Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Business Continuity Plan — guide from Governance Docs

Business Continuity Plan: What ISO 22301 Requires It to Contain

A business continuity plan is judged by one test: can someone execute it under
pressure, without the person who wrote it? ISO 22301 clause 8.4 sets out what it must contain. This
guide covers the required structure, what separates a plan that works from a document that exists,
and how the exercise programme in clause 8.5 proves the difference.

What clause 8.4 requires a business continuity plan to contain

ISO 22301 requires plans and procedures that implement the strategies selected under clause 8.3.
Between them they must establish a response structure, cover warning and
communication
, provide the business continuity plans themselves, and
address recovery. In practice that means each plan needs:

  • Purpose and scope — which activities it covers, and its RTOs from the
    business impact analysis.
  • Activation criteria and who can activate. Ambiguity here costs hours. Name roles
    with authority to invoke, and define what triggers consideration.
  • Response structure — the teams, their roles and their decision authority,
    including deputies. Every named role needs at least one alternate, because disruptions do not wait
    for people to be available.
  • Immediate actions, in order, in the first minutes and hours.
  • Communication — internal notification, and external communication to
    customers, suppliers, regulators and where relevant the media, with pre-drafted holding statements.
  • Resource requirements to reach the minimum acceptable level of service, drawn
    from the BIA.
  • Interdependencies with other plans and with suppliers.
  • Recovery — how the activity returns to normal, which is the section most
    often missing entirely.
  • Version, date, owner and distribution, including how the plan is reachable when
    normal systems are down.

What separates a working business continuity plan from a document

Length is the clearest warning sign. A hundred-page business continuity plan will not be read
during an incident; it will be searched, badly, by someone under stress. Split the material: a short
executable plan with triggers, roles and first actions, and separate reference annexes for the detail.
If the first three pages do not tell a competent stranger what to do, the structure is wrong.

The second differentiator is assumption hygiene. Plans routinely assume the intranet is available,
the office is accessible, the IT manager is contactable, and the supplier will answer. Write the
assumptions down explicitly, then check each one against the scenarios the plan is meant to cover.
The ones that fail that check are your real gaps.

Plan templates written to be executed, not filed.

The ISO 22301 Toolkit includes incident response and business continuity plan templates, call trees, pre-drafted communication templates, the exercise programme and evaluation forms — all aligned to clause 8.4.

Explore the ISO 22301 Toolkit →

Exercising the business continuity plan

Clause 8.5 requires an exercise programme, and clause 8.6 requires evaluation of your continuity
documentation and capabilities. This is where certification is really won or lost, because it is the
only part of the standard that tests capability rather than paperwork.

Exercises escalate. A walkthrough confirms people know the plan exists and what
their role is. A tabletop runs a scenario in discussion and surfaces decision
ambiguity. A simulation exercises the response structure in something close to real
time. A live test actually fails over the capability. Most organisations plateau at
tabletop, and that is where the untested assumptions survive.

Two rules make exercises worth their cost. Exercise the shortest RTOs, because that is where
failure is expensive and where the plan is least likely to hold. And record what went
wrong
: an exercise report concluding that everything went well is either untrue or describes
an exercise too easy to be informative. Auditors read these reports specifically for evidence that
the programme finds problems.

Keeping the business continuity plan current

Plans decay faster than any other management system document, because they depend on people,
contact details, suppliers and systems that all change. Tie review to events as well as dates: a
reorganisation, a new supplier for a prioritized activity, a system migration, or any change to the
BIA should trigger a plan review rather than waiting for the annual cycle. Verify contact details
more often than that — quarterly is not excessive, and stale contact lists are among the most
commonly raised findings because they take an auditor two minutes to test.

For the analysis the plan depends on, see our guide to the
business impact analysis; for the wider system,
ISO 22301 and organizational resilience.

References

More on ISO 22301 and business continuity

All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.