Business continuity
ISO 22301
ISO 22301 is the international standard for business continuity management. It asks which of your activities cannot stop, how long they can be interrupted before the damage is material, and whether you have tested your answer rather than written it down.
- المعيار
- ISO 22301:2019
- الاعتماد
- EIAC
- Typical timeline
- Ten to fourteen weeks for a single site, and longer where the impact analysis is being done for the first time. A system with no completed exercise cannot pass Stage 2, so the exercise programme usually sets the date rather than the paperwork.
Who needs it
Banks, insurers and payment providers working to Central Bank expectations; data centers, telecom operators and managed service providers who contract on availability; logistics operators, hospitals and utilities. It appears in UAE tenders wherever an interruption to your service becomes an interruption to the buyer's.
What the standard requires
- Business impact analysis
- Identify the activities that deliver your products and services, and for each one establish how quickly it must resume and what it needs in order to do so. This is the analysis the rest of the system is built on, and a plan written without it is a plan for the interruption somebody imagined rather than the one that would hurt.
- Risk assessment
- Assess what could disrupt those prioritized activities. The standard does not ask you to predict the cause; it asks you to understand the disruption, so a single-supplier dependency matters whether it fails through fire, sanction or insolvency.
- Continuity strategies and solutions
- Choose and resource what you will actually do — alternate sites, standby capacity, cross-trained staff, arrangements with suppliers — and show that the chosen solutions meet the timeframes the impact analysis set. Auditors check that the resources named in a strategy exist and are available.
- Documented plans and a response structure
- Named roles with the authority to invoke a plan, a way of reaching people when normal systems are down, and procedures written to be usable by whoever is on duty. We raise findings where the only copy of a plan is on the system the plan exists to survive.
- Exercising and testing
- This is the clause that separates a certified system from a documented one. Plans have to be exercised on a defined programme, the results recorded honestly including what failed, and the plans changed in response. An exercise nobody failed is usually an exercise that tested nothing.
Why organizations certify
- Answers the continuity and resilience sections of financial-sector and government tenders with an independent certificate rather than a self-assessment
- Gives clients contracting on availability third-party evidence behind the commitment
- Turns continuity from a document owned by one person into a system with named roles, a tested response and a review cycle
What drives the fee
Audit duration under our accreditation is set by defined criteria, not by negotiation. These are the factors that move it, so you can see where your quote comes from:
- Number of prioritized activities and the number of distinct products and services in scope
- Number of employees and how many sites, data centers and operating locations are covered
- Complexity of the dependency map, particularly reliance on outsourced providers whose arrangements have to be evidenced
- Whether an exercise programme is already running, since evidence of exercising is what the audit spends most of its time on
How the audit runs
- 01
Certification
Stage 1 and Stage 2
Two stages. Stage 1 is a document review and information gathering exercise; Stage 2 is the audit that determines certification.
- 02
1st Annual Surveillance
First follow-up audit
A follow-up audit in the first year of the cycle, confirming the system is still operating and that corrective actions were effective.
- 03
2nd Annual Surveillance
Second follow-up audit
The second follow-up audit, in the final year before recertification, covering the parts of the system not sampled in year one.
- 04
Recertification
Renewal audit for the next cycle
A renewal audit before the certificate expires, assessing the whole management system and its performance across the full three years.
Questions we are asked
Is this the same as a disaster recovery plan?
No, and the distinction is the point of the standard. Disaster recovery restores technology. ISO 22301 starts from the activities the organization has to keep delivering, works out how quickly each must resume, and treats technology as one of the resources that has to be available in time. A recovery plan for the systems is part of it, never the whole of it.
Do we have to run a full exercise before the audit?
You have to have exercised, and you have to be able to show what the exercise found and what changed as a result. The standard does not prescribe a scale, so a focused exercise of a prioritized activity carries more weight than a walkthrough of everything. A system that has never been exercised has not been implemented.
Can it be certified alongside ISO 9001?
Yes. Both follow the harmonized structure, so management review, internal audit, document control and corrective action are shared clauses. We combine the audits where the scopes and sites allow it, which shortens the audit and lowers the fee.
Does it cover information security?
Only where a security incident is a disruption to be recovered from. ISO 22301 governs continuity of activities; the controls that prevent and detect a security incident belong to ISO/IEC 27001, which is a separate standard and outside what we certify.
- Multi-site sampling: which of your sites an auditor visits
- Witness audits: why an assessor joins your audit
- How to check a supplier's ISO certificate
- What we ask before we quote, and why it shapes your audit
- Closing a nonconformity: correction, cause, and evidence
- What you can claim once you hold an ISO certificate
- Climate change amendments: what changed in your standard in 2024