ISO 22301 coverage that proves your recovery objectives work
Impact analysis, recovery objectives, continuity plans and exercise results held as one connected record, with every shortfall tracked to closure.
Compliance at a glance
What ISO 22301 requires
Impact analysis that drives the system
Prioritised activities, their impact over time and recovery objectives captured in one place. The analysis tells you what to protect before solutions are discussed.
Recovery objectives traceable to evidence
Every recovery time and point objective links back to the impact assessment that produced it. When an auditor asks why, the answer is in the record.
Dependencies mapped once, reused everywhere
People, systems, suppliers and sites each activity depends on, recorded once and shared with third-party risk and operational risk.
Exercises that produce tracked actions
What the test achieved is recorded against what the plan promised. Every shortfall becomes an owned action with a date, not an observation in a filed report.
ISO 22301 compliance, covered by default
Business impact analysis, recovery objectives, continuity plans and exercise tracking are built into the platform, so the management system runs from a single record rather than scattered documents.
Business impact analysis templates
Pre-structured business impact analysis worksheets that capture activities, impact over time and recovery objectives, justified by the analysis rather than chosen arbitrarily.
Recovery objective tracking
Recovery time and recovery point objectives linked to the impact analysis that produced them, with each exercise result measured against the stated objective.
Disruption risk assessment
Risks to prioritised activities scored on the same criteria as the enterprise risk register. Single points of failure surface automatically across all activities.
Dependency mapping
People, systems, suppliers and sites each activity depends on, recorded once and reused by third-party risk and operational risk.
Exercise programme management
Exercise calendar with scope, type and objectives per test. Shortfalls become owned actions with dates rather than observations in a filed report.
The obligations Dimeri tracks
Dimeri holds the impact analysis, the dependencies, the plans and the exercise results as one connected record rather than four documents that age apart.
Context, scope and leadership
The scope of the management system defined against the products and services it protects, with top management accountable for it.
- Scope held with the activities and sites it covers
- Interested parties and their continuity requirements
- Business continuity policy with review dates
- Roles, responsibilities and authorities assigned
Business impact analysis
Prioritised activities identified, the impact of their disruption assessed over time, and resumption timeframes derived from that impact rather than chosen.
- Activities recorded with the products they support
- Impact over time captured against agreed categories
- Recovery time and point objectives derived and justified
- Dependencies on people, systems, suppliers and sites
Risk assessment
The disruption risks to prioritised activities identified and assessed, using the same method as the wider risk register rather than a parallel one.
- Disruption risks scored on the organisation's own criteria
- Single points of failure surfaced across activities
- Treatment actions with owners and due dates
- Residual position reassessed after treatment
Strategies, solutions and plans
Continuity strategies selected against the requirements the impact analysis set, with plans carrying activation criteria, roles and contacts.
- Strategy recorded per prioritised activity
- Plans held with owners and review cycles
- Activation criteria and escalation defined
- Contact and resource lists kept current
Exercise programme
Exercises that test the plans against their stated objectives, with results recorded and shortfalls acted on.
- Exercise calendar with scope and type per test
- Actual recovery measured against the objective
- Shortfalls raised as owned actions, not observations
- Post exercise reports drawn from the record
Evaluation and improvement
Performance evaluation, internal audit, management review, and corrective action on nonconformities.
- Internal audit programme covering the whole BCMS
- Management review inputs gathered through the year
- Nonconformities tracked with root cause to closure
- Improvement actions on the system, not just the plans
Getting ISO 22301 coverage in place
4 steps from where you are today to a ISO 22301 position your auditor can rely on.
Book a demoThe scope is defined by what the organisation must keep delivering, not by departments. Getting this wrong is the most common reason a first certification attempt stalls.
How Dimeri covers ISO 22301
Objectives traceable to the analysis
Every recovery time objective links back to the impact assessment that produced it. When an auditor asks why four hours rather than twelve, the answer is the analysis rather than an opinion.
Exercises that produce actions
What the test achieved is recorded against what the plan promised, and every shortfall becomes an owned action with a date. That is the difference between an exercise programme and a filing exercise.
Dependencies mapped once
The systems, suppliers, sites and people each activity relies on are recorded once and reused by third party risk and operational risk, so the analysis earns its cost three times over.
ISO 22301 questions
What is the difference between the business impact analysis and the risk assessment?
The impact analysis asks what the organisation must resume and how quickly, by assessing the consequence over time of not performing each activity. The risk assessment then asks what could disrupt those prioritised activities. The analysis identifies what to protect; the assessment identifies what to protect it from. ISO 22301 covers both, in that order.
Do we need to be certified to use ISO 22301?
No. Many organisations align to the standard for the structure it provides without seeking certification, and its requirements work perfectly well as an internal discipline. Certification matters mainly when a client, regulator or insurer asks for independent assurance.
How often do plans need to be exercised?
ISO 22301 calls for an exercise programme rather than a fixed frequency, leaving the organisation to justify a schedule proportionate to the activity's priority. Most set annual exercises for the highest priority activities with lighter walkthroughs in between. Dimeri enforces whichever cycle you set and shows when it slips.
How does this relate to the business continuity module?
This page describes the standard; the business continuity platform page covers the product in more depth, including the recovery objective tracking and dependency mapping. Both draw on the same underlying record.
Is this a substitute for the standard itself?
No. ISO 22301 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.