked to ISO 27001 Annex A so you don't duplicate work.

Evidence Vault stores signed, versioned artefacts (screenshots, logs, attestations) auditors and buyers accept.

Trust Center publishes your current ISO 22301 posture to prospects on demand — no PDF chase.

Internal Audit, CAPA and Management Review workflows built in, mapped to ISO 22301 clauses.

Policy templates with attestation, review cycles and change history that satisfy assessor sampling.

10 in-depth articles

The Business Impact Analysis: the heart of ISO 22301

Without a real BIA, everything else in your BCMS is guessing. This is where recovery objectives actually come from.

The purpose

Identify prioritised activities, their dependencies, and the impact over time of their disruption. This drives every recovery decision.

MTPD, RTO, RPO

Maximum Tolerable Period of Disruption, Recovery Time Objective, Recovery Point Objective. Set them from the BIA, not from IT preferences.

Interdependencies

Activities depend on people, technology, information, suppliers, facilities. The BIA maps them so recovery plans have concrete targets.

Refresh cycle

Annual as minimum; more often for high-change organisations. Old BIAs make bad plans.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Risk assessment vs Business Impact Analysis: not the same

One tells you what could go wrong; the other tells you what happens if it does. You need both.

Risk assessment

Identifies threats and vulnerabilities. Aligns with your general ISO 27001 or 31000 risk process where possible.

BIA

Identifies impact of loss regardless of cause. Threat-agnostic — 'if this activity stops for 3 days, what happens?'

Feeding each other

Risk assessment tells you which threats need controls. BIA tells you which activities need recovery capability. Together they scope your BCMS.

Audit-ready traceability

Every recovery capability should trace back to a BIA-identified activity. Every treatment should trace back to a risk.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Running tabletop exercises that actually improve things

The exercises that improve capability are the ones with real scenarios and post-exercise action tracking.

Scenario realism

Base scenarios on your BIA activities and your risk assessment. Generic disaster scenarios train muscle but not judgement.

Participants

The people who'd actually respond — including business, not just IT. Executives too, for the decisions only they can make.

Post-exercise report

Documented findings with owners and dates. This is the input to next year's BCMS improvement plan.

Frequency

At least annually for the whole BCMS; quarterly or more for critical scenarios. Muscle memory decays.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

DR vs BC: how ISO 22301 uses both

Disaster recovery is IT-centric. Business continuity is business-centric. 22301 wants both in a coherent BCMS.

Disaster recovery

IT service and infrastructure recovery. RTO/RPO for systems. Owned by IT.

Business continuity

Continuing critical business activities during and after disruption. Owned by business functions with IT as an enabler.

The BCMS umbrella

22301 doesn't distinguish sharply — it wants a Business Continuity Management System that covers both.

Integration

The DR runbook is a component of the wider BC plan. Test them together, not in isolation.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

ISO 22301 vs operational resilience frameworks (UK/EU financial)

22301 is the foundation. UK PRA/FCA operational resilience and DORA operational resilience test go further.

ISO 22301 as base

You need a BCMS. 22301 gives you the shape.

Operational resilience additions

Impact tolerances for important business services, mapping of resources supporting each service, severe-but-plausible scenario testing.

DORA specifics

For EU financial entities, DORA adds prescriptive testing (including TLPT), reporting timelines and third-party regime.

A shared programme

The overlap is 70%+. Run one programme, tag artefacts to multiple frameworks, evidence once.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Supplier and third-party dependencies in ISO 22301

Your continuity is only as good as your suppliers'. Assess and rehearse the dependencies.

Identification

The BIA lists supplier dependencies for each activity. Rank by criticality.

Assessment

Critical suppliers should have their own BCMS or equivalent. Ask for evidence — 22301 certificate, BC test summary, exit plan.

Contract terms

Reciprocal notification obligations, cooperation in exercises, exit clauses. Not boilerplate — negotiated.

Substitutability

Critical suppliers you can't substitute in RTO time are a governance issue. Escalate to executive/board.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Management review of the BCMS

22301 requires management review at planned intervals. It's a real meeting, not a governance ritual.

Inputs

Status of actions from prior reviews, changes in external and internal issues, exercise findings, non-conformities, opportunities for improvement, resource needs.

Outputs

Decisions and actions on continual improvement of the BCMS and any need for changes.

Frequency

Typically annual; often quarterly for regulated organisations. Documented minutes.

Escalation

Sits within wider ISO 27001 / 9001 / 42001 management review where possible. Fewer meetings, coherent decisions.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Setting the scope of your BCMS

Scope decisions echo through every plan and exercise. Get them wrong and the BCMS bites your worst-case scenario.

Products and services in scope

Which lines of business the BCMS covers. Excluded scope must be defensible.

Locations and legal entities

Every site and entity that hosts in-scope activities.

Interested parties

Customers, regulators, employees, suppliers, insurers. Each has expectations the BCMS should acknowledge.

Change management

New product line, new location, acquisition = scope review. Not annual — event-driven.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Crisis communications: the plan you hope you never need

22301 wants documented, tested crisis communications. In an actual event, this is what customers and press remember.

Audiences

Employees, customers, regulators, suppliers, media, shareholders. Different messages, different channels.

Pre-drafted templates

Templates for common scenarios accelerate response. Legal review during peace, not during crisis.

Authority to communicate

Named individuals authorised to speak publicly. Escalation path documented.

Exercises

Communications rehearsals are separate from technical DR exercises. Both matter.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Getting ISO 22301 certified: a realistic timeline

9–15 months from zero for a mid-sized organisation. Faster if you have ISO 27001 already.

Months 1–3

Scope, BIA, risk assessment, stakeholder engagement. Executive sponsor confirmed.

Months 4–8

Plans developed, tested, adjusted. Documentation catalogue built. Exercises delivered.

Months 9–12

Internal audit, management review, corrective actions. Certification body Stage 1 audit.

Months 12–15

Stage 2 audit, findings closed, certificate issued. Surveillance audits annually.

How ISO-STANDARD.app helps with ISO 22301

Inside the workspace, this topic maps to concrete artefacts: pre-loaded ISO 22301 controls with crosswalks to ISO 27001, Evidence Vault items with signed timestamps, policy templates with attestation tracking, and a Trust Center page you can share with buyers on demand. You don't have to build a compliance system from scratch — you configure one that already knows the ISO 22301 shape.

Ready to evidence ISO 22301?

Load the pre-mapped controls, capture evidence continuously, and publish your ISO 22301 posture to buyers on demand.

Prefer a conversation? Email hello@iso-standard.app — a practitioner responds within one business day.

AI-enabled — privacy-respecting

AI does the drafting. You keep the control — and the data.

How we handle data →
  • AI that assists — not replaces

    Assisted drafting for policies, risks, controls and buyer questionnaires. Every AI suggestion is reviewed and approved by you before it lands in the record.

  • Opt-in, workspace-scoped

    AI features run only when you invoke them, only against the workspace you're in. We never mine your data to answer someone else's prompt.

  • Your data stays yours

    Prompts routed via the Lovable AI Gateway to model providers whose API terms exclude your content from model training. Nothing is sold or shared for advertising.

  • Isolated by design

    Row-level security enforces workspace boundaries at the database. MFA, SSO, audit logs and least-privilege roles govern who sees what.

We never sell personal information, never share it for advertising, and never use your workspace content to train third-party models. Full sub-processor list and Acceptable Use Policy on the Trust page.

MM
Michael McCarroll
Founder · 25+ years
IT governance · Information security · AI
Why this platform exists

Enterprise-grade governance — built for the SMEs and consultants enterprise GRC forgets.

I've spent 25 years in corporate governance — aligning technology, controls and compliance with what the business is actually trying to do. Time and again, the same pattern: the organisations that win new clients aren't the ones with the biggest GRC budget. They're the ones who can demonstrate trust on demand. This platform is the tool I wanted for the SMEs and consultants I've worked with — institutional-grade governance without an institutional price tag, built on the way audits and buyer reviews actually happen.