An ISO 22301 self-assessment is a clause-by-clause check of a business continuity management system against ISO 22301:2019, run by the organisation on itself, with three columns that make it useful: where in the system each requirement is met, how that was verified, and whether it is an area of concern. It is the instrument between reading the standard and being audited against it, and — unlike a maturity assessment or a readiness review — it follows the standard’s own structure exactly, clauses 4 to 10, so its output maps directly onto what a certification auditor will ask.
This guide explains how to score each clause, walks through the requirements in each of the seven clauses that most often surprise self-assessors, explains why clause 8 has to be scored at sub-clause level, and sets out the rules that keep an ISO 22301 self-assessment honest enough to be worth the day it takes.

What an ISO 22301 self-assessment is for
Three uses. Before implementation it is the gap analysis — every “No” is work to do, and our guide to the ISO 22301 gap analysis explains which “No” matters most. During implementation it is the progress record — the reference column fills in as documents and processes are built. Before certification it is the evidence index — the reference and verification columns are what the auditor will follow at stage 1.
The standard does not require a self-assessment by that name, but clause 9.1 requires the organisation to evaluate the performance and effectiveness of the BCMS, and clause 8.6 requires it to evaluate the adequacy and effectiveness of its business continuity documentation and capabilities; a documented self-assessment against the standard is the simplest evidence of both.
The three columns
| Column | What to record | What not to record |
|---|---|---|
| Reference in your system | The document, register, record or process that meets the requirement — by name, version and location | ‘Yes’ with nothing behind it; a person’s name as the reference; ‘the BCMS’ |
| How verified | Read it, sampled records, interviewed the owner, observed the exercise, tested the alternate access | ‘Confirmed’ with no method; verification by the person who wrote the document |
| Area of concern | Yes/No plus one line: what would fail an audit or a real disruption, and why | A percentage; a colour with no reason |
Scoring the ISO 22301 self-assessment clause by clause
| Clause | Requirements that surprise self-assessors | What a ‘Yes’ needs behind it |
|---|---|---|
| 4 Context | 4.1 issues now explicitly include climate change (Amd 1:2024); 4.2 interested parties include regulators, customers and suppliers with continuity requirements; 4.3 scope must state exclusions and why | Context register; interested-party register with requirements; scope statement with justified exclusions |
| 5 Leadership | 5.1 top management ensures the policy and objectives are compatible with strategic direction and integrates BCMS requirements into business processes; 5.2 policy; 5.3 roles with authority to report on BCMS performance | Signed policy; governance minutes showing decisions; role descriptions with reporting lines |
| 6 Planning | 6.1 risks and opportunities to the BCMS itself (not disruption risks — those are 8.2.3); 6.2 objectives measurable and monitored; 6.3 planned changes | Register of BCMS risks; objectives with measures and owners; change records |
| 7 Support | 7.1 resources; 7.2 competence evidence for BCMS roles and response teams; 7.3 awareness of one’s role in a disruption; 7.4 internal and external communication including during disruption; 7.5 control of documented information | Training records for response roles; awareness evidence; communication plan; document register |
| 8 Operation | See the sub-clause table below | Scored at 8.1–8.6, never as one row |
| 9 Performance evaluation | 9.1 what is measured, methods, when, and evaluation of effectiveness; 9.2 audit programme by importance and past results, auditor independence; 9.3 review inputs include exercise results, risks, changes, and outputs include changes to the BCMS | Metrics; audit programme and reports; review minutes with decisions |
| 10 Improvement | 10.1 nonconformity: react, evaluate the need to eliminate the cause, act, review effectiveness, retain evidence; 10.2 continual improvement | Nonconformity records with root cause and effectiveness check |
Clause 8 in the ISO 22301 self-assessment
| Sub-clause | Requirement | Reference should point to | Concern if |
|---|---|---|---|
| 8.1 Operational planning and control | Processes planned, implemented and controlled; outsourced processes controlled | Process descriptions; supplier controls | Outsourced processes not in the BCMS |
| 8.2.1 General | BIA and risk assessment process documented, systematic, reviewed at planned intervals and on significant change | BIA and risk assessment procedure | No review trigger; last run undated |
| 8.2.2 Business impact analysis | Impact types and criteria; activities and impact over time; prioritised activities; timeframes for resumption at a minimum acceptable capacity (RTO, MBCO) and for data (RPO); dependencies and resources | BIA workbook per activity | RTOs set by IT; dependencies stop at internal processes |
| 8.2.3 Risk assessment | Disruption risks to prioritised activities and resources identified, analysed, evaluated; treatments determined | Risk register for disruption | Risk assessment is the enterprise register renamed |
| 8.3 Strategies and solutions | Strategies to protect, stabilise, continue, resume and recover; selected on BIA and risk outputs; resource requirements determined; solutions implemented | Strategy record citing BIA rows; resource plan | Solutions predate the BIA; resources unfunded |
| 8.4 Plans and procedures | 8.4.2 response structure; 8.4.3 warning and communication; 8.4.4 plans with purpose, scope, roles, actions, resources, information flow; 8.4.5 recovery | Response structure chart; communication procedure; plans; recovery procedures | Names out of date; plans inaccessible off-site |
| 8.5 Exercise programme | Programme consistent with scope and objectives; scenarios; exercises that build teamwork and competence; post-exercise reports; review at planned intervals and on change | Programme; reports with findings and actions | One tabletop, no findings |
| 8.6 Evaluation of documentation and capabilities | Evaluate adequacy and effectiveness of BIA, risk assessment, strategies, solutions, plans and procedures; results reviewed | Evaluation record — often the self-assessment itself | Missing entirely; the clause most often absent from templates |
Our guides to the business impact analysis and RTO and RPO cover the 8.2.2 rows where most concerns are recorded.
Rules that keep an ISO 22301 self-assessment honest
- The reference must be openable. If the assessor cannot open what the reference column names, the row is No.
- Verification by someone other than the author. The BCMS owner scores; a second person verifies a sample, or the internal auditor does.
- Records beat documents. A procedure for exercising is not evidence of exercising. For 8.5, 9.2, 9.3 and 10.1 the reference must be a dated record.
- Test one thing per clause in the field. Open a plan from a phone; ring an alternate; ask a process owner their RTO.
- Concerns are findings, not notes. Each gets an owner and a date, and the list feeds management review under 9.3.
- Date the assessment and keep the previous one. The trend between two assessments is the 9.1 evidence of improvement.
Frequently asked questions
What is an ISO 22301 self-assessment?
A clause-by-clause check of the BCMS against ISO 22301:2019, recorded with three columns per requirement — the reference in your system, how it was verified, and whether it is an area of concern — run by the organisation itself before or between audits.
How is it scored?
Per requirement, not per clause: Yes with an openable reference and a verification method, or No. Clause 8 is scored at sub-clause level 8.1 to 8.6 because that is where the substantive BCMS requirements sit. Percentages hide the load-bearing gaps.
How long does it take?
A day for a single-site organisation with the documents to hand; two to three for multi-site scopes. The verification step is what takes the time, and it is the step that makes the result worth having.
Does it replace the internal audit?
No. Clause 9.2 requires an internal audit performed by auditors independent of the area; a self-assessment is by definition not independent. It prepares the audit and can be the evidence for 8.6 and 9.1.
What does the tool add?
Structure and consistency: every requirement of clauses 4 to 10 pre-listed, the three columns, and a summary per clause so the concerns are visible at once rather than buried in a spreadsheet you built from the standard.
Where this leaves you
Run the ISO 22301 self-assessment with three columns and a rule that every Yes has an openable reference and a verification method, score clause 8 at sub-clause level, verify one thing per clause in the field, and turn the concerns into owned actions that reach management review. Done that way it is the gap analysis before the build, the progress record during it and the evidence index the auditor follows.
References
- ISO 22301:2019 — Security and resilience — Business continuity management systems — Requirements — Second edition, October 2019, with Amd 1:2024 (climate change in 4.1); a third edition is at committee-draft stage.
- ISO 22313:2020 — Guidance on the use of ISO 22301 — Guidance on each clause the self-assessment scores.
More on ISO 22301 assessment
- ISO 22301 self-assessment — you are here
- ISO 22301 assessment: the four types
- ISO 22301 readiness assessment
- ISO 22301 maturity assessment
- ISO 22301 gap analysis
- ISO 22301 internal audit checklist
The ISO 22301 Assessment Tool pre-lists every requirement of clauses 4 to 10 with the three columns and a per-clause summary, or start with the free templates.