A business continuity plan is judged by one test: can someone execute it under
pressure, without the person who wrote it? ISO 22301 clause 8.4 sets out what it must contain. This
guide covers the required structure, what separates a plan that works from a document that exists,
and how the exercise programme in clause 8.5 proves the difference.
What clause 8.4 requires a business continuity plan to contain
ISO 22301 requires plans and procedures that implement the strategies selected under clause 8.3.
Between them they must establish a response structure, cover warning and
communication, provide the business continuity plans themselves, and
address recovery. In practice that means each plan needs:
- Purpose and scope — which activities it covers, and its RTOs from the
business impact analysis. - Activation criteria and who can activate. Ambiguity here costs hours. Name roles
with authority to invoke, and define what triggers consideration. - Response structure — the teams, their roles and their decision authority,
including deputies. Every named role needs at least one alternate, because disruptions do not wait
for people to be available. - Immediate actions, in order, in the first minutes and hours.
- Communication — internal notification, and external communication to
customers, suppliers, regulators and where relevant the media, with pre-drafted holding statements. - Resource requirements to reach the minimum acceptable level of service, drawn
from the BIA. - Interdependencies with other plans and with suppliers.
- Recovery — how the activity returns to normal, which is the section most
often missing entirely. - Version, date, owner and distribution, including how the plan is reachable when
normal systems are down.
What separates a working business continuity plan from a document
Length is the clearest warning sign. A hundred-page business continuity plan will not be read
during an incident; it will be searched, badly, by someone under stress. Split the material: a short
executable plan with triggers, roles and first actions, and separate reference annexes for the detail.
If the first three pages do not tell a competent stranger what to do, the structure is wrong.
The second differentiator is assumption hygiene. Plans routinely assume the intranet is available,
the office is accessible, the IT manager is contactable, and the supplier will answer. Write the
assumptions down explicitly, then check each one against the scenarios the plan is meant to cover.
The ones that fail that check are your real gaps.
Plan templates written to be executed, not filed.
The ISO 22301 Toolkit includes incident response and business continuity plan templates, call trees, pre-drafted communication templates, the exercise programme and evaluation forms — all aligned to clause 8.4.
Exercising the business continuity plan
Clause 8.5 requires an exercise programme, and clause 8.6 requires evaluation of your continuity
documentation and capabilities. This is where certification is really won or lost, because it is the
only part of the standard that tests capability rather than paperwork.
Exercises escalate. A walkthrough confirms people know the plan exists and what
their role is. A tabletop runs a scenario in discussion and surfaces decision
ambiguity. A simulation exercises the response structure in something close to real
time. A live test actually fails over the capability. Most organisations plateau at
tabletop, and that is where the untested assumptions survive.
Two rules make exercises worth their cost. Exercise the shortest RTOs, because that is where
failure is expensive and where the plan is least likely to hold. And record what went
wrong: an exercise report concluding that everything went well is either untrue or describes
an exercise too easy to be informative. Auditors read these reports specifically for evidence that
the programme finds problems.
Keeping the business continuity plan current
Plans decay faster than any other management system document, because they depend on people,
contact details, suppliers and systems that all change. Tie review to events as well as dates: a
reorganisation, a new supplier for a prioritized activity, a system migration, or any change to the
BIA should trigger a plan review rather than waiting for the annual cycle. Verify contact details
more often than that — quarterly is not excessive, and stale contact lists are among the most
commonly raised findings because they take an auditor two minutes to test.
For the analysis the plan depends on, see our guide to the
business impact analysis; for the wider system,
ISO 22301 and organizational resilience.
References
- ISO 22301:2019 — the standard itself on iso.org.
- ISO 22313:2020 — guidance on the use of ISO 22301.
- ISO/TS 22317:2021 — guidelines for business impact analysis.
- ISO 22301:2019/Amd 1:2024 — the climate action amendment.
More on ISO 22301 and business continuity
- ISO 22301 certification
- ISO 22301 implementation guide
- ISO 22301 mandatory documents
- business impact analysis
- business continuity plan — you are here
- ISO 22301 internal audit checklist
All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.