Standards › ISO 22301

Certifiable standard

ISO 22301 — Business Continuity

The international standard for business continuity management systems: keep priority activities running through disruption, and recover in a planned way.

What it covers

Business impact analysis, continuity risk assessment, continuity strategies and plans, exercising, and improvement after tests or real incidents.

Who it is for

Contractors delivering time-critical or framework work, businesses dependent on a single yard, system or key people, and suppliers asked about resilience in prequalification.

Key requirement themes

  • Business impact analysis: what must keep running, and how quickly
  • Continuity risk assessment for the things that could stop you
  • Strategies and documented plans proportionate to the impact
  • Exercise programme that tests plans rather than filing them
  • Post-incident and post-exercise improvement

Theme-level description in our own words — the standard itself defines the requirements, and no standard text is reproduced here.

Construction-sector relevance

Losing a yard, a CDE, a fuel supplier or a TWC mid-project has programme consequences. Continuity planning names the priority activities (live sites, temporary works checks, payroll), the recovery time you can stand, and the workaround you have rehearsed.

Benefits

  • Priority activities and recovery times agreed before an incident
  • Framework resilience questions answered
  • Less improvisation when something fails
  • Insurance conversations from evidence

Common gaps we find

  • Plans written but never exercised
  • Key-person dependencies unaddressed
  • IT recovery assumed rather than tested
  • Supply chain single points ignored

Implementation process

  1. Gap analysis of current arrangements against the standard
  2. Prioritised closure plan with owners and dates
  3. Documents and registers built or adapted with the people who use them
  4. System operated: records, audits, review — evidence accumulating
  5. Readiness review and mock assessment
  6. Independent certification-body assessment (their decision, not ours)

Typical documents

  • BIA and risk assessment
  • Continuity strategy and plans
  • Exercise programme and reports
  • Improvement log

Typical evidence

  • Exercise records with findings actioned
  • Recovery test results
  • Reviewed dependencies

Certification-readiness route

We take organisations to the point where an accredited certification body can assess them with confidence: gap analysis → implementation → operating evidence → internal audit and management review → readiness review. The assessment and the certificate belong to the certification body; our role ends at prepared-and-ready, and continues afterwards only as support.

Related standards

Certifiable standard

ISO 27001 — Information Security

The international standard for information security management systems: protecting the confidentiality, integrity and availability of the information you hold.

Certifiable standard

ISO 9001 — Quality Management

The international standard for quality management systems: consistent processes, controlled documents, measured performance and evidenced improvement.

Implementation approach

IMS — Integrated Management Systems

One management system meeting several standards at once — commonly ISO 9001 + 14001 + 45001 — with one document set, one audit programme and one review, instead of parallel systems.

Questions we are actually asked

Is this just an IT disaster recovery plan?

No — IT recovery is one part. The standard covers whatever your priority activities depend on: people, premises, plant, suppliers and information.

How often should we exercise?

At least annually for priority plans, and after significant change. An unexercised plan is treated by auditors — and reality — as unproven.

Can a small business justify this?

A proportionate system can be lean. The BIA alone — knowing what must not stop and for how long you could stand it — is worth having at any size.

Professional disclaimer: this page is orientation, not advice on your specific circumstances, and not a reproduction of any standard. Implementation support, templates and platform tools do not confer certification or legal compliance; certification decisions rest solely with independent certification bodies, and legal duties apply regardless of certification.