FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
34of34items
Across 8 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
ISO 22301 Business Impact Analysis

What is a BIA for under ISO 22301?

Under ISO 22301, the BIA is the process that turns business disruption into concrete continuity priorities and requirements. It should start from the BCMS scope and the products or services the organization has decided to protect.

The output should tell a visitor, auditor, or internal owner which activities are prioritized, why they matter, when disruption becomes unacceptable, what minimum capacity is needed, and which resources and dependencies must be available for recovery. It is not limited to IT: activities may depend on people, facilities, information, data, equipment, logistics, finance, partners, and suppliers.

  • Define impact types and assessment criteria that fit the organization, such as operational, financial, contractual, legal, safety, customer, and reputational impact.
  • Identify the activities that support in-scope products and services rather than listing applications or departments with no business context.
  • Use the BIA result to drive continuity strategy and solutions; do not leave it as a standalone spreadsheet.
Citations
ISO 22301 Business Impact Analysis

What should the BIA record for MTPD, RTO, and RPO?

The BIA should assess impacts over time and identify the point where not resuming an activity becomes unacceptable. That point is commonly expressed as the maximum tolerable period of disruption, or MTPD.

The recovery time objective, or RTO, should sit inside that maximum tolerable period and state when the disrupted activity must resume at a defined minimum acceptable capacity. ISO 22301:2019 does not define or explicitly require RPO. For information- and ICT-dependent activities, an organization can add an RPO or equivalent data-loss tolerance when missing records or transactions would affect continuity.

  • For each prioritized activity, record the MTPD, RTO, minimum acceptable capacity, assumptions, and approval owner.
  • If the organization uses RPO for data-dependent activities, record it as a supporting target and map it to backup, replication, restoration, and reconciliation evidence.
  • Flag impossible targets early, such as a one-hour RTO when supplier contracts, staffing, facilities, or data recovery evidence cannot support it.
Citations
ISO/IEC 27002:2022 standard page

Supports the ICT continuity link between BIA outcomes, recovery time expectations, and recovery point expectations for information resources.

ISO 22301 Business Impact Analysis

How should dependencies and resources be handled?

A BIA is weak if it only ranks activities. It should also identify the resources needed to support prioritized activities and the dependencies and interdependencies that affect recovery.

The useful version names the people, facilities, information, data, technology, suppliers, partners, utilities, records, and decision forums needed to continue or recover the activity within the agreed time frame and capacity.

  • Map each prioritized activity to required resources, including minimum staffing, critical records, systems, facilities, suppliers, and manual workarounds.
  • Separate internal dependencies from external dependencies so supplier contracts, service levels, and alternate arrangements can be tested.
  • Connect each dependency to evidence: owner, contract, runbook, backup record, access path, exercise result, or corrective action.
Citations
ISO 22301 Business Impact Analysis

How does the BIA hand off to strategy, plans, and exercises?

The BIA and risk assessment feed the selection of business continuity strategies and solutions. ISO 22301 requires selected strategies and solutions to meet the identified timeframes and agreed capacity. If current capability cannot do so, record the gap and change the solution, resources, or justified continuity requirement; risk acceptance alone does not establish conformity with the strategy-selection requirement.

Business continuity plans, recovery procedures, exercise scenarios, and post-exercise actions should all be traceable back to BIA outputs. Otherwise the organization may test convenient scenarios while leaving the most important recovery assumptions unproven. For example, if order fulfilment must resume within eight hours at 40 percent capacity, the selected solution should name the minimum staff, system access, inventory data, carrier dependency, and manual fallback needed to meet that result; the exercise should test those same conditions.

  • Trace each prioritized activity from BIA row to selected strategy, continuity solution, plan step, exercise scenario, and improvement action.
  • Use exercises and tests to validate whether strategy and solution choices actually meet the BIA recovery targets.
  • After incidents, activations, exercises, supplier changes, or technology changes, update the BIA and related plans together.
Citations
ISO 22301:2019 standard page

Identifies ISO 22301 as the BCMS requirements source for linking BIA outputs to strategies, solutions, plans, and exercises.

ISO 22301 Business Impact Analysis

What evidence proves the BIA is current?

Good BIA evidence shows both the analysis and the operating process around it. Keep the approved BIA, criteria, assumptions, owner approvals, dependency records, resource decisions, strategy links, exercise results, audit findings, corrective actions, and management-review inputs together.

Review the BIA at planned intervals and when significant changes affect the organization or its context. Practical triggers include a new product, site, supplier, system, legal obligation, customer commitment, incident lesson, exercise failure, major staffing model change, or recovery target change.

  • Use versioned BIA records with owner, reviewer, approval date, change summary, assumptions, and next review trigger.
  • Keep unresolved recovery gaps visible as risk acceptance, funded improvement work, supplier remediation, or management-review action.
  • Avoid audit-day screenshots with no business owner, no activity scope, no time-based impact logic, and no link to continuity strategy.
Citations
ISO 22301:2019 standard page

Identifies the ISO 22301 requirements standard used for periodic review, documented information, evaluation, and improvement of the BCMS.

ISO 22301 Certification Evidence

What counts as ISO 22301 certification evidence?

Certification evidence includes documented information that ISO 22301 explicitly requires the organization to retain or maintain, plus other records needed to show that BCMS processes were carried out as planned. A policy folder alone cannot show operation: reviewers need traceability across scope, objectives, BIA, risk assessment, strategies, plans, exercises, evaluation, internal audit, management review, and corrective action.

Start with the BCMS boundary. The scope record must identify the included parts of the organization and products and services, and it must document and explain exclusions. Supporting dependency, location, outsourced-process, and interested-party records help show how that scope was determined and whether exclusions affect the organization's continuity ability or responsibility.

  • Keep a current BCMS scope record with covered entities, sites, functions, products, services, dependencies, exclusions, approver, and review date.
  • Link business continuity policy and objectives to named owners, resources, responsibilities, and continuity outcomes that are measurable if practicable.
  • Retain enough information to show that required processes were carried out as planned and that required results were achieved.
  • As a practical control, record title, date, owner, version, approval status, access, storage location, retention rule, and change history; ISO 22301 requires appropriate identification, format, review, approval, access, protection, retention, and disposition but does not mandate one filing scheme.
Citations
ISO 22301 Certification Evidence

Which operational records should be in the evidence pack?

The core operating evidence should show how the organization determined continuity priorities and selected recovery arrangements. That means business impact analysis records, risk assessment records, continuity requirements, strategy and solution decisions, resource requirements, plans, procedures, warning and communication steps, response structure, and recovery processes.

The BIA and risk assessment should be fresh enough to represent the current organization. ISO 22301 expects these processes to be reviewed at planned intervals and when significant changes occur, so the evidence pack should show the last review, change trigger, approval, and resulting updates.

  • BIA evidence: impact types and criteria, activities supporting products and services, impacts over time, the unacceptable-impact timeframe (which may be called MTPD), prioritized resumption timeframes (which may be called RTO), minimum acceptable capacity, resources, dependencies, and approvals. RPO is optional supporting evidence where the organization uses a data-loss target; ISO 22301:2019 does not define or explicitly require it.
  • Risk assessment evidence: disruption scenarios, risk criteria, assumptions, existing controls, selected treatment, residual risk, and review trigger.
  • Strategy evidence: selected business continuity strategies and solutions for before, during, and after disruption, with resource requirements and activation conditions.
  • Procedure evidence: response structure, warning and communication procedures, business continuity plans, recovery processes, contact lists, and dependency owners.
Citations
ISO 22301:2019 standard page

Supports the focus on BCMS operation, BIA, risk assessment, strategies, solutions, plans, procedures, response, and recovery.

ISO/TS 22331:2018 standard page

Published ISO technical specification for business continuity strategy determination and selection; ISO lists it as current but under revision.

ISO 22301 Certification Evidence

How do exercises, audits, and management review show whether the BCMS works?

Exercises and tests show whether strategies, solutions, plans, communications, teams, and suppliers can perform over time. Keep the scenario, aims, objectives, participants, assumptions, results, recommendations, action owners, due dates, and closure proof together with the plan or capability being tested.

Internal audit and management review close the evidence loop. Audit records should show criteria, scope, auditor independence, findings, reported results, and follow-up. Management review records should show inputs, decisions, scope changes, BIA or risk updates, plan updates, resource decisions, and improvement opportunities.

  • Exercise evidence should include the programme, scenario, objective, participants, observed results, post-exercise report, recommendations, actions, and effectiveness review.
  • Capability evaluation evidence should cover plans, procedures, post-incident reports, tests, partner or supplier capabilities, and legal or regulatory conformity checks.
  • Internal audit evidence should include audit programme, audit scope, audit criteria, selected auditors, results, findings, corrective actions, and verification of follow-up actions.
  • Management review evidence should show previous-action status, BCMS performance trends, audit results, interested-party feedback, BIA and risk information, decisions, and communicated outputs.
Citations
ISO 22301:2019 standard page

Grounds the need for exercise and test evidence, performance evaluation, internal audit, management review, and retained records.

ISO 22301 Certification Evidence

How should teams keep certification evidence current?

Keep an evidence map instead of a last-minute audit folder. Each evidence item should have a record owner, storage location, review frequency, change trigger, retention rule, and status. When the scope, product, service, site, supplier, system, incident pattern, legal requirement, or continuity objective changes, update the affected evidence and show what changed.

Corrective-action records show whether the organization reacts to nonconformities, evaluates their causes and possible recurrence, implements needed action, reviews effectiveness, changes the BCMS where necessary, and retains evidence of the nonconformity, subsequent action, and results.

  • Set freshness rules for scope, policy, objectives, BIA, risk assessment, plans, supplier continuity evidence, exercises, audits, management review, and corrective actions.
  • Connect every nonconformity or issue to cause analysis, action owner, due date, evidence of completion, effectiveness review, and closure approval.
  • Avoid screenshots without context; preserve source-system exports, approvals, version history, and links to the process that produced the record.
  • Use management review to decide on scope changes, BIA and risk updates, plan changes, resources, measures, and continual improvement.
Citations
ISO 22301:2019 standard page

Supports evidence freshness, corrective action, management review, continual improvement, and retained documented information.

ISO 22301 Management Review

What should ISO 22301 management review include?

Treat the review as a top-management decision meeting for the BCMS. The agenda should start with open actions from the previous review, then move through changes in internal and external context, interested-party feedback, BCMS performance, audit results, nonconformities, corrective actions, and monitoring results.

The review should also use business impact analysis and risk-assessment information, evaluation of business continuity documentation and capabilities, lessons from near misses and disruptions, and opportunities for continual improvement. If those inputs are missing, the review record will look complete but will not prove that leadership reviewed the real continuity system.

  • Bring forward unresolved actions from the previous management review with owners and due dates.
  • Show what changed in scope, sites, services, suppliers, people, technology, threats, interested-party expectations, and continuity objectives.
  • Summarize BCMS performance trends, audit results, exercise outcomes, nonconformities, corrective actions, disruptions, near misses, BIA updates, and risk-assessment changes.
  • Record resource constraints, procedure gaps, capability weaknesses, and improvement opportunities that require leadership decisions.
Citations
ISO 22301:2019 standard page

Official ISO page for the ISO 22301:2019 business continuity management system requirements standard and its edition status.

ISO 22301 Management Review

What outputs should management approve?

Use a short decision log that separates decisions from the meeting transcript. Each decision should say what will change, why it matters to continuity, who owns it, when it is due, and which evidence will prove completion.

Typical outputs include changes to the BCMS scope, updates to the BIA or risk assessment, revisions to continuity strategies and solutions, updates to business continuity plans, modifications to procedures and controls, and decisions about how control effectiveness will be measured.

  • Separate decisions from discussion notes so owners can execute them.
  • Tie each approved change to a BCMS artifact: scope statement, BIA, risk assessment, continuity plan, exercise programme, audit action, corrective action, resource plan, or performance metric.
  • Escalate decisions that affect recovery targets, customer commitments, critical suppliers, certification scope, continuity resources, or unresolved nonconformities.
  • Carry rejected or deferred improvements as explicit risk acceptance, backlog items, or next-review inputs.
Citations
ISO 22301 Management Review

What evidence proves the review happened?

Retain the management-review record with enough detail for a later auditor, customer reviewer, or executive sponsor to reconstruct the decision. At minimum, keep the agenda, attendance or approval record, input pack, decision log, assigned actions, communication record, and follow-up status.

Good evidence links back to live BCMS records: exercise and test reports, post-incident reports, internal audit results, monitoring and measurement data, nonconformity and corrective-action records, BIA and risk-assessment updates, documentation capability reviews, and prior management-review actions.

  • Keep evidence in the BCMS record system instead of scattered email threads.
  • Make the record clear about which leadership role reviewed and approved the outputs.
  • Preserve action closure evidence, not only the original review minutes.
  • Communicate the results of the management review to relevant interested parties, including when decisions change commitments, procedures, responsibilities, or recovery expectations.
Citations
ISO 22301 Management Review

When should management review run?

ISO 22301 requires management review at planned intervals but does not prescribe an annual or other fixed frequency. Set the interval so top management receives the required inputs and can act before unresolved issues undermine the BCMS; do not let the certification-audit calendar determine the only review date.

A material change, disruption, near miss, serious exercise gap, systemic audit finding, or blocked continuity objective can justify an additional full or targeted leadership review. This event-based review is a practical governance choice, while the explicit ISO 22301 requirement is review at planned intervals.

  • Define the planned interval and event-based triggers in the BCMS governance calendar.
  • Use internal audit, exercise reports, monitoring results, and corrective-action trends to decide whether the cadence is still adequate.
  • Do not close the review until owners, due dates, communication needs, and evidence locations are recorded.
  • Feed outputs into continual improvement so review decisions become visible changes to the BCMS.
Citations
ISO 22301 MTPD

What does MTPD mean in ISO 22301?

MTPD is the name ISO 22301 permits for the timeframe within which the impacts of not resuming an activity would become unacceptable. This is more precise than treating MTPD as elapsed outage time alone: the decision depends on impact types, impact criteria, the affected activity, and how impacts develop over time.

A useful MTPD record names the activity, the product or service it supports, the impact criteria used, the point where impact becomes unacceptable, and the person or forum that accepted that tolerance. Without that context, the number is hard to defend during an audit, supplier review, or real disruption.

  • Assess the unacceptable-impact timeframe for each activity in the BIA, then use the analysis to identify prioritized activities; do not set one generic MTPD for the whole organization.
  • Base the value on impacts over time: operational loss, customer harm, legal or regulatory exposure, safety, financial loss, reputation, or contractual commitments.
  • Record the assumptions behind the decision, including minimum acceptable capacity, dependency limits, supplier constraints, and escalation thresholds.
Citations
ISO 22301:2019 standard page

Primary ISO listing for the business continuity management system requirements standard that frames MTPD as part of BCMS planning and operation.

ISO 22301 MTPD

How is MTPD different from RTO and RPO?

MTPD is the unacceptable-impact boundary. RTO is the prioritized timeframe for resuming the disrupted activity at a specified minimum acceptable capacity, and it should sit inside the MTPD. ISO 22301:2019 does not define or explicitly require RPO; an organization can use RPO as a supporting data-loss or transaction-rework target where information recovery affects continuity.

If an activity has a 48-hour MTPD, setting a 48-hour RTO leaves no margin for activation delays, failed recovery steps, supplier dependencies, or management escalation. The BIA should therefore show why the selected RTO and resource strategy can recover the activity before the MTPD is reached.

  • Use MTPD to define when impact becomes unacceptable.
  • Use RTO to set the recovery target for the prioritized activity at minimum acceptable capacity.
  • Where the organization adopts RPO, use it for data recovery expectations and label it as a supporting target rather than an explicit ISO 22301 requirement.
  • Flag any activity where the chosen RTO, RPO, supplier commitment, or workaround cannot realistically fit inside the MTPD.
Citations
ISO 22301:2019 standard page

Supports the ISO 22301 context for BIA, continuity requirements, and business continuity management system requirements.

Page 1 of 3
Previous123Next