Secure Trust Accounting & Finances
ES WhatsApp
22301

ISO 22301:2019

Business Continuity Management System

What the organisation does when something stops.

Current edition: ISO 22301:2019.

What it is

What the standard covers

ISO 22301 establishes how an organisation identifies critical activities, sets recovery time objectives and prepares responses to disruption: technology failure, weather events, utility outages, loss of premises or key personnel. The starting point is the business impact analysis, which determines what is recovered first and with which resources.

Who it is for

  • Financial and fiduciary services
  • Data centres, BPO and technology services
  • Healthcare, logistics and essential services
  • Organisations with contractual continuity obligations

Problems it helps manage

  • Contingency plans written but never tested
  • No clarity on which process recovers first
  • Critical dependence on one supplier or a single site
  • Continuity requirements imposed by clients or regulators

Business benefits

  • Critical activities prioritised with defined recovery times
  • Plans validated through exercises and drills
  • Shorter downtime and lower associated loss
  • Continuity evidence for clients and regulators

Sectors

Where it applies

Financial servicesTechnology and data centresHealthcareLogistics and transportPublic sectorUtilities

Support

What the engagement includes

  • Documented initial gap analysis
  • Management system design
  • Complete, tailored documentation
  • Implementation support, on site or remote
  • Training for the key team
  • Internal audit and closure of findings
  • Readiness and support through the certification audit

Integration with other standards

This standard commonly integrates with: ISO/IEC 27001, ISO/IEC 20000-1, ISO 9001. An integrated system reduces duplicated documentation and audit time.

Stages

How the project runs

Gap analysis and planning

We review the real operation, not a questionnaire. We identify gaps against the standard, critical processes, existing evidence and regulatory risk.

Selecting the standard or combination

We define which standard answers the organisation's risk and objective. The choice is technical, not a matter of popularity.

Management system design

We structure processes, responsibilities, indicators and controls according to size, sector and applicable regulation.

Documentation development

We write policy, procedures, records and matrices tailored to the operation. No generic templates.

Guided implementation

We work with each process owner until the system is used day to day, not only stored in a folder.

Team training

We train the key team on the standard, on the system and on their role during the audit.

FAQ

Frequently asked questions — ISO 22301

Is it the same as an IT disaster recovery plan?
No. Technology recovery is one part. ISO 22301 covers people, premises, suppliers, crisis communication and continuity of client service.
How often are plans tested?
An exercise programme is defined by criticality; typically at least one documented test per year for each relevant scenario.
Can only part of the organisation be certified?
Yes. Scope is defined by processes, services or sites, provided it is coherent and auditable.

Next step

Every organisation is different. The right system starts with a gap analysis.

Write to us and we will arrange a strategy meeting: we review your current situation, define the right system, set scope and timelines and resolve technical and regulatory questions.

A certification done properly is not chased. It is built.

WhatsApp