Industry

ISO 22301 Clause 7: Support

Equip IgeraSolutions
September 25, 2026
9 min read
ISO 22301 Clause 7: Support
🎧 Listen with AI Voice

2-minute executive summary

⚡ Quick Answer in 30s

ISO 22301 Clause 7 explained: resources, competence, awareness, communication for real incidents, and documented information — plus common audit gaps.

✓ Citing current regulationsSee detailed guide below ↓

ISO 22301 Clause 7: Support

ISO 22301:2019 Clause 7 (Support) requires organizations to provide the resources, competent people, awareness, communication arrangements, and controlled documentation needed to build and maintain a working business continuity management system (BCMS). It's the clause that turns a business continuity policy into something an organization can actually operate under pressure — and it contains one requirement that sets it apart from most other management system standards: a communication plan built specifically for real incidents and disruptions, not just for routine BCMS updates. Get Clause 7 wrong and the gap usually doesn't show up in a tabletop exercise — it shows up during an actual disruption, when the plan, the people, and the paperwork all need to work together at once.

In this article: what Clause 7 requires across resources, competence, awareness, communication, and documented information; why incident communication planning deserves separate attention from routine BCMS communication; what building this support infrastructure looks like in practice; and the audit findings that come up most often.

What Clause 7 covers, at a structural level

Clause 7 sits between the leadership and planning requirements of Clauses 5 and 6 and the operational requirements of Clause 8 — its job is to make sure the organization has everything it needs in place before it tries to run a BCMS day to day and before it has to activate a response during an actual disruption. Like the equivalent clause in other ISO management system standards, it's built around five sub-clauses: resources, competence, awareness, communication, and control of documented information.

What makes Clause 7 distinct in a business continuity context is the stakes attached to each element. A training gap in a quality management system shows up as a defect. A support gap in a BCMS shows up when the organization is already dealing with a disruption — a flood, an outage, a supplier failure — and discovers that the people who should respond don't know their role, the plan can't be found, or there's no agreed way to tell staff, customers, and regulators what's happening.

Resources: what the BCMS actually needs to function

The resources sub-clause requires the organization to determine and provide the resources needed to establish, implement, maintain, and continually improve the BCMS. This is deliberately broad — it covers people, time, budget, technology, and facilities — because a BCMS that looks complete on paper but has no allocated budget for testing, no protected time for the continuity team, or no functioning alternate site is not a system that will perform when it's needed.

In practice, auditors expect to see resourcing decisions that can be traced back to the business impact analysis and risk assessment carried out under Clause 6 — the resources committed should match the recovery time objectives and recovery point objectives the organization has actually set, not a generic allocation copied from a template.

Competence: the people who respond need to be capable, not just assigned

Clause 7.2 requires the organization to determine the necessary competence of people doing work under its control that affects business continuity performance, ensure those people are competent on the basis of appropriate education, training, or experience, and retain documented evidence of that competence.

For a BCMS, this goes beyond the continuity manager. It extends to everyone with a defined role in the continuity plans — incident commanders, communication leads, IT recovery teams, facilities staff, and anyone named in an activation procedure. Three things auditors typically look for:

  • Defined competence requirements tied to the specific role in the continuity plan, not a generic statement that someone "understands business continuity."
  • Evidence the competence was tested, which in a BCMS context usually means participation in exercises and tests, not classroom attendance alone — a named incident commander who has never taken part in a live exercise is a common audit concern.
  • A process for keeping competence current as people change roles, leave the organization, or as plans are updated — stale role assignments are one of the most frequent gaps found during recertification.

Awareness: everyone needs to know their part, not just the specialists

Clause 7.3 requires that people doing work under the organization's control are aware of the business continuity policy, their contribution to the effectiveness of the BCMS, the benefits of improved performance, and the implications of not conforming to BCMS requirements.

Awareness is deliberately wider than competence. It's not about training every employee to run a recovery procedure — it's about making sure staff across the organization know that a BCMS exists, understand roughly what it means for them, and know what to do if a disruption starts, even if their part is simply following an evacuation route or knowing who to contact. Organizations that treat awareness as a one-off induction slide rather than a maintained program tend to struggle here, because awareness needs to be refreshed as plans, contacts, and procedures change.

Communication: why the incident communication plan is not optional

Clause 7.4 is arguably the sub-clause with the most operational weight in the whole of Clause 7, because it requires two distinct things that are easy to conflate.

The first is routine internal and external communication about the BCMS itself — what to communicate, when, with whom, and how, covering the normal lifecycle of maintaining, reviewing, and improving the system. This is comparable to the communication requirements found in other ISO management system standards.

The second, and the one specific to ISO 22301, is communication during an actual incident or disruption. The standard explicitly calls for the organization to establish, document, implement, and maintain procedures for communicating with relevant interested parties in the event of a disruption, and requires that these arrangements work reliably even if normal infrastructure — networks, buildings, key systems — is itself unavailable. This means an incident communication plan needs to address who needs to be contacted, in what order, and through what channel when the usual channels may not be working; how updates are provided to employees, customers, suppliers, regulators, and, where relevant, the media; and who is authorized to speak externally on the organization's behalf during an incident, so messaging stays consistent and accurate under pressure.

Treating incident communication as an extension of routine BCMS communication is one of the most consequential mistakes an organization can make against Clause 7. A policy document that says "communication will be managed appropriately during a disruption" is not a plan — it's an intention. Clause 7.4 expects a documented, testable procedure that assigns responsibility and specifies channels, and it expects that procedure to have been exercised, not just written.

Control of documented information: the BCMS has to be findable and current

Clause 7.5 requires the organization to maintain documented information required by the standard and by its own determination of what's necessary for the BCMS to be effective, and to control it properly — meaning it's identified and described, in an appropriate format, reviewed and approved for adequacy, and controlled for distribution, access, storage, retrieval, and version control, with obsolete versions removed or clearly identified.

For a BCMS specifically, this control matters in a way it doesn't for many other management systems, because the documented information is often needed at the exact moment when normal access to systems is compromised. A continuity plan stored only on a server that goes down in the same disruption it's meant to address defeats its own purpose. This is precisely the gap tools like IgeraIndustria are built to close — by letting teams ask a direct question about an activation procedure, a recovery time objective, or a named responsibility and get an answer sourced from the organization's own current BCMS documents, with the exact document and clause cited, rather than relying on someone finding the right version of a plan during a disruption.

Practical implications for building the BCMS support infrastructure

A few consequences follow directly from these requirements for organizations building or maturing a Clause 7 program.

On resourcing: resource decisions should be reviewed alongside the business impact analysis, not set once and forgotten — recovery objectives that change as the business changes need matching resource commitments.

On competence and awareness: role-specific competence for continuity team members should be verified through exercises, not assumed from job title, while awareness needs a maintenance cycle — a refresh whenever plans, contacts, or procedures change, not just at onboarding.

On communication: the incident communication plan deserves its own documented procedure, separate from the general BCMS communication plan, with named contacts, defined channels that don't depend on normal infrastructure, and a clear statement of who is authorized to communicate externally — and it needs to be tested as part of the organization's exercise programme, not left untested until a real event proves whether it works.

On documented information: critical BCMS documents — activation procedures, contact lists, recovery plans — need to be accessible even when normal systems aren't, which typically means considering redundant storage or access methods as part of the control process itself.

Certification body auditors see a recurring pattern of findings against Clause 7. Most trace back to the same underlying issue: a requirement is met on paper but hasn't been tested or kept current in practice.

  • Incident communication procedures that exist only as a general statement, without named contacts, defined channels, or an order of notification.
  • No consideration of how communication works if normal infrastructure is down — the plan assumes email and the corporate network will be available.
  • Competence records that show training attendance but no evidence of exercise participation for people with defined roles in the continuity plan.
  • Awareness activities that happened once, at induction, with no refresh as plans and contacts changed.
  • Outdated versions of continuity plans or contact lists still in circulation, with no clear indication of which version is current.
  • Documented information that can't be retrieved quickly when an auditor asks to see a specific procedure or record during the audit itself — a strong indicator of how it would perform during a real disruption.

Frequently asked questions

What is the difference between competence and awareness under Clause 7?

Competence applies to people whose work directly affects BCMS performance — typically continuity team members and incident responders — and requires evidence of education, training, or experience for their specific role. Awareness is broader and applies to everyone under the organization's control; it's about understanding that the BCMS exists, why it matters, and what part they play, without requiring the same depth of demonstrated capability.

Why does ISO 22301 treat incident communication separately from routine communication?

Because the two situations are fundamentally different. Routine BCMS communication happens under normal conditions, through normal channels, on a planned schedule. Incident communication has to work when normal conditions and channels may themselves be disrupted, on no notice, with high stakes for accuracy and consistency — which is why the standard requires a specific, documented, and tested procedure for it.

Does every employee need business continuity training to satisfy Clause 7?

Not to the same depth. Employees with a defined role in the continuity plan need demonstrated competence for that role. The wider workforce needs awareness — knowing the BCMS exists, understanding their general contribution, and knowing what to do if a disruption occurs — which is a lighter requirement than full competence.

How often should the incident communication plan be tested?

ISO 22301 doesn't prescribe a fixed frequency; it expects the organization to determine a testing and exercise programme appropriate to its risks and to demonstrate the plan works, including under conditions where normal channels aren't available. What matters to an auditor is evidence that it has actually been exercised, not just documented.

What counts as "documented information" under Clause 7.5?

Any information the standard explicitly requires to be documented, plus anything the organization itself has determined is necessary for the BCMS to be effective — commonly continuity plans, activation procedures, contact and escalation lists, competence records, and exercise reports. All of it needs to be controlled for version, access, and retrievability.

Who is typically responsible for maintaining Clause 7 requirements — a single BCM manager or multiple functions?

Practice varies, but ownership of the overall support infrastructure usually sits with the business continuity manager or equivalent role, while specific elements — HR for competence records, IT for infrastructure resilience, corporate communications for external messaging — are typically owned by the relevant function. An auditor will expect to see clear accountability regardless of how it's distributed.

Can an AI tool help an organization meet Clause 7 requirements?

An AI assistant doesn't replace the underlying resourcing, training, or communication planning the standard requires, but it can make the documented information behind it faster and more reliably retrievable — for example, surfacing the current activation procedure or a specific role's responsibilities, sourced directly from an organization's own BCMS documents with the exact reference cited. That's the specific gap IgeraIndustria is designed to close.

Disclaimer: This article is provided for general informational purposes only and does not constitute certification, legal, or professional advice. ISO 22301 requirements and their interpretation can vary by organization, sector, and certification body, and this content should not be relied on as a substitute for professional guidance. Organizations should consult a qualified business continuity consultant and their chosen certification body before making compliance decisions.

Retrieve your BCMS answers in seconds with IgeraIndustria

IgeraIndustria answers questions directly from your own continuity plans, procedures, and records — citing the exact source document, every time.

See how it works
#ISO 22301 Clause 7#ISO 22301 support requirements#business continuity management system#BCMS documented information#incident communication plan#ISO 22301 competence and awareness#ISO 22301 audit findings#business continuity certification

Ask this article

IA 2026

Igera's AI answers questions citing the facts and regulations in this article

2 of 2 free queries

Suggested questions (click to test):

Diagnóstico Interactivo 60s

Technical Compliance & Industrial Operations Diagnostic

Analyze speed of access to regulations (CTE, OSH, CE) in your plant or jobsite

Pregunta 1 de 3

How do technicians and operators access safety protocols and manuals?

Was this article helpful?

⚙️IgeraIndustriaOperations Template
GUÍA DESCARGABLE (TXT)

Preventive Maintenance & ISO 9001/45001 Industrial Checklist

Floor inspection template for machine operations, failure tracking and unplanned downtime reduction.

  • Shift inspection standardization for plant operators
  • Up to 40% faster anomaly response times
  • Full traceability for ISO audits and HSE compliance

Instant download · No card · 100% spam-free

Share this article

Help spread knowledge by sharing this content with your network