10.2 BCMS Internal Audit per ISO 19011

Key Takeaways

  • ISO 22301:2019 Clause 9.2 mandates conducting internal audits at planned intervals to determine whether the BCMS conforms to the organization's own requirements, ISO 22301 requirements, and is effectively implemented and maintained.
  • ISO 19011:2018 provides the international benchmark for management system auditing, establishing the seven core principles: Integrity, Fair presentation, Due professional care, Confidentiality, Independence, Evidence-based approach, and Risk-based approach.
  • Auditor objectivity and impartiality are strict requirements; auditors must never audit their own work or processes they personally designed, managed, or implemented.
  • Audit preparation requires developing a risk-prioritized Audit Programme, an engagement-specific Audit Plan, and detailed Audit Working Papers / Checklists covering all ISO 22301 clauses.
  • Audit findings must be systematically classified into Major Nonconformity, Minor Nonconformity, Opportunity for Improvement (OFI), and Conformity based on verifiable objective evidence.
Last updated: August 2026

BCMS Internal Audit per ISO 19011

Internal auditing is the primary internal governance mechanism providing independent assurance to top management that the Business Continuity Management System (BCMS) is properly designed, compliant with international standards, and capable of operating during severe disruptions. ISO 22301:2019 Clause 9.2 (Internal audit) mandates that the organization conduct internal audits at planned intervals. To execute internal audits effectively and achieve credible, audit-ready compliance, Lead Implementers and Internal Auditors must apply the standardized guidelines established in ISO 19011:2018 (Guidelines for auditing management systems).

Internal audits are not adversarial inspections; they are structured, systematic, independent, and documented processes for obtaining objective evidence and evaluating it impartially to determine the extent to which audit criteria are fulfilled.


1. ISO 22301 Clause 9.2 Requirements & ISO 19011 Principles

Clause 9.2 requires organizations to conduct internal audits to determine whether the BCMS:

  1. Conforms to:
    • The organization's own requirements for its BCMS (including policies, procedures, and SLAs);
    • The requirements of the ISO 22301:2019 standard (Clauses 4 through 10);
  2. Is effectively implemented and maintained across all operational units within the defined scope.

The 7 Core Principles of Auditing (ISO 19011:2018)

Audit credibility rests upon strict adherence to the seven foundational principles of ISO 19011:

                               ┌─────────────────────────────────────────┐
                               │    The 7 Principles of ISO 19011:2018   │
                               └────────────────────┬────────────────────┘
                                                    │
         ┌───────────────────┬──────────────────────┼──────────────────────┬───────────────────┐
         ▼                   ▼                      ▼                      ▼                   ▼
  ┌──────────────┐    ┌──────────────┐       ┌──────────────┐       ┌──────────────┐    ┌──────────────┐
  │ 1. Integrity │    │ 2. Fair      │       │ 3. Due       │       │ 4. Confiden- │    │ 5. Indepen-  │
  │  & Ethics    │    │ Presentation │       │ Professional │       │    tiality   │    │    dence     │
  │ (Foundation) │    │  (Truthful)  │       │  Care (Dilig)│       │ (Security)   │    │(Impartiality)│
  └──────────────┘    └──────────────┘       └──────────────┘       └──────────────┘    └──────┬───────┘
                                                                                               │
                                             ┌─────────────────────────────────────────────────┴───────┐
                                             ▼                                                         ▼
                                      ┌──────────────┐                                          ┌──────────────┐
                                      │ 6. Evidence- │                                          │ 7. Risk-     │
                                      │    Based     │                                          │    Based     │
                                      │   Approach   │                                          │   Approach   │
                                      └──────────────┘                                          └──────────────┘
  1. Integrity (The Foundation of Professionalism): Auditors must perform their work with honesty, diligence, responsibility, and strict compliance with applicable legal requirements.
  2. Fair Presentation (The Obligation to Report Truthfully and Accurately): Audit findings, conclusions, and reports must reflect truthfully and accurately the audit activities. Significant obstacles and unresolved divergent opinions must be documented.
  3. Due Professional Care (The Application of Diligence and Judgement): Auditors must exercise care proportional to the importance of the task and the confidence placed in them by the audit client.
  4. Confidentiality (Security of Information): Auditors must maintain strict confidentiality regarding proprietary business data, BIA impact thresholds, and vulnerability disclosures.
  5. Independence (The Basis for Impartiality and Objectivity): Auditors must be independent of the activity being audited whenever practicable, and must act free from bias and conflict of interest.
  6. Evidence-Based Approach (The Rational Method for Reaching Reliable Conclusions): Audit evidence must be verifiable. It is based on samples of the information available, since an audit is conducted during a finite period and with finite resources.
  7. Risk-Based Approach (An Audit Approach that Considers Risks and Opportunities): The risk-based approach must substantively influence the planning, conducting, and reporting of audits to ensure focus on matters of critical significance to the BCMS.

2. Managing the BCMS Audit Programme (Clause 9.2.2)

An Audit Programme consists of arrangements for a set of one or more audits planned for a specific time frame and directed toward a specific purpose. Under Clause 9.2.2, the organization must plan, establish, implement, and maintain an audit programme.

                      ┌────────────────────────────────────────────────┐
                      │     ESTABLISHING THE BCMS AUDIT PROGRAMME      │
                      ├────────────────────────────────────────────────┤
                      │ • Define Programme Objectives & Governance     │
                      │ • Determine Extent, Frequency & Methods        │
                      │ • Calibrate by Process Risk & Criticality      │
                      │ • Allocate Competent, Independent Auditors     │
                      │ • Establish Audit Procedures & Checklists      │
                      │ • Monitor, Review & Improve the Programme      │
                      └────────────────────────────────────────────────┘

Risk-Based Audit Programme Planning

Under ISO 22301, the audit programme must take into consideration the importance of the processes concerned and the results of previous audits:

  • High-Risk / Critical Processes: Core revenue-generating platforms, primary data centers, high-impact BIA activities, and units that suffered major exercise failures must be audited more frequently (e.g., semi-annually).
  • Low-Risk / Supporting Processes: Non-critical administrative functions or areas with consistently mature, stable audit performance may be scheduled for less frequent audits (e.g., every 18–24 months).
  • Trigger-Based Audits: Conducted following major organizational restructuring, post-incident failures, major IT architecture migrations, or significant acquisitions.

3. Auditor Competence, Objectivity & Impartiality

Clause 9.2.2 explicitly requires that the organization shall "select auditors and conduct audits to ensure objectivity and the impartiality of the audit process."

The Iron Rule of Auditing: No Self-Auditing

[!CAUTION] The Mandatory Principle of Independence Auditors must not audit their own work. An individual who wrote the Business Continuity Plans for the Finance department cannot act as the internal auditor for the Finance department's BCPs. Doing so constitutes an immediate Major Nonconformity under Clause 9.2.

Practical Strategies for Small and Large Organizations

Organizational SizeRecommended Audit Resourcing StrategyIndependence Safeguards
Large EnterpriseDedicated, centralized Internal Audit Department independent of operational business units and BCMS implementation teams.Auditors report administratively to the Audit Committee of the Board of Directors, ensuring zero operational conflict.
Mid-Sized OrganizationCross-Functional Peer Auditing: Trained internal auditors from IT audit Human Resources; trained auditors from Operations audit IT and Facilities.Strict segregation of duties; Lead Implementer coordinates the programme but does not audit core BCMS documentation they authored.
Small Organization (SMB)Reciprocal Audits or External Contractors: Partnering with a peer non-competing organization for reciprocal audits, or hiring an independent external consultant.The external contractor must not have provided implementation consulting or plan-writing services for the BCMS being audited.

Auditor Competency Requirements (ISO 19011 Clause 7)

Internal auditors must possess a combination of:

  • Audit Skills: Interview techniques, sampling methodologies, evidence evaluation, nonconformity drafting.
  • ISO 22301 Knowledge: Deep understanding of High-Level Structure (HLS), Clauses 4 through 10, BIA concepts (MTPD, RTO, RPO, MBCO), and incident command principles.
  • Sector / Technical Understanding: Familiarity with the operational environment, relevant legal/regulatory frameworks (e.g., DORA, HIPAA, GDPR), and critical technology architectures.

4. Audit Preparation: Scoping, Audit Plan & Checklists

Thorough audit preparation is essential for executing a high-value internal audit within allocated timeframes.

  ┌───────────────────────────────────────────────────────────────────────────────────────┐
  │                          THE AUDIT PREPARATION LIFECYCLE                              │
  ├───────────────────────────────────────────────────────────────────────────────────────┤
  │ 1. Define Audit Scope: Boundaries, physical sites, business units, systems included.  │
  │ 2. Define Audit Criteria: Reference standards (ISO 22301), policies, legal mandates. │
  │ 3. Review Documented Information: Preliminary review of BIA, BCPs, exercise reports.  │
  │ 4. Draft Formal Audit Plan: Timetable, interviewees, operational process walkthroughs.│
  │ 5. Develop Working Papers & Checklists: Tailored clause-by-clause inquiry templates.  │
  └───────────────────────────────────────────────────────────────────────────────────────┘

Audit Scope vs. Audit Criteria

  • Audit Scope: The extent and boundaries of the audit, including physical locations, organizational units, activities, processes, and time period covered.
  • Audit Criteria: The set of requirements used as a reference against which objective evidence is compared (e.g., ISO 22301:2019 standard, corporate BC Policy, local disaster recovery regulations, contractual customer SLAs).

ISO 22301 Internal Audit Checklist Template

Auditors utilize working papers and checklists to ensure comprehensive, systematic inquiry:

ISO 22301 ClauseAudit Investigation FocusObjective Evidence to InspectSample Audit Questions
Clause 4.1 & 4.2Context & StakeholdersContext register, legal regulatory matrix, interested party needs register.How does the organization track changes in statutory continuity regulations? Are supplier requirements captured?
Clause 5.1 & 5.2Leadership & PolicyApproved BC Policy, resource allocation records, Steering Committee charter.How does top management demonstrate commitment? Is the BC policy communicated across all operational sites?
Clause 6.1 & 6.2Risks & BC ObjectivesRisk assessment register, SMART objective tracking dashboard.Are continuity objectives measurable? Do they align with prioritized activities and stated recovery timeframes?
Clause 7.2 & 7.3Competence & AwarenessTraining logs, competence matrices, awareness broadcast records.How is competence verified for incident response commanders? Are deputies trained to the same standard?
Clause 8.2BIA & Risk AssessmentCompleted BIA worksheets, executive sign-offs, MTPD/RTO/RPO calculations.What methodology was used to calculate financial/operational impact over time? Are interdependencies mapped?
Clause 8.4Business Continuity PlansDepartmental BCPs, Incident Management Plans, contact directories.Are action-oriented checklists present? Do plans specify immediate containment steps and clear invocation criteria?
Clause 8.5Exercising and TestingMulti-year exercise schedule, exercise plans, After-Action Reports (AARs).Did exercises test recovery against stated RTOs? Were corrective actions tracked and closed in a timely manner?
Clause 9.3 & 10.1Management Review & CAPReview meeting minutes, nonconformity logs, root cause analysis files.Did executive management review all mandatory Clause 9.3 inputs? Was root cause analysis conducted for failures?

5. Audit Execution & Evidence Gathering Techniques

Audit execution centers on the Audit Evidence Triangle, which triangulates three independent sources of information to verify compliance:

                               ┌─────────────────────────────────────────┐
                               │       THE AUDIT EVIDENCE TRIANGLE       │
                               └────────────────────┬────────────────────┘
                                                    │
                     ┌──────────────────────────────┴──────────────────────────────┐
                     ▼                                                             ▼
      ┌─────────────────────────────┐                               ┌─────────────────────────────┐
      │ 1. Documented Information   │                               │ 2. Personnel Interviews     │
      │ • Policies, BIAs, BCPs      │                               │ • Open-ended questioning    │
      │ • System logs & SLAs        │                               │ • Verifying practical recall│
      │ • Historical test reports   │                               │ • Testing deputies & staff  │
      └──────────────┬──────────────┘                               └──────────────┬──────────────┘
                     │                                                             │
                     └──────────────────────────────┬──────────────────────────────┘
                                                    ▼
                                     ┌─────────────────────────────┐
                                     │ 3. Direct Observation       │
                                     │ • Inspect alternate sites   │
                                     │ • Witness live drills       │
                                     │ • Inspect UPS / generators  │
                                     └─────────────────────────────┘

5.1 Interviewing Techniques

Auditors must utilize effective questioning strategies:

  • Open-Ended Questions (Using What, How, Why, When, Where, Who): "Can you walk me through the exact steps you take when an emergency facility denial is declared at 02:00?"
  • Corroborating Evidence: Following up verbal assertions by asking to inspect the corresponding record: "You mentioned that call trees are tested quarterly. Can we review the timestamped logs from the June notification test?"
  • Active Listening: Allowing the auditee to speak without interruption while observing behavioral confidence and procedural familiarity.

5.2 Audit Sampling Methodologies

Because auditors cannot inspect every document or transaction, they must use sound sampling:

  • Judgmental (Non-Statistical) Sampling: Selecting sample items based on knowledge, risk, and process criticality (e.g., sampling 5 BCPs from Tier-1 critical departments and 2 from supporting departments).
  • Statistical Sampling: Using mathematical algorithms to select representative samples when auditing large volumes of uniform records (e.g., verifying 50 random user access revocation tickets following employee departures).

6. Finding Classification & Grading Taxonomy

Audit findings evaluate the collected objective evidence against the audit criteria. Findings must be clearly categorized to drive appropriate corrective action:

  ┌───────────────────────────────────────────────────────────────────────────────────────────┐
  │                           AUDIT FINDING CLASSIFICATION HIERARCHY                          │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 🔴 MAJOR NONCONFORMITY: Total breakdown or absence of a mandatory ISO 22301 clause;       │
  │    systemic failure that jeopardizes BCMS integrity or recovery capability.               │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 🟡 MINOR NONCONFORMITY: Isolated lapse or procedural inconsistency that does not          │
  │    undermine the overall effectiveness of the BCMS or recovery capabilities.              │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 🔵 OPPORTUNITY FOR IMPROVEMENT (OFI): Conforming situation where efficiency, robustness,  │
  │    or automation could be enhanced. No mandatory corrective action required.              │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ 🟢 CONFORMITY / COMMENDATION: Full compliance with audit criteria and exemplary practice. │
  └───────────────────────────────────────────────────────────────────────────────────────────┘

Detailed Classification Matrix with ISO 22301 Examples

ClassificationDefinition & Standard CriteriaISO 22301 Practical ExampleImplication for Certification
Major Nonconformity• Total failure to implement a mandatory ISO 22301 clause.<br/>• A systemic breakdown across multiple business units.<br/>• A direct situation where the organization cannot achieve its stated RTOs or recover prioritized activities during a disruption.<br/>• Failure to close a previously identified Minor Nonconformity.• The organization has not conducted an internal audit or management review in 18 months.<br/>• No Business Impact Analysis (Clause 8.2.2) has been performed for any core operational units.<br/>• Critical IT disaster recovery replication scripts fail completely, resulting in permanent data loss exceeding MTPD.Blocks Certification.<br/>Certification cannot be granted or maintained until root cause analysis is completed, corrective action is implemented, and the auditor conducts a re-audit verification.
Minor Nonconformity• A single, isolated procedural lapse.<br/>• Incomplete documented record that does not compromise BCMS integrity or recovery capability.<br/>• A minor documentation inconsistency.• Out of 45 audited departmental BCPs, 2 contained outdated emergency contact phone numbers for alternate deputies.<br/>• One internal auditor forgot to sign the attendance sheet of a closing meeting.<br/>• A training session was conducted but formal competency quiz records were missing for 3 attendees.Certification Permitted.<br/>Certification can proceed provided the organization submits a formal Corrective Action Plan (CAP) with root cause analysis and agreed closure timelines (typically 30–90 days).
Opportunity for Improvement (OFI)• A situation that currently meets ISO 22301 requirements, but where the auditor identifies potential risks or opportunities to optimize process maturity, efficiency, or automation.• BCPs are maintained in spreadsheet format, which satisfies Clause 7.5; the auditor suggests migrating to an automated BCMS software platform to streamline version control and dynamic alerting.Informational.<br/>No mandatory corrective action required; reviewed at subsequent audits to assess organizational enhancement.
Conformity / Good Practice• Objective evidence confirms full adherence to ISO 22301 requirements, demonstrating robust, mature, and well-managed processes.• The organization implemented automated satellite-cellular dual-path alerting with 99.8% confirmed staff response within 8 minutes, exceeding benchmark criteria.Compliant.<br/>Recorded as objective proof of operational excellence.

7. Audit Reporting & Presentation to Top Management

Under Clause 9.2.2(e), internal auditors must ensure that the results of the audits are reported to relevant management.

The Anatomy of an Audit Nonconformity Statement

A properly formulated nonconformity statement must never be vague. In accordance with ISO 19011, every nonconformity statement must contain three distinct elements:

  1. The Statement of Nonconformity: Clear, concise description of what is failing.
  2. The Audit Criteria: The specific ISO 22301 clause, internal policy, or regulatory requirement breached.
  3. The Objective Evidence: Specific, verifiable facts, document IDs, sample sizes, and interview records demonstrating the failure.
  ┌───────────────────────────────────────────────────────────────────────────────────────────┐
  │                       STRUCTURE OF A VALID NONCONFORMITY STATEMENT                        │
  ├───────────────────────────────────────────────────────────────────────────────────────────┤
  │ "The organization failed to conduct annual exercise validations for its Payment           │
  │ Gateway recovery procedures [STATEMENT], as required by ISO 22301:2019 Clause 8.5 and     │
  │ Section 4.2 of the Corporate Business Continuity Policy [CRITERIA]. Audit inspection of    │
  │ the 2025–2026 Exercise Programme records revealed zero exercise logs or After-Action     │
  │ Reports for the Payment Gateway system since October 2024 [OBJECTIVE EVIDENCE]."          │
  └───────────────────────────────────────────────────────────────────────────────────────────┘

The Closing Meeting Protocol

  • Conducted with operational managers, process owners, and the BCMS Lead Implementer.
  • Objective: Present findings, explain classifications, resolve factual misunderstandings, and agree upon target timeframes for submitting Corrective Action Plans (CAPs).

8. Worked Implementation Scenario: Financial Institution Internal Audit

Context

Apex Global Trust, a commercial banking entity, is preparing for its ISO 22301 Stage 2 certification audit. An independent internal audit team conducts a comprehensive BCMS audit covering retail banking, data centers, and treasury operations.

Audit Observations & Findings

  1. Observation 1 (Treasury): The Treasury department has full BCPs and completed a tabletop exercise in March. However, during staff interviews, the Primary Treasury Trader stated that their secondary trading floor relocated to an alternate building six months ago, but the BCP still listed the old facility address and network connection details. Classification: Minor Nonconformity (Clause 8.4 & 8.2.2).
  2. Observation 2 (Core IT Hosting): During inspection of the primary data center, the auditors requested the maintenance and load-test records for the emergency standby diesel generators. The Facilities Manager admitted that the generator fuel had not been tested or cycled for 26 months, and no functional load-bank test had been executed since initial commissioning. Classification: Major Nonconformity (Clause 8.3.3 & 8.5) due to total unvalidated dependency of a primary critical infrastructure asset supporting all prioritized banking activities.
  3. Observation 3 (HR): HR maintains comprehensive records of employee emergency contact info, but updates are processed manually via email once a year. The auditor suggests implementing self-service employee portal updates. Classification: Opportunity for Improvement (OFI).

Executive Reporting & Outcome

The Lead Auditor presented the formal audit report to the Executive Risk Committee and CEO. The Major Nonconformity triggered an immediate emergency generator fuel replacement and certified full-load failover test within 14 days, clearing the path for successful certification.


9. PECB Exam Warning Traps & Implementation Pitfalls

[!CAUTION] Critical Exam Traps for Section 10.2

  1. Trap: The Lead Implementer Auditing Their Own Work: Exam questions frequently present a scenario where a single BCMS manager designs the BCMS, writes all the plans, and then conducts the internal audit alone. This is an immediate violation of Clause 9.2.2 (impartiality and objectivity) and constitutes a Major Nonconformity.
  2. Trap: Confusing Audit Scope with Audit Criteria: Remember: Scope defines where and what you are auditing (boundaries, locations, departments). Criteria defines the standard and requirements you are auditing against (ISO 22301 standard, company policies, legal regulations).
  3. Trap: Vague Nonconformity Writing: A finding that states "staff don't know their roles" is invalid. It must cite the specific clause (e.g., Clause 7.3), the exact evidence (e.g., 4 out of 5 interviewed floor wardens could not identify emergency assembly points), and the specific nonconformity statement.
  4. Trap: Downgrading Major Nonconformities to OFIs to Avoid Conflict: Internal auditors must maintain professional integrity. If a mandatory clause requirement is entirely absent (e.g., no BIA performed), an auditor cannot classify it as an OFI to preserve organizational harmony.
Loading diagram...
ISO 19011 BCMS Internal Audit Process & Corrective Action Lifecycle
Test Your Knowledge

A mid-sized logistics enterprise is preparing for its first ISO 22301 certification audit. The company's dedicated Business Continuity Manager developed the entire BCMS, authored all departmental Business Continuity Plans, and conducted all risk assessments. Due to budget constraints, the BC Manager conducts the comprehensive BCMS internal audit alone and submits the report to the CEO. How would a certification auditor evaluate this internal audit arrangement?

A
B
C
D
Test Your Knowledge

During a BCMS internal audit of an international cloud provider, the internal audit team discovers that the organization has operated for twelve months without establishing a formal Business Impact Analysis (BIA) methodology or calculating Recovery Time Objectives (RTOs) for any of its critical services. How must this audit finding be categorized in accordance with ISO 19011 grading principles?

A
B
C
D
Test Your Knowledge

Which of the following correctly defines the distinction between 'Audit Criteria' and 'Audit Scope' in accordance with ISO 19011:2018 guidelines?

A
B
C
D