Learn why and how to audit your organisation’s business continuity management systems against ISO 22301, to lower the risk of and be prepared for unexpected business interruption.

A business continuity management system (BCMS) can help your organisation prepare for, minimise the risk of, and respond to unexpected operational disruption.

By carrying out internal audits of your BCMS you can identify how well that system is performing against your own organisational requirements and those of the ISO 22301 standard for business continuity management systems. Auditing helps you to determine where improvements can be made, not just once but on a continual basis.

This 2-day ISO 22301 Internal Auditor training course explains the standard and describes the role of the internal auditor in maintaining as effective BCMS. Led by an expert tutor, the course incorporates engaging teaching modules, supported by interactive workshops to practise skills as they are learned.

The course is suitable for anyone who wishes to understand the principles and practicalities of auditing business continuity management systems, including:

  • those responsible for undertaking internal audits against ISO 22301:2019
  • managers responsible for implementing, maintaining and continually improving a business continuity management system
  • those seeking to ensure conformity with the stated business continuity policy
  • those responsible for monitoring and reviewing the performance of the BCMS
  • auditees wishing to understand the audit process.

It also includes an overview of ISO 22301 so no prior knowledge of the standard is required.

Key topics covered by the course include:

  • introduction to auditing
  • the role of an internal auditor
  • auditor skills
  • overview of ISO 22301:2019 clauses
  • the audit programme
  • audit planning
  • documented information
  • business impact analysis and risk assessment
  • business continuity plans and procedures
  • opening and closing meetings
  • audit checklists
  • nonconformity report writing
  • corrective action

This typical course agenda offers a flavour of the breadth and structure of this 2-day training course. Exact timings are tailored to whether the course is delivered face-to-face or online in our virtual classroom. Across the 2 days we will cover:

  • Day 1
    • Section 1 Introduction
    • Exercise
    • Section 2 What is a management system?
    • Section 3 ISO 22301 structure
    • Section 4 Potential benefits of implementing ISO 22301
    • Section 5 Contents of ISO 22301
    • Section 6 Summarising ISO 22301
    • Section 7 The PDCA approach
    • Section 8 The process approach
    • Section 9 Planning
    • Section 10 Risk-based thinking
    • Section 11 Needs and expectations of interested parties
    • Section 12 Stakeholders in implementing ISO 31000 – risk management
    • Section 13 ISO 22301 clause 5 (role and responsibilities of leaders)
    • Section 14 ISO 22301 clause 6 (planning)
    • Exercise
    • LUNCH
    • Exercise
    • Section 15 ISO 22301 clause 7 (support)
    • Section 16 ISO 22301 clause 8 (operational control)
    • Section 17 ISO 22301 clause 9 (performance evaluation)
    • Section 18 ISO 22301 clause 10 (improvement)
    • Exercise
    • Section 19 Benefits of a formal business continuity system
    • Section 20 Planning the implementation of a BCMS
    • Section 21 Building the control document
    • Section 22 Management system auditing requirements
    • Section 23 Requirements of ISO 19011 guidelines for auditing
    • Section 24 Types of internal systems audits
    • CLOSE
  • Day 2
    • Exercise
    • Section 25 Introduction to management system auditing
    • Section 26 Audit planning and checklist
    • Section 27 Checklists
    • Section 28 Audit as part of performance monitoring and improvement
    • Section 29 Opening meetings
    • Section 30 Audit questions and use of checklists
    • Section 31 Communications and behavioural issues during audit
    • LUNCH
    • Section 32 Checklists
    • Exercise
    • Section 33 The five main steps in the audit process
    • Section 34 Conducting the audit
    • Section 35 Nonconformity reports and audit reporting
    • Section 36 Audit reporting
    • Section 37 Corrective action
    • Exercise
    • Section 38 Closing out nonconformities
    • Section 39 Closing meetings
    • Section 40 Particular closing meetings scenarios for discussions in meetings
    • CLOSE AND REVIEW

On completion delegates will:

  • be able to confidently plan, conduct, report and follow up an internal audit based on ISO 22301
  • summarise audit findings and discuss these within the closing meeting
  • contribute to the continual improvement of the BCMS

An ISO 22301 Internal Auditor training course certificate will be received by delegates who attend and complete all elements of the course.

ISO 22301 Internal Auditor Certificate