- Explains that certification is performed by independent certification bodies rather than ISO and is not the only way to use a management-system standard.
"ISO does not perform certification"
Use this checklist to trace BCMS evidence from scope and policy through BIA, risk assessment, continuity solutions, plans, exercises, internal audit, management review, and corrective action.
Keep the checklist tied to real owners, controlled documents, dated records, and public source references. It is implementation guidance, not certification advice from a certification body.
Structured answer sets in this page tree.
Cited legal and guidance references.
is optional. ISO 22301:2019 allows an organization to demonstrate conformity through self-determination and self-declaration, confirmation of conformity by an interested party, external confirmation of a self-declaration, or certification by an external organization. ISO develops the standard but does not certify organizations. When certification is the chosen route, evidence should show that the business continuity management system is defined, operated, evaluated, and improved. This checklist is based on the published 2019 edition, including its 2024 amendment; a revision is under development but has not replaced it. The checklist can organize preparation, but it cannot determine conformity or guarantee certification.
The first evidence set should show what the BCMS covers, what it excludes, which products and services matter, which interested-party requirements were considered, and how top management approved the business continuity policy and objectives.
Make the scope available as controlled and connect it to the and risk assessment. The scope must identify the included parts of the organization and products and services. Document and explain exclusions; they cannot reduce the organization's ability or responsibility to provide continuity as determined by the BIA or risk assessment and applicable legal or regulatory requirements.
For each checklist item, record one of four states: present and current, present but needs review, missing, or not applicable with a documented reason. Name the record owner, reviewer, evidence location, result date, retention rule, and next change trigger. These states are Sorena's implementation aid, not ISO-mandated labels.
This checklist helps assign record owners, link each evidence item to the BCMS clause it supports, and keep audit, exercise, management review, and corrective-action proof current.
Convert certification evidence needs into accountable tasks, cited evidence requests, and audit-ready review checkpoints.
Check whether your current scope, BIA, plans, exercises, audits, and management reviews can support certification readiness.
The record should define impact types and criteria, identify activities that support products and services, assess impact over time, and identify when not resuming an activity would become unacceptable. It should then set a prioritized resumption time within that limit and at a specified minimum acceptable capacity, identify prioritized activities, and record their resources, dependencies, and interdependencies.
The disruption risk assessment should identify risks to prioritized activities and their required resources, analyse and evaluate those risks, and determine which need treatment. Strategy records should then show how and risk-assessment outputs led to options for before, during, and after disruption.
Continuity plans and procedures should be based on selected strategies and solutions. Collectively they should identify the response structure, activation thresholds, immediate actions, warning and communication steps, delivery at agreed capacity, recovery actions, resource needs, interdependencies, reporting, and stand-down. Each plan must be usable and available where and when it is needed.
evidence should prove version control, approval, access, storage, distribution, protection, retention, and change control. Auditors should be able to identify the current plan, who approved it, what changed, and whether obsolete versions are controlled.
The exercise programme must validate the effectiveness of continuity strategies and solutions over time. Exercises and tests should use planned scenarios with clear aims and objectives, produce formal post-exercise reports with outcomes, recommendations, and improvement actions, and occur at planned intervals and after significant changes.
Capability evaluations should cover the suitability, adequacy, and effectiveness of the , risk assessment, strategies, solutions, plans, and procedures. They should also assess relevant partner and supplier capabilities and lead to timely document or procedure updates.
A certification evidence checklist should end with performance evaluation and improvement. records should show audit criteria, scope, schedule, independence, results, reported findings, and corrective actions. Management review records should show decisions about scope, policy, objectives, resources, updates, risk assessment updates, plans, and improvement opportunities.
Corrective-action evidence should connect each nonconformity or issue to cause analysis, action taken, effectiveness review, and retained proof of closure. Keep these records in a single evidence map so certification preparation does not depend on one person remembering where each proof item lives.
"ISO does not perform certification"
"Business continuity management systems — Requirements"
"Guidelines for business impact analysis"
"Guidelines for business continuity strategy"