Internal Audit for ISO 22301 Business Continuity

ISO 22301 Clause 9.2

This sub-clause requires planned internal audits to confirm the BCMS conforms to the standard and the organisation's own requirements and is effectively implemented and maintained.

ISO 22301 Clause 9.2 - Internal Audit

Clause 9.2 is the internal audit clause. It mirrors the equivalent clause in other Annex SL standards, so organisations with established audit programmes for ISO 9001 or ISO 14001 will find the structure familiar. The work to comply with 9.2 for ISO 22301 is usually adding the BCMS-specific elements to the existing audit programme rather than building a separate one.

What ISO 22301 Clause 9.2 Requires

Under Clause 9.2.1, internal audits must be conducted at planned intervals to provide information on whether the BCMS conforms to the organisation's own requirements and the requirements of the standard, and whether it is effectively implemented and maintained.

Under Clause 9.2.2, the organisation must establish, implement and maintain an audit programme that includes frequency, methods, responsibilities, planning requirements and reporting, and that takes into account the importance of the processes concerned and the results of previous audits. Audit criteria and scope must be defined for each audit. Auditors must be selected and audits conducted to ensure objectivity and impartiality. Audit results must be reported to relevant management. Documented information must be retained as evidence of the audit programme and results. Corrective actions must be made without undue delay. Follow-up activity must verify the actions taken and the results of verification reported.

Building the BCMS into the Audit Programme

For organisations integrating ISO 22301 with other standards, the audit programme typically covers all clauses across all standards across the cycle, with BCMS-specific elements (BIA, risk assessment, plans, exercise programme, supplier continuity) built in as audit objects. For standalone BCMS certification, an annual programme covering each clause area at least once across the year is the usual pattern.

Auditor competence and independence are particular considerations. The auditor must understand the BCMS sufficiently to audit it effectively, and must not have direct responsibility for the area being audited. In small organisations independence can be hard to achieve, and external auditors are sometimes used to audit functions that the in-house auditor manages.

The audit schedule is the central document - it shows what gets audited when, who is auditing, and how the results will be reported. For ISO 22301 specifically, make sure the schedule covers the BIA, the risk assessment, the BC plan, the exercise programme and the supplier continuity arrangements, not just the generic management system clauses.

I look at the audit programme, the schedule and the audit reports. I check that auditors are competent and independent of what they are auditing. I look at how findings have been handled - if there are non-conformities recorded with no evidence of corrective action, that is a finding in itself. I also like to see internal audits picking things up that I would otherwise have to find.

Practical Compliance Guidance

The ER11 Audit Schedule records the planned and completed audits across the management system. The F-Q2 Audit Checklist is the standard checklist template used to record audit findings. The GG-1-10 Internal Audits Guidance describes the audit process and provides guidance for auditors.

alphaZ document How to use it
ISO 22301 Toolkit The full set of policies, procedures, registers and plans that build a BCMS to the requirements of the standard.
ER11 Audit Schedule The audit schedule that records the planned and completed audits, including BCMS-specific audits.
F-Q2 Audit Checklist The audit checklist template used to record audit findings against the standard's requirements.
GG-1-10 Internal Audits Guidance Guidance for auditors on the audit process, planning, conduct and reporting.

Subscribers to alphaZ have access to all of these documents and supporting material. Find out more about the alphaZ subscription.

Frequently Asked Questions

The standard requires audits at planned intervals but does not set a frequency. The most common pattern is to cover all BCMS clauses across the year, with the schedule weighted towards the higher-risk or more complex elements such as BIA, risk assessment and the BC plan.
Not the parts they are responsible for - that breaches the impartiality requirement. The BC Lead can be audited by another internal auditor, an auditor from elsewhere in the organisation, or an external auditor used to provide independence in small organisations.
No. Internal audits check conformance and effectiveness of the management system; exercises validate the operational capability of the response. Both are required by the standard and they answer different questions.

Further Resources

payment logos