Business Continuity
ISO 22301
-
Gap assessment Gap assessment
-
Regulatory implementation Gap closure and evidence
-
Gap assessment + implementation Both services, together−15%
A management system built on ISO 22301 to keep operating when something goes down, and to be able to prove it.
Almost every organisation that calls us already has a continuity plan. It is written, approved and filed away. What they do not have is any certainty that it works: nobody has ever run it, the phone numbers in it are out of date, and the person who knew how to do it left two years ago.
ISO 22301 makes that distinction explicit: its clause 8.5 requires an exercise programme, and 8.6 requires evaluating continuity capabilities. Documenting is not enough; you have to test and leave a record that you tested.
And it all starts with the business impact analysis: which processes cannot stop, how long they can hold out and how much data you can afford to lose. Without those figures agreed with the business —not with IT—, any plan is an expensive assumption.
The standard
NCh-ISO 22301:2020 — Chilean standard from the INN, an adoption of ISO 22301:2019
Methodology we bring
ISO 22317 — business impact analysis
ISO 22313 — implementation guidance
ISO 31000 — risk management
It integrates with ISO 27001: continuity of information security is an Annex A control, and anyone who already has an ISMS reuses context, roles and internal audit.
They run through clauses 4 to 10 of the standard. Estimated duration of 4 to 7 months depending on the number of critical processes and sites.
A gap assessment against ISO 22301 and a defined system scope: which sites, which processes and which services are included. An executive report for top management.
Continuity policy, roles for the continuity and crisis teams, and measurable objectives approved by top management.
The BIA: prioritised processes with their maximum tolerable period of disruption, and the recovery time and recovery point objectives agreed with each area of the business.
Continuity risk assessment and the strategies chosen for each critical process, with their cost and their resource requirements.
Continuity and recovery plans, activation procedures, call tree and crisis communication protocol, including communication to clients and to the authority.
An exercise programme with at least one actually run —desktop or field— with its results report and the corrections applied to the plans.
Assessment of capabilities, internal audit, management review and preparation for certification.
Phase 6 ends with an exercise actually run and its report, not with a procedure describing how it would be done. That is where the phone numbers that no longer exist turn up, and the backups nobody had ever tried to restore — and it is cheaper to find out in a drill.
The gap assessment can be engaged on its own: it is a useful diagnosis in itself and commits you to nothing. Inside the full programme it comes at a discount.
ISO 22301
How the value is determined
Proposals are quoted in UF, plus VAT. The value of each project comes from four factors:
Build your scope in the quote builder and get the proposal with figures in UF within 24 business hours. No meeting first, and no details needed until the end.
A 30-minute call, at no cost. The first question is always the same: if your main system goes down tomorrow, how many hours can you keep operating without it?
Your basket is empty
Add regulatory documentation packs or plans