5.2 The business continuity policy
The policy is the visible artefact of Clause 5, and it is usually the first document an auditor asks for. ISO 22301 requires the policy to be appropriate to the purpose of the organisation, to provide a framework for setting business continuity objectives, to include a commitment to satisfy applicable requirements, and to include a commitment to continual improvement of the BCMS. It must be documented, communicated within the organisation, and available to interested parties as appropriate.
A compliant policy is short, specific to the organisation, and signed by someone with real authority to commit resources to it. A weak policy is generic — the kind that could be printed for almost any company by changing the logo — and that genericness is itself a signal auditors are trained to notice.
5.3 Organizational roles, responsibilities and authorities
Top management must assign responsibility and authority for relevant roles, and communicate this both internally and to relevant interested parties. In practice, this means the BCMS needs an unambiguous answer to questions such as: who owns the BCMS overall, who can declare a disruption, who leads the response once one is declared, and who is authorised to invoke a continuity or recovery plan.
Common structural elements organisations put in place to satisfy this sub-clause include:
- A named BCMS owner or manager with defined authority over the management system itself.
- An incident or crisis management team structure, with defined roles (such as incident commander, communications lead, and functional leads for the areas most exposed to disruption).
- Deputies or delegates for key roles, so the structure does not fail if a single individual is unavailable when a disruption occurs.
- A clear escalation path from the point of first detection to the people authorised to make continuity decisions.
The brief for this article does not specify a fixed, universal team structure, and none should be assumed — the right structure depends on the organisation's size, sector and risk profile, and ISO 22301 deliberately leaves the exact shape to the organisation rather than prescribing one. What the standard does require is that whatever structure is chosen, it is documented, assigned to named individuals or roles, and known to the people who would need to act on it.
Practical impact on how the BCMS is run
Clause 5 shapes the rest of the system in tangible ways. Resourcing decisions in Clause 7 (Support) trace back to the commitment made here. The scope and objectives set in Clause 4 and Clause 6 need to be consistent with the policy. And the roles defined under 5.3 are the same people who, later, will be expected to act during Clause 8 (Operation) activities such as business impact analysis, risk assessment, and incident response.
Organisations that treat Clause 5 seriously tend to find the rest of the BCMS easier to build, because decisions about scope, resourcing and testing already have a mandate behind them. Organisations that treat it as a formality tend to find those same decisions contested or under-resourced later, when it is more disruptive to fix.
Common audit findings on Clause 5
Certification and internal audits repeatedly surface a similar pattern of issues around this clause:
- Policy without visible engagement: a signed policy exists, but interviews with staff or with top management itself reveal little awareness of its content or of how it connects to day-to-day decisions.
- No resourcing trail: the policy commits to "ensuring adequate resources," but there is no budget line, staffing allocation, or documented resourcing decision that supports the claim.
- Roles assigned on paper only: a RACI chart or org chart names roles, but the individuals named cannot describe their responsibilities when interviewed, or are unaware they hold the role at all.
- Policy not communicated: the policy exists on a shared drive but has never been actively communicated to staff, and there is no evidence of awareness activity.
- Generic, un-tailored policy: wording that is clearly templated and never adapted to the organisation's actual context, objectives or risk profile.
- Leadership commitment that stops at certification: strong engagement is visible in the run-up to the initial audit, but management review records and subsequent activity show attention dropping off afterwards.
- No link between top management and the incident response structure: the people named as BCMS leaders on paper are not the people who would actually be contacted if a real disruption occurred.
The common thread across all of these is a gap between documentation and reality. Auditors are specifically trained to probe for that gap — through interviews with people outside the compliance function, by asking for evidence rather than accepting assertions, and by cross-checking whether roles named in policy documents match what actually happens operationally.
How to close the gap between paper and practice
The organisations that pass Clause 5 audits comfortably tend to share a few habits: top management discusses business continuity at genuine management review meetings, not just before an audit; the policy is revisited and re-approved on a defined cycle rather than left static for years; roles are tested during exercises so people in them actually practise what they are responsible for; and resourcing decisions are documented at the point they are made, rather than reconstructed retrospectively for the auditor.
One recurring, practical obstacle is simply findability. As a BCMS matures, the policy, the roles matrix, management review minutes, and resourcing decisions accumulate across different documents, and demonstrating a consistent thread between them — the exact evidence an auditor is looking for — can become time-consuming to assemble by hand. This is where a tool like IgeraIndustria is useful in practice: it lets an organisation ask a direct question — such as who is authorised to invoke the continuity plan, or what the current business continuity policy commits to — and get an answer sourced directly from the organisation's own BCMS documents, with the exact source cited. That does not replace genuine leadership engagement, but it does make the evidence of that engagement much faster to locate and present.
Frequently asked questions
What is the difference between Clause 5.1 and Clause 5.2 in ISO 22301?
Clause 5.1 concerns the behaviour of top management — the actions and evidence that demonstrate real leadership and commitment to the BCMS. Clause 5.2 concerns a specific document, the business continuity policy, which is one output of that commitment but not the only evidence auditors expect to see.
Who counts as "top management" for the purposes of Clause 5?
ISO 22301 uses this term to mean the person or group of people who direct and control the organisation at the highest level relevant to the scope of the BCMS. The exact individual or committee varies by organisation, and it should be defined clearly within the BCMS documentation rather than left implicit.
Does the business continuity policy need to be a public document?
ISO 22301 requires the policy to be available to interested parties "as appropriate," which is a judgement the organisation makes rather than a blanket requirement to publish it externally. It must, however, be communicated internally within the organisation.
What evidence do auditors typically ask for to verify Clause 5?
Typical evidence includes the approved and dated policy document, management review minutes discussing business continuity, records of resourcing decisions, the roles and responsibilities matrix or org chart, and interviews with both top management and staff named in continuity roles to confirm awareness matches documentation.
Can a single person hold both the BCMS management role and an incident response role?
ISO 22301 does not prescribe a fixed organisational structure, so this depends on the size and complexity of the organisation. What matters to an auditor is that the roles are clearly defined, that authority is unambiguous, and that the structure works in practice — the specific staffing model is a decision for the organisation to justify against its own context.
This depends on the certification body's own criteria and the severity of the gap found, and it is not something that can be stated as a fixed rule here. Organisations preparing for certification or surveillance audits should discuss classification thresholds directly with their chosen certification body or a qualified consultant.
How often should the business continuity policy be reviewed?
ISO 22301 does not set a fixed review interval; it requires the policy to remain appropriate and to be reviewed as part of the organisation's management review process. Many organisations align this with their annual management review cycle, but the appropriate frequency should be defined in the organisation's own BCMS procedures.
Need to show an auditor exactly where your BCMS commits to a policy, a role or a resourcing decision? IgeraIndustria answers directly from your own documents, with the source cited.
Try it free for 14 days
Summary:
- Clause 5 has three parts: leadership and commitment (5.1), the business continuity policy (5.2), and organizational roles, responsibilities and authorities (5.3).
- Demonstrating leadership means observable behaviour — resourcing, integration into business processes, communication — not just a signed policy.
- The most common audit finding is a gap between what the policy and org chart say and what people actually know or do in practice.
- ISO 22301 deliberately does not prescribe a fixed incident response team structure; it requires whatever structure is chosen to be documented, assigned and known.
- This article is general guidance, not certification or legal advice — consult a qualified business continuity consultant or your chosen certification body for decisions specific to your organisation.
This article is for general informational purposes and does not constitute certification, legal or compliance advice. Requirements, interpretations and audit criteria can vary by certification body and by organisational context. Organisations preparing for ISO 22301 certification or audit should consult a qualified business continuity consultant or their chosen certification body directly. Reference standard: ISO 22301:2019, Security and resilience — Business continuity management systems — Requirements.
What is Igera and how does its technology work?
Igera provides AI-powered SaaS solutions based on RAG (Retrieval-Augmented Generation) that answer complex questions by securely indexing a company's own internal documents.
Do Igera's assistants hallucinate answers?
No. By limiting the model's knowledge base to the authorised documents uploaded by the client, Igera avoids fabricated information by design.
How is confidential company data protected?
All information is processed and stored on secure servers within the European Union, complying with strict encryption standards and GDPR.
Which sectors benefit from Igera's solutions?
Igera offers optimised verticals for property management (IgeraFincas), law firms (IgeraLegal), accounting firms (IgeraGestories), human resources (IgeraHR), hospitality (IgeraHospit) and industrial/regulatory compliance (IgeraIndustria).
Does it integrate with existing business systems?
Yes, Igera's tools are built to integrate via APIs and native connectors with the most widely used CRM, ERP and database systems in each sector.
The platform automatically detects the end user's query language and can respond in English, Spanish, Catalan, Portuguese, French and German.