An ISO 22301 internal audit is not optional: clause 9.2 requires internal audits at planned
intervals, and requires them before your certification audit rather than after it. This is a working ISO 22301 internal audit
checklist by clause, together with how to build the programme itself — which is what
an external auditor examines first.
The ISO 22301 internal audit programme comes before the checklist
Clause 9.2 asks for an audit programme that takes account of the importance of the processes
concerned and the results of previous audits. Build the ISO 22301 internal audit programme from the
business impact analysis: the activities with the shortest recovery time objectives get audited more
often and in more depth than everything else. Record that reasoning, because a programme that cannot
explain its own frequencies is itself a finding.
Two further ISO 22301 internal audit requirements catch smaller organisations. Auditors must be objective and impartial, so
the person who wrote the continuity plans cannot audit them — train a colleague from another
function or buy in an auditor. And results must reach relevant management and feed into management
review under 9.3.
The ISO 22301 internal audit checklist by clause
Clause 4 — Context. Are internal and external issues current, including
climate change under the 2024 amendment? Are interested parties and their requirements recorded,
including legal and regulatory obligations? Is the scope documented, with exclusions justified, and
does it cover the products and services customers actually depend on?
Clause 5 — Leadership. Can top management describe the policy and their own
role in an invocation? Are roles, responsibilities and authorities documented, and do the named people
know they hold them? Test one: pick a name from the response structure and ask.
Clause 6 — Planning. Are risks and opportunities addressed with actions that
have owners? Are continuity objectives measurable and monitored? Under 6.3, were changes to the
management system planned rather than absorbed informally?
Clause 7 — Support. Competence against defined requirements for response
roles, not general awareness. Can staff state what they would do on invocation? Are plans accessible
when normal systems are unavailable — check this practically rather than by asking.
Clause 8 — Operation. The substance of the audit. Is the BIA current, and
was it validated by activity owners and senior management? Do the strategies selected under 8.3
actually meet the RTOs the BIA sets, with resources behind them? Do the plans under 8.4 contain
activation criteria, response structure, communication and recovery? Has the exercise programme under
8.5 run, and did clause 8.6 evaluation happen and change anything?
Clause 9 — Performance evaluation. What is actually monitored and measured,
and against what target? Does management review cover every required input and produce decisions with
owners and dates?
Clause 10 — Improvement. Take a nonconformity or an exercise finding: was
root cause reached, was the fix verified as effective, and did the BIA or the plans get updated as a
result?
Score yourself before an auditor does.
The ISO 22301 Assessment Tool walks every clause in Excel, scores current maturity and outputs a weighted gap report — useful for the internal audit programme and for management review evidence.
Findings that recur at almost every ISO 22301 internal audit
- Strategy does not meet the BIA. The most consequential finding in the standard,
and the easiest to test: compare one RTO against the capability that supports it. - Exercises with no evaluation report, or reports that record no problems.
- Contact lists and call trees out of date.
- Plans not accessible during the scenarios they cover, typically stored on the
system the plan assumes has failed. - BIA never refreshed after a reorganisation or a new supplier.
- Corrective actions closed on completion rather than verified effectiveness.
- Recovery sections missing — plans that get you into disruption but not out
of it.
Getting value from an ISO 22301 internal audit, not a paper exercise
The most informative audit of this standard is a trace, not a clause march. Take a single
prioritized activity and follow it end to end: its BIA entry and RTO, the strategy chosen to meet it,
the resources committed, the plan that invokes it, the last exercise that tested it, and the findings
that exercise produced. One trace tests clauses 8.2 through 8.6 plus 7.2 and 10, and it surfaces the
strategy-versus-BIA mismatch that a checklist read clause by clause will miss entirely. Pair it with
an unannounced check of one contact list and you have a genuinely useful
ISO 22301 internal audit.
References
- ISO 22301:2019 — the standard itself on iso.org.
- ISO 22313:2020 — guidance on the use of ISO 22301.
- ISO/TS 22317:2021 — guidelines for business impact analysis.
- ISO 22301:2019/Amd 1:2024 — the climate action amendment.
More on ISO 22301 and business continuity
- ISO 22301 certification
- ISO 22301 implementation guide
- ISO 22301 mandatory documents
- business impact analysis
- business continuity plan
- ISO 22301 internal audit checklist — you are here
All of these are covered by the ISO 22301 Toolkit. To score where you stand first, use the ISO 22301 Assessment Tool, or start with the free ISO 22301 templates.