Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 22301 Internal Audit Checklist — guide from Governance Docs

ISO 22301 Internal Audit Checklist: Clause 4 to 10

An ISO 22301 internal audit is not optional: clause 9.2 requires internal audits at planned
intervals, and requires them before your certification audit rather than after it. This is a working ISO 22301 internal audit
checklist
by clause, together with how to build the programme itself — which is what
an external auditor examines first.

The ISO 22301 internal audit programme comes before the checklist

Clause 9.2 asks for an audit programme that takes account of the importance of the processes
concerned and the results of previous audits. Build the ISO 22301 internal audit programme from the
business impact analysis: the activities with the shortest recovery time objectives get audited more
often and in more depth than everything else. Record that reasoning, because a programme that cannot
explain its own frequencies is itself a finding.

Two further ISO 22301 internal audit requirements catch smaller organisations. Auditors must be objective and impartial, so
the person who wrote the continuity plans cannot audit them — train a colleague from another
function or buy in an auditor. And results must reach relevant management and feed into management
review under 9.3.

The ISO 22301 internal audit checklist by clause

Clause 4 — Context. Are internal and external issues current, including
climate change under the 2024 amendment? Are interested parties and their requirements recorded,
including legal and regulatory obligations? Is the scope documented, with exclusions justified, and
does it cover the products and services customers actually depend on?

Clause 5 — Leadership. Can top management describe the policy and their own
role in an invocation? Are roles, responsibilities and authorities documented, and do the named people
know they hold them? Test one: pick a name from the response structure and ask.

Clause 6 — Planning. Are risks and opportunities addressed with actions that
have owners? Are continuity objectives measurable and monitored? Under 6.3, were changes to the
management system planned rather than absorbed informally?

Clause 7 — Support. Competence against defined requirements for response
roles, not general awareness. Can staff state what they would do on invocation? Are plans accessible
when normal systems are unavailable — check this practically rather than by asking.

Clause 8 — Operation. The substance of the audit. Is the BIA current, and
was it validated by activity owners and senior management? Do the strategies selected under 8.3
actually meet the RTOs the BIA sets, with resources behind them? Do the plans under 8.4 contain
activation criteria, response structure, communication and recovery? Has the exercise programme under
8.5 run, and did clause 8.6 evaluation happen and change anything?

Clause 9 — Performance evaluation. What is actually monitored and measured,
and against what target? Does management review cover every required input and produce decisions with
owners and dates?

Clause 10 — Improvement. Take a nonconformity or an exercise finding: was
root cause reached, was the fix verified as effective, and did the BIA or the plans get updated as a
result?

Score yourself before an auditor does.

The ISO 22301 Assessment Tool walks every clause in Excel, scores current maturity and outputs a weighted gap report — useful for the internal audit programme and for management review evidence.

See the ISO 22301 Assessment Tool →

Findings that recur at almost every ISO 22301 internal audit

  • Strategy does not meet the BIA. The most consequential finding in the standard,
    and the easiest to test: compare one RTO against the capability that supports it.
  • Exercises with no evaluation report, or reports that record no problems.
  • Contact lists and call trees out of date.
  • Plans not accessible during the scenarios they cover, typically stored on the
    system the plan assumes has failed.
  • BIA never refreshed after a reorganisation or a new supplier.
  • Corrective actions closed on completion rather than verified effectiveness.
  • Recovery sections missing — plans that get you into disruption but not out
    of it.

Getting value from an ISO 22301 internal audit, not a paper exercise

The most informative audit of this standard is a trace, not a clause march. Take a single
prioritized activity and follow it end to end: its BIA entry and RTO, the strategy chosen to meet it,
the resources committed, the plan that invokes it, the last exercise that tested it, and the findings
that exercise produced. One trace tests clauses 8.2 through 8.6 plus 7.2 and 10, and it surfaces the
strategy-versus-BIA mismatch that a checklist read clause by clause will miss entirely. Pair it with
an unannounced check of one contact list and you have a genuinely useful
ISO 22301 internal audit.

References

More on ISO 22301 and business continuity

All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.