Lesson16 min

ISO 22301: what the standard actually requires

A standard of requirements, not method

ISO 22301 systematically says "the organization shall" and never says "how". That is deliberate: the standard must fit a forty-bed clinic as well as a hundred-thousand-person banking group. The "how" lives in ISO 22313, its application guide.

That characteristic has a practical consequence: two organisations can be certified with radically different arrangements, as long as each demonstrates it meets the requirement.

The ten clauses

Clauses 1 to 3 are formal — scope, references, terms. The system starts at clause 4.

ClauseRequirementWhat the auditor looks for
4 ContextIssues, interested parties, scopeA justified scope, argued exclusions
5 LeadershipPolicy, commitment, rolesA real trade-off where continuity carried weight
6 PlanningRisks to the system, objectivesMeasurable objectives, not intentions
7 SupportResources, competence, documentationPlans accessible outside the information system
8 OperationBIA, risks, strategies, plans, exercisesThe complete chain, with no missing link
9 PerformanceIndicators, internal audit, reviewDecisions in the management review
10 ImprovementNonconformities, continual improvementA corrective action whose effectiveness was verified

The distinction that traps everybody

Clause 6.1 — risks and opportunities: these are risks to the management system. Examples: the continuity manager is a team of one and is retiring; the budget is rolled over at zero; a merger makes the scope obsolete.

Clause 8.2.3 — risk assessment: these are risks of disruption to prioritised activities. Examples: fire at the main site, ransomware, failure of a sole-source supplier.

Both are required, and they do not overlap. The classic error fills 6.1 with a register of disaster scenarios, which leaves clause 6.1 formally empty.

Integration with other systems

The Harmonized Structure — the former Annex SL — imposes the same ten-clause architecture on ISO 9001, ISO 14001, ISO/IEC 27001, ISO 45001 and ISO 22301.

In practice, clauses 4, 5, 7, 9 and 10 are nearly superimposable across standards. An organisation already certified to ISO/IEC 27001 can reuse its context analysis, its documentation system, its internal audit programme and its management review. Only clauses 6 and 8 demand genuinely specific work.

In practice that cuts the effort by roughly a third — and it is the argument that most often unlocks a certification budget.

Key takeaways

  • The Harmonized Structure makes the BCMS integrable with other systems
  • BIA and risk assessment are two distinct requirements
  • Clause 6.1 covers risk to the system, not disaster risk