Business continuity practice is international, but the standards, regulatory language and evidence expected by organisations differ by country and sector. This hub starts with ISO 22301 as the common management-system baseline, then explains important national standards, government guidance and sector rules for the United States, United Kingdom, India, Germany and South Africa. It is designed for practitioners who need to build one coherent BCM programme without pretending that every organisation has the same legal obligations.
Important scope noteA national guide does not mean every document listed is mandatory for every organisation in that country. Financial services, public authorities, critical infrastructure and regulated sectors often have additional requirements. Always identify the legal entity, sector, regulator, location and contract before deciding what applies.
International baseline: the core BCM reference set
| Reference | Primary use | Practical output |
|---|
| ISO 22301:2019 + Amendment 1:2024 | Requirements for a business continuity management system | Scope, policy, leadership, planning, support, BIA/risk assessment, strategies, plans, exercises, evaluation and improvement |
| ISO 22313:2020 | Guidance on using ISO 22301 | Practical interpretation of BCMS requirements; current edition was confirmed in 2025 |
| ISO/TS 22317:2021 | Business impact analysis guidance | A formal, documented BIA process adapted to organisational needs |
| ISO/TS 22331:2018 | Business continuity strategy guidance | Strategy determination and selection |
| ISO 22398:2013 | Exercise guidance | Structured exercise planning, conduct and evaluation |
| BCI Good Practice Guidelines 7.0 | Practitioner good practice | Six professional practices: establish BCMS, embrace BC, analysis, solutions design, enabling solutions, validation |
Country comparison at a glance
| Country | Useful BCM references | Sector emphasis to understand | Start with |
|---|
| United States | ISO 22301; NFPA 1660; FEMA continuity guidance; NIST SP 800-34; FFIEC for banking | Continuity of essential functions, emergency/crisis management, IT contingency planning, sector guidance | Define sector and applicable regulator, then map BIA/BCP/DR to the relevant reference set |
| United Kingdom | BS EN ISO 22301:2019+A1:2024; Civil Contingencies Act guidance for responders; FCA/PRA operational resilience for in-scope finance; BCI GPG | Important business services, impact tolerances, mapping and severe-but-plausible scenario testing in regulated finance | Separate ISO BCMS conformity from statutory/public-sector duties and financial regulatory operational resilience |
| India | ISO 22301; RBI IT Governance/Risk/Controls directions for covered regulated entities; SEBI BCP/DR rules for covered market entities; CERT-In CCMP/security guidance | RTO/RPO, DR sites/drills, cyber crisis management, backup and transaction integrity in regulated sectors | Identify whether RBI, SEBI, CERT-In/government or another sector framework applies |
| Germany | ISO 22301; BSI Standard 200-4; IT-Grundschutz synergies; DORA for in-scope EU financial entities | BCM maturity/staged implementation, ISMS/BCM synergy, digital operational resilience and third-party ICT risk | Use BSI 200-4 when German public guidance/IT-Grundschutz alignment is valuable; layer sector law such as DORA |
| South Africa | ISO 22301; SARB Prudential Authority operational-resilience direction for banks; Basel operational resilience; government contingency guidance | Enterprise-wide operational resilience for banks, core business services and disruption preparedness | Identify sector/regulator first; for banks align BCM evidence to operational-resilience expectations |
How to build one programme across countries
- Create a global control model around ISO 22301 concepts: governance, BIA, strategy, plans, exercises, assurance and improvement.
- Maintain an applicability register by legal entity, country, sector and regulator. Do not embed every regulation into every plan.
- Map local terms to the global data model. For example, UK “important business service / impact tolerance” can coexist with process RTO and MBCO without treating the terms as identical.
- Create evidence once where possible: a dependency map, DR test or supplier assessment can support several frameworks when it proves the required outcome.
- Record local deltas: testing frequency, notification obligation, DR-site expectations, board approvals, outsourcing controls or public-sector duties.
- Review changes regularly. Standards and regulatory guidance evolve; the current ISO 22301 revision project is under development, while ISO 22301:2019 remains the published requirements edition.
Country guides
| Guide | What you will learn |
|---|
| United States BCM standards & guidance | NFPA 1660, FEMA continuity, NIST IT contingency planning and FFIEC banking context |
| United Kingdom BCM & operational resilience | BS EN ISO 22301, Civil Contingencies Act guidance, FCA/PRA impact tolerances and BCI practice |
| India BCM, BCP & DR guidance | RBI, SEBI, CERT-In and how to structure evidence for covered sectors |
| Germany BCM: BSI 200-4, ISO 22301 & DORA | German BSI BCM approach, IT-Grundschutz alignment and EU financial-sector resilience |
| South Africa BCM & operational resilience | ISO baseline, SARB Prudential Authority banking expectations and Basel alignment |
Official references and further reading
Build a jurisdiction applicability register
| Field | Example |
|---|
| Legal entity / service | Example Payments Ltd / Card authorisation |
| Country / regulator | United Kingdom / FCA |
| Reference | FCA operational resilience rules/guidance |
| Applicability basis | Entity and service are within firm’s regulated scope |
| Required BCM evidence | Important business service, impact tolerance, mapping, scenario testing, self-assessment |
| Owner | Operational Resilience Lead |
| Source URL / version date | Official regulator link + review date |
| Last legal/compliance verification | Quarterly / material change |
| Gap / action | Third-party mapping incomplete; action due |
This register prevents two common failures: claiming a rule applies where it does not, and running a global BCM framework that never checks local obligations. The country pages below are educational starting points, not legal advice.
Global crosswalk: translate local language into operating evidence
| Concept | ISO-style BCM evidence | Possible local overlay |
|---|
| Criticality | BIA + priority products/services/activities | US essential functions; UK important business services; South African banking core business services |
| Maximum disruption | MTPD/MAO and approved service requirement | UK impact tolerance includes broader harm outcome for in-scope firms |
| Technology recovery | RTO/RPO + DR strategy/tests | NIST contingency planning; RBI/SEBI DR expectations; DORA ICT continuity/recovery |
| Dependencies | People, technology, facilities, information, suppliers | FCA/PRA mapping; Basel operational-resilience mapping; DORA ICT third parties |
| Testing | Exercise programme with objectives and evaluation | FCA severe-but-plausible scenarios; RBI/SEBI DR drills for covered entities; DORA periodic ICT testing |
| Improvement | Findings, corrective action, management review | Regulator self-assessment/remediation/supervisory evidence where applicable |