Guide

Business Continuity Standards & Guidance by Country

A practitioner hub comparing international BCM standards with major national and sector guidance in the United States, United Kingdom, India, Germany and South Africa.

Business continuity practice is international, but the standards, regulatory language and evidence expected by organisations differ by country and sector. This hub starts with ISO 22301 as the common management-system baseline, then explains important national standards, government guidance and sector rules for the United States, United Kingdom, India, Germany and South Africa. It is designed for practitioners who need to build one coherent BCM programme without pretending that every organisation has the same legal obligations.

Important scope note

A national guide does not mean every document listed is mandatory for every organisation in that country. Financial services, public authorities, critical infrastructure and regulated sectors often have additional requirements. Always identify the legal entity, sector, regulator, location and contract before deciding what applies.

International baseline: the core BCM reference set

ReferencePrimary usePractical output
ISO 22301:2019 + Amendment 1:2024Requirements for a business continuity management systemScope, policy, leadership, planning, support, BIA/risk assessment, strategies, plans, exercises, evaluation and improvement
ISO 22313:2020Guidance on using ISO 22301Practical interpretation of BCMS requirements; current edition was confirmed in 2025
ISO/TS 22317:2021Business impact analysis guidanceA formal, documented BIA process adapted to organisational needs
ISO/TS 22331:2018Business continuity strategy guidanceStrategy determination and selection
ISO 22398:2013Exercise guidanceStructured exercise planning, conduct and evaluation
BCI Good Practice Guidelines 7.0Practitioner good practiceSix professional practices: establish BCMS, embrace BC, analysis, solutions design, enabling solutions, validation

Country comparison at a glance

CountryUseful BCM referencesSector emphasis to understandStart with
United StatesISO 22301; NFPA 1660; FEMA continuity guidance; NIST SP 800-34; FFIEC for bankingContinuity of essential functions, emergency/crisis management, IT contingency planning, sector guidanceDefine sector and applicable regulator, then map BIA/BCP/DR to the relevant reference set
United KingdomBS EN ISO 22301:2019+A1:2024; Civil Contingencies Act guidance for responders; FCA/PRA operational resilience for in-scope finance; BCI GPGImportant business services, impact tolerances, mapping and severe-but-plausible scenario testing in regulated financeSeparate ISO BCMS conformity from statutory/public-sector duties and financial regulatory operational resilience
IndiaISO 22301; RBI IT Governance/Risk/Controls directions for covered regulated entities; SEBI BCP/DR rules for covered market entities; CERT-In CCMP/security guidanceRTO/RPO, DR sites/drills, cyber crisis management, backup and transaction integrity in regulated sectorsIdentify whether RBI, SEBI, CERT-In/government or another sector framework applies
GermanyISO 22301; BSI Standard 200-4; IT-Grundschutz synergies; DORA for in-scope EU financial entitiesBCM maturity/staged implementation, ISMS/BCM synergy, digital operational resilience and third-party ICT riskUse BSI 200-4 when German public guidance/IT-Grundschutz alignment is valuable; layer sector law such as DORA
South AfricaISO 22301; SARB Prudential Authority operational-resilience direction for banks; Basel operational resilience; government contingency guidanceEnterprise-wide operational resilience for banks, core business services and disruption preparednessIdentify sector/regulator first; for banks align BCM evidence to operational-resilience expectations

How to build one programme across countries

  1. Create a global control model around ISO 22301 concepts: governance, BIA, strategy, plans, exercises, assurance and improvement.
  2. Maintain an applicability register by legal entity, country, sector and regulator. Do not embed every regulation into every plan.
  3. Map local terms to the global data model. For example, UK “important business service / impact tolerance” can coexist with process RTO and MBCO without treating the terms as identical.
  4. Create evidence once where possible: a dependency map, DR test or supplier assessment can support several frameworks when it proves the required outcome.
  5. Record local deltas: testing frequency, notification obligation, DR-site expectations, board approvals, outsourcing controls or public-sector duties.
  6. Review changes regularly. Standards and regulatory guidance evolve; the current ISO 22301 revision project is under development, while ISO 22301:2019 remains the published requirements edition.

Country guides

GuideWhat you will learn
United States BCM standards & guidanceNFPA 1660, FEMA continuity, NIST IT contingency planning and FFIEC banking context
United Kingdom BCM & operational resilienceBS EN ISO 22301, Civil Contingencies Act guidance, FCA/PRA impact tolerances and BCI practice
India BCM, BCP & DR guidanceRBI, SEBI, CERT-In and how to structure evidence for covered sectors
Germany BCM: BSI 200-4, ISO 22301 & DORAGerman BSI BCM approach, IT-Grundschutz alignment and EU financial-sector resilience
South Africa BCM & operational resilienceISO baseline, SARB Prudential Authority banking expectations and Basel alignment

Official references and further reading

Build a jurisdiction applicability register

FieldExample
Legal entity / serviceExample Payments Ltd / Card authorisation
Country / regulatorUnited Kingdom / FCA
ReferenceFCA operational resilience rules/guidance
Applicability basisEntity and service are within firm’s regulated scope
Required BCM evidenceImportant business service, impact tolerance, mapping, scenario testing, self-assessment
OwnerOperational Resilience Lead
Source URL / version dateOfficial regulator link + review date
Last legal/compliance verificationQuarterly / material change
Gap / actionThird-party mapping incomplete; action due

This register prevents two common failures: claiming a rule applies where it does not, and running a global BCM framework that never checks local obligations. The country pages below are educational starting points, not legal advice.

Global crosswalk: translate local language into operating evidence

ConceptISO-style BCM evidencePossible local overlay
CriticalityBIA + priority products/services/activitiesUS essential functions; UK important business services; South African banking core business services
Maximum disruptionMTPD/MAO and approved service requirementUK impact tolerance includes broader harm outcome for in-scope firms
Technology recoveryRTO/RPO + DR strategy/testsNIST contingency planning; RBI/SEBI DR expectations; DORA ICT continuity/recovery
DependenciesPeople, technology, facilities, information, suppliersFCA/PRA mapping; Basel operational-resilience mapping; DORA ICT third parties
TestingExercise programme with objectives and evaluationFCA severe-but-plausible scenarios; RBI/SEBI DR drills for covered entities; DORA periodic ICT testing
ImprovementFindings, corrective action, management reviewRegulator self-assessment/remediation/supervisory evidence where applicable