ISO 22301 Implementation Checklist (Free Template)

A free ISO 22301 implementation checklist — every clause area, the evidence a certification auditor asks for, and where SAMA expects more than the standard.

GRC Vantage TeamGRC Vantage Team2026-08-265 min read

ISO 22301 certification fails on evidence far more often than on capability. Organisations that genuinely recover well still get findings, because the management-system clauses — context, interested parties, documented information, management review — are the parts nobody owns until the auditor asks.

This checklist is organised by the standard's clause structure, and it flags separately the places where SAMA expects more than ISO 22301 does, which is what catches Saudi banks running an otherwise conformant programme. A downloadable working copy is available at the end.

How to use this checklist

  1. Mark the current state — in place, partial, or absent.
  2. Name the owner. For management-system clauses, that owner is rarely the BCM manager.
  3. Note the documented information that evidences it, and where it lives.
  4. Record when it was last reviewed — staleness fails as surely as absence.
  5. Identify the gap and the action to close it.

Clause 4 — Context of the organisation

The clause most often skipped, and the one that determines whether scope is defensible.

4.1 Internal and external issues relevant to continuity identified and documented.

4.2 Interested parties identified, with their requirements captured — including regulators. For a SAMA-supervised entity, SAMA is an interested party with documented expectations.

4.3 Scope of the management system defined, with exclusions justified. An auditor will test whether an excluded activity genuinely sits outside scope.

4.4 The management system established, documented and maintained as a system rather than a folder of plans.

Clause 5 — Leadership

5.1 Top management demonstrating leadership — evidenced by decisions and resourcing, not a signed statement.

5.2 A continuity policy, approved, communicated and available as documented information.

5.3 Roles, responsibilities and authorities assigned and communicated, including who is authorised to invoke a plan.

Clause 6 — Planning

6.1 Risks and opportunities addressed, with actions planned and evaluated for effectiveness.

6.2 Continuity objectives established at relevant functions and levels — measurable, monitored and updated.

6.3 Changes to the management system planned rather than absorbed.

Clause 7 — Support

7.1 Resources determined and provided.

7.2 Competence — the people with continuity responsibilities are demonstrably competent, with the evidence retained.

7.3 Awareness across the organisation of the policy, their role, and the implications of not conforming.

7.4 Communication — internal and external, with what, when, to whom and how all defined.

7.5 Documented information controlled: identified, reviewed, approved, version-controlled and available where needed. Including when the primary network is unavailable.

Clause 8 — Operation

The clause most programmes are strongest on, and where the artefacts live.

8.2 Business impact analysis and risk assessment

8.2.1 A documented, repeatable process for BIA and risk assessment.

8.2.2 BIA — activities identified, impacts over time assessed, prioritised timeframes (RTO) set, and dependencies and resources determined.

8.2.3 Risk assessment — risks of disruption to prioritised activities and their resources identified, analysed and evaluated.

8.3 Business continuity strategies and solutions

8.3.1–8.3.5 Strategies identified and selected against the BIA output, with solutions implemented and resource requirements determined — people, information, technology, premises, suppliers.

8.4 Plans and procedures

8.4.1 A structure of plans and procedures, with a response structure defined.

8.4.2 Warning and communication — detecting, monitoring and communicating an incident, including to interested parties.

8.4.3 Business continuity plans — with purpose, scope, roles, activation criteria and named responsibilities.

8.4.4 Recovery — restoring activities from the temporary measures adopted during response.

8.5 Exercise programme

Exercises consistent with scope and objectives, based on scenarios, producing formalised results and post-exercise reports with recommendations and actions.

8.6 Evaluation of documentation and capabilities

Continuity documentation and capabilities evaluated periodically, and after an incident, activation or significant change.

Clause 9 — Performance evaluation

9.1 Monitoring, measurement, analysis and evaluation — what is measured, when, and by whom.

9.2 Internal audit at planned intervals, with an audit programme and impartial auditors. See our internal audit checklist.

9.3 Management review at planned intervals, with the required inputs and documented outputs. This is the single most common non-conformity — the review either does not happen or does not cover the required inputs.

Clause 10 — Improvement

10.1 Nonconformity and corrective action — reacted to, root cause established, action taken and effectiveness reviewed.

10.2 Continual improvement of the suitability, adequacy and effectiveness of the management system.

Where SAMA expects more than ISO 22301

An ISO 22301-certified programme is most of the way to SAMA compliance. These five gaps are what remain — and each is invisible to a certification audit.

AreaThe SAMA addition
Regulator notificationDefined timeframes and channels for notifying SAMA of significant continuity events. ISO 22301 says nothing about regulator notification at all.
National shared servicesDependency on shared national payments and clearing infrastructure mapped and scenario-tested.
Cyber resilienceDestructive cyber scenarios, immutable backups and BCM–CSIRT cross-rehearsal — not cyber as one risk among many.
Board engagementA prescribed reporting cadence and periodic board participation in crisis exercises.
OutsourcingContinuity assessment, contractual recovery commitments and monitoring per material provider, intersecting the SAMA Outsourcing Regulations.

And where the NCA expects more

For entities inside the NCA's scope, continuity is also a cybersecurity control:

  • ECC subdomain 3-1 — cybersecurity resilience aspects of business continuity management
  • CSCC 3-1 — the same, applied to critical systems
  • OTCC 3-1 — including the requirement that essential functions keep operating locally during a network or power outage

Those are assessed by the NCA against its own control sets, not against ISO 22301. See the NCA frameworks list.

Get the downloadable checklist

The full checklist — a working spreadsheet organised by clause, with state, owner, documented-information reference and last-reviewed columns, plus the SAMA gap items as a separate tab — is available on request. Contact us to receive a copy.

For the discipline in depth, read ISO 22301 in Saudi Arabia and business continuity management in Saudi Arabia. For the regulated overlay, see the SAMA BCM Framework and its checklist.

To run the BIA, plans, exercise schedule and management review on connected data rather than documents, see GRC Vantage's BCM module.

Want to see this in the platform?

Schedule a demo with the GRC Vantage team in Riyadh or Dammam.

See BCM
GRC Vantage Team
GRC Vantage Team
Saudi GRC Practitioners

The GRC Vantage team brings together compliance, risk, audit and business continuity practitioners based in Riyadh and Dammam. We help Saudi banks, government entities and regulated enterprises navigate the SAMA framework family, the NCA framework family, PDPL, ISO 27001 and ISO 22301.