When should recovery strategies be reviewed or changed?
Review strategies at planned intervals and after significant changes to the organization, context, prioritized activities, resource requirements, suppliers, sites, systems, legal obligations, customer commitments, or disruption risks. ISO 22301 also expects exercising and testing over time to validate business continuity strategies and solutions.
If a test shows the selected solution cannot meet the required time frame or capacity, the issue should not stay buried in the exercise report. Update the strategy, plan, resource decision, corrective action, and management-review inputs so the BCMS reflects the real recovery capability.
- Trigger review when BIA assumptions, risk assessment results, supplier capabilities, technology architecture, staffing, facilities, or customer obligations change.
- Use exercises, tests, post-incident reports, audits, and performance evaluations to confirm whether the strategy remains suitable.
- Carry material strategy changes and unresolved gaps into management review so leadership decisions are documented.
Primary ISO listing for the current ISO 22301 business continuity management system requirements standard.
Supports the strategy lifecycle and review focus for business continuity strategy decisions.