Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

supplier business continuity assessment explained

Supplier Business Continuity Assessment: 7 Essential Checks (2026)

A supplier business continuity assessment is the check most ISO 22301 systems fail quietly: the business impact analysis identifies the suppliers a prioritised activity depends on, the strategy assumes they will be there, and nobody has asked whether they would be. ISO 22301:2019 does not use the phrase, but it requires the result three times — clause 8.2.2’s business impact analysis has to identify the dependencies and supporting resources of prioritised activities, clause 8.3’s strategies and solutions have to address the resources those activities need, and clause 8.1 requires outsourced processes to be controlled — and ISO/TS 22318:2021 exists to supply the method, as the technical specification “for supply chain continuity management” that extends the principles of ISO 22301 and ISO 22313 “to the management of supplier relationships”. This guide explains which suppliers to assess and how to tier them, what to ask and what evidence to accept, how to score the answers, what to do with a supplier that fails, and how the assessment feeds the BIA, the strategies and the exercise programme.

Supplier business continuity assessment: from the BIA to the contract
Prioritised activities (8.2.2) → dependencies and tiering → questionnaire and evidence → score → treatment: contract, alternate, buffer, accept → exercise the dependency (8.5).

Where the supplier business continuity assessment sits in ISO 22301

Clause What it requires What the supplier assessment provides
4.1, 4.2 Context; needs and expectations of interested parties, including suppliers and partners Suppliers as interested parties with continuity requirements in both directions
8.1 Operational planning and control, including control of outsourced processes Evidence that outsourced processes have continuity arrangements
8.2.2 BIA: prioritised activities, their dependencies and supporting resources The list of suppliers that matter and how fast their failure bites
8.2.3 Risk assessment of disruption-related risks to prioritised activities Supplier failure as a risk with likelihood and impact
8.3 Strategies and solutions to protect, stabilise, continue, resume and recover prioritised activities, and resource requirements The treatment for each critical supplier: dual-source, buffer, alternate, contractual recovery commitments
8.4 Plans and procedures including warning and communication Supplier contacts, escalation and their notification duties in the plans
8.5 Exercise programme Supplier-failure scenarios exercised, with suppliers participating where critical
9.1 Monitoring and measurement Coverage and currency of supplier assessments as a metric

ISO/TS 22318:2021 adds the method. Its abstract states that it “enables an organization to develop and document the strategy to be better prepared to manage supply chain continuity” and applies “to suppliers of products, services and resources, both upstream and downstream”. Our guide to the business impact analysis covers the dependency mapping the assessment starts from.

Which suppliers the supplier business continuity assessment covers

Tier Definition Assessment depth Frequency
Critical Failure stops a prioritised activity within its RTO; no ready alternate Full questionnaire, evidence review, contractual continuity terms, joint exercise Annually and on change
Important Failure degrades a prioritised activity or exhausts a buffer before the RTO; alternates exist but take time Questionnaire and evidence review Annually
Standard Failure is absorbed by stock, alternates or workaround within the RTO Self-declaration; contract clause At onboarding and renewal
Concentration risk Any tier where several prioritised activities share the supplier, or the supplier shares a location, platform or sub-supplier with another critical supplier Assess as critical; map the fourth party Annually

The tier is set by the BIA, not by spend. A low-cost SaaS tool that every recovery procedure logs into is critical; the largest contract by value may be standard. Concentration is the tier most organisations miss — two “independent” suppliers on the same cloud region or the same logistics hub are one dependency. Our guide to the third-party risk assessment covers the wider TPRM tiering the continuity assessment fits inside.

What the supplier business continuity assessment asks

Area Questions Evidence to request Red flags
Governance Is there a BCMS? Certified to ISO 22301? Who owns continuity? Certificate and scope; policy; named owner Certificate scope excludes the service you buy
BIA and recovery objectives What RTO and RPO does the supplier commit to for your service? Do they match your BIA? BIA extract or service continuity statement; SLA terms Supplier RTO longer than your RTO for the activity that depends on it
Strategies and solutions Alternate sites, systems, people, sub-suppliers? Single points of failure? Solution description; sub-supplier list Sole sub-supplier; single site; key-person dependency
Plans and communication How and when will they notify you of a disruption? Who is the contact? Plan extract; notification procedure; contacts No notification commitment; contacts unverified
Exercising When was the last exercise covering your service? What were the findings? Exercise report summary; action status Never exercised; findings unavailable
Their supply chain Who do they depend on? Are those suppliers assessed? Fourth-party register Cannot name their critical suppliers
Contract Continuity, notification, audit and exit terms Contract clauses No continuity clause; no right to information

Scoring the supplier business continuity assessment

  1. Score each area 0–3: 0 no evidence, 1 assertion only, 2 documented evidence, 3 evidence plus exercise or certification covering the service.
  2. Compare recovery objectives first. A supplier whose committed RTO exceeds your RTO for the dependent activity is a gap whatever else scores 3; record it as a BIA input, not a supplier score.
  3. Weight by tier. Critical suppliers need 2 or 3 in every area; important suppliers need no zeros; standard suppliers need a contract clause and a declaration.
  4. Record the result against the BIA row so the strategy under 8.3 can cite it.
  5. Decide the treatment: accept, contract (recovery commitments, notification, audit rights), mitigate (buffer stock, alternate supplier, data escrow, portable configuration), or replace.
  6. Exercise it. Add a supplier-failure scenario to the 8.5 programme; invite critical suppliers to participate.

When a critical supplier fails the assessment

When a critical supplier fails the supplier business continuity assessment, the answer is rarely termination. In order of cost: obtain the missing evidence — many suppliers have a BCMS and a poor questionnaire team; negotiate contractual recovery commitments with notification duties and the right to evidence; build a mitigation inside your own strategy — buffer, alternate, workaround — sized to the supplier’s realistic recovery time rather than your target; and only then dual-source or replace. Whichever route, the BIA row changes: either the dependency now has a treatment under 8.3 or the RTO for the activity is revised to what is achievable, and the plan under 8.4 says what to do on the day. An assessment whose result changes nothing in the BIA, strategy or plans has produced a record and no continuity. Our guide to the vendor due diligence checklist covers the onboarding controls that keep the next supplier from arriving unassessed.

Frequently asked questions

Does ISO 22301 require a supplier business continuity assessment?
Not by name. It requires the BIA to identify dependencies and supporting resources (8.2.2), strategies to address the resources prioritised activities need (8.3) and outsourced processes to be controlled (8.1). Assessing critical suppliers’ continuity is how those requirements are evidenced, and ISO/TS 22318:2021 provides the method.

Which suppliers do we have to assess?
Those a prioritised activity depends on within its recovery time objective, tiered from the BIA, plus any supplier that creates concentration risk across activities or shares infrastructure with another critical supplier.

Is an ISO 22301 certificate from the supplier enough?
Only if the certificate’s scope covers the service you buy and the supplier’s committed recovery objectives meet yours. A certificate covering head office says nothing about the data centre your service runs in.

How often should we reassess?
Critical suppliers annually and on change — new sub-supplier, new site, ownership change, an incident; important suppliers annually; standard suppliers at onboarding and renewal.

What if the supplier refuses to answer?
Treat the refusal as a zero score, mitigate inside your own strategy, add continuity and information rights at the next contract renewal, and record the decision under 8.3. A refusal from a critical supplier is a management review input.

Where this leaves you

Start the supplier business continuity assessment from the BIA rather than the procurement register, tier by dependency and concentration, ask for evidence rather than assurances, compare recovery objectives before anything else, and make the result change the strategy and the plans. Then exercise a supplier failure, because the dependency the BIA found is only continuity once it has been tested.

References

More on ISO 22301 assessment

To score how the BCMS handles dependencies alongside every other clause 4–10 requirement, use the ISO 22301 Assessment Tool, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.