ISO 22301: Business Continuity — Excellence Institute
ISO Standard · Business Continuity

ISO 22301:
Business Continuity

When Disruption Strikes, Your System Responds.

Every organisation faces disruption — natural disasters, cyber incidents, power failures, supply chain collapses, or pandemic-level crises. The difference between those that survive and those that don't is rarely luck. It is the system they built before the disruption arrived. ISO 22301 provides the internationally recognised framework for building that system, and this programme teaches professionals how to design, implement, and sustain it.

BCMS Design Business Impact Analysis Recovery Strategies Crisis Response Operational Resilience Continuity Planning Exercising & Testing
Duration 3 Days
Level Intermediate – Advanced
Delivery In-Person · Virtual · Self-Paced
Standard ISO 22301:2019
Choose Your Format
Enrol in ISO 22301
Select a delivery mode to get started
🏫
In-Person Group work, simulations & live exercises
💻
Virtual Live online, fully interactive
🕐
Self-Paced Learn on your own schedule
Enrol Now → Request In-House Delivery
ISO 22301:2019 certified content
Certificate of completion included
BCP & BIA templates provided
In-house cohort delivery available
About This Programme

Resilience Is Not a Reaction —
It Is a System You Build

Most organisations believe they are resilient until they are tested. A server failure brings operations to a standstill. A key supplier collapses. A natural disaster disables a facility. In that moment, the absence of a structured Business Continuity Management System becomes acutely, expensively apparent.

Disruption is inevitable. Unpreparedness is a choice. Organisations with a mature BCMS recover faster, protect their reputation, satisfy regulatory requirements, and maintain the trust of clients and stakeholders through even the most severe operational disruptions. ISO 22301 is the framework that makes this possible — and this programme shows professionals exactly how to build it.

This programme is delivered by practitioners who have designed business continuity frameworks across complex, multi-site organisations — across sectors including financial services, healthcare, critical infrastructure, and logistics. Every module is structured around real-world application, not theoretical compliance.

Participants leave with a working BCMS architecture, a completed Business Impact Analysis for a real function, recovery strategy options documented, and a tested business continuity plan — built during the programme and immediately applicable to their organisation.

Learning Outcomes

What You Will Walk Away With

🏗️

The ability to design and implement a Business Continuity Management System fully aligned to ISO 22301:2019 — from scoping and policy through to continual improvement.

📊

A working mastery of Business Impact Analysis — identifying critical functions, dependencies, MTPoD, RTO, and RPO with confidence and precision.

🗺️

Practical skills in designing recovery strategies — people, premises, technology, supply chain, and communications — that are realistic and achievable under pressure.

📋

The ability to write a Business Continuity Plan that crisis responders can actually use — clear, structured, pre-tested, and maintained over time.

🎯

Confidence designing and running BCMS exercises — from tabletop walkthroughs to full simulations — and using the findings to strengthen the programme.

📁

Ready-to-use outputs: BCMS scope statement, BIA template, recovery strategy worksheet, BCP structure, exercise design guide, and crisis communications framework.

The BCMS Lifecycle

How ISO 22301 Structures Your Resilience Programme

ISO 22301:2019 follows the Plan-Do-Check-Act (PDCA) high-level structure common to all ISO management system standards. This programme walks participants through each stage of the BCMS lifecycle — ensuring they can design a programme that is not just implemented once, but continually maintained and improved.

The ISO 22301 BCMS Lifecycle
Each stage builds on the last. This programme covers all six stages in sequence — giving participants a complete, end-to-end picture of what a mature business continuity management system looks like in practice.
🏢
Stage 01
Context & Scope

Understand the organisation, its stakeholders, and the environment it operates in. Define the BCMS scope and establish leadership commitment and policy.

📊
Stage 02
Business Impact Analysis

Identify critical activities, map dependencies, establish recovery time objectives (RTOs), and determine the maximum tolerable period of disruption (MTPoD).

🛠️
Stage 03
Recovery Strategy Design

Design proportionate, realistic recovery strategies across all resource categories — people, technology, premises, supply chain, and information.

📋
Stage 04
Business Continuity Plans

Document actionable, role-based BCPs that cover incident response, crisis communications, workaround procedures, and escalation protocols.

🧪
Stage 05
Exercising & Testing

Validate plans through structured exercises — tabletop walkthroughs, functional drills, and full simulations — and use findings to identify gaps before a real incident does.

🔄
Stage 06
Review & Continual Improvement

Monitor BCMS performance, conduct internal audits and management reviews, and embed the continual improvement cycle that keeps the programme current and credible.

What You're Preparing For

The Disruption Scenarios This Course Covers

A robust BCMS is scenario-agnostic — it prepares the organisation to respond to any disruption, not just the ones you can predict. This programme uses real-world disruption scenarios throughout, ensuring participants can apply their learning across the full range of threats their organisation faces.

🌊
Natural Disasters

Flooding, fire, extreme weather, and facility loss

🔐
Cyber Incidents

Ransomware, data breaches, and system outages

⛓️
Supply Chain Failure

Critical supplier collapse or logistics disruption

💡
Utility & Infrastructure Loss

Power outages, telecoms failure, and connectivity loss

🦠
Pandemic & Health Crisis

Workforce unavailability and public health emergencies

📢
Reputational Crisis

Media incidents, regulatory action, and stakeholder trust failures

Programme Curriculum

What the Course Covers

MODULE 01
Business Continuity Fundamentals & ISO 22301
Half day · Foundations, context & the case for a BCMS
  • What is business continuity? Definitions, objectives, and the difference between continuity, resilience, and recovery
  • The evolution of BC management — from disaster recovery to enterprise resilience
  • Overview of ISO 22301:2019 — structure, high-level structure (HLS), and how it differs from the 2012 version
  • How ISO 22301 relates to ISO 31000, ISO 27001, and crisis management frameworks
  • The business case for a BCMS — regulatory drivers, client requirements, and reputational protection
  • Understanding the organisation and its context: internal and external factors relevant to business continuity
MODULE 02
Scoping, Leadership & BCMS Policy
Half day · Governance, scope design & leadership obligations
  • Identifying interested parties and determining their continuity-related requirements
  • Scoping the BCMS: defining boundaries, inclusions, and exclusions — and the common scoping mistakes that undermine programmes
  • Top management obligations under ISO 22301 — what senior leadership must own, not just endorse
  • Writing a business continuity policy that reflects strategic intent — not just compliance language
  • Roles, responsibilities, and authorities within the BCMS — the governance structure that makes it work
  • Communication and awareness requirements — building a continuity-conscious organisational culture
MODULE 03
Business Impact Analysis
Full day · The foundation of every effective BCMS
  • Understanding the BIA: purpose, scope, and why it is the most critical document in your BCMS
  • Identifying and prioritising critical activities — the functions the organisation cannot afford to lose
  • Mapping dependencies: people, technology, premises, suppliers, and information
  • Establishing Maximum Tolerable Period of Disruption (MTPoD) — how long can each activity be unavailable?
  • Determining Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each critical activity
  • Documenting resource requirements at the point of recovery — not at normal operating level
  • Hands-on: conducting a full BIA for a real-world function using structured templates
MODULE 04
Recovery Strategy Design
Half day · Proportionate, realistic recovery options
  • The five resource categories for recovery strategy design: people, premises, technology, supply chain, information
  • People strategies: cross-training, staff redeployment, mutual aid, and contractor arrangements
  • Premises strategies: work-from-home, alternate sites, reciprocal arrangements, and split operations
  • Technology strategies: data backup, cloud recovery, alternative systems, and manual workarounds
  • Supply chain strategies: dual sourcing, emergency supplier agreements, and stockpiling
  • Evaluating strategy options against cost, feasibility, and alignment with RTOs from the BIA
  • Hands-on: designing and documenting recovery strategies for a complex, multi-dependency scenario
MODULE 05
Business Continuity Plans & Crisis Communications
Half day · Writing plans people can actually use
  • The anatomy of an effective BCP — structure, format, and the common mistakes that make plans unreadable under pressure
  • Incident response procedures: detection, notification, escalation, and initial response actions
  • Workaround procedure documentation: step-by-step, role-based, and scenario-specific
  • Crisis management team design: composition, roles, decision-making protocols, and activation criteria
  • Crisis communications planning: internal communications, media handling, regulatory notifications, and stakeholder management
  • Hands-on: drafting a business continuity plan section using real-world incident scenarios
MODULE 06
Exercising, Audit & Continual Improvement
Half day · Testing, assurance & keeping the BCMS alive
  • Why exercising is the most neglected and most important element of any BCMS
  • Types of exercises: document reviews, tabletop walkthrough, functional exercise, and full simulation — when to use each
  • Designing an exercise: scenario selection, participant roles, inject design, and facilitation techniques
  • Capturing and acting on exercise findings — turning lessons learned into genuine programme improvements
  • Internal audit of the BCMS: scope, methodology, and reporting findings to leadership
  • Management review requirements under ISO 22301 — what must be reviewed and how often
  • Embedding continual improvement: maintaining the BCMS through organisational change and emerging threats
Who Should Attend

Built For These Professionals

🔄 Business Continuity Managers

Those responsible for designing, implementing, or managing a BCMS — whether building from scratch or maturing an existing programme.

⚙️ Operations & Resilience Leaders

Senior managers overseeing critical operations who need structured frameworks to protect business continuity through any disruption scenario.

🛡️ Risk & Compliance Professionals

Risk managers and compliance officers who need to integrate business continuity requirements into enterprise risk frameworks and regulatory submissions.

🏢 Senior Leaders & Executives

Board members, directors, and C-suite executives who bear strategic responsibility for organisational resilience and stakeholder trust through crises.

🔍 Internal Auditors

Audit professionals preparing to assess BCMS effectiveness against ISO 22301 requirements — or supporting external certification audits.

🌐 Consultants & Advisors

GRC and resilience advisory professionals supporting organisations through BCMS implementation, gap assessments, or ISO 22301 certification preparation.

Participant Feedback

What Past Delegates Say

Before this programme, our business continuity plan was a document that sat in a folder and hadn't been tested in three years. After completing ISO 22301, I led our organisation through a full BIA, redesigned our recovery strategies, and ran our first realistic tabletop exercise. When a real incident hit eight months later, we responded with a clarity that genuinely surprised our leadership team.

B
Bola A.
Head of Operational Resilience, Financial Services — Lagos

The Business Impact Analysis module alone changed how our entire organisation thinks about critical functions. We had assumptions about what was important — the BIA methodology forced us to test those assumptions with data. Several of our findings were genuinely surprising and led to strategic decisions we would never have made otherwise.

D
Dapo O.
Group Risk Director, Infrastructure & Logistics

Ready to Build an Organisation That Survives Anything?

Join resilience leaders, risk professionals, and operations managers who have used ISO 22301 to transform their organisation's ability to withstand, respond to, and recover from disruption.

Scroll to Top