ISO 22301:2019
The register cites 17 of its 57 clauses, on 15 policy types. Rendered when the buyer ticks "ISO 22301:2019".
Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the ISO 22301 regime page.
Clauses cited
17 of 57ISO 22301 4.2.2 Legal and regulatory requirementsRun and maintain a process that finds, obtains access to and assesses the legal and regulatory requirements applying to the continuity of the organization's products, services, activities and resources, ensure those requirements are reflected in how the BCMS is built and run, and keep that information documented and current.
Common gap: Obligations register held by legal and never reconciled against the BCMS
Source: ISO 22301:2019
ISO 22301 5.2.1 Establishing the business continuity policyTop management must set a business continuity policy that suits the organization's purpose, gives a frame for setting continuity objectives, and commits the organization to satisfying applicable requirements and to continually improving the BCMS.
Common gap: Generic policy text lifted from a template that says nothing about this organization's purpose
Source: ISO 22301:2019
ISO 22301 5.3 Roles, responsibilities and authoritiesTop management must assign and communicate the responsibilities and authorities for the roles the BCMS depends on, and must specifically assign responsibility and authority for ensuring the BCMS conforms to the standard and for reporting BCMS performance back to top management.
Common gap: Roles assigned in a matrix that the holders have never seen
Source: ISO 22301:2019
ISO 22301 7.3 AwarenessPeople doing work under the organization's control must be aware of the business continuity policy, of how they contribute to BCMS effectiveness and what better continuity performance delivers, of the implications of not conforming, and of their own role and responsibilities before, during and after a disruption.
Common gap: Awareness content covering the policy only, silent on individual roles during a disruption
Source: ISO 22301:2019
ISO 22301 7.5.3 Control of documented informationControl the documented information the BCMS and the standard require so it is available and suitable for use where and when needed and adequately protected, addressing distribution, access, retrieval and use, storage and preservation including legibility, change control, and retention and disposition; documented information of external origin that the BCMS depends on must also be identified and controlled.
Common gap: Plans stored only on the corporate network, so they are unavailable in the scenario they exist for
Source: ISO 22301:2019
ISO 22301 8.2.2 Business impact analysisUse the impact analysis process to set continuity priorities and requirements: define the impact types and criteria relevant to the organization's context, identify the activities supporting delivery of products and services, assess impacts over time from disrupting those activities, fix the point at which non resumption becomes unacceptable, set prioritized time frames within that point for resuming activities at a specified minimum acceptable capacity, identify the prioritized activities, and determine the resources, dependencies and interdependencies they rely on including partners and suppliers.
Common gap: Recovery time frames set by aspiration and never reconciled to the impact analysis that should produce them
Source: ISO 22301:2019
ISO 22301 8.2.3 Risk assessmentImplement and maintain a risk assessment process that identifies the risks of disruption to the organization's prioritized activities and the resources they require, analyses and evaluates those risks, and determines which of them require treatment.
Common gap: Risk register covering the enterprise generally rather than the prioritized activities specifically
Source: ISO 22301:2019
ISO 22301 8.4.1 GeneralImplement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source: ISO 22301:2019
ISO 22301 8.4.2 Response structureImplement and maintain a structure of one or more teams responsible for responding to disruptions, with roles, responsibilities and inter team relationships clearly stated, collectively competent to assess a disruption and its impact against pre defined thresholds justifying a formal response, activate the response and the continuity solutions, plan actions, set priorities with life safety first, monitor the disruption and the response, and communicate with interested parties, authorities and the media; each team must have identified personnel and alternates with the necessary responsibility, authority and competence, and documented procedures for activation, operation, coordination and communication.
Common gap: Alternates named on paper but never included in an exercise
Source: ISO 22301:2019
ISO 22301 8.4.3 Warning and communicationDocument and maintain procedures for communicating internally and externally with relevant interested parties covering what, when, with whom and how, for receiving, documenting and responding to communications including from national or regional risk advisory systems, for keeping the means of communication available during a disruption, for structured communication with emergency responders, for the organization's media response and communications strategy, and for recording the disruption, the actions taken and the decisions made; where applicable also alert parties potentially impacted by an actual or impending disruption and ensure coordination between multiple responding organizations, and exercise these procedures within the exercise programme.
Common gap: Communication cascade depends on the corporate email and telephony that the disruption removes
Source: ISO 22301:2019
ISO 22301 8.4.4 Business continuity plansDocument and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source: ISO 22301:2019
ISO 22301 8.4.5 RecoveryMaintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.
Common gap: Recovery treated as implicit once the incident is closed, with no process behind it
Source: ISO 22301:2019
ISO 22301 8.5 Exercise programmeImplement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.
Common gap: The same comfortable scenario rehearsed annually, so rare failure modes are never stressed
Source: ISO 22301:2019
ISO 22301 8.6 Evaluation of business continuity documentation and capabilitiesEvaluate whether the business impact analysis, risk assessment, strategies, solutions, plans and procedures remain suitable, adequate and effective, carrying out those evaluations through reviews, analysis, exercises, tests, post incident reports and performance evaluations, evaluating the continuity capabilities of relevant partners and suppliers, evaluating compliance with applicable legal and regulatory requirements and industry practice and conformity with the organization's own policy and objectives, and updating documentation and procedures promptly; conduct these evaluations at planned intervals, after an incident or activation, and when significant change occurs.
Common gap: Supplier continuity accepted on a self assessment questionnaire with nothing verified
Source: ISO 22301:2019
ISO 22301 9.2.2 Audit programme(s)Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and the results of previous audits; define the criteria and scope of each audit, select auditors and conduct audits so the process is objective and impartial, report results to relevant managers, retain documented evidence of the programme and the audit results, ensure necessary corrective actions are taken without undue delay to eliminate detected nonconformities and their causes, and ensure follow up actions verify what was done and report the verification results.
Common gap: Programme frequency uniform across all processes, ignoring importance and prior audit results
Source: ISO 22301:2019
ISO 22301 9.3.2 Management review inputThe review must consider the status of actions from previous reviews, changes in external and internal issues relevant to the BCMS, BCMS performance information including trends in nonconformities and corrective actions, monitoring and measurement results and audit results, feedback from interested parties, the need for changes including to policy and objectives, procedures and resources that could improve performance and effectiveness, information from the business impact analysis and risk assessment, the output of the evaluation of continuity documentation and capabilities, risks or issues not adequately addressed in any previous risk assessment, lessons learned and actions arising from near misses and disruptions, and opportunities for continual improvement.
Common gap: Input pack covering audit results and little else
Source: ISO 22301:2019
ISO 22301 10.1 Nonconformity and corrective actionDetermine opportunities for improvement and implement the actions needed to achieve the intended BCMS outcomes; when a nonconformity occurs, react to it and deal with its consequences, evaluate whether action is needed to eliminate the cause by reviewing the nonconformity, determining its causes and checking whether similar ones exist or could occur, implement whatever action is needed, review the effectiveness of the corrective action, and change the BCMS if necessary, with corrective action proportionate to the effects encountered and documented evidence retained of the nature of the nonconformities, the actions taken and the results.
Common gap: Correction recorded as corrective action, with the cause never examined
Source: ISO 22301:2019
See which clauses your list answers
Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.
Build a register