11.4 Preventive Action, Change Monitoring & Documenting Improvements

Key Takeaways

  • ISO 22301:2019 contains no separate "preventive action" clause — Annex SL replaced it with Clause 6.1, actions to address risks and opportunities, which makes the entire management system preventive by design.
  • PECB Domain 6 nonetheless examines the ability to determine corrective and preventive actions, so candidates must hold both framings: the concept is examinable even though the 2012-era clause is not.
  • Corrective action eliminates the cause of a nonconformity that has occurred; preventive action addresses a potential nonconformity that has not occurred; correction merely contains the immediate effect.
  • Change factor monitoring is the forward-looking half of continual improvement, tracking internal, external, technological, regulatory, and supply-chain triggers that invalidate BIA assumptions before a disruption exposes them.
  • Continual improvement means recurring stepwise enhancement with periods of consolidation, and it must be evidenced: an improvement that leaves no documented trace cannot be demonstrated at surveillance or recertification.
Last updated: August 2026

Domain 6 — Continual improvement of a BCMS based on ISO 22301 — carries 10 of the 80 exam questions (12.5%), all at the evaluation level. Section 10.3 covered nonconformity handling, root cause analysis, and management review outputs. Section 11.3 covered long-term governance and the certification cycle. Three Domain 6 competencies remain, and each contains a distinct trap:

  • "Ability to determine the corrective and preventive actions to treat nonconformities"
  • "Ability to monitor change factors"
  • "Ability to gather inputs to continual improvement and maintain and update documented information", with the associated knowledge statement "Knowledge of documenting the improvements"

1. Preventive Action: The Clause That Isn't There

This is the single most reliable trap in Domain 6, because the PECB competency statement and the current standard appear to disagree.

ISO 22301:2012 had a distinct preventive action clause, inherited from the old ISO management-system template. ISO 22301:2019 does not. When the standard was rewritten to the Annex SL harmonized structure, the preventive action clause was deliberately removed and its function absorbed into Clause 6.1, Actions to address risks and opportunities.

The reasoning, and the point the exam wants you to articulate: a management system that identifies risks during planning and acts on them is a preventive system. Preventive action was never a separate activity to be performed after the fact — it was the whole purpose of planning. Bolting it on as a reactive clause implied the opposite.

So Clause 10 of ISO 22301:2019 reads:

ClauseTitleContent
10.1Nonconformity and corrective actionReact to the nonconformity; evaluate the need to eliminate its causes; implement action; review effectiveness; update risks and opportunities if necessary; make changes to the BCMS if necessary; retain documented information
10.2Continual improvementContinually improve the suitability, adequacy, and effectiveness of the BCMS

There is no 10.3, and no preventive action clause anywhere in the standard.

Holding both framings

PECB's Domain 6 competency nonetheless says "corrective and preventive actions." This is not an error in the blueprint — it reflects that preventive action remains a live implementation concept even though it is no longer a standalone requirement. The Lead Implementer is expected to be able to:

  • Explain that ISO 22301:2019 has no preventive action clause, and say where the function went (Clause 6.1)
  • Still determine and apply preventive measures in practice, distinguishing them from corrective ones

The three terms, precisely

TermTriggerPurposeWhere it lives in ISO 22301:2019
CorrectionA nonconformity has occurredContain or eliminate the immediate effect. Does not touch the cause.Clause 10.1(a) — "react to the nonconformity"
Corrective actionA nonconformity has occurredEliminate the cause, so it cannot recurClause 10.1(b)-(d)
Preventive actionA nonconformity has not occurred but couldEliminate the cause of a potential nonconformityClause 6.1 — risks and opportunities (no dedicated clause)

A worked illustration:

The Year 1 surveillance audit finds that the alternate work site contract expired four months ago and was never renewed.

  • Correction: Renew the contract immediately. The gap is closed; nothing has been learned.
  • Corrective action: Root cause analysis shows no contract in the BCMS resource inventory has a renewal owner or a diarised expiry alert. Add expiry dates and named owners for all continuity-critical contracts, with automated 90-day alerts. Recurrence is now prevented.
  • Preventive action: No nonconformity has occurred regarding supplier insolvency — but horizon scanning identifies that the alternate site provider is loss-making. Qualify a second provider before any failure occurs. This is Clause 6.1 territory, not Clause 10.1.

The exam discriminator: corrective action always looks backwards from something that happened; preventive action always looks forwards at something that has not. And "we fixed it" is a correction, not a corrective action — the most frequently tested confusion in the entire standard.


2. Monitoring Change Factors

A BCMS is a set of assumptions about the organization: which activities matter, how long they can be down, what they depend on, and who recovers them. Every one of those assumptions decays. Change factor monitoring is the discipline of detecting decay before a disruption does.

Clause 10.1 requires the organization to determine whether similar nonconformities exist or could potentially occur, and Clause 6.3 requires that changes to the BCMS be carried out in a planned manner. Together they make change monitoring a requirement, not an optional maturity practice.

Change categoryRepresentative triggersBCMS elements invalidated
OrganizationalMerger, acquisition, divestment, restructure, new site, site closure, outsourcing a functionScope (4.3), interested parties (4.2), roles (5.3), BIA, plans
OperationalNew product or service line, process redesign, changed operating hours, volume growthBIA activity list, RTO/RPO, resource requirements
TechnologicalCloud migration, ERP replacement, new SaaS dependency, end-of-life infrastructureDependency map, ICT recovery solutions, RPO feasibility
PeopleKey-person departure, high turnover in a recovery team, loss of a scarce competenceCompetence matrix (7.2), succession, call trees
Supply chainNew critical supplier, supplier merger, supplier financial distress, concentration into one providerExternal dependency map, supplier continuity SLAs
RegulatoryNew or amended resilience regulation, new contractual continuity obligationsCompliance obligations (4.2), objectives (6.2), testing frequency
Threat landscapeNew attack techniques, changed climate exposure, geopolitical shiftsRisk assessment (8.2.3), scenario library, exercise programme

Making monitoring systematic

Monitoring fails when it depends on someone remembering. Three mechanisms make it structural:

  1. Embed BCMS triggers in existing governance. The change advisory board, project gate reviews, procurement onboarding, and HR leaver processes all already exist. Add a mandatory BCMS-impact question to each. A cloud migration that reaches production without anyone asking whether the RPO is still achievable represents a process failure, not an individual one.
  2. Define review triggers alongside review cycles. Documents carry both a periodic review date and event triggers — "review on any change of scope, any new critical supplier, or any material incident."
  3. Assign horizon scanning explicitly. Regulatory and threat-landscape monitoring must have a named owner and a reporting route into the management review, or it will not happen.

Change factor monitoring outputs feed Clause 9.3.2 as a mandatory management review input — changes in external and internal issues relevant to the BCMS.


3. Gathering Improvement Inputs and Documenting Improvements

The inputs

Continual improvement is not a mood; it is fed by identifiable sources, and an implementer should be able to list them:

SourceWhat it yields
Internal audit findings (9.2)Nonconformities and OFIs
Certification audit findingsExternal nonconformities and OFIs
Management review outputs (9.3.3)Improvement decisions and resource allocations
Exercise after-action reports (8.5)Capability gaps under realistic conditions
Real incident post-incident reviewsThe highest-value evidence available — actual performance against RTO and MBCO
Performance monitoring and KPI trends (9.1)Drift detected before it becomes failure
Change factor monitoringAssumptions that have decayed
Interested party feedbackCustomer, regulator, insurer, and supplier expectations
Corrective action effectiveness reviews (10.1)Whether previous fixes actually worked

Continual, not continuous

ISO uses continual improvement deliberately. Continuous implies uninterrupted, unbroken change. Continual means recurring, stepwise improvement with periods of consolidation between increments — which is what management systems actually do and can sustain. An organization that stabilises a new process for two quarters before improving it again is conforming to Clause 10.2, not failing it.

Documenting the improvements

PECB lists "Knowledge of documenting the improvements" as a distinct knowledge statement, and the reason is practical: an improvement that leaves no trace cannot be demonstrated. At surveillance and recertification, the auditor asks how the BCMS has improved since the last visit. "We have made lots of small improvements" is not evidence; a maintained record is.

Minimum documented information for an improvement:

FieldPurpose
SourceWhich input generated it — audit ref., AAR, incident, KPI trend, review decision
DescriptionWhat was changed
RationaleWhy, and what it was expected to achieve
Owner and dateAccountability and chronology
Documents updatedVersion numbers of every artefact changed — the traceability an auditor samples
Verification of effectEvidence the improvement achieved its intent (see Section 10.4 on effectiveness)

Two document-control obligations follow from Clause 7.5.3 and are routinely failed:

  • Every improvement that changes a document must move that document's version, with the change recorded and the superseded version controlled. An improved procedure circulating alongside three uncontrolled older copies has created a nonconformity while trying to fix one.
  • Downstream artefacts must be swept. Changing the incident escalation threshold means updating the incident response plan, the affected BCPs, the action cards, the awareness materials, and the exercise scenarios. Partial propagation is one of the most common minor nonconformities at surveillance.

The improvement register — alongside the corrective action log and the exercise programme — is the evidence base that proves Clause 10.2 conformity. It is also, in practice, the first artefact an experienced surveillance auditor asks to see.


4. Worked Implementation Scenario: A Logistics Operator's Improvement Cycle

Context. A certified logistics operator completes its Year 1 surveillance audit with one minor nonconformity: the after-action report from its June functional exercise recorded four findings, of which two had no assigned owner.

Correction. The BCMS Manager assigns owners to the two orphaned findings within a week. The immediate gap is closed.

Corrective action. Root cause analysis using the 5 Whys reveals that the AAR template contains an owner field but the post-exercise workflow has no gate requiring the field to be populated before the report is issued. The corrective action adds a mandatory completeness check to the exercise coordinator's checklist and configures the tracking tool to reject an AAR with unassigned findings. This eliminates the cause.

Preventive action (Clause 6.1, not 10.1). The same review notes that the corrective action log has the identical weakness — entries can be created without owners — although no nonconformity has yet arisen there. Because this is a potential nonconformity rather than an actual one, the fix is registered as a risk treatment under Clause 6.1, and the same validation is applied to the corrective action log.

Change factor monitoring in the same cycle. The operator's horizon scanning flags two changes: a planned WMS migration to a SaaS platform in Q3, and the acquisition of a regional competitor with two additional depots. Both trigger BCMS review — the migration invalidates the current dependency map and the achievable RPO, and the acquisition expands the scope boundary and the interested party matrix.

Documenting the improvements. All of it is recorded in the improvement register: source (surveillance NC 2026-01 and horizon scanning), description, rationale, owner, and the documents updated — exercise procedure v3.1 to v3.2, corrective action procedure v2.4 to v2.5, BCMS scope statement v4.0 to v5.0, dependency map v6.2 to v7.0. Awareness materials and the exercise scenario library are swept for consistency.

Outcome. At Year 2 surveillance the auditor samples the improvement register, traces the exercise finding through root cause to the workflow control and to the verified absence of recurrence across three subsequent exercises, and closes the prior nonconformity as effectiveness-verified rather than merely completed. The auditor records the register as a strength.


5. PECB Exam Warning Traps & Implementation Pitfalls

[!WARNING] Trap 1 (There is no preventive action clause): ISO 22301:2019 has no preventive action clause. Annex SL replaced it with Clause 6.1, actions to address risks and opportunities. An option asserting that the organization must maintain a documented preventive action procedure "as required by Clause 10.3" is doubly wrong — no such clause and no such requirement.

[!WARNING] Trap 2 (Correction is not corrective action): Fixing the instance is a correction. Eliminating the cause so it cannot recur is corrective action. Clause 10.1 requires both, and exam scenarios that describe an organization "resolving" findings without root cause analysis are describing corrections presented as corrective actions.

[!WARNING] Trap 3 (Direction of travel): Corrective action responds to something that has happened; preventive action addresses something that has not. If the scenario contains an actual nonconformity, the answer is corrective action however forward-looking the fix appears.

[!WARNING] Trap 4 (Continual is not continuous): ISO 22301 requires continual improvement — recurring, stepwise, with consolidation between increments. Options implying that a compliant BCMS must be under constant unbroken change misread Clause 10.2.

[!WARNING] Trap 5 (Undocumented improvement is undemonstrable): Clause 10.2 conformity is proven from the improvement register, updated document versions, and effectiveness evidence. Real improvements that were never recorded will not be credited at surveillance.

[!WARNING] Trap 6 (Sweep the downstream documents): An improvement that updates a procedure but leaves the dependent plans, action cards, awareness material, and exercise scenarios stating the old rule creates a fresh nonconformity under Clause 7.5.3. Partial propagation is a classic surveillance minor.

Loading diagram...
Clause 6.1 vs Clause 10.1: Where Preventive and Corrective Action Live, and How Improvements Are Evidenced
Test Your Knowledge

A candidate is asked how ISO 22301:2019 addresses preventive action. Which response is correct?

A
B
C
D
Test Your Knowledge

A surveillance audit finds that a critical supplier's continuity agreement lapsed six months ago. The BCMS Manager renews the agreement the same week and reports the finding as resolved. What is the deficiency in this response under Clause 10.1?

A
B
C
D
Test Your Knowledge

At a recertification audit the auditor asks how the BCMS has improved over the three-year cycle. The BCMS Manager describes numerous refinements made to procedures, training, and exercise scenarios, all of which genuinely occurred, but can produce no register, no version history for the changed documents, and no evidence of effect. What is the likely audit outcome and why?

A
B
C
D
Congratulations!

You've completed this section

Continue exploring other exams