Institute for continuity and resilience

Continuity is not a plan.It is a capability.

Training, annotated standards, working templates and certifications across business continuity, operational resilience, operational risk, IT continuity and crisis management.

32

courses

99

annotated requirements

45

working templates

8

certifications

Tracks

Eight tracks, one discipline

Each track leads to a certification and rests on the standards that carry authority in its field.

View all

Standards

The standards library, clause by clause

For every requirement: its intent, the evidence an auditor will ask for, and the pitfalls seen in audit. Original editorial summaries — never the normative text, which remains its publishers’ property.

View all
ISO 22301:2019

Business continuity management systems — Requirements

The global reference for building, running and certifying a business continuity management system (BCMS). It states what an organisation must have in place — not how — and is the only text in the 223xx family against which an accredited body can issue a certificate.

ISO

ISO 22361:2022

Crisis management — Guidelines

The international reference for crisis management since it superseded the UK PAS 200. It cleanly separates incident (known procedure) from crisis (novel, ambiguous, high-stakes) and focuses on decision-making capability rather than on the plan.

ISO

ISO/IEC 27031:2011

Guidelines for information and communication technology readiness for business continuity (IRBC)

The bridge between business continuity and IT. It introduces ICT readiness for business continuity (IRBC) and the metrics that are now common currency: RTO, RPO, and degraded service level objectives.

ISO/IEC

Règlement (UE) 2022/2554 — DORA

Digital operational resilience for the financial sector

In force since 17 January 2025, DORA imposes a single digital operational resilience baseline on some twenty categories of EU financial entities. Five pillars: ICT risk governance and management, major incident reporting, resilience testing, third-party risk management, and cyber threat information sharing.

Union européenne

Directive (UE) 2022/2555 — NIS 2

Measures for a high common level of cybersecurity across the Union

NIS 2 substantially widens its predecessor's scope: eighteen sectors, essential and important entities, management liability and significant administrative fines. Article 21 explicitly requires business continuity and crisis management among the minimum measures.

Union européenne

BCI Good Practice Guidelines

Good Practice Guidelines for business continuity

The practitioner corpus, structured around the business continuity lifecycle: two management professional practices and four technical ones. Where ISO 22301 says what to do, the GPG says how to do it day to day, in practitioner language.

BCI

BCBS 195 / PSMOR (révisé 2021)

Principles for the Sound Management of Operational Risk

The twelve principles underpinning banking operational risk management worldwide. They structure the three lines of defence, the identification and assessment toolkit (RCSA, loss data collection, key risk indicators, scenario analysis), and the governance around them.

BCBS

BCBS 516 — Principes de résilience opérationnelle

Principles for Operational Resilience

The text that shifted the financial sector from process-based continuity to a logic of critical services and impact tolerance. Seven principles requiring identification of critical operations, mapping of the resources supporting them, and explicit tolerances.

BCBS

Compare two standards

The texts presented here are original editorial summaries of each requirement’s intent. They do not reproduce the normative text, which must be obtained from its publisher.

Method

How we work

Durations, not opinions

Every method taught produces a number that stands up in an audit: MTPD, RTO, impact tolerance, measured gap. A course that does not lead to a decision has no place in the catalogue.

Pitfalls before procedures

For every requirement we document the error that fails it in an audit. Confusing 6.1 with 8.2.3, aligning an RTO with the MTPD, calling a documentation review a “test”: those are the gaps that cost.

Files, not slides

Forty-five working templates, generated in the format you need and shipped with their instructions. You leave with the deliverable, not with a picture of it.

Diagnostic

Where do you actually stand?

Twenty questions, a score per dimension, and the three gaps that cost most in an audit. Immediate result, shareable by link.

Run a diagnostic
  • ISO 22301 diagnostic — 20 questions, 6 dimensions
  • DORA readiness diagnostic — 15 questions, 5 pillars
  • Operational resilience diagnostic — 12 questions

Insights

What we observe in the field

View all