KITE 2025 New Product Award โ€” Local IT | SACEEC
Risk and continuity

ISO 22301 coverage that proves your recovery objectives work

Impact analysis, recovery objectives, continuity plans and exercise results held as one connected record, with every shortfall tracked to closure.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Compliance at a glance

What ISO 22301 requires

Impact analysis that drives the system

Prioritised activities, their impact over time and recovery objectives captured in one place. The analysis tells you what to protect before solutions are discussed.

Recovery objectives traceable to evidence

Every recovery time and point objective links back to the impact assessment that produced it. When an auditor asks why, the answer is in the record.

Dependencies mapped once, reused everywhere

People, systems, suppliers and sites each activity depends on, recorded once and shared with third-party risk and operational risk.

Exercises that produce tracked actions

What the test achieved is recorded against what the plan promised. Every shortfall becomes an owned action with a date, not an observation in a filed report.

ISO 22301 compliance, covered by default

Business impact analysis, recovery objectives, continuity plans and exercise tracking are built into the platform, so the management system runs from a single record rather than scattered documents.

app.dimeri.ai/compliance
87%Compliant
24Controls
3Pending
Access control policy
Incident response plan
Vendor assessments
Awareness training

Business impact analysis templates

Pre-structured business impact analysis worksheets that capture activities, impact over time and recovery objectives, justified by the analysis rather than chosen arbitrarily.

app.dimeri.ai/controls
RefControlStatus
A.5.1Information security policiesโœ“ Implemented
A.6.1Screeningโœ“ Implemented
A.7.4Physical security monitoringIn progress
A.8.2Privileged access rightsโœ“ Implemented

Recovery objective tracking

Recovery time and recovery point objectives linked to the impact analysis that produced them, with each exercise result measured against the stated objective.

Exposure heatmapResidual
Likelihood
213114223512621431
LowImpactSevere
Critical 4High 10Medium 17Low 11

Disruption risk assessment

Risks to prioritised activities scored on the same criteria as the enterprise risk register. Single points of failure surface automatically across all activities.

Control libraryISO 31000
Segregation of duties92%Preventive
Exception reporting74%Detective
Incident escalation61%Corrective

Dependency mapping

People, systems, suppliers and sites each activity depends on, recorded once and reused by third-party risk and operational risk.

Board packGenerated
Audit & risk committeeQ3 ยท 18 pp
12Above appetite โ†“ 387%Controls tested โ†‘ 9
01Risk appetite position3 pp02Movements since last meeting2 pp03Control effectiveness4 pp04Overdue treatment actions1 p

Exercise programme management

Exercise calendar with scope, type and objectives per test. Shortfalls become owned actions with dates rather than observations in a filed report.

The obligations Dimeri tracks

Dimeri holds the impact analysis, the dependencies, the plans and the exercise results as one connected record rather than four documents that age apart.

Context, scope and leadership

The scope of the management system defined against the products and services it protects, with top management accountable for it.

  • Scope held with the activities and sites it covers
  • Interested parties and their continuity requirements
  • Business continuity policy with review dates
  • Roles, responsibilities and authorities assigned

Business impact analysis

Prioritised activities identified, the impact of their disruption assessed over time, and resumption timeframes derived from that impact rather than chosen.

  • Activities recorded with the products they support
  • Impact over time captured against agreed categories
  • Recovery time and point objectives derived and justified
  • Dependencies on people, systems, suppliers and sites

Risk assessment

The disruption risks to prioritised activities identified and assessed, using the same method as the wider risk register rather than a parallel one.

  • Disruption risks scored on the organisation's own criteria
  • Single points of failure surfaced across activities
  • Treatment actions with owners and due dates
  • Residual position reassessed after treatment

Strategies, solutions and plans

Continuity strategies selected against the requirements the impact analysis set, with plans carrying activation criteria, roles and contacts.

  • Strategy recorded per prioritised activity
  • Plans held with owners and review cycles
  • Activation criteria and escalation defined
  • Contact and resource lists kept current

Exercise programme

Exercises that test the plans against their stated objectives, with results recorded and shortfalls acted on.

  • Exercise calendar with scope and type per test
  • Actual recovery measured against the objective
  • Shortfalls raised as owned actions, not observations
  • Post exercise reports drawn from the record

Evaluation and improvement

Performance evaluation, internal audit, management review, and corrective action on nonconformities.

  • Internal audit programme covering the whole BCMS
  • Management review inputs gathered through the year
  • Nonconformities tracked with root cause to closure
  • Improvement actions on the system, not just the plans

Getting ISO 22301 coverage in place

4 steps from where you are today to a ISO 22301 position your auditor can rely on.

Book a demo

The scope is defined by what the organisation must keep delivering, not by departments. Getting this wrong is the most common reason a first certification attempt stalls.

How Dimeri covers ISO 22301

Objectives traceable to the analysis

Every recovery time objective links back to the impact assessment that produced it. When an auditor asks why four hours rather than twelve, the answer is the analysis rather than an opinion.

Exercises that produce actions

What the test achieved is recorded against what the plan promised, and every shortfall becomes an owned action with a date. That is the difference between an exercise programme and a filing exercise.

Dependencies mapped once

The systems, suppliers, sites and people each activity relies on are recorded once and reused by third party risk and operational risk, so the analysis earns its cost three times over.

ISO 22301 questions

What is the difference between the business impact analysis and the risk assessment?

The impact analysis asks what the organisation must resume and how quickly, by assessing the consequence over time of not performing each activity. The risk assessment then asks what could disrupt those prioritised activities. The analysis identifies what to protect; the assessment identifies what to protect it from. ISO 22301 covers both, in that order.

Do we need to be certified to use ISO 22301?

No. Many organisations align to the standard for the structure it provides without seeking certification, and its requirements work perfectly well as an internal discipline. Certification matters mainly when a client, regulator or insurer asks for independent assurance.

How often do plans need to be exercised?

ISO 22301 calls for an exercise programme rather than a fixed frequency, leaving the organisation to justify a schedule proportionate to the activity's priority. Most set annual exercises for the highest priority activities with lighter walkthroughs in between. Dimeri enforces whichever cycle you set and shows when it slips.

How does this relate to the business continuity module?

This page describes the standard; the business continuity platform page covers the product in more depth, including the recovery objective tracking and dependency mapping. Both draw on the same underlying record.

Is this a substitute for the standard itself?

No. ISO 22301 is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.

Ready to Transform Your GRC?

Join governance, risk, and compliance teams using AI to work smarter.