Ideal Additions Consulting & Training (IAC)

  • Home
  • About Us
  • Consulting
  • Training
  • Methodology
  • Impact
  • Insights & Articles
  • News
  • Contact Us
  • …  
    • Home
    • About Us
    • Consulting
    • Training
    • Methodology
    • Impact
    • Insights & Articles
    • News
    • Contact Us
WhatsApp

Ideal Additions Consulting & Training (IAC)

  • Home
  • About Us
  • Consulting
  • Training
  • Methodology
  • Impact
  • Insights & Articles
  • News
  • Contact Us
  • …  
    • Home
    • About Us
    • Consulting
    • Training
    • Methodology
    • Impact
    • Insights & Articles
    • News
    • Contact Us
WhatsApp

ISO 22301 and Business Continuity

Understanding ISO 22301

· InfoSec and Assets

How Does ISO 22301 Help Companies Maintain Business Continuity During Crises?

Understanding ISO 22301

An organization may operate normally for years, only to experience an event that changes its ability to deliver products or services within a matter of hours. This could include:

  • Failure of a critical technology system
  • Disruption of electricity or telecommunications
  • Loss of a critical supplier
  • Loss of access to a workplace
  • A security incident
  • A sudden shortage of personnel
  • A crisis affecting access to facilities or the supply chain

At that moment, the question is not simply:

How do we solve the problem?

The organization must also ask:

  • Which activities must not stop?
  • How long can each activity tolerate disruption?
  • What is the minimum acceptable level of service?
  • Who has the authority to activate the business continuity plan?
  • Which resources must be restored first?
  • How will the organization communicate with employees, customers, suppliers, and other stakeholders?

This is the area addressed by ISO 22301 for Business Continuity Management Systems.

The standard does not merely produce a standalone emergency plan that is stored in a file. It establishes a Business Continuity Management System (BCMS) that connects an understanding of the organization with disruption risks and impacts, continuity strategies, plans, responsibilities, training, exercises, performance evaluation, and continual improvement.

What Is ISO 22301?

As of 17 August 2026, the current published edition is:

ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements

An amendment related to climate-action changes was published in 2024. ISO currently lists the 2019 edition as published but “to be revised.”

A third edition is already under development as ISO/CD 22301. This project is intended eventually to replace the 2019 edition, but it has not yet become a published International Standard. ISO 22301:2019 therefore remains the applicable published edition.

An organization beginning implementation now should not wait for the new edition or treat the current draft as if it were already an enforceable requirement.

Does ISO 22301 “Guarantee” Business Continuity?

The professionally accurate statement is:

ISO 22301 improves an organization’s preparedness and its ability to continue and recover, but it does not guarantee that disruption or loss will never occur.

A crisis may exceed the expected scenario. An alternative supplier may fail, several events may occur simultaneously, or circumstances may develop in a way that was not included in the organization’s assumptions.

The value of the management system lies in helping leadership understand:

  • What must be protected first
  • How decisions will be made
  • Which alternatives are available
  • How organizational capability will be tested before an actual crisis occurs

ISO associates the standard with stronger organizational resilience, improved risk management, more systematic responses to disruption, and better recovery performance.

Business Continuity, Emergency Response, and Disaster Recovery

An organization should not reduce ISO 22301 to an evacuation plan or a technical recovery plan.

Emergency management focuses on responding safely and systematically to the immediate event, including activities such as evacuation and incident response.

Disaster Recovery (DR) generally focuses more specifically on restoring technology, systems, data, and digital infrastructure.

Business Continuity (BC) addresses the organization’s ability to continue delivering priority products and services during and after a disruption.

An emergency plan may operate during the first hour of an incident. A business continuity plan may remain active throughout the following days, while a disaster recovery plan works to restore the applications, infrastructure, and data required by priority operations.

In a mature organization, these levels complement one another rather than compete.

Do Not Begin by Writing a Business Continuity Plan

One of the most common mistakes occurs when management says:

“We need a Business Continuity Plan.”

The team then begins writing the plan immediately.

But how can an organization determine what must be restored first if it has not identified its critical activities?

How can it define alternative resources without understanding each activity’s dependence on people, premises, technology, information, and suppliers?

Business continuity must therefore begin with understanding the organization before writing the plan.

IAC’s methodology follows this logic. The ISO 22301 pathway begins with a Business Impact Analysis (BIA) to identify priority activities and recovery priorities, followed by an assessment of disruption scenarios and the development of response, recovery, and continuity plans.

Business Impact Analysis: The Core of Business Continuity

A Business Impact Analysis (BIA) answers a different question from a risk assessment.

It does not begin primarily by asking:

How likely is the incident to occur?

It asks:

What will happen to the organization if this activity stops, and how will the impact increase over time?

The organization may examine impacts such as:

  • Disruption of customer service
  • Inability to process transactions
  • Financial loss
  • Contractual or regulatory consequences
  • Reputational damage
  • Disruption of other activities that depend on the affected process

ISO publishes a specialist supporting reference, ISO/TS 22317:2021, which provides guidance for conducting a Business Impact Analysis as part of the ISO 22301 family of standards.

The purpose of a BIA is not to describe every activity as “critical.” If every activity is assigned the same degree of criticality, management will not know what to restore first when resources are limited.

From the BIA to Recovery Priorities

Once the impact analysis has been completed, management can begin defining operational and time-based recovery priorities.

One service may be able to remain unavailable for several days without causing severe consequences. Another activity may create a significant problem after only a few hours of disruption.

This introduces concepts such as the Recovery Time Objective (RTO): the targeted period within which an activity or required capability should be restored, according to the organization’s continuity needs.

The Recovery Point Objective (RPO) is particularly relevant when data and information recovery form part of the disruption scenario. It establishes the acceptable point to which data must be restored based on the needs of the affected activity.

IAC’s continuity analysis uses RTO and RPO according to context. Identical values should not be assigned automatically to every process and system.

A common problem arises when the technology department says:

“We can restore the system within four hours.”

Yet the business activity itself must be restored within one hour.

This creates a gap between the business requirement and the organization’s technical recovery capability.

One of the functions of the BCMS is to identify such gaps before a crisis occurs.

BIA and Risk Assessment Are Not the Same

A BIA asks:

If the activity is disrupted, what will the impact be, and how long can the organization tolerate the disruption?

A risk assessment helps the organization understand:

Which scenarios could cause the disruption, and what is the organization’s exposure to them?

For example, a service may be highly important according to the BIA but exposed to several different disruption scenarios, including:

  • Loss of premises
  • System failure
  • Supplier disruption
  • Unavailability of personnel

The continuity strategy must therefore consider both the impact that must be avoided and the disruption scenarios for which the organization should prepare.

This is why IAC’s ISO 22301 service combines the BIA with operational risk assessment and disruption-scenario analysis.

Do Not Build a Separate Plan for Every Possible Disaster

An organization does not necessarily need a separate document for every imaginable scenario.

In many cases, it is more practical to plan around the loss of resources or capabilities.

For example:

  • What will the organization do if it loses access to the building, regardless of whether the cause is fire, structural damage, or an external incident?
  • What will it do if the main system becomes unavailable?
  • What will it do if a critical supplier fails?
  • What will it do if a large proportion of employees become unavailable?

This approach can make continuity plans more flexible and usable when the actual crisis differs from the scenario originally anticipated.

Business Continuity Strategy: How Will the Organization Continue Operating?

After identifying its priorities, the organization must determine how it will maintain or recover them.

Depending on its circumstances, the continuity strategy may include:

  • Working from an alternative location
  • Remote-working arrangements
  • Temporary manual procedures
  • Backup systems
  • Greater supplier resilience
  • Alternative operational capabilities
  • Arrangements for restoring data, facilities, or other resources

The appropriate option must be based on the BIA, cost, risk exposure, and organizational capability. It should not be assumed that every organization needs a duplicate data center or a fully equipped alternative location.

In some cases, the cost of the alternative may exceed the loss that the organization is attempting to prevent.

Business continuity is therefore a risk-management and investment decision, not a competition to build the largest possible backup capability.

The Supply Chain Is Part of Business Continuity

An organization may be prepared internally yet remain unable to operate because of one supplier.

For every critical supplier, the organization should ask:

  • Is an alternative supplier available?
  • How long would it take to qualify and activate the alternative?
  • What safety stock is available?
  • Does the supplier depend on a single source?
  • What happens if transportation or communication with the supplier is disrupted?

The ISO 22301 family includes ISO/TS 22318:2021, which provides specialist guidance on supply-chain continuity management. It is intended for organizations that depend on the continued provision of resources and services and on their own ability to continue delivering products and services. The edition was confirmed in 2025 and remains current.

Business continuity that stops at the organization’s gate is not complete business continuity.

People Are Also a Critical Resource

An organization may have backup systems and an alternative site, but what happens if a critical activity depends on one employee who is the only person who knows how to perform it?

That employee becomes a human single point of failure.

The organization should therefore review:

  • Required competencies
  • Trained substitutes
  • Delegated authorities
  • Remote-working capability
  • Contact information
  • Responsibilities of response and recovery teams

A resilient organization does more than maintain data backups. It also reduces excessive dependence on one person, function, supplier, system, or location.

Developing the Business Continuity Plan

After completing the BIA, risk assessment, and continuity strategy, the Business Continuity Plan becomes meaningful.

A good plan must assist the team during a crisis. It should not be a lengthy document that requires an hour to understand.

It should explain clearly:

  • When the plan should be activated
  • Who has the authority to activate it
  • What the roles and responsibilities are
  • Which activities take priority
  • Which resources and alternatives are available
  • How communication and escalation will operate
  • How the organization will move to alternative operations
  • How it will return to normal operations

ISO publishes ISO/TS 22332:2021, which provides specialist guidance for developing and maintaining business continuity plans and procedures.

There is no single template that should be copied by every organization.

A hospital’s continuity plan will differ substantially from that of a factory, bank, software company, or educational institution.

Who Has the Authority to Activate the Plan?

This is a fundamental governance question.

During a crisis, the organization should not begin debating:

Should we declare a business continuity incident, and who has the authority to decide?

Escalation and activation levels should be defined in advance.

Different incident levels may be established, each with corresponding authorities. Alternates should also be appointed in case the primary decision-makers are unavailable.

IAC’s ISO 22301 scope includes defining roles, responsibilities, and emergency communication channels as part of the continuity system.

Crisis Communication Is More Than a Public Statement

Communication during a crisis is an operational process.

Depending on the nature of the incident, the organization may need to communicate with:

  • Employees
  • Customers
  • Suppliers
  • Management
  • Regulators
  • Partners
  • Other relevant stakeholders

The organization should determine in advance:

  • Who communicates?
  • With whom?
  • Through which channel?
  • Who approves the message?
  • What alternative will be used if the primary communication channel is unavailable?

Do not assume that email will remain available during a technology incident.

Do not assume that all contact details are still correct.

A contact list that has not been tested or updated for two years may be far less reliable than it appears.

An Untested Plan Is Only a Hypothesis

This is one of the most important principles of business continuity.

An organization can prepare an excellent plan on paper, but it cannot know how effective the plan will be until it is exercised and tested.

IAC’s ISO 22301 service includes readiness testing through exercises and simulations, documenting lessons learned, and developing improvement actions.

An organization may begin with a tabletop exercise in which the team discusses a defined scenario. It can then progress to more realistic tests according to its risks and implementation capability.

The purpose of an exercise is not to report:

“We completed it without any problems.”

If the exercise identifies weaknesses, it may have succeeded in performing its intended function.

What Should a Business Continuity Exercise Test?

An exercise may assess whether:

  • The team can access the plan
  • Contact details are accurate
  • Each participant understands their role
  • Alternative arrangements can be activated
  • Systems can be restored within the required timeframe
  • The alternative supplier is genuinely available
  • The team understands when and how to escalate decisions

The findings should then be translated into improvement and corrective actions.

An exercise that ends with group photographs but produces no corrective actions does not strengthen the BCMS.

The Difference Between Data Backup and Business Continuity

Maintaining backups is important, but it does not by itself establish business continuity.

Imagine that an organization has a complete copy of its data, but restoring that data takes three days while customers can tolerate only four hours of service disruption.

The backup exists.

The continuity capability remains insufficient.

Technical recovery capability must therefore be aligned with the business requirements identified through the BIA.

Restoration should also be tested in practice rather than relying solely on a message stating:

“Backup completed successfully.”

The Difference Between Risk Management and Business Continuity

ISO 31000 helps an organization establish a comprehensive framework for managing risk.

ISO 22301 focuses specifically on the organization’s ability to continue, respond, and recover when disruption occurs.

Risk management may identify the risk of a data-center failure and introduce controls to reduce its likelihood.

Business continuity also asks:

If the failure occurs despite those controls, how will the organization continue operating?

The two disciplines therefore complement one another.

ISO itself presents ISO 31000 alongside ISO 22301 among the standards associated with risk management and organizational resilience.

How Does ISO/IEC 27001 Relate to Business Continuity?

Organizations that depend heavily on technology and information have a clear connection between their BCMS and Information Security Management System.

ISO/IEC 27001 addresses information-security risks, while ISO 22301 takes a broader view of the organization’s ability to continue delivering products and services during disruption.

A cyberattack may cause the disruption.

The business continuity plan must still determine what the organization will do operationally if its systems become unavailable.

ISO 22301 can be integrated with other management-system standards, including ISO/IEC 27001 and ISO 9001, because its structure supports integration across management systems.

Business Continuity Is Not the Sole Responsibility of IT

This is one of the most widespread misconceptions.

The IT function can manage technical recovery, but it cannot independently determine:

  • Which business service has the highest priority
  • Which customer should be served first
  • Which activity can be performed manually
  • Which contractual obligation is most urgent
  • What minimum level of service is acceptable

These are business decisions.

The BCMS should therefore involve process owners, senior management, finance, human resources, procurement, technology, communications, and other relevant functions according to the organization’s context.

Business continuity should be owned by the business and supported by technology—not the other way around.

What Should the Organization Measure?

The success of a BCMS should not be measured by the number of plans written.

The organization may instead evaluate:

  • Whether recovery times were achieved during exercises
  • The percentage of exercise-related actions that were closed
  • The current status of continuity plans for priority activities
  • The readiness of alternative resources and suppliers
  • The accuracy of contact information
  • Internal audit findings
  • The effectiveness of response and recovery exercises

The actual indicators will vary according to the organization.

The essential principle is to measure continuity capability, not the volume of documentation.

Internal Audit and Management Review

ISO 22301 is a management-system standard. Its application does not end when the Business Continuity Plan has been written.

The BCMS must be monitored, reviewed, maintained, and continually improved.

During an internal audit, the organization might select a priority activity and ask:

  • Is its BIA current?
  • Is its RTO defined?
  • Are the required resources available?
  • Is the continuity plan aligned with the analysis?
  • When was the plan last exercised?
  • What weaknesses were identified?
  • Were the resulting actions closed?

Significant findings should then be presented during management review so that leadership can decide whether investment, corrective action, or system modification is required.

When Should the BCMS Be Updated?

The organization should not wait for its annual review if a significant change occurs.

Relevant parts of the BIA, strategies, and plans may need to be reviewed when the organization:

  • Launches a new service
  • Changes a critical technology system
  • Relocates to another site
  • Changes a critical supplier
  • Completes an organizational restructuring
  • Develops a new dependency on cloud services
  • Identifies a gap through an exercise or actual incident

Business continuity arrangements must evolve with the organization.

Is ISO 22301 Certifiable?

Yes. ISO 22301 is a requirements standard for a Business Continuity Management System. An organization may choose to undergo an assessment by an independent certification body.

However, ISO does not perform certification or issue certificates. Certification is provided by external certification bodies. ISO also distinguishes between a certification body and an accreditation body, which assesses the competence of the certification body.

Certification does not mean the organization will never experience disruption. It indicates that the management system has been assessed against the standard’s requirements within the defined certification scope.

How Can You Tell Whether the BCMS Has Become Operational?

The system has become practical when a process owner can say:

“This is my priority activity. This is the timeframe within which it must be recovered. These are its resources and dependencies. These are the available alternatives. This person has the authority to activate the plan. This is when we last tested it, and these are the gaps we are still addressing.”

If the answer is:

“The plan is held by the Quality or Risk Department,”

then business continuity has not yet been fully integrated into operations.

Common Business Continuity Mistakes

Common mistakes include:

  • Writing the plan before conducting a BIA
  • Classifying every activity as equally critical
  • Establishing RTOs without considering actual recovery capability
  • Assigning the entire system to the IT function
  • Failing to address supplier dependencies
  • Maintaining contact lists without reviewing or testing them
  • Assuming that backups alone demonstrate readiness
  • Failing to conduct realistic exercises
  • Conducting exercises without following up on the resulting actions

Another, more serious mistake is building the BCMS solely to obtain certification.

In that situation, the documentation may be ready for an audit, but the people expected to use it during a crisis may not understand it.

This conflicts directly with IAC’s position that standards should support performance and decision quality rather than serve merely as a route to certification.

A Practical ISO 22301 Implementation Pathway

The implementation project can be organized as one interconnected sequence:

Define the BCMS scope and organizational context → diagnose the current state → conduct the BIA → identify priority activities and recovery time requirements → assess disruption risks and scenarios → define continuity strategies and alternatives → develop continuity, recovery, and communication plans → define activation, escalation, roles, and responsibilities → train relevant teams → conduct exercises and tests → address identified gaps → conduct internal audits → perform management review → pursue continual improvement → undergo an independent external assessment if the organization chooses certification

This sequence transforms business continuity from a written plan into an organizational capability.

What Is IAC’s Role?

Ideal Additions Consulting & Training (IAC) provides ISO 22301 Business Continuity Management System consulting to strengthen organizational preparedness for crises and emergencies, support the continuity of priority activities, and reduce the effects of disruption on service delivery, reputation, and compliance.

The scope may include:

  • Conducting the Business Impact Analysis
  • Identifying priority activities and recovery priorities
  • Establishing RTO and RPO values according to context
  • Assessing disruption scenarios
  • Developing Business Continuity Plans and Disaster Recovery Plans
  • Defining activation mechanisms
  • Establishing emergency communication roles and responsibilities
  • Conducting readiness exercises and simulations
  • Documenting lessons learned
  • Supporting continual improvement
  • Connecting business continuity with governance and risk management

The engagement follows IAC’s overarching methodology:

Objective diagnosis → tailored design → phased implementation → internal capability building → impact measurement

The objective is not to produce a plan that is opened only during an audit. It is to develop continuity arrangements that can be activated, exercised, evaluated, and improved.

Frequently Asked Questions

What Is the Current Edition of ISO 22301?

As of 17 August 2026, ISO 22301:2019 remains the current published edition, together with Amendment 1:2024. A third edition is under development at the Committee Draft stage, but it has not yet replaced the 2019 edition.

What Is the Difference Between a BIA and a Risk Assessment?

A BIA examines the effects of activity disruption, how those effects develop over time, and the resulting recovery priorities. A risk assessment examines disruption scenarios, causes, and levels of exposure. Both are used to design an effective continuity strategy.

Is Data Backup Sufficient for ISO 22301?

No. Backup is one possible component of technical recovery. A BCMS also addresses activities, people, premises, suppliers, communications, resources, technology, response, recovery, performance evaluation, and continual improvement.

Is ISO 22301 Only for Large Companies?

No. The standard can be used by organizations of different sizes and types. The depth and complexity of implementation should be adapted to the organization’s context, risks, activities, and operational requirements.

Does ISO 22301 Prevent Crises?

No. It helps an organization prepare for disruption and respond and recover more systematically. No management system or certificate can guarantee that a crisis will not occur or that every service will remain uninterrupted.

Can ISO 22301 Be Integrated with ISO/IEC 27001 or ISO 9001?

Yes. ISO 22301 can be integrated with other ISO management systems. Integration can be particularly beneficial when an organization wants to align governance, risk management, documentation, internal audits, corrective actions, and management review.

Must the Business Continuity Plan Be Tested?

Yes. An effective BCMS requires exercises, tests, reviews, and improvement. IAC’s ISO 22301 service explicitly includes readiness testing, simulations, and documentation of lessons learned.

Conclusion

Business continuity does not begin only with the question:

“What disaster might occur?”

It begins with the more important question:

“What must the organization continue delivering if disruption occurs?”

The answer is then translated into:

Priority activities → recovery time requirements → resources and dependencies → disruption scenarios → continuity strategies and alternatives → activatable plans → roles and communication → tests and exercises → measurement and improvement

This is the value of ISO 22301: transforming continuity from a reaction during a crisis into an organizational capability that is designed, tested, and improved before it is needed.

To request an initial business continuity readiness diagnostic session, contact IAC to assess your priority activities, Business Impact Analysis, disruption scenarios, response and recovery plans, and the development pathway most appropriate for your organization.

Previous
ISO/IEC 27001 in Jordan: A Guide
Next
ISO 55001 for Real Estate Assets
 Return to site
Cookie Use
We use cookies to improve browsing experience, security, and data collection. By accepting, you agree to the use of cookies for advertising and analytics. You can change your cookie settings at any time. Learn More
Accept all
Settings
Decline All
Cookie Settings
These cookies enable core functionality such as security, network management, and accessibility. These cookies can’t be switched off.
These cookies help us better understand how visitors interact with our website and help us discover errors.
These cookies allow the website to remember choices you've made to provide enhanced functionality and personalization.
Save