Governance and risk
ISO 22301:2019
Business continuity management systems
ISO 22301 sets out requirements for a business continuity management system.
A certified organisation understands which of its activities matter most and how quickly they must be restored after a disruption, has strategies and plans to protect and recover them, and tests those plans regularly. The aim is to keep delivering products and services at an acceptable level when something goes wrong.
Who it suits
Organisations whose customers depend on uninterrupted service, such as financial services, IT and cloud providers, outsourcers, logistics, utilities, telecommunications, healthcare and public services, and suppliers that are asked to show resilience in contracts or tenders.
What certification involves
ISAO, or a certification body accredited for ISO 22301, audits the system in two stages: first the scope, the business impact analysis, the risk assessment and readiness; then whether continuity strategies, plans and procedures work in practice. Auditors look for evidence of exercises and tests, and of how their results led to improvements. The certificate states the products, services and sites covered. Certification does not mean an organisation will never be disrupted; it shows that it has prepared, tested and reviewed its response. Certificates are normally valid for three years, with surveillance audits at least once a year and a recertification audit before expiry. ISAO carries out this certification itself, and also accredits certification bodies to do it. Every certificate ISAO issues, and every certificate issued under ISAO accreditation, is recorded on the public register.
Key themes
- A business impact analysis that sets recovery priorities and timeframes
- Assessing the risk of disruption to prioritised activities
- Continuity strategies and the resources they need: people, premises, technology, information and suppliers
- Incident response structures and business continuity plans
- A programme of exercises that tests plans and builds confidence in them
- Evaluating continuity capability and improving it
Edition
- Current edition
- ISO 22301:2019
ISO 22301:2019, the second edition, was published in October 2019 and replaced ISO 22301:2012. The revision did not add requirements; it made them clearer and reorganised them, so that the business continuity requirements now sit together in the clause on operation. An amendment published in February 2024 asks the organisation to consider whether climate change matters to it when it reviews its context, and adds a note that interested parties may have expectations about climate change. ISO has a revision of the standard in progress. Until a new edition is published, ISO 22301:2019 remains the edition that certificates refer to.
Check a certificate for ISO 22301:2019
- Enter the certificate number or verification code at Verify a certificate, or scan the QR code on the certificate. The record shows the certificate's status today, for example valid, suspended, withdrawn or expired.
- Compare the organisation name, scope and sites on the record with the copy you were given. Check that the products, services and sites you depend on are within the stated scope.
- Check who issued the certificate, as named on the record. Where a certification body accredited by ISAO issued it, the record shows the status of that accreditation and its accreditation number, and says so if the accreditation did not cover ISO 22301:2019 when the certificate was issued.
- If the certificate is not on the register, ISAO cannot confirm it: it may have been issued under another accreditation, or a detail may be wrong. Ask the issuing body, and report a concern if something does not look right.
Related standards
This is ISAO’s own summary, not the text of the standard. Copies of ISO 22301:2019 can be bought from ISO or from national standards bodies.
