ISO 22301 Internal Audit Checklist (Downloadable)
A useful internal audit checklist walks through all seven mandatory clauses of ISO 22301:2019 — clauses 4 to 10 — verifying that context, leadership, planning, support, operation, performance evaluation, and improvement are each backed by documented evidence. Used consistently before certification or surveillance audits, it turns a vague sense of "we're probably ready" into a structured, defensible self-assessment. This article gives you that checklist, organised clause by clause, plus the mistakes that most often surface during real audits.
Preparing for an ISO 22301 audit — whether it's your first certification audit or a routine surveillance visit — is rarely about writing new documentation. It's about proving that the business continuity management system (BCMS) you already built actually runs the way your documents say it does. Auditors are not looking for perfect prose; they are looking for consistency between policy, records, and practice. This checklist is built to help a BCMS manager find the gaps before the auditor does.
Why a structured checklist matters more than a document review
Most internal BCMS failures aren't caused by missing policies — they're caused by policies that exist on paper but aren't reflected in day-to-day evidence: a business impact analysis (BIA) that was never updated after a process changed, a continuity plan that references a supplier no longer under contract, or exercise records that were never signed off. A clause-by-clause checklist forces you to look for that evidence directly, rather than re-reading the standard and assuming compliance.
ISO 22301:2019 is structured around the same high-level structure (HLS) as other management system standards, which means the checklist below will look familiar if you've prepared for ISO 9001 or ISO 27001 audits. The content, however, is entirely continuity-specific.
The checklist: all 7 mandatory clauses (4-10)
Clause 4 — Context of the organisation
- ☐ Internal and external issues relevant to the BCMS are identified and documented, and reviewed periodically.
- ☐ Interested parties (regulators, customers, employees, supply chain) and their requirements are identified and kept current.
- ☐ The scope of the BCMS is documented, justified, and matches what is actually being audited — no undocumented exclusions.
- ☐ Products, services, activities, and locations covered by the scope are explicitly listed, not implied.
Clause 5 — Leadership
- ☐ Top management commitment to the BCMS is demonstrable — minutes, sign-offs, resourcing decisions, not just a signed policy.
- ☐ The business continuity policy is approved, dated, communicated, and available to relevant staff.
- ☐ Roles, responsibilities, and authorities for the BCMS are assigned and documented (an org chart alone is not sufficient evidence).
- ☐ Management review of the BCMS has taken place, at a defined interval, with recorded inputs and outputs.
Clause 6 — Planning
- ☐ Risks and opportunities affecting the BCMS are identified, assessed, and have documented treatment actions.
- ☐ Business continuity objectives are documented, measurable, and traceable to the policy.
- ☐ Plans exist to achieve those objectives, with owners and target dates.
- ☐ Where changes to the BCMS are planned, the impact of the change has been considered before implementation.
Clause 7 — Support
- ☐ Resources (people, budget, technology) needed for the BCMS are identified and allocated.
- ☐ Competence of personnel with BCMS responsibilities is defined, and evidence of training or experience is kept.
- ☐ Awareness activities have reached relevant staff — not just the BCMS team — and can be evidenced.
- ☐ Internal and external communication processes for continuity matters are documented.
- ☐ Documented information is controlled: version history, approval status, and retention are consistent across policies, the BIA, and continuity plans.
Clause 8 — Operation
- ☐ Operational planning and control processes are documented and being followed in practice.
- ☐ The business impact analysis (BIA) is current, covers all in-scope activities, and identifies recovery time objectives (RTOs) and priorities.
- ☐ A risk assessment specific to continuity (distinct from a general enterprise risk register) has been carried out and is up to date.
- ☐ Business continuity strategies and solutions are documented and justified against the BIA findings.
- ☐ Business continuity plans exist for in-scope activities, are accessible to those who need them, and reference current contacts, suppliers, and resources.
- ☐ An exercise and testing programme is in place, with records of what was tested, when, and what was learned.
- ☐ Evaluation of continuity documentation happens after exercises and after any real invocation, with resulting updates recorded.
Clause 9 — Performance evaluation
- ☐ Monitoring and measurement of the BCMS is defined — what is measured, how, and how often.
- ☐ Internal audits are planned, scheduled, and executed against a documented audit programme.
- ☐ Internal audit records — findings, evidence reviewed, auditor competence — are retained and traceable.
- ☐ Management review inputs include audit results, exercise outcomes, and changes in context, not only a status update.
Clause 10 — Improvement
- ☐ Nonconformities are logged, root-caused, and corrective actions tracked to closure — from audits, exercises, or real incidents alike.
- ☐ Evidence exists that corrective actions were verified as effective, not just marked "closed."
- ☐ Continual improvement of the BCMS is demonstrable over time — objectives, plans, or documentation that have measurably evolved.