Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 22301 readiness assessment explained

ISO 22301 Readiness Assessment: 6 Proven Checks Before the Audit

An ISO 22301 readiness assessment answers one question: if the certification body arrived next month, would the business continuity management system pass? It is narrower than a gap analysis, which compares the system against every requirement of ISO 22301:2019, and later — it assumes the BCMS has been built and has operated, and checks whether the evidence exists in the form a stage 1 and stage 2 auditor will test.

Six checks decide the answer for most organisations, because six clauses produce most first-audit findings: the business impact analysis and risk assessment, the strategies traced to them, the plans and procedures, the exercise programme, the internal audit and the management review. This guide sets out the six checks, what “ready” looks like for each, how stage 1 and stage 2 test them differently, how to score the assessment so the decision to book the audit is made on evidence, and the readiness errors that turn a stage 2 into a second visit.

ISO 22301 readiness assessment: six checks before the audit
8.2 BIA and risk assessment · 8.3 strategies traced to the BIA · 8.4 plans current and accessible · 8.5 exercise run and reported · 9.2 internal audit completed · 9.3 management review held — scored ready / partial / not ready.

ISO 22301 readiness assessment vs gap analysis vs self-assessment

The three are run at different times. A gap analysis is run before implementation, against all of clauses 4 to 10, to plan the work; our guide to the ISO 22301 gap analysis explains why clause 8.2 has to be weighted above the rest. A self-assessment scores every requirement with a reference to where it is met and can be run at any point; our guide to the ISO 22301 self-assessment covers the clause-by-clause version. A readiness assessment is run last, on an operating system, and concentrates on the requirements that fail audits — because an auditor does not test every clause equally and neither should the final check.

The six ISO 22301 readiness assessment checks

# Check Clause Ready looks like Common failure
1 BIA and risk assessment complete and current 8.2.2, 8.2.3 Every in-scope activity has impact over time, prioritised activities, RTO/RPO and dependencies, reviewed within the last year or on change; a risk assessment of disruption to prioritised activities BIA older than the last organisational change; dependencies stop at internal processes; RTOs set by IT rather than the business
2 Strategies and solutions traced to the BIA 8.3 Each continuity solution cites the BIA output that requires it; resource requirements determined and provided Solutions chosen before the BIA and retrofitted; requirements listed but unfunded
3 Plans and procedures current and usable 8.4 Response structure with named alternates; warning and communication arrangements; plans with triggers, roles and first actions; recovery procedures; all accessible when the primary site and systems are down Plans naming staff who have left; contact lists undated; the only copy on the file server the plan assumes has failed
4 Exercise programme run and reported 8.5 A programme; at least one exercise completed with a report, findings and actions; actions closed or scheduled Exercise planned but not held; attendance recorded, findings not; findings never re-tested
5 Internal audit completed 9.2 A programme covering all clauses and the scope; audit performed by someone independent of the area; findings raised and closed Audit scheduled for after certification; auditor audited own work; no nonconformities raised (auditors read that as a weak audit)
6 Management review held 9.3 Minutes covering the required inputs — audit results, exercise results, performance, nonconformities, changes, opportunities — with decisions and actions A management meeting with continuity on the agenda; no decisions recorded

Three checks — 4, 5 and 6 — are time-gated. They cannot be closed on paper the week before the audit; an exercise has to have run, an audit has to have been performed and a review has to have been held, each with a dated record. Discovering them late sets the certification date regardless of everything else. Our guide to the business continuity exercise covers the one most often missing.

How stage 1 and stage 2 test readiness

Stage What the auditor does What the ISO 22301 readiness assessment should confirm
Stage 1 (documentation and readiness review) Reviews documented information, scope, context, policy, objectives, BIA and risk assessment, the audit and review records; assesses site-specific conditions; decides whether stage 2 can proceed Every document in the mandatory list exists, is controlled and is consistent; the cycle records (exercise, audit, review) exist and are dated
Stage 2 (implementation audit) Tests that the BCMS is implemented and effective: interviews process owners about RTOs and plans, samples exercise findings and corrective actions, walks the response structure, checks supplier arrangements People can answer without the manual; findings have been closed; plans can be produced from an alternate location
Between stages Stage 1 findings are closed before stage 2 — the interval is set with the certification body Any check scored ‘partial’ has a dated close-out plan

Scoring the ISO 22301 readiness assessment

  1. Score each check ready, partial or not ready — never a percentage. Partial means the evidence exists but is dated, incomplete or unverified; not ready means the activity has not happened.
  2. Attach the evidence reference to every ready score: the document, the record, the date. A ready score without a reference is a not-ready score.
  3. Verify one item per check in the field. Ask a process owner their RTO; open the plan from a phone; read the last exercise report’s actions and check their status.
  4. Apply the rule: book stage 2 only when all six are ready, or when the partials are checks 1–3 with a close-out date before stage 1. Any not-ready among checks 4–6 means the date moves.
  5. Add the documentation sweep. The mandatory documents list is the stage 1 checklist; our guide to ISO 22301 mandatory documents gives it clause by clause.

Readiness errors that turn stage 2 into a second visit

  • Booking on the documentation. Stage 1 passes; stage 2 finds no one below the risk manager knows the plan.
  • The single exercise that proved nothing. A tabletop with no injects, no findings and no actions is read by the auditor as an untested system.
  • Corrective actions open at the audit. Internal audit and exercise findings with no closure evidence are the auditor’s easiest nonconformity.
  • Scope larger than the evidence. Sites or activities in the scope statement with no BIA rows or plans.
  • Suppliers in the BIA, absent from the strategy. Dependencies identified under 8.2 with nothing under 8.3 or 8.4 addressing their failure.

Frequently asked questions

What is an ISO 22301 readiness assessment?
A final check, run on an operating business continuity management system, of whether the evidence exists in the form a certification auditor will test — concentrated on the six clauses that produce most first-audit findings: 8.2, 8.3, 8.4, 8.5, 9.2 and 9.3.

When should we run it?
After the BCMS has completed one cycle — BIA, strategies, plans, at least one exercise, an internal audit and a management review — and before the certification body is booked. Typically two to three months before the intended stage 1.

Who should perform it?
Someone independent of the BCMS owner: an internal auditor from another function, or an external assessor. The value is in the field verification, which the owner cannot do objectively.

Can we pass with an exercise still planned?
Not stage 2. Clause 8.5 requires exercises to be conducted and the results retained; an exercise that has not run is a nonconformity, and it is the check that most often moves the certification date.

How is it different from the self-assessment tool?
The self-assessment scores every requirement of clauses 4 to 10 with a reference to where it is met; the readiness assessment takes six of them, verifies each in the field and scores ready, partial or not ready. Run the self-assessment first and the readiness assessment last.

Where this leaves you

Run the ISO 22301 readiness assessment on the six checks, score them ready, partial or not ready with an evidence reference each, verify one item per check in the field, and book the audit only when the time-gated three — exercise, internal audit, management review — have happened. The BCMS that passes stage 2 first time is the one whose readiness was decided on records, not on optimism.

References

More on ISO 22301 assessment

To score all of clauses 4 to 10 before the six-check readiness review, use the ISO 22301 Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.