Guide

ISO 22301 Internal Audit Checklist

A service-trace approach to auditing whether a Business Continuity Management System is implemented and effective.

Internal audit should determine whether the BCMS conforms to its audit criteria and whether it is effectively implemented and maintained. It should not become a friendly document review performed only by the person who owns the process.

What this means in practice

A powerful audit method is to combine clause coverage with an end-to-end service trace. Select an important service and follow its scope, ownership, BIA, dependencies, strategy, plan, exercise, performance evidence and corrective actions. Then sample supporting leadership, competence, document control and management-review processes.

Decision and evidence map

AreaPractical questionEvidence
Scope/contextDoes the BCMS boundary match real operations and relevant requirements?Scope, context and interested-party records
BIAAre recovery requirements justified, approved and current?BIA samples, impact criteria and dependencies
StrategyCan chosen solutions meet recovery requirements?Capability evidence and gap decisions
PlansAre procedures usable, current and controlled?Activation, workarounds, contacts and versions
ExercisesAre objectives evaluated and significant findings corrected?Reports, timings, actions and retests
PerformanceDo audit and management review lead to decisions?KPIs, audit trail, review minutes and corrective action

Practical implementation checklist

  • Define audit scope, criteria, locations/functions and sampling before interviews.
  • Use auditors with suitable competence and objectivity.
  • Review previous findings, significant incidents and material changes.
  • Ask for evidence of operation rather than accepting blank templates.
  • Sample both current and older records to test maintenance.
  • Write findings against a criterion and objective evidence.
  • Check root cause and effectiveness for recurring issues.
  • Escalate systemic or high-consequence gaps appropriately.

Worked example

An audit samples a payment service whose BIA requires recovery within four hours. The latest DR evidence demonstrates six hours and no accepted risk or corrective action exists. A useful finding states the criterion, the four-hour requirement, the six-hour evidence and the missing governance response. “The DR plan needs improvement” would be too vague to drive action.

Common mistakes

  • Auditing only the existence of documents.
  • Allowing process owners to audit their own work without adequate objectivity.
  • Writing findings with no criterion or objective evidence.
  • Closing recurring issues after a text edit instead of correcting process cause.
  • Ignoring whether exercise and audit actions are actually effective.

Governance, review and improvement

Audit planning should reflect process importance, previous results and changes. Track findings to correction and, where needed, cause analysis and effectiveness review. Feed significant findings and trends into management review so audit changes the BCMS rather than producing an isolated report.

Authoritative references

BCM.Center paraphrases standards and guidance; use the official publication for authoritative wording and current status.

Frequently asked questions

Does an internal auditor need external certification?

Not necessarily; the organization should ensure competence and suitable objectivity for the audit scope and criteria.

Can the BCM manager audit the BCMS?

They can support evidence collection, but auditing their own work can compromise objectivity. Plan appropriate independence.

How much evidence should be sampled?

Use risk-based sampling sufficient to support a reasonable conclusion across the audit scope; there is no universal count.

Must every audit follow clause order?

No. Process- or service-based auditing can be effective if the audit program still covers relevant criteria.

When is a finding closed?

After correction and, where appropriate, cause and effectiveness have been addressed with evidence.