The certifiable business continuity standard. Proof you have planned to keep operating through disruption, and increasingly asked for under APRA CPS 230.
ISO 22301 is the international standard for a Business Continuity Management System. It governs how an organisation prepares to keep delivering its most important activities through disruption — outage, cyber incident, supplier failure, loss of premises or loss of key people — and how it recovers when delivery is interrupted.
The heart of the standard is the business impact analysis: identifying the activities the organisation cannot do without, how quickly each must be restored, and what each depends on to run. From that flow the recovery time and recovery point objectives, the continuity strategies, the plans, and the exercise programme that tests whether any of it works.
It follows the Annex SL structure across Clauses 4 to 10, so it integrates cleanly with ISO 27001 and ISO/IEC 20000-1.
One distinction worth holding onto: ISO 22301 is the certifiable management system for continuity of the business. ISO/IEC 27031 is guidance on the ICT readiness that underpins it. They are complementary, and only one of them is certifiable.
Organisations where an outage has consequences beyond inconvenience.
CPS 230 requires identification of critical operations, tolerance levels for disruption and tested continuity arrangements. Those obligations flow down the supply chain to providers, which is why suppliers to banks, insurers and superannuation funds are increasingly asked for continuity evidence.
Under the SOCI Act, risk management programme obligations include hazards to continuity of service.
Now a standard section in enterprise vendor assessment alongside security. "What happens if you go down" needs a better answer than an assurance.
Health, utilities, logistics, payments, emergency and essential services.
Five to eight months typically, with the business impact analysis as the pacing item.
Against existing continuity, disaster recovery and crisis documentation. Most organisations have fragments — a DR runbook here, a call tree there — that have never been reconciled.
The core of the engagement. Identify prioritised activities, set maximum tolerable periods of disruption, and map the people, systems, suppliers and facilities each depends on. This is where single points of failure surface.
Assess what could disrupt prioritised activities and select strategies proportionate to impact. Not every activity justifies a hot standby, and pretending otherwise produces a plan nobody funds.
Continuity plans, incident response and escalation structure, crisis communications, and recovery procedures written for someone acting under pressure rather than for an auditor.
Plans must be tested and results recorded. A plan that has never been exercised is an assumption in a binder.
Soveriq runs the business impact analysis, sets recovery objectives against what your infrastructure can actually deliver, and facilitates the executive tabletop exercises — producing a post-exercise report that says where decision-making broke down rather than confirming everyone did well.
Where ISO 27001 is in scope, continuity risk enters the same register as security risk rather than sitting in a separate document nobody reads.
On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.
What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.
Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.
A DR plan restores technology. ISO 22301 governs continuity of the business — which activities matter, how long they can be down, and what the organisation does while systems are unavailable. The technical layer beneath it is ISO/IEC 27031. Most organisations have the DR plan and not the rest.
No. APRA does not mandate any particular standard. CPS 230 requires identified critical operations, tolerance levels for disruption and tested continuity arrangements, and a certified BCMS is a well-recognised way of evidencing those. The obligation is APRA's; the standard is a means of meeting it.
The standard requires a programme of exercises rather than a set frequency, proportionate to your risk. In practice an annual executive tabletop plus more frequent technical recovery tests is a defensible baseline.
Three to four weeks of elapsed time, but it depends almost entirely on how quickly business owners can be assembled to make prioritisation decisions. It is the pacing item in nearly every engagement.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope