ISO 22301:2019 is a short standard — 21 pages of requirements — but it names a
specific set of ISO 22301 mandatory documents. This is the working list of ISO 22301 mandatory
documents, clause by clause, and the separate list of things no clause names that every
audit asks for anyway.
The ISO 22301 mandatory documents do not include a manual
The ISO 22301 mandatory documents do not include a business continuity manual. Clause 7.5 asks you to maintain the documented
information the standard specifies plus whatever else you determine is necessary for effectiveness.
Writing a manual that restates the clauses earns nothing at audit, because it evidences no activity.
The documents that earn something are the ones with your own analysis in them.
The ISO 22301 mandatory documents, by clause
- 4.1 — internal and external issues relevant to the BCMS, now explicitly
including climate change under the 2024 amendment. - 4.2 — interested parties and their relevant requirements, including legal
and regulatory requirements. - 4.3 — the scope of the business continuity management system, including
what is excluded and why. - 5.2 — the business continuity policy.
- 5.3 — roles, responsibilities and authorities.
- 6.2 — the business continuity objectives.
- 7.5 — the documented information the BCMS itself needs, controlled.
- 8.1 — operational planning and control, to the extent needed for
confidence that processes run as planned. - 8.2 — the business impact analysis and risk assessment:
the process, and its results. This is the substantive one. - 8.3 — the business continuity strategies and solutions selected, and the
resource requirements behind them. - 8.4 — the business continuity plans and procedures,
including the response structure, warning and communication arrangements, and recovery. - 8.5 — the exercise programme and the results of exercises.
- 8.6 — the results of evaluating business continuity documentation and
capabilities.
The records ISO 22301 requires you to retain
- 7.2 — evidence of competence.
- 9.1 — results of monitoring, measurement, analysis and evaluation.
- 9.2 — the internal audit programme and the audit results.
- 9.3 — the results of management review.
- 10 — nonconformities, the actions taken and their results, including the
results of corrective action.
Records are sampled far harder than the ISO 22301 mandatory documents themselves. An auditor will read your policy once and spend an
hour on your exercise results.
Every document on this list, already drafted.
The ISO 22301 Toolkit provides the scope, policy, BIA and risk assessment workbooks, strategy and solution records, plan templates, exercise programme and audit set in Word and Excel — cross-referenced to the clause each satisfies.
Beyond the ISO 22301 mandatory documents: what auditors still ask for
Beyond the ISO 22301 mandatory documents, a second tier exists that no clause names outright
and no audit skips. Dependency and
supplier maps supporting the BIA — the standard asks you to determine dependencies,
and a BIA that stops at internal processes cannot evidence that. Call trees and contact
lists, with a date showing they are current; an out-of-date contact list is one of the most
frequently raised minor findings, precisely because it is so easy to verify. Exercise
evaluation reports rather than just attendance. And evidence that plans were
distributed and are accessible during a disruption — a continuity plan stored only on
the file server that the plan assumes has failed is a finding waiting to happen.
How much detail the ISO 22301 mandatory documents need
Clause 7.5.1 settles the question: the extent of documented information can differ by organisation
size, complexity of processes, and competence of people. A thirty-person professional services firm
does not need what a hospital group needs. The test is whether someone competent could execute from
what is written, under stress, possibly at 3am, possibly without the person who wrote it.
That last point is the practical standard to write to. Continuity documents are the only management
system documents likely to be read by a stressed person in a hurry. Favour short plans with clear
triggers, roles and first actions over comprehensive prose. Keep the set of ISO 22301 mandatory
documents tight and current rather than voluminous, and see the
free ISO 22301 templates if you want the format first.
References
- ISO 22301:2019 — the standard itself on iso.org.
- ISO 22313:2020 — guidance on the use of ISO 22301.
- ISO/TS 22317:2021 — guidelines for business impact analysis.
- ISO 22301:2019/Amd 1:2024 — the climate action amendment.
More on ISO 22301 and business continuity
- ISO 22301 certification
- ISO 22301 implementation guide
- ISO 22301 mandatory documents — you are here
- business impact analysis
- business continuity plan
- ISO 22301 internal audit checklist
All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.