ISO 22301
Definition
ISO 22301
ISO 22301 is the international standard for business continuity, setting requirements for how an organisation prepares for, responds to and recovers from disruption. Its outsourcing value is the recovery target a provider commits to, not the badge on the wall.
Continuity is the one area where outsourcing buyers ask the right question by instinct.
Everybody wants to know what happens when the site goes down. The certificate does not answer that — it confirms a system exists for working the answer out.
The numbers that matter sit underneath: how long recovery takes, how much data is lost, and whether anyone has tested the plan against a real outage rather than a tabletop exercise.
Key takeaways
- ISO 22301 certifies a business continuity management system, not a guaranteed recovery time.
- Recovery targets belong in the contract, because the standard does not set them.
- A plan that has never been tested against a live disruption is a document, not a capability.
- Offshore delivery concentrates continuity risk in weather, power and connectivity.
How it works
ISO 22301 requires an organisation to build a management system for continuity. DNV describes it as a standard that provides requirements for a business continuity management system, covering preparation, response and recovery.
Microsoft records that the standard came out of ISO technical committee TC 223 and was the first international standard for management systems that help ensure business continuity. The current requirements edition is ISO 22301:2019.
The method runs through impact analysis first. An organisation identifies which activities matter, how quickly each must resume, and what it needs in place to resume them.
Two numbers come out of that work — and both belong in your contract. Recovery time objective is how long restoration may take. Recovery point objective is how much data you accept losing.
| Term | What it measures | Why a buyer cares |
|---|---|---|
| Business impact analysis | Which activities are critical | Decides what gets restored first |
| Recovery time objective | Hours until service resumes | The number your own customers feel |
| Recovery point objective | Data loss tolerated | Determines backup frequency |
| Exercise programme | Whether plans get tested | A plan untested is a plan unproven |
| Alternate site | Where work moves to | Useless if it shares the same grid |
The last row is the one buyers miss. A second site on the same power supply and the same fibre route is geographic separation — on paper only.
Examples
Continuity arrangements look convincing in a proposal and reveal themselves during the first genuine disruption. What follows are decisions that got made, not options that got presented.
A Philippine delivery centre invokes its plan during a typhoon and moves 600 agents to home working within a day. The certificate did not achieve that; the tested playbook did.
A bank discovers its provider’s alternate site sits eleven kilometres from the primary one. Both lost power in the same regional outage, which is a failure of business continuity plan (BCP) design rather than of certification.
An insurer writes recovery time objectives into its contract with service credits attached, treating continuity as a commercial term. That moves the issue into risk outsourcing territory.
A healthcare client requires evidence of two live exercises a year. Its provider had certified in 2023 and last tested anything in 2022.
Related terms
Continuity, recovery and risk terminology overlap constantly, and providers exploit the slippage between them. Every line below gives one meaning and names the thing it is not.
- Business continuity plan (BCP): the document itself, which the standard governs but does not write.
- Risk outsourcing: transferring exposure to a third party, rather than planning around it.
- Business risk: the general category of threats to objectives, wider than disruption alone.
- ISO certification: the audit process common to every ISO management standard.
- Compliance outsourcing: buying regulatory capability as a service.
- Service level agreement compliance: meeting contracted performance, which continues to apply during disruption.
- Data center outsourcing: the infrastructure layer where most recovery capability physically sits.
FAQ
Does ISO 22301 guarantee a recovery time?
No. It requires an organisation to set, document and test recovery objectives. The specific times are yours to negotiate and put in the contract.
What is the difference between RTO and RPO?
Recovery time objective is how long until service resumes. Recovery point objective is how much data you can afford to lose.
Which edition is current?
ISO 22301:2019 is the current requirements edition, replacing the 2012 original that first established the standard.
Is certification worth requiring from an offshore provider?
Often yes, because offshore sites carry concentrated weather and power risk. Pair it with evidence of tested exercises rather than accepting the certificate alone.
How far apart should alternate sites be?
Far enough to avoid a shared failure. Separate power grids and separate network routes matter more than raw distance.
How often should plans be tested?
At least annually, and more for critical services. Ask for exercise reports, not a statement that exercises take place.
Browse source partners in the Outsource Accelerator hubs directory and ask what the recovery targets are actually tested against.







Independent




