What is ISO 22301?
ISO 22301:2019 (Business Continuity Management Systems). Any organisation whose customers, regulators or board demand provable business continuity: financial services, healthcare, utilities, manufacturing, B2B SaaS, ICT third parties.
Who needs to comply
- Financial services and fintech (often combined with DORA)
- Healthcare providers (often combined with NEN 7510 or HIPAA-equivalent)
- Critical infrastructure: energy, water, transport
- B2B SaaS with strict customer SLAs
- ICT third parties supporting regulated entities
Key ISO 22301 controls covered by Dazr
What auditors look for
ISO 22301 auditors sample three things: a current BIA with RTO and RPO per process, a BCP that has actually been tested in the past 12 months with documented findings, and management-review evidence. Dazr holds the cadence.
How Dazr helps with ISO 22301
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. ISO 22301 is one of its eleven frameworks, included from Pro, €99 a month. In practice that means:
- Link the business impact analysis, with RTO and RPO per process, and review it on cadence
- Track BCP and DR test exercises as recurring controls with documented findings
- Record critical suppliers in the vendor register with review and contract-expiry dates (Pro and Enterprise)
- Log disruptions in the incident register alongside security incidents, with timestamps and lessons learned
- Hand the auditor or supervisor a read-only view of the entire continuity programme
Back to the full Dazr Compliance overview › | Sign up free ›