6.2 Business continuity objectives and planning to achieve them
Clause 6.2 requires the organization to establish business continuity objectives at relevant functions and levels. The standard sets out that these objectives must be consistent with the business continuity policy, be measurable (if practicable), take into account applicable requirements, be monitored, be communicated, and be updated as appropriate.
Alongside the objectives themselves, the organization must determine, for each one, what will be done, what resources will be required, who will be responsible, when it will be completed, and how the results will be evaluated. In other words, an objective on its own — "improve our resilience" — is not sufficient; it needs a resourced, owned, dated plan attached to it before it can be considered to meet clause 6.2.
What a well-formed clause 6.2 objective looks like
A useful objective is specific enough to be monitored and traced back to the BCMS's intended outcomes: it names what will change, who is responsible, what resources are committed, and the date by which it will be evaluated. A vague statement of intent with no owner, no resource commitment and no review date does not meet the requirement, however well-intentioned it is — and it is precisely this kind of gap that auditors flag most often under 6.2.
6.3 Planning of changes to the BCMS
Clause 6.3 requires that when the organization determines the need for changes to the business continuity management system, those changes are carried out in a planned manner. The clause does not prescribe a specific change-management procedure, but it does establish the principle: BCMS changes — a new business unit brought into scope, a restructured continuity team, a change of top management sponsor, a new critical supplier — should be deliberate and documented, not ad hoc.
In practice, this means significant changes to the BCMS should prompt a review of whether they affect the risks and opportunities identified under 6.1, whether existing objectives under 6.2 are still appropriate, and whether other parts of the system — scope, policy, roles — need to be revisited as a result.
Why clause 6 is not the business impact analysis
The single most important conceptual point about clause 6 is what it deliberately does not contain: the detailed, activity-by-activity business impact analysis (BIA) and risk assessment that most people associate with "business continuity planning." That work — identifying prioritized activities, determining their recovery time objectives and recovery point objectives, and assessing the specific threats and vulnerabilities that could disrupt them — sits in clause 8, Operation, specifically under 8.2 (business impact analysis and risk assessment).
Clause 6 comes first in the standard's structure for a reason: it establishes the management-system-level foundation — what risks threaten the BCMS itself, what the organization is trying to achieve with it, and how it will evolve — before the organization moves into the detailed operational analysis of clause 8 that determines which specific business activities and resources actually need continuity arrangements. Skipping straight to a BIA without this planning foundation in place is a common shortcut that tends to produce a BCMS that looks thorough on paper but lacks a clear, documented rationale for why it prioritizes what it prioritizes.
| Subclause |
What it requires |
Typical evidence |
| 6.1 |
Determine and plan actions to address BCMS-level risks and opportunities |
BCMS risk and opportunity log linked to clause 4 context/interested parties |
| 6.2 |
Set measurable business continuity objectives and plans to achieve them |
Objectives register with owners, resources, dates, evaluation method |
| 6.3 |
Carry out BCMS changes in a planned manner |
Change record showing review of risks, objectives and scope impact |
Common audit findings on clause 6
Recurring gaps seen when clause 6 is assessed during an ISO 22301 audit:
- 6.1 — Risks and opportunities not linked to clause 4 context: a risk log exists, but there is no visible connection between it and the internal/external issues or interested-party requirements identified earlier in the BCMS.
- 6.1 — Clause 6 conflated with the BIA: teams document operational, activity-level risks here instead of BCMS-level risks, duplicating or pre-empting the work that belongs in clause 8.2.
- 6.2 — Objectives without a plan attached: an objective is stated, but there is no documented resource, owner, or completion date behind it.
- 6.2 — Objectives that are not measurable: aspirational language with no indicator or target that could be monitored over time.
- 6.3 — Changes made without revisiting the BCMS: a new site, team, or supplier is added to scope without any documented review of whether it affects the risks, opportunities, or objectives already established.
Frequently asked questions about ISO 22301 clause 6
Is clause 6 the same as the business impact analysis?
No. Clause 6 plans the BCMS at a management-system level — risks and opportunities affecting the system itself, business continuity objectives, and how BCMS changes are planned. The business impact analysis and the detailed risk assessment of specific activities and resources are addressed later, under clause 8.2, once the foundation from clause 6 is in place.
Does ISO 22301 specify how to assess risks and opportunities under 6.1?
The standard sets out what clause 6.1 must achieve — determining risks and opportunities linked to context and interested parties, and planning actions to address them — without mandating a specific methodology. Organizations typically use whatever risk management approach already fits their existing management systems, applied at the BCMS level.
What must a business continuity objective include to satisfy clause 6.2?
The objective itself should be consistent with the business continuity policy and measurable where practicable. Alongside it, the organization must document what will be done, what resources are needed, who is responsible, the completion timeframe, and how the results will be evaluated.
What counts as a "change to the BCMS" under clause 6.3?
The standard does not provide an exhaustive list, but the principle is that any change the organization determines is needed to the management system — rather than to a single operational plan — should be carried out in a planned way, with consideration given to how it may affect the risks, opportunities and objectives already established.
Because it is easy to skip past conceptually: teams are often eager to get to the "real" continuity work of the BIA and recovery plans, and treat clause 6 as a formality. The result is objectives with no owner or date, or a risk log that duplicates clause 8.2 content instead of addressing the BCMS itself — both of which are straightforward for an auditor to spot.
How does clause 6 connect to clause 8 in practice?
Clause 6 establishes the BCMS-level risks, opportunities and objectives that give the rest of the system its direction. Clause 8 then operationalizes business continuity through the business impact analysis, risk assessment, strategy selection and procedures. An auditor will often check that the objectives and priorities set in clause 6 are visibly reflected in the scope and focus of the clause 8 work that follows.
Do business continuity objectives need to be reviewed every year?
ISO 22301 requires objectives to be monitored and updated as appropriate, without prescribing a fixed review interval. Most organizations align this review with their existing management review cycle, but the exact frequency depends on the organization's own procedures and should be defined internally rather than assumed from the standard's wording.
Where IgeraIndustria fits
Keeping clause 6 evidence — the risk and opportunity log, the objectives register with owners and dates, and the record of planned BCMS changes — traceable and up to date is largely a documentation discipline problem. IgeraIndustria is AI that answers directly from a company's own BCMS documents, citing the exact source, so a team preparing for an audit can ask, for example, which objectives are still missing an owner or a completion date, and get an answer traced back to the actual register rather than a guess.
Disclaimer: This article is for general information only and does not constitute certification or legal advice. Requirements for certification, interpretation of specific clauses, and audit outcomes can vary by certification body and by organization. For guidance on your specific situation, consult a qualified business continuity consultant or an accredited certification body.
Struggling to keep BCMS objectives, risk logs and change records aligned?
IgeraIndustria answers directly from your own business continuity documentation, citing the exact source, instead of leaving clause 6 evidence scattered across spreadsheets.
View ISO 22301 solution
ISO 22301 business continuity series · Updated 2026-09-25