
The 2015 revision of ISO 9001 introduced risk-based thinking into Clause 6.1, and sector-specific standards such as AS9100 went further by addressing operational risk in Clause 8.1.1. Once identified, a risk may be treated, accepted, or used as an opportunity for improvement. What these standards do not fully address, however, is how an organization will continue operating when a risk becomes a disruptive event.
That is the territory of business continuity. A cyberattack locks employees out of critical systems. A supplier failure halts production. A storm closes a facility. A key utility is lost, or a public-health emergency depletes the available workforce, as COVID-19 demonstrated on a global scale. The trigger may vary, but the leadership question remains the same, can the organization continue delivering its most important products and services at an acceptable, predefined capacity?
Resilience is not the ability to predict every disruption. It is the discipline of deciding—before pressure arrives—what must continue, how quickly it must recover, what resources it will require, and who has the authority to act.
ISO 22301 provides a structured approach. The international standard specifies requirements for a business continuity management system (BCMS): a management framework for understanding the organization and its disruption-related risks, establishing continuity priorities, preparing response and recovery arrangements, exercising those arrangements, evaluating performance, and continually improving capability.
Its value is not found in a binder on a shelf or a certificate on a wall. Its value lies in a practiced capability that helps people make sound decisions when normal assumptions no longer hold.
Continuity Begins Before the Incident. Many organizations begin with a plan template containing contact lists, emergency numbers, alternate locations, and recovery checklists. Those items may be useful, but beginning with the document reverses the logic.
A sound continuity program first establishes the organization’s context, the needs and expectations of relevant interested parties, the BCMS scope, leadership intent, responsibilities, and measurable continuity objectives. It then analyzes what the organization does, what its activities depend on, and what the consequences would be if those activities stopped. These foundations align with ISO 22301 Clauses 4.1–4.3, 5.1–5.3, and 6.2.
Organizations should also account for ISO 22301:2019/Amd 1:2024. The amendment adds an explicit requirement in Clause 4.1 to determine whether climate change is a relevant issue and adds a note to Clause 4.2 recognizing that interested parties may have climate-related requirements.
Business continuity is related to, but distinct from, other response disciplines:
- Emergency response protects life, property, and the environment during the immediate event.
- Crisis management coordinates strategic decisions, leadership, and communications.
- IT disaster recovery restores technology and data.
- Business continuity connects these disciplines to the continued delivery of prioritized products and services.
ISO 22301 helps align these elements within one managed system and, because it follows ISO’s harmonized management-system structure, it can be integrated with other management systems.
A Practical Path from Risk Assessment to Recovery. The following sequence turns business continuity from a broad aspiration into an operating capability.
Establish scope, governance, and decision rights
Define which sites, services, legal entities, technologies, and third parties fall within the BCMS scope. Appoint an accountable executive, assign process owners, and clarify who may declare an incident, activate a plan, authorize emergency expenditure, communicate with stakeholders, or accept temporary operating risk.
Ambiguity in these decisions consumes precious time during a disruption, and, in a severe event, may threaten the organization’s survival. Relevant requirements appear in Clauses 4.3, 5.1, 5.3, and 8.4.2.
Assess disruption risks
Identify plausible sources of interruption and evaluate their likelihood and consequences. These may include cyber events, utility loss, fire, severe weather, equipment failure, transportation interruption, labor shortages, civil disturbance, and the loss of critical suppliers or data.
The purpose is not to develop a separate plan for every imagined scenario. It is to understand vulnerabilities and select measures that reduce the likelihood or impact of disruption. ISO 22301 addresses the assessment of risks of disruption to prioritized activities in Clause 8.2.3. This should not be confused with Clause 6.1, which concerns risks and opportunities affecting whether the BCMS itself achieves its intended outcomes.
Conduct the business impact analysis
The risk assessment asks, “What could happen?” The business impact analysis (BIA) asks, “What happens to the organization as time passes after an activity stops?”
The BIA establishes recovery priorities and provides the evidence needed to define continuity strategies, resource requirements, and recovery objectives. ISO 22301 addresses the BIA in Clause 8.2.2.
Select continuity strategies and solutions
Choose proportionate ways to protect, continue, or restore prioritized activities. Options may include cross-trained personnel, remote-working capability, alternate facilities, redundant utilities, backup communications, diversified suppliers, emergency inventory, manual workarounds, resilient cloud architecture, and tested data recovery.
A strategy is credible only when its people, capacity, cost, and activation time are consistent with the BIA. ISO 22301 addresses business continuity strategies and solutions, associated resource requirements, and implementation in Clauses 8.3.1–8.3.5.
Develop response and recovery plans
Translate strategy into action. Plans should define activation criteria, initial actions, roles, escalation paths, communications, dependencies, workarounds, resource requirements, recovery steps, and stand-down arrangements.
Make plans usable under stress: concise, role-based, accessible when primary systems are unavailable, and clear about what must occur during the first hour, the first day, and the subsequent recovery period. These matters are addressed principally in Clauses 8.4.1–8.4.5.
The BIA: Identifying What Cannot Be Allowed to Fail. Not every process is equally urgent. Labeling everything “critical” leaves leaders with no meaningful priority. The BIA creates a time-based view of impact. It examines how disruption may affect life and safety, customers, revenue, contractual obligations, regulatory compliance, reputation, cash flow, and other operations. It also reveals the chain of dependencies supporting each activity: people, information, applications, facilities, equipment, utilities, logistics, and external providers.
A useful BIA produces decisions, not merely scores. For each prioritized activity, the organization should determine the time within which impacts would become unacceptable, the prioritized time frame for resuming the activity, the minimum acceptable capacity during recovery, and the resources and dependencies required over time. Where information and communications technology are involved, data-loss and restoration targets should also be aligned with business needs.
The following table summarizes the decisions a BIA should support:
| Decision area | Question for the organization | What it drives |
| Priority | Which activities must resume first? | Recovery sequence |
| Time objective | When would the impacts of interruption become unacceptable, and by when must the activity resume? | Recovery design and investment |
| Minimum capacity | What level of service is acceptable initially? | Staffing, sites, systems, and workarounds |
| Dependencies | What must be available for the activity to operate? | Supplier, technology, facility, utility, and data controls |
These targets must be reconciled across departments. One function’s recovery may depend on another function that has assigned itself a lower priority. The BIA should be challenged, approved, and reviewed when products, technologies, suppliers, locations, or operating models change. It is not a one-time questionnaire owned by the continuity coordinator; it is a management decision about what the organization is prepared to sustain. Clause 8.6 requires the organization to evaluate the suitability, adequacy, and effectiveness of its business impact analysis, risk assessment, strategies, solutions, plans, and procedures.
Designing a Response People Can Actually Use. A continuity plan must work amid incomplete information, unavailable colleagues, and competing priorities. Effective plans therefore emphasize decisions and interfaces. They identify the incident leadership structure, primary and alternate role holders, communication channels, escalation criteria, and the point at which a local response becomes an enterprise-level crisis.
Plans must also address stakeholder communication. Employees need instructions. Customers need honest service expectations. Regulators may require notification. Suppliers need revised priorities, and leadership needs a consistent operating picture. Preapproved message frameworks can save time, but facts must be verified before release. Speed matters; credibility matters more. ISO 22301 addresses warning and communication in Clause 8.4.3, supported by the broader communication requirements in Clause 7.4.
Continuity arrangements must account for their weakest dependencies. An alternate site is ineffective if access credentials, specialized equipment, or key records remain at the affected location. Remote work is not a recovery strategy if the identity platform is the failed system. A backup is not a recovery capability until data have been restored within the required time and shown to be usable. Plans also require appropriate control as documented information under Clause 7.5. Accessibility, protection, version control, distribution, retention, and availability during a disruption all matter.
Exercising the Plan and Proving the Capability. Documentation creates potential capability; exercises provide evidence. ISO 22301 Clause 8.5 requires an exercise program to validate business continuity strategies and solutions over time. Clause 8.6 requires evaluation of the continuing suitability, adequacy, and effectiveness of the organization’s continuity arrangements.
A mature exercise program progresses from simple checks to realistic, cross-functional tests:
- Walkthroughs and checklist reviews confirm that roles, contact information, resources, and procedures remain accurate.
- Tabletop exercises present an evolving scenario and require leaders to make decisions, communicate, and resolve competing priorities.
- Functional exercises activate selected capabilities, such as emergency notification, remote operations, supplier substitution, or restoration from backup.
- Full or integrated exercises test multiple teams and dependencies together under realistic time pressure while controlling safety and operational risk.
An exercise is not successful merely because participants completed the script. It succeeds when the organization learns. Observers should record decisions, elapsed times, assumptions, bottlenecks, communication failures, and gaps between stated and actual capability. Corrective actions need owners, due dates, and verification of effectiveness. Repeating the same unresolved finding in the next exercise signals a weakness in the management system, not merely in the plan. Corrective action and continual improvement are addressed in Clauses 10.1 and 10.2.
The exercise schedule should be risk-based. High-impact activities and fragile dependencies deserve greater frequency and realism. Exercises should also follow material changes, significant incidents, major technology migrations, acquisitions, facility moves, or supplier changes. Where a live test would create unacceptable risk, controlled simulations and component tests can provide evidence without exposing the organization unnecessarily.
Keeping the BCMS Alive. People change roles. Suppliers consolidate. Applications migrate. Inventories shrink. Workarounds become obsolete. Sustained readiness therefore depends on monitoring and measurement, internal audit, management review, corrective action, and continual improvement—the disciplines covered by Clauses 9.1–9.3 and 10.1–10.2.
Useful performance measures may include:
- completion of scheduled exercises;
- achievement of recovery objectives;
- overdue corrective actions;
- supplier continuity assurance;
- currency of plans and contact information;
- training and awareness coverage; and
- trends identified through incidents, exercises, and near misses.
Leadership review should go beyond asking whether documents are current. It should examine whether continuity objectives remain aligned with organizational strategy, whether resources match exposure, whether risk acceptance is explicit, and whether exercises demonstrate the promised capability. Internal audits should likewise evaluate effectiveness—not simply whether a procedure exists, but whether it is understood, implemented, exercised, and improved.
The Role of Lead Auditor Training. Sustained conformity with ISO 22301 requires long-term ownership by people who can see the BCMS as a connected system. A capable lead auditor follows the evidence from leadership commitments to the BIA, from recovery objectives to continuity solutions, from exercise results to corrective action, and from management review back to investment decisions. This line of sight helps distinguish polished documentation from genuine resilience.
QMII’s ISO 22301 Lead Auditor Training is designed to develop the competence to assess a BCMS against ISO 22301, identify vulnerabilities and improvement opportunities, evaluate the effectiveness of plans and controls, and support continual improvement.
For organizations building internal capability, lead auditor training can strengthen three essential forms of ownership:
- Independent assurance: Auditors can test whether practice matches policy and whether recovery claims are supported by evidence.
- Cross-functional understanding: Trained personnel can examine the links among operations, technology, facilities, suppliers, communications, and leadership decisions.
- Improvement discipline: Audit findings can be framed around systemic causes and followed through to effective corrective action, rather than treated as a documentation clean-up exercise.
Training alone does not own the BCMS. Leadership and process owners do. Trained auditors, however, provide the challenge, structure, and feedback that help keep continuity integrated with everyday management. They enable the organization to ask uncomfortable questions before a real incident asks them under pressure.
Preparedness Is a Management Habit. No continuity program can eliminate uncertainty. What ISO 22301 can do is replace improvisation with informed priorities, rehearsed responsibilities, viable recovery options, and a repeatable cycle of learning.
The objective is not uninterrupted perfection. It is the ability to absorb disruption, protect essential commitments, recover within acceptable limits, and emerge better prepared for the next test. The best time to discover that a recovery objective is unrealistic, a supplier has no viable alternative, or a contact list is obsolete is before operations are at risk. Begin with the BIA. Build strategies from evidence. Turn them into usable plans. Exercise those plans honestly. Audit the system for effectiveness. Then improve it-again and again.
—
About the Author:
Inderjit (IJ) Arora, Ph.D., is the Chairman of QMII. He serves as a team leader for consulting, advising, auditing, and training regarding management systems. He has conducted many courses for the United States Coast Guard and is a popular speaker at several universities and forums on management systems. Arora is a Master Mariner who holds a Ph.D., a master’s degree, an MBA, and has a 35-year record of achievement in the military, mercantile marine, and civilian industry.





