ISO 22301 Business Continuity Management Systems

Confirms that an organisation can keep its critical activities running — or restore them quickly — through disruption such as disaster, outage or system failure.

ITS own scheme

This standard is not covered by our IAS or UAF accreditation scopes. ITS certifies it under its own scheme. See our accreditations →

What this certification proves

ISO 22301 is not a certificate that incidents will not happen. They will. What it certifies is that you have decided in advance what gets restored first, and have actually rehearsed doing it.

Two things carry the standard. The first is the business impact analysis (BIA) — measuring, in numbers, how much damage each hour of downtime does to each activity. Without it, priorities in a crisis are decided by whoever shouts loudest. The second is exercising. A plan that has never been tested does not work when it is needed; people cannot be reached, the backup will not restore, the alternate site has no network.

An audit does not weigh the plan. It looks for exercise records and evidence that the plan was changed because of what the exercise revealed.

Who this is for

  • Finance, telecoms, logistics and public services where stopping is costly
  • Data centre and cloud operators
  • Organisations whose customers require a business continuity plan (BCP)
  • Organisations under regulatory continuity obligations

🌱 How this relates to ESG

G Governance

Maps onto the G (Governance) pillar. Governance in ESG covers enterprise risk management, and continuity is the «crisis response» part of it.

  • Korea's K-ESG guideline, G domain «risk management» — asks whether a crisis response framework exists and operates. The certificate and exercise records answer it
  • Regulated industries — finance, telecoms and energy supervisors require business continuity planning directly; certification is evidence of compliance
  • Customer due diligence almost always includes «what happens if you stop supplying us». This is one of the most commonly requested items from large buyers
  • Protecting employment through disruption touches S as well, but what the standard actually governs is the organisation's risk structure, so it sits under G

What certification gives you

How the requirements are structured

This is the overall shape of what the standard asks for. Working through it in this order is a sensible way to prepare.

ISO 22301Business Continuity Management SystemsP · 조항 4 · 5 · 6PlanSet the scope,continuity policy…D · 조항 8DoRun the BIA, choosestrategies, write…C · 조항 9CheckEvaluate exerciseresults; audit…A · 조항 10ActFix the plan wherethe exercise showed…
계획 → 실행 → 점검 → 개선이 한 번으로 끝나지 않고 계속 돕니다. 심사에서 보는 것도 «이 바퀴가 실제로 도는가» 입니다.
ClauseTitleIn plain terms
4ContextIdentify what must be protected — critical products and services — plus legal duties, and set the scope.
5LeadershipTop management sets the continuity policy and assigns authority.
6PlanningAddress risks and set business continuity objectives.
7SupportPeople, budget, contact structures, training and documented information.
8OperationBusiness impact analysis and risk assessment, continuity strategies, incident response structure, plans and procedures, and exercising. The heart of the standard.
9Performance evaluationMeasure whether exercises met the target times; audit internally and review.
10ImprovementCorrect what exercises and real incidents exposed.

※ This is a summary written to help you, not the text of the standard. Please refer to the published standard for the exact requirements.

Before you apply, please check

Having these in place makes the audit considerably smoother. If you are not ready yet, you are still welcome to get in touch — we will set out what to do first, with a timeline.

  • Have you completed a business impact analysis showing what each hour of downtime costs, activity by activity?
  • Are recovery time objectives (RTO) and recovery point objectives (RPO) set as numbers for each activity?
  • Is the emergency contact list current? Leavers still on it means it will fail when used
  • Is there a business continuity plan that names deputies for when the primary person is unavailable?
  • 🔴 Have you run at least one exercise and recorded the result? This is what auditors look at first
  • Have you carried out at least one internal audit yourselves? (required before the audit)
  • Have you held a management review and kept the minutes?
  • Are the alternate site, alternate staff and backup data actually usable, verified rather than assumed?
See the 8-step certification process →

You can apply for ISO 22301 certification here

Tell us your organisation’s size and the standards you need, and we will send you the audit duration and a fee proposal. You are free to decide after seeing it.

Tel 02-786-9242Email info@itscert.or.krFax 02-6940-9317

※ ITS Certification Body does not provide management system consultancy. Auditing and consultancy must remain separate. What we can do is explain the certification process and what you need to have in place.

Which audit division handles this

Audits against this standard are carried out by our 정보보안심사본부. See the organisation chart →