ISO 22301:2019 — Business Continuity Management

The certifiable business continuity standard. Proof you have planned to keep operating through disruption, and increasingly asked for under APRA CPS 230.

ISO, through technical committee ISO/TC 292. Certification is issued by accredited certification bodies.

What it is

ISO 22301 is the international standard for a Business Continuity Management System. It governs how an organisation prepares to keep delivering its most important activities through disruption — outage, cyber incident, supplier failure, loss of premises or loss of key people — and how it recovers when delivery is interrupted.

The heart of the standard is the business impact analysis: identifying the activities the organisation cannot do without, how quickly each must be restored, and what each depends on to run. From that flow the recovery time and recovery point objectives, the continuity strategies, the plans, and the exercise programme that tests whether any of it works.

It follows the Annex SL structure across Clauses 4 to 10, so it integrates cleanly with ISO 27001 and ISO/IEC 20000-1.

One distinction worth holding onto: ISO 22301 is the certifiable management system for continuity of the business. ISO/IEC 27031 is guidance on the ICT readiness that underpins it. They are complementary, and only one of them is certifiable.

Who it's for

Organisations where an outage has consequences beyond inconvenience.

APRA-regulated entities and their material service providers

CPS 230 requires identification of critical operations, tolerance levels for disruption and tested continuity arrangements. Those obligations flow down the supply chain to providers, which is why suppliers to banks, insurers and superannuation funds are increasingly asked for continuity evidence.

Critical infrastructure operators

Under the SOCI Act, risk management programme obligations include hazards to continuity of service.

Organisations facing continuity questions in due diligence

Now a standard section in enterprise vendor assessment alongside security. "What happens if you go down" needs a better answer than an assurance.

Providers of services that cannot simply stop

Health, utilities, logistics, payments, emergency and essential services.

Why implement it

  • It directly supports CPS 230. The business impact analysis, tolerance levels and testing regime map closely onto what APRA expects around critical operations and tolerance for disruption.
  • It answers the continuity section of due diligence. A tested plan with exercise records is a materially better answer than an assurance that you would cope.
  • It forces the priority conversation in the calm. The business impact analysis makes the executive decide what gets recovered first, before the incident rather than during it.
  • It exposes single points of failure. Dependency mapping routinely surfaces a supplier, system or individual the business did not realise it could not operate without.
  • It shares the Annex SL spine with ISO 27001, so continuity risk sits in the same register as security risk.

How implementation works

Five to eight months typically, with the business impact analysis as the pacing item.

1. Gap assessment

Against existing continuity, disaster recovery and crisis documentation. Most organisations have fragments — a DR runbook here, a call tree there — that have never been reconciled.

2. Business impact analysis

The core of the engagement. Identify prioritised activities, set maximum tolerable periods of disruption, and map the people, systems, suppliers and facilities each depends on. This is where single points of failure surface.

3. Continuity risk assessment and strategy

Assess what could disrupt prioritised activities and select strategies proportionate to impact. Not every activity justifies a hot standby, and pretending otherwise produces a plan nobody funds.

4. Build the plans

Continuity plans, incident response and escalation structure, crisis communications, and recovery procedures written for someone acting under pressure rather than for an auditor.

5. Exercise the plans

Plans must be tested and results recorded. A plan that has never been exercised is an assumption in a binder.

6. Internal audit and management review

7. Stage 1 and Stage 2 certification audit

How Soveriq helps

Soveriq runs the business impact analysis, sets recovery objectives against what your infrastructure can actually deliver, and facilitates the executive tabletop exercises — producing a post-exercise report that says where decision-making broke down rather than confirming everyone did well.

Where ISO 27001 is in scope, continuity risk enters the same register as security risk rather than sitting in a separate document nobody reads.

On internal audit. Where Soveriq has built your management system, we do not then audit it and present that as an independent internal audit. What we provide is readiness validation, labelled as such. Where an independent internal audit is needed after a Soveriq build, it is performed by someone independent of that build and disclosed to you in writing.

What we will not do. Soveriq does not issue certificates, is not a certification body, and does not promise a certification outcome.

What the engagement looks like

  • Module 01 — Gap analysis against existing continuity, disaster recovery and crisis documentation.
  • Module 02 — Build. Business impact analysis, continuity strategies, plans and crisis communications.
  • Module 03 — Internal audit, subject to the impartiality position above.
  • Module 04 — Audit representation through Stage 1 and Stage 2.
  • Module 05 — Continuous compliance, including the recurring exercise programme.

Price floors are published on the pricing page. Certification body fees are separate and paid directly to that body.

Common questions

How is this different from a disaster recovery plan?

A DR plan restores technology. ISO 22301 governs continuity of the business — which activities matter, how long they can be down, and what the organisation does while systems are unavailable. The technical layer beneath it is ISO/IEC 27031. Most organisations have the DR plan and not the rest.

Does CPS 230 require ISO 22301?

No. APRA does not mandate any particular standard. CPS 230 requires identified critical operations, tolerance levels for disruption and tested continuity arrangements, and a certified BCMS is a well-recognised way of evidencing those. The obligation is APRA's; the standard is a means of meeting it.

How often do plans need testing?

The standard requires a programme of exercises rather than a set frequency, proportionate to your risk. In practice an annual executive tabletop plus more frequent technical recovery tests is a defensible baseline.

How long does the business impact analysis take?

Three to four weeks of elapsed time, but it depends almost entirely on how quickly business owners can be assembled to make prioritisation decisions. It is the pacing item in nearly every engagement.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope