Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Business Continuity Audit and ISO 22301 Readiness | Resilience Guard
Home  ›  Consulting  ›  Business continuity audit
The proof

The business continuity audit

How to audit a continuity programme against ISO 22301, what auditors actually look for, and how to arrive at certification with no surprises.

A business continuity audit tests whether the capability an organisation claims on paper exists in practice. Resilience Guard delivers internal audits, gap assessments and certification readiness reviews against ISO 22301, drawing on senior practitioners who have sat on both sides of the audit table since 2014.

What a rigorous audit covers

  • Governance and leadership. Policy, objectives, resources and evidence that senior management owns the programme, not just signs it.
  • Analysis. A business impact analysis and risk assessment that are current, approved and actually drive the strategies chosen.
  • Plans and procedures. Continuity plans that are executable, owned, version controlled and consistent with the analysis.
  • Competence and awareness. Whether the people named in the plans know their roles and have been trained and exercised in them.
  • Exercising and testing. An exercise programme with results, corrective actions and closure evidence, not a single annual walkthrough.
  • Performance evaluation and improvement. Internal audit, management review and a living corrective action log, clauses 9 and 10 of the standard.

The output you should demand

Not a traffic light slide. A findings register that separates nonconformities from opportunities, each finding tied to a clause and to evidence, with a prioritised, costed corrective action plan the board can act on.

Certification readiness in one line: if your last exercise, your internal audit and your management review all happened in the past twelve months and their actions are closed, the certification audit becomes an administrative event.

Related
Frequently asked questions
What is a business continuity audit?

A structured, evidence based assessment of a business continuity programme against a defined reference, usually ISO 22301, the organisation's own policy, or a regulator's expectations. It examines documentation, interviews the people who would respond, and tests whether the claimed capability actually exists.

What do auditors look for first?

Leadership and evidence of life: a current business impact analysis, plans with named owners, a recent exercise with corrective actions closed, and management review minutes. A programme with a beautiful plan and no exercise record fails the first hour of a serious audit.

What is the difference between an internal audit and certification?

An internal audit is your own check, required by ISO 22301 clause 9.2, and can be delivered by an independent internal function or an external specialist such as Resilience Guard. Certification is a third party audit by an accredited certification body that results in an ISO 22301 certificate. A good internal audit six months before the certification audit removes most surprises.

How often should we audit?

At least annually for the programme as a whole, with a risk based rotation so that every critical site and activity is covered across the cycle, plus a focused audit after significant change or a real incident.

Start the conversation

Know where you stand before the auditor tells you.

We deliver internal audits and certification readiness reviews against ISO 22301. Tell us your timeline and we will respond within 24 hours.

Book a consultation
All consultations are treated with strict confidentiality.