Industry

ISO 22301 Internal Audit Checklist (Downloadable)

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 22301 Internal Audit Checklist (Downloadable)
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

Free downloadable ISO 22301 internal audit checklist covering all 7 mandatory clauses (4-10) — practical, self-assessment ready before certification.

✓ Citing current regulationsSee detailed guide below ↓

ISO 22301 Internal Audit Checklist (Downloadable)

A useful internal audit checklist walks through all seven mandatory clauses of ISO 22301:2019 — clauses 4 to 10 — verifying that context, leadership, planning, support, operation, performance evaluation, and improvement are each backed by documented evidence. Used consistently before certification or surveillance audits, it turns a vague sense of "we're probably ready" into a structured, defensible self-assessment. This article gives you that checklist, organised clause by clause, plus the mistakes that most often surface during real audits.

Preparing for an ISO 22301 audit — whether it's your first certification audit or a routine surveillance visit — is rarely about writing new documentation. It's about proving that the business continuity management system (BCMS) you already built actually runs the way your documents say it does. Auditors are not looking for perfect prose; they are looking for consistency between policy, records, and practice. This checklist is built to help a BCMS manager find the gaps before the auditor does.

Why a structured checklist matters more than a document review

Most internal BCMS failures aren't caused by missing policies — they're caused by policies that exist on paper but aren't reflected in day-to-day evidence: a business impact analysis (BIA) that was never updated after a process changed, a continuity plan that references a supplier no longer under contract, or exercise records that were never signed off. A clause-by-clause checklist forces you to look for that evidence directly, rather than re-reading the standard and assuming compliance.

ISO 22301:2019 is structured around the same high-level structure (HLS) as other management system standards, which means the checklist below will look familiar if you've prepared for ISO 9001 or ISO 27001 audits. The content, however, is entirely continuity-specific.

The checklist: all 7 mandatory clauses (4-10)

Clause 4 — Context of the organisation

  • ☐ Internal and external issues relevant to the BCMS are identified and documented, and reviewed periodically.
  • ☐ Interested parties (regulators, customers, employees, supply chain) and their requirements are identified and kept current.
  • ☐ The scope of the BCMS is documented, justified, and matches what is actually being audited — no undocumented exclusions.
  • ☐ Products, services, activities, and locations covered by the scope are explicitly listed, not implied.

Clause 5 — Leadership

  • ☐ Top management commitment to the BCMS is demonstrable — minutes, sign-offs, resourcing decisions, not just a signed policy.
  • ☐ The business continuity policy is approved, dated, communicated, and available to relevant staff.
  • ☐ Roles, responsibilities, and authorities for the BCMS are assigned and documented (an org chart alone is not sufficient evidence).
  • ☐ Management review of the BCMS has taken place, at a defined interval, with recorded inputs and outputs.

Clause 6 — Planning

  • ☐ Risks and opportunities affecting the BCMS are identified, assessed, and have documented treatment actions.
  • ☐ Business continuity objectives are documented, measurable, and traceable to the policy.
  • ☐ Plans exist to achieve those objectives, with owners and target dates.
  • ☐ Where changes to the BCMS are planned, the impact of the change has been considered before implementation.

Clause 7 — Support

  • ☐ Resources (people, budget, technology) needed for the BCMS are identified and allocated.
  • ☐ Competence of personnel with BCMS responsibilities is defined, and evidence of training or experience is kept.
  • ☐ Awareness activities have reached relevant staff — not just the BCMS team — and can be evidenced.
  • ☐ Internal and external communication processes for continuity matters are documented.
  • ☐ Documented information is controlled: version history, approval status, and retention are consistent across policies, the BIA, and continuity plans.

Clause 8 — Operation

  • ☐ Operational planning and control processes are documented and being followed in practice.
  • ☐ The business impact analysis (BIA) is current, covers all in-scope activities, and identifies recovery time objectives (RTOs) and priorities.
  • ☐ A risk assessment specific to continuity (distinct from a general enterprise risk register) has been carried out and is up to date.
  • ☐ Business continuity strategies and solutions are documented and justified against the BIA findings.
  • ☐ Business continuity plans exist for in-scope activities, are accessible to those who need them, and reference current contacts, suppliers, and resources.
  • ☐ An exercise and testing programme is in place, with records of what was tested, when, and what was learned.
  • ☐ Evaluation of continuity documentation happens after exercises and after any real invocation, with resulting updates recorded.

Clause 9 — Performance evaluation

  • ☐ Monitoring and measurement of the BCMS is defined — what is measured, how, and how often.
  • ☐ Internal audits are planned, scheduled, and executed against a documented audit programme.
  • ☐ Internal audit records — findings, evidence reviewed, auditor competence — are retained and traceable.
  • ☐ Management review inputs include audit results, exercise outcomes, and changes in context, not only a status update.

Clause 10 — Improvement

  • ☐ Nonconformities are logged, root-caused, and corrective actions tracked to closure — from audits, exercises, or real incidents alike.
  • ☐ Evidence exists that corrective actions were verified as effective, not just marked "closed."
  • ☐ Continual improvement of the BCMS is demonstrable over time — objectives, plans, or documentation that have measurably evolved.

Practical impact: what this checklist actually changes

Running through these items before an audit does three concrete things. First, it surfaces gaps while there's still time to close them — a missing management review, an outdated supplier list in a continuity plan — rather than during the audit itself, when a nonconformity gets written up. Second, it forces cross-referencing between documents: the BIA should drive the continuity strategies, the strategies should drive the plans, and the plans should be what gets exercised. Auditors specifically look for that thread, and it breaks more often than most BCMS managers expect. Third, it gives you a defensible trail of self-assessment, which auditors and certification bodies generally view favourably — it shows the BCMS is being managed, not just maintained on paper.

Common mistakes found during ISO 22301 audits

  • BIA and continuity plans drift apart. The BIA gets updated after a process review, but the continuity plans referencing it don't — auditors will cross-check RTOs between the two.
  • Exercises happen but aren't evaluated. A tabletop or simulation is run, but there's no record of lessons learned or resulting document updates — which makes Clause 8's evaluation requirement hard to evidence.
  • Internal audits cover the BCMS superficially. A single internal audit that checks "does the policy exist" without sampling actual operational evidence rarely satisfies Clause 9 in a certification audit.
  • Corrective actions are closed without verification. A nonconformity gets an action assigned and marked done, but nobody checks whether the root cause was actually addressed.
  • Scope statements don't match reality. A location, subsidiary, or process quietly falls outside what's actually being managed under the BCMS, but the documented scope was never updated to reflect it.

Finding the evidence, faster

The hardest part of this checklist is rarely knowing what to check — it's finding the evidence quickly enough to check it. A BIA update from eighteen months ago, a continuity plan revision, last year's internal audit report, and the minutes from a management review are often scattered across shared drives, email threads, and different document owners. This is where IgeraIndustria fits naturally into audit preparation: it lets a BCMS manager ask a direct question — "what was the RTO for the order processing system in the last BIA?" or "when was the supplier continuity plan for our logistics partner last updated?" — and get an answer sourced directly from the company's own BCMS documents, with the exact document and section cited. Instead of manually searching through folders before every audit cycle, the standard, the BIA, the continuity plans, and the audit history become instantly searchable, with a verifiable source for every answer.

Frequently asked questions

What are the 7 mandatory clauses of ISO 22301:2019?

Clauses 4 through 10: Context of the organisation, Leadership, Planning, Support, Operation, Performance evaluation, and Improvement. Clauses 1-3 (scope, normative references, terms and definitions) are introductory and not themselves audited as requirements.

How often should an internal ISO 22301 audit be carried out?

The standard requires internal audits "at planned intervals," which most organisations interpret as at least annually, often aligned with the certification or surveillance audit cycle. The exact frequency should be defined in your own audit programme, based on the size and risk profile of the BCMS.

Is a business impact analysis (BIA) mandatory under ISO 22301?

Yes. The BIA sits within Clause 8 (Operation) and underpins recovery time objectives and continuity strategy. Auditors will typically ask to see how recent it is and how its findings connect to your continuity plans.

What's the difference between a certification audit and a surveillance audit?

A certification audit is the initial, full assessment against all clauses before certification is granted. Surveillance audits happen at defined intervals afterwards (commonly annually) and typically sample a subset of clauses and processes rather than reviewing everything each time.

Can this checklist replace a formal internal audit?

No. It's a self-assessment aid to prepare for one. A conformant internal audit under Clause 9 needs a documented programme, defined audit criteria, competent auditors, and retained records — this checklist helps you get ready for that process, not substitute it.

What happens if a nonconformity is found during the certification audit?

Depending on severity (minor or major), the certification body will typically require a corrective action plan within a set timeframe before certification is issued or maintained. Preparing with a checklist like this one reduces the likelihood of major findings.

Does ISO 22301 apply only to large organisations?

No. The standard is scalable and applies to organisations of any size or sector; the depth of documentation and formality of processes should be proportionate to the organisation's size, complexity, and risk exposure.

Disclaimer: This checklist is intended as a practical self-assessment aid and does not constitute certification, legal, or professional advice. ISO 22301 certification decisions, audit findings, and compliance determinations should always be made in consultation with a qualified business continuity consultant or an accredited certification body.
#ISO 22301 audit checklist#ISO 22301 internal audit#business continuity management system audit#ISO 22301 clauses 4-10#BCMS audit preparation#business impact analysis audit#ISO 22301 certification audit#downloadable compliance checklist

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network