731 901 601
Will your business survive a crisis? A business continuity plan in accordance with ISO 22301

Will your business survive a crisis? A business continuity plan in accordance with ISO 22301

Most companies know they should be prepared for crisis situations. However, few have a documented, tested and genuinely effective business continuity plan. ISO 22301 is a standard that turns declarations into a system – and allows the question of survival to be answered not by intuition, but by a concrete plan.

Business Continuity Plan – what it must contain and how to develop it

A Business Continuity Plan (BCP) is the central document of a business continuity management system. ISO 22301 specifies the elements it must contain in order to be effective – not only as a document, but as a practical crisis management tool.

The starting point is a Business Impact Analysis (BIA), which identifies the processes critical to the organisation’s survival and determines the maximum acceptable downtime (RTO) and the maximum acceptable data loss (RPO). The BIA forms the basis of the entire strategy – without it, the continuity plan is a collection of guesswork rather than a data-driven system. If you are just getting to grips with the principles of business continuity management, you may also wish to read the article ‘What happens when a company ceases to operate? ISO 22301 and business continuity management’, in which we explain the basic principles of the standard and the objectives of the system.

Based on the results of the BIA, business continuity strategies are developed – alternative methods for carrying out critical processes during an incident. These may be technical solutions (a backup data centre, cloud backup, system redundancy), organisational solutions (remote working, functions being taken over by another branch, emergency outsourcing) or a combination of both. The standard does not impose specific solutions – rather, it requires that strategies be appropriate to the identified threats and RTO/RPO targets.

The BCP itself must include: procedures for activating the plan (who decides, when and on what basis), the roles and responsibilities of key personnel, procedures for internal and external communication during an incident (including guidelines for informing customers, partners and the media), procedures for restoring critical processes in order of priority, and procedures for returning to normal operations once the incident has ended.

A key requirement of ISO 22301, which distinguishes it from mere document creation, is the testing of plans. The standard requires regular exercises and simulations – ranging from simple table-top exercises, through functional simulations, to full-scale emergency tests involving actual infrastructure. Test results must be analysed, and plans updated accordingly. A plan that has never been tested is a plan that will not work in a crisis.

The most common mistakes when establishing a business continuity management system

Companies establishing a business continuity management system for the first time tend to make similar mistakes. Being aware of these mistakes helps to avoid costly rectifications and speeds up the path to successful certification.

  • A BIA carried out only once and not updated – a business impact analysis reflects the state of the organisation at the time it is carried out. Changes to the structure, processes, IT systems and key suppliers must be reflected in an updated BIA. The standard requires regular review of all elements of the system.
  • Plans known only to the IT department – business continuity is not solely a technical issue. Plans must cover all critical business functions and be known to key staff in every department. Staff who have never familiarised themselves with the plan will not be able to implement it under the stress of a crisis.
  • No defined threshold for activating the plan – a business continuity plan must contain clear criteria for its activation. If the decision to activate the plan depends on a subjective assessment of the situation, this may lead to delays or a lack of response during a crisis. ISO 22301 requires documented incident management procedures, including criteria for escalation and activation of the BCP.
  • IT recovery plans without business process plans – restoring an IT system does not mean restoring a business process. The plan must describe not only how to restore the system, but also how the organisation operates during an outage and who carries out which tasks in emergency mode.
  • No testing or testing on paper only – this is the most common and most serious error. Table-top exercises are valuable, but they are no substitute for tests involving actual systems and staff. The standard requires the testing programme and its implementation to be documented, and auditors verify both that the tests were actually carried out and that their results were analysed and implemented.

A well-prepared business continuity management system involves not only documentation, but also practical procedures that prove effective in crisis situations. Find out how we help organisations implement the requirements of ISO 22301.

 

Read other posts

What energy data really matters in a business? (and what most businesses fail to measure)

What energy data really matters in a business? (and what most businesses fail to measure)

In many organisations, energy management is still based on bills and general monthly costs. read more
TISAX-certified companies are growing faster in the automotive sector. Coincidence or the norm?

TISAX-certified companies are growing faster in the automotive sector. Coincidence or the norm?

When a company first hears about TISAX, it is usually presented as a requirement. read more
Key GMP requirements – what must a pharmaceutical wholesaler comply with?

Key GMP requirements – what must a pharmaceutical wholesaler comply with?

Obtaining a licence for the wholesale distribution of medicinal products is only the beginning. read more
More posts