ISO 22301 refresher: is your business continuity management system still fit for purpose?

24/09/26 Colin Jeffs
ISO 22301 refresher

If your Business Continuity Management System (BCMS) has not been reviewed against ISO 22301 for some time, you're not alone. Organisations change quickly: processes evolve, technologies advance, risks emerge and operational dependencies shift. Over time, continuity plans and supporting documentation can fall out of step with how the organisation works in practice.

Although the standard has remained relatively stable in recent years, there has been one notable amendment to be aware of. This makes now a good time for a practical health check. This doesn’t necessarily mean a full certification exercise, but it provides an opportunity to confirm whether your BCMS still reflects how your organisation operates today.

In this article, we'll explore the current ISO 22301 standard and highlight a few important questions to help you identify potential gaps, strengthen resilience and maintain confidence in your continuity arrangements.

Where ISO 22301 stands today

ISO 22301:2019 remains the internationally recognised standard for Business Continuity Management Systems (BCMS), providing a structured framework for establishing, maintaining and continually improving organisational resilience. It’s widely adopted across sectors and referenced within UK government resilience guidance as a recognised approach to business continuity management.

ISO 22301 amendment 1:2024

The most significant recent update came in the form of Amendment 1:2024, which introduced a requirement for organisations to consider the relevance of climate change within their BCMS. Rather than creating a new set of obligations, the amendment encourages organisations to assess how climate-related risks, such as extreme weather, supply chain disruption or workforce impacts, could affect their ability to maintain critical operations.

This is less about implementing new processes and more about ensuring existing risk assessments, business impact analyses and continuity strategies reflect the changing operating environment. It's a practical extension of the resilience planning already expected under the standard.

While a future revision of ISO 22301 is under development, it remains at an early stage. Organisations should continue to focus on aligning with the current ISO 22301:2019 standard and its 2024 amendment, rather than delaying improvements in anticipation of future changes.

How accurate is your BCMS right now?

The key question is simple: does your BCMS accurately reflect the risks, dependencies and operational realities your organisation faces today?  

A practical refresher: the questions worth asking

Rather than starting with a full audit, these six questions provide a practical way to assess whether your BCMS still reflects operational reality.

1. Scope: does your BCMS still reflect how the organisation actually operates, (the structure, leadership, goals etc.) or has the business changed shape since you last reviewed the scope?

2. Dependencies: is your business impact analysis up to date, including the suppliers, systems and people your important activities depend on today?

3. Climate and emerging risk: have you given genuine thought to climate change and other emerging risks, in line with the 2024 amendment, rather than treating it as a box to tick?

4. Testing: have your plans been tested realistically and recently, in a way that would show whether they would hold up?

5. Leadership: is leadership actively engaged with the programme, rather than supporting it on paper alone? Is the programme mandated at the highest level?

6. Improvement: are lessons from tests, near misses and real incidents fed back into the plan, or are they simply recorded and left unresolved?

The wider picture beyond ISO 22301

ISO 22301 does not exist in isolation. It forms part of a wider framework of standards designed to help organisations strengthen resilience, manage risk and improve governance.

Alongside ISO 22301, organisations may also benefit from standards such as BS 65000 for organisational resilience, ISO 31000 for risk management, ISO 22361 for crisis management, and ISO 37000 for governance. While adopting these standards is not a requirement for an effective Business Continuity Management System (BCMS), they can provide valuable guidance in areas that support long-term resilience, operational performance, and good governance.

Understanding how ISO 22301 fits within this broader landscape can be particularly useful when discussing your continuity strategy with board members, auditors, regulators or customers. It helps demonstrate that your approach to business continuity is aligned with recognised best practices and supported by a wider resilience framework.

How Shadow-Planner supports your BCMS and resilience

Shadow-Planner helps you maintain a robust and audit-ready Business Continuity Management System (BCMS) by keeping key information accurate, accessible and up to date. Our programme management tools provide a clear view of policy compliance across your organisation, making it easy to demonstrate progress and provide evidence during audits or management reviews.

With business impact analysis and dependency mapping, you can keep critical processes, assets and dependencies up to date, ensuring your plans reflect the reality of your business. Real-time gap analysis also provides a clear view of resilience gaps. Our strategy module helps you review and refine recovery strategies as business requirements evolve, while the exercising module enables you to create, manage and record realistic testing programmes with confidence, as well as record and track live incidents.

If you're considering whether business continuity software is the right fit for your organisation, take a look at our guide to BCM software versus traditional continuity planning. You may also find our article on five essential tips for effective business continuity planning useful for strengthening your overall continuity approach.

Next steps - see how Shadow-Planner can help

ISO 22301 refresher: key points 

  • ISO 22301:2019 is still the current edition, now updated by Amendment 1:2024, which asks organisations to consider climate change as part of their BCMS.
  • A third edition is in early development but is still years from publication, so there's no reason to delay updating your BCMS against the current edition.
  • A short, honest refresher covering scope, dependencies, climate and emerging risk, testing, leadership and improvement is a practical way to confirm whether your BCMS still reflects operational reality.
  • ISO 22301 sits within a wider family of resilience, risk and governance standards recognised in UK government guidance, including BS 65000, ISO 31000, ISO 22361 and ISO 37000.
  • Shadow-Planner's programme management, business impact analysis, strategy and exercising tools are built to keep your BCMS evidence current between formal reviews.

FAQs

What is ISO 22301

ISO 22301 is the international standard that sets out the requirements for a business continuity management system (BCMS), covering how an organisation identifies, prepares for, responds to and recovers from disruption.

Is ISO 22301:2019 still the current version?

Yes, ISO 22301:2019 is still the current edition, now updated by Amendment 1:2024, which asks organisations to consider climate change as part of their BCMS.

What does the climate action amendment require?

It asks organisations to determine whether climate change is a relevant issue for their BCMS and, where it is, to take it into account, rather than introducing a separate climate strategy.

Is a new edition of ISO 22301 coming?

A third edition is in early development and currently at committee draft stage. Based on typical ISO revision timescales, it's still likely years from publication, so there's no need to wait for it before updating your BCMS.

What other standards work alongside ISO 22301?

UK government guidance points to several complementary standards, including BS 65000:2022 for organisational resilience, ISO 31000 for risk management, ISO 22361:2022 for crisis management, and ISO 37000:2021 for governance.


colin-jeffsAbout the author

Colin Jeffs MBCI transitioned into business continuity from IT project management, where resilience was a core requirement of system implementation. He has over 30 years’ experience in business continuity, operational resilience, and crisis management, holding senior leadership roles within major financial institutions in the City of London. Colin now leads Wavenet’s award-winning operational resilience consulting and software division and co-designed the latest version of Shadow-Planner.

blogs, business continuity

Latest blogs

See all posts
shadow-planner alert
Wavenet launches Shadow-Planner Alert to keep organisations connected during cyber incidents and outages

Wavenet has launched Shadow-Planner Alert, a secure mass communications solution designed to help organisations keep people informed and coordinated when disruption strikes. Built for cyber incidents, outages and operational emergencies, the platform enables organisations to reach employees, suppliers and response teams quickly through one structured, auditable system. Unlike standard communications tools that may be unavailable during an IT outage or cyberattack, Shadow-Planner Alert operates independently from an organisation’s primary IT environment. This gives resilience, security and IT teams a reliable route to issue urgent updates via email, SMS, or both, even when core systems are compromised. The platform combines multi-channel delivery, pre-approved message templates, structured contact management and real-time delivery tracking, helping teams act faster and reduce confusion during high-pressure events. The comprehensive communications audit trail supports governance, compliance and post-incident review. Shadow-Planner Alert also includes a secure, air-gapped document repository, ensuring critical information remains accessible during incidents when core systems may be unavailable. The launch comes as organisations place greater emphasis on cyber resilience, incident readiness and demonstrable continuity planning. Shadow-Planner Alert gives IT leaders a practical way to strengthen their organisation’s response plans by ensuring communications remain available when other systems do not. Paul Colwell, Chief Information Security Officer at Wavenet, commented: “During an incident, communication can be the difference between a controlled response and a wider operational crisis. If core systems are unavailable, organisations still need a secure, reliable way to reach the right people, issue clear instructions and evidence what has been communicated. Shadow-Planner Alert gives teams that capability, helping them maintain control when pressure is at its highest.” Designed for scenarios including cyber incident response, business continuity, supplier notification and resilience testing, Shadow-Planner Alert supports organisations working towards recognised resilience standards, including ISO 22301, the NCSC Cyber Assessment Framework and DORA.

Read more