731 901 601
Will your business survive a crisis? A business continuity plan in accordance with ISO 22301

Will your business survive a crisis? A business continuity plan in accordance with ISO 22301

Most companies know they should be prepared for crisis situations. However, few have a documented, tested and genuinely effective business continuity plan. ISO 22301 is a standard that turns declarations into a system – and allows the question of survival to be answered not by intuition, but by a concrete plan.

Business Continuity Plan – what it must contain and how to develop it

A Business Continuity Plan (BCP) is the central document of a business continuity management system. ISO 22301 specifies the elements it must contain in order to be effective – not only as a document, but as a practical crisis management tool.

The starting point is a Business Impact Analysis (BIA), which identifies the processes critical to the organisation’s survival and determines the maximum acceptable downtime (RTO) and the maximum acceptable data loss (RPO). The BIA forms the basis of the entire strategy – without it, the continuity plan is a collection of guesswork rather than a data-driven system. If you are just getting to grips with the principles of business continuity management, you may also wish to read the article ‘What happens when a company ceases to operate? ISO 22301 and business continuity management’, in which we explain the basic principles of the standard and the objectives of the system.

Based on the results of the BIA, business continuity strategies are developed – alternative methods for carrying out critical processes during an incident. These may be technical solutions (a backup data centre, cloud backup, system redundancy), organisational solutions (remote working, functions being taken over by another branch, emergency outsourcing) or a combination of both. The standard does not impose specific solutions – rather, it requires that strategies be appropriate to the identified threats and RTO/RPO targets.

The BCP itself must include: procedures for activating the plan (who decides, when and on what basis), the roles and responsibilities of key personnel, procedures for internal and external communication during an incident (including guidelines for informing customers, partners and the media), procedures for restoring critical processes in order of priority, and procedures for returning to normal operations once the incident has ended.

A key requirement of ISO 22301, which distinguishes it from mere document creation, is the testing of plans. The standard requires regular exercises and simulations – ranging from simple table-top exercises, through functional simulations, to full-scale emergency tests involving actual infrastructure. Test results must be analysed, and plans updated accordingly. A plan that has never been tested is a plan that will not work in a crisis.

The most common mistakes when establishing a business continuity management system

Companies establishing a business continuity management system for the first time tend to make similar mistakes. Being aware of these mistakes helps to avoid costly rectifications and speeds up the path to successful certification.

  • A BIA carried out only once and not updated – a business impact analysis reflects the state of the organisation at the time it is carried out. Changes to the structure, processes, IT systems and key suppliers must be reflected in an updated BIA. The standard requires regular review of all elements of the system.
  • Plans known only to the IT department – business continuity is not solely a technical issue. Plans must cover all critical business functions and be known to key staff in every department. Staff who have never familiarised themselves with the plan will not be able to implement it under the stress of a crisis.
  • No defined threshold for activating the plan – a business continuity plan must contain clear criteria for its activation. If the decision to activate the plan depends on a subjective assessment of the situation, this may lead to delays or a lack of response during a crisis. ISO 22301 requires documented incident management procedures, including criteria for escalation and activation of the BCP.
  • IT recovery plans without business process plans – restoring an IT system does not mean restoring a business process. The plan must describe not only how to restore the system, but also how the organisation operates during an outage and who carries out which tasks in emergency mode.
  • No testing or testing on paper only – this is the most common and most serious error. Table-top exercises are valuable, but they are no substitute for tests involving actual systems and staff. The standard requires the testing programme and its implementation to be documented, and auditors verify both that the tests were actually carried out and that their results were analysed and implemented.

A well-prepared business continuity management system involves not only documentation, but also practical procedures that prove effective in crisis situations. Find out how we help organisations implement the requirements of ISO 22301.

 

Read other posts

New cybersecurity obligations for businesses – what do you need to know?

New cybersecurity obligations for businesses – what do you need to know?

The NIS 2 Directive is not just a set of new legal obligations. Above all, it represents a shift in the way organisations think about cybersecurity. read more
ISO 22716 and the Cosmetics Regulation 1223/2009 – how does the standard support compliance with EU law?

ISO 22716 and the Cosmetics Regulation 1223/2009 – how does the standard support compliance with EU law?

Regulation (EC) No 1223/2009 of the European Parliament and of the Council on cosmetic products is the primary piece of legislation governing the cosmetics industry in the European Union. read more
Why should educational institutions implement ISO 9001?

Why should educational institutions implement ISO 9001?

The quality of education plays a key role in the development of societies. In an era of globalisation and growing competition, educational institutions – from nurseries and schools to universities – are increasingly focusing on the quality of their services. read more
More posts