How to audit a continuity programme against ISO 22301, what auditors actually look for, and how to arrive at certification with no surprises.
A business continuity audit tests whether the capability an organisation claims on paper exists in practice. Resilience Guard delivers internal audits, gap assessments and certification readiness reviews against ISO 22301, drawing on senior practitioners who have sat on both sides of the audit table since 2014.
Not a traffic light slide. A findings register that separates nonconformities from opportunities, each finding tied to a clause and to evidence, with a prioritised, costed corrective action plan the board can act on.
Certification readiness in one line: if your last exercise, your internal audit and your management review all happened in the past twelve months and their actions are closed, the certification audit becomes an administrative event.
A structured, evidence based assessment of a business continuity programme against a defined reference, usually ISO 22301, the organisation's own policy, or a regulator's expectations. It examines documentation, interviews the people who would respond, and tests whether the claimed capability actually exists.
Leadership and evidence of life: a current business impact analysis, plans with named owners, a recent exercise with corrective actions closed, and management review minutes. A programme with a beautiful plan and no exercise record fails the first hour of a serious audit.
An internal audit is your own check, required by ISO 22301 clause 9.2, and can be delivered by an independent internal function or an external specialist such as Resilience Guard. Certification is a third party audit by an accredited certification body that results in an ISO 22301 certificate. A good internal audit six months before the certification audit removes most surprises.
At least annually for the programme as a whole, with a risk based rotation so that every critical site and activity is covered across the cycle, plus a focused audit after significant change or a real incident.
We deliver internal audits and certification readiness reviews against ISO 22301. Tell us your timeline and we will respond within 24 hours.
Book a consultation