Toolkit · Compliance · about 5 minutes

ISO 22301 Readiness Check

Business continuity certification is usually lost on three things: no business impact analysis, a plan nobody has exercised, and no management review. Detailed continuity documents fail on all three surprisingly often, because they were written once and never tested.

21 questions. Nothing is sent anywhere as you answer, the scoring runs in your browser, and we only receive anything if you ask for the written version at the end.

0 of 21 answered0%

Scope and context

What the continuity system covers and what it is protecting.

Is there a documented scope stating which activities, locations and services the continuity system covers?

Have you identified the legal, regulatory and contractual continuity obligations you are subject to?

Customer contracts frequently contain recovery commitments nobody has checked against actual capability.

Are interested parties and their continuity expectations identified, including customers and regulators?

Business impact analysis

The foundation. Everything downstream depends on it being real.

Has a business impact analysis been completed, identifying prioritised activities and the impact of their disruption over time?

The first document an auditor asks for. Without it there is no basis for any recovery target.

Have you defined the maximum tolerable period of disruption for each prioritised activity?

Are recovery time and recovery point objectives set, and have they been validated as achievable rather than aspirational?

Have you identified the resources each prioritised activity depends on, including people, systems, suppliers and premises?

Is there a minimum acceptable level of service defined for operating in a degraded state?

Continuity strategies

What you will actually do when something is unavailable.

Are continuity solutions selected and documented for each prioritised activity, rather than assumed?

Do the chosen solutions meet the recovery objectives within the tolerable disruption period?

Have single points of failure been identified, including individual people and sole-source suppliers?

Are critical suppliers assessed for their own continuity capability, with obligations in contract?

Plans and response

Documents that work when the systems holding them do not.

Are continuity plans documented with defined roles, triggers and escalation, and available offline?

A plan stored only on the file server that has just failed is not available.

Is there an incident response structure with named decision-makers and deputies?

Is there a communication plan covering staff, customers, suppliers, regulators and media?

Can you reach staff and key contacts without your normal systems?

Exercising and improvement

Whether any of it works, and how you would know.

Has a continuity exercise been run in the last 12 months, with the outcome recorded?

An untested plan is a hypothesis. This is where most certification attempts fail.

Do exercises test against the recovery objectives rather than merely walking through the document?

Has management formally reviewed the continuity system in the last 12 months?

Has an internal audit of the continuity system been completed?

Are findings from exercises and incidents tracked to closure rather than noted and forgotten?

More in the toolkit