ISO 22301: what the standard actually requires
A standard of requirements, not method
ISO 22301 systematically says "the organization shall" and never says "how". That is deliberate: the standard must fit a forty-bed clinic as well as a hundred-thousand-person banking group. The "how" lives in ISO 22313, its application guide.
That characteristic has a practical consequence: two organisations can be certified with radically different arrangements, as long as each demonstrates it meets the requirement.
The ten clauses
Clauses 1 to 3 are formal — scope, references, terms. The system starts at clause 4.
| Clause | Requirement | What the auditor looks for |
|---|---|---|
| 4 Context | Issues, interested parties, scope | A justified scope, argued exclusions |
| 5 Leadership | Policy, commitment, roles | A real trade-off where continuity carried weight |
| 6 Planning | Risks to the system, objectives | Measurable objectives, not intentions |
| 7 Support | Resources, competence, documentation | Plans accessible outside the information system |
| 8 Operation | BIA, risks, strategies, plans, exercises | The complete chain, with no missing link |
| 9 Performance | Indicators, internal audit, review | Decisions in the management review |
| 10 Improvement | Nonconformities, continual improvement | A corrective action whose effectiveness was verified |
The distinction that traps everybody
Clause 6.1 — risks and opportunities: these are risks to the management system. Examples: the continuity manager is a team of one and is retiring; the budget is rolled over at zero; a merger makes the scope obsolete.
Clause 8.2.3 — risk assessment: these are risks of disruption to prioritised activities. Examples: fire at the main site, ransomware, failure of a sole-source supplier.
Both are required, and they do not overlap. The classic error fills 6.1 with a register of disaster scenarios, which leaves clause 6.1 formally empty.
Integration with other systems
The Harmonized Structure — the former Annex SL — imposes the same ten-clause architecture on ISO 9001, ISO 14001, ISO/IEC 27001, ISO 45001 and ISO 22301.
In practice, clauses 4, 5, 7, 9 and 10 are nearly superimposable across standards. An organisation already certified to ISO/IEC 27001 can reuse its context analysis, its documentation system, its internal audit programme and its management review. Only clauses 6 and 8 demand genuinely specific work.
In practice that cuts the effort by roughly a third — and it is the argument that most often unlocks a certification budget.
Key takeaways
- The Harmonized Structure makes the BCMS integrable with other systems
- BIA and risk assessment are two distinct requirements
- Clause 6.1 covers risk to the system, not disaster risk