D-WINGS Consulting LLP
BUSINESS CONTINUITY

ISO 22301 and the Difference Between a BCP Document and a Plan That Works

D-WINGS Consulting LLP · 19 May 2026

Most organisations that have “done” business continuity have a document: a Business Continuity Plan, often produced once, during a compliance push, and rarely opened again until the next audit. ISO 22301, the international standard for Business Continuity Management Systems, is built around a different premise — that a plan is only as good as the evidence that it works.

The core building blocks of ISO 22301:

Why the exercise programme is the part that matters. A tabletop exercise reveals whether the plan’s assumptions hold — whether the named recovery team members are actually reachable, whether the “alternate” data centre has been kept in sync, whether a supplier’s own continuity commitments were ever verified rather than assumed. A plan that has only ever existed on paper reliably fails on details that seem trivial until the moment they matter: an outdated contact list, a recovery site that was quietly decommissioned, a dependency on a system that itself has no continuity plan.

What “certifiable” business continuity looks like in practice:

The connection to the rest of governance. Business continuity doesn’t operate in isolation from information security — a ransomware incident is both a security event and a continuity event, and organisations whose ISMS and BCMS are managed as separate, disconnected programmes routinely discover the gap between them during the incident they were both supposed to prepare for.

Have a question on this?

Talk to an Expert