
Most companies know they should be prepared for crisis situations. However, few have a documented, tested and genuinely effective business continuity plan. ISO 22301 is a standard that turns declarations into a system – and allows the question of survival to be answered not by intuition, but by a concrete plan.
A Business Continuity Plan (BCP) is the central document of a business continuity management system. ISO 22301 specifies the elements it must contain in order to be effective – not only as a document, but as a practical crisis management tool.
The starting point is a Business Impact Analysis (BIA), which identifies the processes critical to the organisation’s survival and determines the maximum acceptable downtime (RTO) and the maximum acceptable data loss (RPO). The BIA forms the basis of the entire strategy – without it, the continuity plan is a collection of guesswork rather than a data-driven system. If you are just getting to grips with the principles of business continuity management, you may also wish to read the article ‘What happens when a company ceases to operate? ISO 22301 and business continuity management’, in which we explain the basic principles of the standard and the objectives of the system.
Based on the results of the BIA, business continuity strategies are developed – alternative methods for carrying out critical processes during an incident. These may be technical solutions (a backup data centre, cloud backup, system redundancy), organisational solutions (remote working, functions being taken over by another branch, emergency outsourcing) or a combination of both. The standard does not impose specific solutions – rather, it requires that strategies be appropriate to the identified threats and RTO/RPO targets.
The BCP itself must include: procedures for activating the plan (who decides, when and on what basis), the roles and responsibilities of key personnel, procedures for internal and external communication during an incident (including guidelines for informing customers, partners and the media), procedures for restoring critical processes in order of priority, and procedures for returning to normal operations once the incident has ended.
A key requirement of ISO 22301, which distinguishes it from mere document creation, is the testing of plans. The standard requires regular exercises and simulations – ranging from simple table-top exercises, through functional simulations, to full-scale emergency tests involving actual infrastructure. Test results must be analysed, and plans updated accordingly. A plan that has never been tested is a plan that will not work in a crisis.

Companies establishing a business continuity management system for the first time tend to make similar mistakes. Being aware of these mistakes helps to avoid costly rectifications and speeds up the path to successful certification.
A well-prepared business continuity management system involves not only documentation, but also practical procedures that prove effective in crisis situations. Find out how we help organisations implement the requirements of ISO 22301.