Industry

ISO 22301 Clause 6: Planning — Risks, Opportunities, Business Continuity Objectives and Planning for Change

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 22301 Clause 6: Planning — Risks, Opportunities, Business Continuity Objectives and Planning for Change
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

ISO 22301 clause 6 explained: planning risks/opportunities, business continuity objectives and BCMS change — and why it isn't the BIA yet.

✓ Citing current regulationsSee detailed guide below ↓

ISO 22301 · Business continuity series

ISO 22301 Clause 6: Planning — Risks, Opportunities, Business Continuity Objectives and Planning for Change

ISO 22301:2019 clause 6 requires an organization to plan, at the level of the whole business continuity management system (BCMS), the actions that will address risks and opportunities, to set measurable business continuity objectives together with the plans to achieve them, and to carry out any changes to the BCMS in a planned way. It is a management-system-level planning clause, not the detailed operational risk work — that deeper analysis, including the business impact analysis and risk assessment of specific activities, belongs to clause 8. Understanding this distinction is one of the most common points of confusion for people new to the standard, and one of the more frequent sources of audit findings.

Clause 6 plans the management system. Clause 8 runs the business continuity analysis.

A recurring mix-up in early implementations is treating clause 6 as the place to do the business impact analysis (BIA) or the detailed risk assessment of specific processes and resources. Clause 6 is about the BCMS as a system: what risks and opportunities affect whether the management system itself works, what objectives the organization sets for its continuity capability, and how changes to that system are planned. The BIA and the operational risk assessment — identifying which activities matter most, their recovery time objectives, and the specific threats to them — sit in clause 8, once the management-system-level planning from clause 6 is in place.

Structure of clause 6: three subclauses

ISO 22301:2019 clause 6, "Planning," follows the same high-level structure shared across ISO management system standards (the Annex SL / Harmonized Structure), adapted to business continuity. It contains:

  • 6.1 Actions to address risks and opportunities: planning, at the BCMS level, how the organization will address risks and opportunities identified in relation to its context (clause 4) and interested parties, so the BCMS can achieve its intended outcomes and continually improve.
  • 6.2 Business continuity objectives and planning to achieve them: establishing measurable objectives for the BCMS and the concrete plans — what will be done, by whom, with what resources, and by when — to reach them.
  • 6.3 Planning of changes to the business continuity management system: ensuring that when the organization decides the BCMS needs to change, that change happens in a planned, controlled manner rather than informally.

6.1 Actions to address risks and opportunities

Clause 6.1 asks the organization to consider the internal and external issues established under clause 4.1, and the requirements of interested parties established under clause 4.2, and to determine the risks and opportunities that need to be addressed. The purpose, as stated in the clause, is threefold: give assurance that the BCMS can achieve its intended outcome or outcomes, prevent or reduce undesired effects, and achieve continual improvement.

Having identified those risks and opportunities, the organization must plan actions to address them, and plan how to integrate and implement those actions into its BCMS processes, and evaluate the effectiveness of the actions taken. This is management-system thinking: the "risks" in scope here are risks to the BCMS functioning as intended — for example, the risk that top management commitment fades after certification, that the BCMS scope no longer reflects how the organization actually operates, or that competing management systems (quality, information security) pull resources away from continuity work. These are different in kind from the operational risks to specific business activities that get assessed later, in detail, under clause 8.2.

Practical tip

Keep clause 6.1 conversations at the level of "will this BCMS work and keep working," not "what would happen if our main warehouse burned down." The second question is legitimate and essential — it's just answered later, in the business impact analysis and risk assessment under clause 8.2, once the objectives and structure planned here are in place. Auditors often ask implementers to explain, in their own words, why the two are separate; being able to answer clearly is itself a sign of a mature BCMS.

6.2 Business continuity objectives and planning to achieve them

Clause 6.2 requires the organization to establish business continuity objectives at relevant functions and levels. The standard sets out that these objectives must be consistent with the business continuity policy, be measurable (if practicable), take into account applicable requirements, be monitored, be communicated, and be updated as appropriate.

Alongside the objectives themselves, the organization must determine, for each one, what will be done, what resources will be required, who will be responsible, when it will be completed, and how the results will be evaluated. In other words, an objective on its own — "improve our resilience" — is not sufficient; it needs a resourced, owned, dated plan attached to it before it can be considered to meet clause 6.2.

What a well-formed clause 6.2 objective looks like

A useful objective is specific enough to be monitored and traced back to the BCMS's intended outcomes: it names what will change, who is responsible, what resources are committed, and the date by which it will be evaluated. A vague statement of intent with no owner, no resource commitment and no review date does not meet the requirement, however well-intentioned it is — and it is precisely this kind of gap that auditors flag most often under 6.2.

6.3 Planning of changes to the BCMS

Clause 6.3 requires that when the organization determines the need for changes to the business continuity management system, those changes are carried out in a planned manner. The clause does not prescribe a specific change-management procedure, but it does establish the principle: BCMS changes — a new business unit brought into scope, a restructured continuity team, a change of top management sponsor, a new critical supplier — should be deliberate and documented, not ad hoc.

In practice, this means significant changes to the BCMS should prompt a review of whether they affect the risks and opportunities identified under 6.1, whether existing objectives under 6.2 are still appropriate, and whether other parts of the system — scope, policy, roles — need to be revisited as a result.

Why clause 6 is not the business impact analysis

The single most important conceptual point about clause 6 is what it deliberately does not contain: the detailed, activity-by-activity business impact analysis (BIA) and risk assessment that most people associate with "business continuity planning." That work — identifying prioritized activities, determining their recovery time objectives and recovery point objectives, and assessing the specific threats and vulnerabilities that could disrupt them — sits in clause 8, Operation, specifically under 8.2 (business impact analysis and risk assessment).

Clause 6 comes first in the standard's structure for a reason: it establishes the management-system-level foundation — what risks threaten the BCMS itself, what the organization is trying to achieve with it, and how it will evolve — before the organization moves into the detailed operational analysis of clause 8 that determines which specific business activities and resources actually need continuity arrangements. Skipping straight to a BIA without this planning foundation in place is a common shortcut that tends to produce a BCMS that looks thorough on paper but lacks a clear, documented rationale for why it prioritizes what it prioritizes.

Subclause What it requires Typical evidence
6.1 Determine and plan actions to address BCMS-level risks and opportunities BCMS risk and opportunity log linked to clause 4 context/interested parties
6.2 Set measurable business continuity objectives and plans to achieve them Objectives register with owners, resources, dates, evaluation method
6.3 Carry out BCMS changes in a planned manner Change record showing review of risks, objectives and scope impact

Common audit findings on clause 6

Recurring gaps seen when clause 6 is assessed during an ISO 22301 audit:

  • 6.1 — Risks and opportunities not linked to clause 4 context: a risk log exists, but there is no visible connection between it and the internal/external issues or interested-party requirements identified earlier in the BCMS.
  • 6.1 — Clause 6 conflated with the BIA: teams document operational, activity-level risks here instead of BCMS-level risks, duplicating or pre-empting the work that belongs in clause 8.2.
  • 6.2 — Objectives without a plan attached: an objective is stated, but there is no documented resource, owner, or completion date behind it.
  • 6.2 — Objectives that are not measurable: aspirational language with no indicator or target that could be monitored over time.
  • 6.3 — Changes made without revisiting the BCMS: a new site, team, or supplier is added to scope without any documented review of whether it affects the risks, opportunities, or objectives already established.

Frequently asked questions about ISO 22301 clause 6

Is clause 6 the same as the business impact analysis?

No. Clause 6 plans the BCMS at a management-system level — risks and opportunities affecting the system itself, business continuity objectives, and how BCMS changes are planned. The business impact analysis and the detailed risk assessment of specific activities and resources are addressed later, under clause 8.2, once the foundation from clause 6 is in place.

Does ISO 22301 specify how to assess risks and opportunities under 6.1?

The standard sets out what clause 6.1 must achieve — determining risks and opportunities linked to context and interested parties, and planning actions to address them — without mandating a specific methodology. Organizations typically use whatever risk management approach already fits their existing management systems, applied at the BCMS level.

What must a business continuity objective include to satisfy clause 6.2?

The objective itself should be consistent with the business continuity policy and measurable where practicable. Alongside it, the organization must document what will be done, what resources are needed, who is responsible, the completion timeframe, and how the results will be evaluated.

What counts as a "change to the BCMS" under clause 6.3?

The standard does not provide an exhaustive list, but the principle is that any change the organization determines is needed to the management system — rather than to a single operational plan — should be carried out in a planned way, with consideration given to how it may affect the risks, opportunities and objectives already established.

Why do auditors flag clause 6 so often as a nonconformity?

Because it is easy to skip past conceptually: teams are often eager to get to the "real" continuity work of the BIA and recovery plans, and treat clause 6 as a formality. The result is objectives with no owner or date, or a risk log that duplicates clause 8.2 content instead of addressing the BCMS itself — both of which are straightforward for an auditor to spot.

How does clause 6 connect to clause 8 in practice?

Clause 6 establishes the BCMS-level risks, opportunities and objectives that give the rest of the system its direction. Clause 8 then operationalizes business continuity through the business impact analysis, risk assessment, strategy selection and procedures. An auditor will often check that the objectives and priorities set in clause 6 are visibly reflected in the scope and focus of the clause 8 work that follows.

Do business continuity objectives need to be reviewed every year?

ISO 22301 requires objectives to be monitored and updated as appropriate, without prescribing a fixed review interval. Most organizations align this review with their existing management review cycle, but the exact frequency depends on the organization's own procedures and should be defined internally rather than assumed from the standard's wording.

Where IgeraIndustria fits

Keeping clause 6 evidence — the risk and opportunity log, the objectives register with owners and dates, and the record of planned BCMS changes — traceable and up to date is largely a documentation discipline problem. IgeraIndustria is AI that answers directly from a company's own BCMS documents, citing the exact source, so a team preparing for an audit can ask, for example, which objectives are still missing an owner or a completion date, and get an answer traced back to the actual register rather than a guess.

Disclaimer: This article is for general information only and does not constitute certification or legal advice. Requirements for certification, interpretation of specific clauses, and audit outcomes can vary by certification body and by organization. For guidance on your specific situation, consult a qualified business continuity consultant or an accredited certification body.

Struggling to keep BCMS objectives, risk logs and change records aligned?

IgeraIndustria answers directly from your own business continuity documentation, citing the exact source, instead of leaving clause 6 evidence scattered across spreadsheets.

View ISO 22301 solution

ISO 22301 business continuity series · Updated 2026-09-25

#iso 22301 clause 6#iso 22301 planning#business continuity objectives iso 22301#iso 22301 risks and opportunities#bcms planning requirements#iso 22301 planning of changes#iso 22301 audit findings#business continuity management system planning

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network