ISO 22301 Business Continuity Management Certification
ISO 22301 business continuity management certification China. Business impact analysis, recovery time objectives and continuity plans. Accredited body.
ISO 22301 business continuity management system (BCMS) certification in Shanghai, Beijing and China — business impact analysis, recovery time objectives, continuity planning and exercising audited on a three-year cycle by an accredited body.
ISO 22301 is the international standard for business continuity management systems. It sets out requirements for planning, establishing and maintaining an organisation's ability to continue delivering products and services at an acceptable level following a disruption.
What the standard requires
- Scope and contextUnderstanding the organisation, its interested parties, and which activities, locations and services fall within the BCMS scope — drawn to reflect what the organisation actually needs to protect, not what is convenient to certify.
- Business impact analysisIdentifying prioritised activities, the time within which they must resume (recovery time objective), and the point to which they must be recovered (recovery point objective). This is the document auditors examine most closely, because every continuity strategy downstream depends on it being accurate.
- Risk assessmentIdentifying the disruptions prioritised activities are exposed to, and evaluating their likelihood and potential impact so strategies are proportionate.
- Continuity strategies and solutionsThe resources, procedures and capabilities needed to achieve recovery within the stated RTOs — including redundancy, alternate sites, supplier alternatives and manual workarounds.
- Continuity plansDocumented plans covering incident response, communication, escalation and recovery, with enough specific detail to be followed under pressure by someone who did not write them.
- Exercising and testingPlans proven through tabletop exercises and operational tests, with records demonstrating what was tested, what was found, and what was changed as a result.
- Warning and communicationArrangements for detecting disruptions early and communicating to staff, customers and authorities at the right time.
- Performance evaluationMeasurement of BCMS effectiveness, internal audit and management review with decisions recorded and acted upon.
- Continual improvementCorrective action on findings from exercises, audits and actual incidents, with verification that changes were effective.
The business impact analysis in practice
The BIA is where most continuity programmes either work or fail. It forces an organisation to state which activities genuinely cannot stop, how long they can be interrupted before consequences become unacceptable, and what the recovery of those activities actually depends on. Most organisations find the dependencies are not where they assumed — IT systems that seem critical turn out to be secondary, and manual processes or supplier relationships that seem routine turn out to be the actual constraint.
Where audits find gaps
Exercising is the most common. Plans written but never tested, or tabletop exercises that confirmed the plan looked reasonable without verifying it actually works. Business impact analyses completed at implementation and never updated as the organisation changed. And continuity plans that identify what needs to recover but not the specific resources, contacts and decision authorities needed to do it — detail that only matters when the plan is being followed under pressure.
The certification process
Stage 1 reviews the documented BCMS, confirms the scope and assesses readiness, examining the business impact analysis, risk assessment and continuity strategies. Stage 2 verifies implementation and effectiveness: continuity plans, the records of exercises actually conducted, and whether personnel can describe their roles in an incident. Certification runs on a three-year cycle with annual surveillance and recertification before expiry.
Who it applies to
- Banking, insurance and financial services subject to regulatory continuity expectations
- Telecommunications, data centres and IT service providers
- Healthcare providers and laboratories
- Oil, gas and utilities operators
- Logistics, ports and aviation services
- Government entities and their contracted service providers
- Any organisation named in a client contract as continuity-critical
Our role and its limits
ITMAD is an accredited certification body. Under ISO/IEC 17021-1 we cannot design or implement the management system we certify. We provide the audit and the certification decision, plus optional pre-assessment identifying gaps without prescribing how you close them.
What you receive
- Stage 1 report identifying readiness gaps before the main audit
- Stage 2 audit report with findings supported by objective evidence
- Non-conformities classified by severity with defined response timescales
- Certificate of registration stating your certified scope and locations
- Certification mark for use under our mark and seal policy
- Annual surveillance audits and reports through the three-year cycle