Policy Register

ISO 22301:2019

The register cites 17 of its 57 clauses, on 15 policy types. Rendered when the buyer ticks "ISO 22301:2019".

Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim. Open the standard on the compliance platform. What it expects of a policy set: the ISO 22301 regime page.

Clauses cited

17 of 57
ISO 22301 4.2.2 Legal and regulatory requirements

Run and maintain a process that finds, obtains access to and assesses the legal and regulatory requirements applying to the continuity of the organization's products, services, activities and resources, ensure those requirements are reflected in how the BCMS is built and run, and keep that information documented and current.

Evidence an auditor accepts: Documented process for identifying and assessing continuity related legal and regulatory requirements; current obligations register with source, applicability and assessment date; traceability from an obligation to the BCMS element that satisfies it
Common gap: Obligations register held by legal and never reconciled against the BCMS
Source: ISO 22301:2019
ISO 22301 5.2.1 Establishing the business continuity policy

Top management must set a business continuity policy that suits the organization's purpose, gives a frame for setting continuity objectives, and commits the organization to satisfying applicable requirements and to continually improving the BCMS.

Evidence an auditor accepts: Approved policy carrying an explicit commitment to applicable requirements and to improvement; approval record naming the top management body and the date; traceability from the policy to the continuity objectives set under it
Common gap: Generic policy text lifted from a template that says nothing about this organization's purpose
Source: ISO 22301:2019
ISO 22301 5.3 Roles, responsibilities and authorities

Top management must assign and communicate the responsibilities and authorities for the roles the BCMS depends on, and must specifically assign responsibility and authority for ensuring the BCMS conforms to the standard and for reporting BCMS performance back to top management.

Evidence an auditor accepts: Role descriptions or a responsibility matrix covering BCMS roles; named individual accountable for BCMS conformity; named reporting line and evidence of performance reporting to top management
Common gap: Roles assigned in a matrix that the holders have never seen
Source: ISO 22301:2019
ISO 22301 7.3 Awareness

People doing work under the organization's control must be aware of the business continuity policy, of how they contribute to BCMS effectiveness and what better continuity performance delivers, of the implications of not conforming, and of their own role and responsibilities before, during and after a disruption.

Evidence an auditor accepts: Awareness material covering all four required points; delivery records covering staff, contractors and new starters; a test of awareness, such as a spot check or survey, rather than delivery evidence alone
Common gap: Awareness content covering the policy only, silent on individual roles during a disruption
Source: ISO 22301:2019
ISO 22301 7.5.3 Control of documented information

Control the documented information the BCMS and the standard require so it is available and suitable for use where and when needed and adequately protected, addressing distribution, access, retrieval and use, storage and preservation including legibility, change control, and retention and disposition; documented information of external origin that the BCMS depends on must also be identified and controlled.

Evidence an auditor accepts: Access and distribution controls with evidence of enforcement; storage and preservation arrangements including offline or alternate site availability; version control history and retention and disposition schedule
Common gap: Plans stored only on the corporate network, so they are unavailable in the scenario they exist for
Source: ISO 22301:2019
ISO 22301 8.2.2 Business impact analysis

Use the impact analysis process to set continuity priorities and requirements: define the impact types and criteria relevant to the organization's context, identify the activities supporting delivery of products and services, assess impacts over time from disrupting those activities, fix the point at which non resumption becomes unacceptable, set prioritized time frames within that point for resuming activities at a specified minimum acceptable capacity, identify the prioritized activities, and determine the resources, dependencies and interdependencies they rely on including partners and suppliers.

Evidence an auditor accepts: Defined impact types and criteria approved for this organization; activity inventory mapped to products and services; impact over time analysis per activity
Common gap: Recovery time frames set by aspiration and never reconciled to the impact analysis that should produce them
Source: ISO 22301:2019
ISO 22301 8.2.3 Risk assessment

Implement and maintain a risk assessment process that identifies the risks of disruption to the organization's prioritized activities and the resources they require, analyses and evaluates those risks, and determines which of them require treatment.

Evidence an auditor accepts: Documented risk assessment process; risk register scoped to prioritized activities and their required resources; analysis and evaluation records with the criteria applied
Common gap: Risk register covering the enterprise generally rather than the prioritized activities specifically
Source: ISO 22301:2019
ISO 22301 8.4.1 General

Implement and maintain a response structure enabling timely warning and communication to relevant interested parties, with plans and procedures to manage the organization through a disruption and to activate continuity solutions, identified and documented from the output of the selected strategies and solutions, and with procedures that are specific about immediate steps, flexible to changing internal and external conditions, focused on the impact of incidents, effective at minimizing that impact, and explicit about roles and responsibilities.

Evidence an auditor accepts: Documented response structure; procedures stating immediate steps and the roles that take them; traceability from selected strategies and solutions to the documented plans
Common gap: Procedures written for one rehearsed scenario, brittle against anything else
Source: ISO 22301:2019
ISO 22301 8.4.2 Response structure

Implement and maintain a structure of one or more teams responsible for responding to disruptions, with roles, responsibilities and inter team relationships clearly stated, collectively competent to assess a disruption and its impact against pre defined thresholds justifying a formal response, activate the response and the continuity solutions, plan actions, set priorities with life safety first, monitor the disruption and the response, and communicate with interested parties, authorities and the media; each team must have identified personnel and alternates with the necessary responsibility, authority and competence, and documented procedures for activation, operation, coordination and communication.

Evidence an auditor accepts: Team structure chart with roles, responsibilities and inter team relationships; pre defined activation thresholds and the authority to invoke them; named team members and alternates with competence evidence
Common gap: Alternates named on paper but never included in an exercise
Source: ISO 22301:2019
ISO 22301 8.4.3 Warning and communication

Document and maintain procedures for communicating internally and externally with relevant interested parties covering what, when, with whom and how, for receiving, documenting and responding to communications including from national or regional risk advisory systems, for keeping the means of communication available during a disruption, for structured communication with emergency responders, for the organization's media response and communications strategy, and for recording the disruption, the actions taken and the decisions made; where applicable also alert parties potentially impacted by an actual or impending disruption and ensure coordination between multiple responding organizations, and exercise these procedures within the exercise programme.

Evidence an auditor accepts: Communication procedures covering internal, external, responder and media routes; verified alternate communication means that survive loss of primary systems; incident log template and completed logs from exercises or real events
Common gap: Communication cascade depends on the corporate email and telephony that the disruption removes
Source: ISO 22301:2019
ISO 22301 8.4.4 Business continuity plans

Document and maintain business continuity plans that guide teams through response and recovery, collectively containing the actions to continue or recover prioritized activities within predetermined time frames, the means of monitoring the disruption and the response, the pre defined thresholds and process for activating the response, procedures to deliver products and services at agreed capacity, and how the immediate consequences are managed with regard to individual welfare, prevention of further loss and environmental impact; each plan must state purpose, scope and objectives, the roles and responsibilities of the implementing team, the actions implementing the solutions, the supporting information needed to activate, operate, coordinate and communicate including activation criteria, internal and external interdependencies, resource requirements, reporting requirements and a stand down process, and must be usable and available at the time and place it is needed.

Evidence an auditor accepts: Plan set with each plan carrying every required element; activation criteria and thresholds stated in the plan itself; interdependency and resource sections reconciled to the BIA
Common gap: Plans that cover activation and response but have no stand down, so the organization never formally returns to normal
Source: ISO 22301:2019
ISO 22301 8.4.5 Recovery

Maintain documented processes to restore and return business activities from the temporary measures adopted during and after a disruption.

Evidence an auditor accepts: Documented restoration and return to normal processes; criteria for deciding that temporary measures can be withdrawn; evidence of use, from exercises or real events, including backlog clearance
Common gap: Recovery treated as implicit once the incident is closed, with no process behind it
Source: ISO 22301:2019
ISO 22301 8.5 Exercise programme

Implement and maintain a programme of exercising and testing that validates the effectiveness of the continuity strategies and solutions over time, running exercises and tests consistent with the continuity objectives, based on well planned scenarios with clearly defined aims, that build teamwork, competence, confidence and knowledge in those with response roles, that taken together over time validate the strategies and solutions, that produce formal post exercise reports with outcomes, recommendations and improvement actions, that are reviewed in the context of continual improvement, and that are held at planned intervals and when significant change occurs; act on the results to implement changes and improvements.

Evidence an auditor accepts: Exercise programme showing scope, scenario and interval coverage over time; exercise aims and objectives defined before each exercise; formal post exercise reports with outcomes, recommendations and actions
Common gap: The same comfortable scenario rehearsed annually, so rare failure modes are never stressed
Source: ISO 22301:2019
ISO 22301 8.6 Evaluation of business continuity documentation and capabilities

Evaluate whether the business impact analysis, risk assessment, strategies, solutions, plans and procedures remain suitable, adequate and effective, carrying out those evaluations through reviews, analysis, exercises, tests, post incident reports and performance evaluations, evaluating the continuity capabilities of relevant partners and suppliers, evaluating compliance with applicable legal and regulatory requirements and industry practice and conformity with the organization's own policy and objectives, and updating documentation and procedures promptly; conduct these evaluations at planned intervals, after an incident or activation, and when significant change occurs.

Evidence an auditor accepts: Evaluation records covering each element of the BCMS documentation set; partner and supplier continuity capability assessments with evidence behind them; compliance and conformity evaluation results
Common gap: Supplier continuity accepted on a self assessment questionnaire with nothing verified
Source: ISO 22301:2019
ISO 22301 9.2.2 Audit programme(s)

Plan, establish, implement and maintain an audit programme covering frequency, methods, responsibilities, planning requirements and reporting, weighted by the importance of the processes concerned and the results of previous audits; define the criteria and scope of each audit, select auditors and conduct audits so the process is objective and impartial, report results to relevant managers, retain documented evidence of the programme and the audit results, ensure necessary corrective actions are taken without undue delay to eliminate detected nonconformities and their causes, and ensure follow up actions verify what was done and report the verification results.

Evidence an auditor accepts: Documented audit programme with frequency, method and responsibility, risk weighted; per audit criteria and scope statements; auditor selection records evidencing objectivity and impartiality
Common gap: Programme frequency uniform across all processes, ignoring importance and prior audit results
Source: ISO 22301:2019
ISO 22301 9.3.2 Management review input

The review must consider the status of actions from previous reviews, changes in external and internal issues relevant to the BCMS, BCMS performance information including trends in nonconformities and corrective actions, monitoring and measurement results and audit results, feedback from interested parties, the need for changes including to policy and objectives, procedures and resources that could improve performance and effectiveness, information from the business impact analysis and risk assessment, the output of the evaluation of continuity documentation and capabilities, risks or issues not adequately addressed in any previous risk assessment, lessons learned and actions arising from near misses and disruptions, and opportunities for continual improvement.

Evidence an auditor accepts: Review pack demonstrably covering every required input; trend data rather than point in time figures for nonconformities, measurement and audits; near miss and disruption lessons presented with the actions arising
Common gap: Input pack covering audit results and little else
Source: ISO 22301:2019
ISO 22301 10.1 Nonconformity and corrective action

Determine opportunities for improvement and implement the actions needed to achieve the intended BCMS outcomes; when a nonconformity occurs, react to it and deal with its consequences, evaluate whether action is needed to eliminate the cause by reviewing the nonconformity, determining its causes and checking whether similar ones exist or could occur, implement whatever action is needed, review the effectiveness of the corrective action, and change the BCMS if necessary, with corrective action proportionate to the effects encountered and documented evidence retained of the nature of the nonconformities, the actions taken and the results.

Evidence an auditor accepts: Nonconformity register with source, description and immediate correction; root cause analysis records; extent of condition check for similar nonconformities elsewhere
Common gap: Correction recorded as corrective action, with the cause never examined
Source: ISO 22301:2019

See which clauses your list answers

Paste the list and every document names the clauses behind it, filtered to the regimes that apply to you. Eight documents free, no account.

Build a register