4.3 Communication Protocols & Documented Information

Key Takeaways

  • ISO 22301 Clause 7.4 mandates a comprehensive communication framework answering the 5 Ws and How (What, When, With whom, How, and Who communicates) for both internal and external stakeholders.
  • A clear distinction must be maintained between routine BCMS governance communications (policies, training, audit results) and emergency/disruption incident communications (warning, alerting, media handling, regulatory notifications).
  • Clause 7.5 establishes requirements for Documented Information, unifying traditional document creation/updating controls (7.5.2) with rigorous distribution, protection, storage, versioning, and retention controls (7.5.3).
  • Business continuity documentation must be safeguarded for availability and suitability during disruptions—including maintaining offline, out-of-band, and immutable hard-copy or distributed electronic copies resistant to cyber or power outages.
  • ISO 22301:2019 contains a non-negotiable list of mandatory documented information across Clauses 4 through 10 that must be retained as auditable objective evidence.
Last updated: August 2026

4.3 Communication Protocols & Documented Information

Executive Summary: Communication and documented information represent the nervous system and institutional memory of an ISO 22301 Business Continuity Management System. Clause 7.4 requires organizations to establish formal protocols for internal and external communications across both steady-state operations and acute disruptions. Clause 7.5 governs the creation, updating, distribution, protection, and retention of documented information, ensuring that critical continuity procedures remain accessible, accurate, and secure when primary systems fail.


1. ISO 22301 Clause 7.4: The Communication Framework

Communication during business-as-usual ensures organizational alignment, while communication during a crisis protects human life, safeguards brand reputation, and maintains stakeholder confidence. Clause 7.4 mandates that the organization determine the internal and external communications relevant to the BCMS.

The 5 Ws and How of BCMS Communication

To comply with Clause 7.4, the Lead Implementer must establish a formal Communication Matrix addressing six structural dimensions:

+-------------------------------------------------------------------------+
|                   THE CLAUSE 7.4 COMMUNICATION MATRIX                   |
+-------------------------------------------------------------------------+
| 1. WHAT       | Message content: policy, objectives, alerts, status     |
| 2. WHEN       | Timing: scheduled cadences vs. acute incident triggers  |
| 3. WITH WHOM  | Target audiences: staff, board, clients, media, reg     |
| 4. HOW        | Channels: ENS, intranet, satellite, press, SMS          |
| 5. WHO        | Authorized communicator: CEO, PR lead, Incident Manager |
+-------------------------------------------------------------------------+
  1. On what it will communicate (What): Defining the specific scope and substance of messages (e.g., BC policy updates, annual exercise schedules, incident alert notifications, executive situation reports).
  2. When to communicate (When): Establishing precise triggers and cadences (e.g., within 15 minutes of crisis invocation, hourly updates during system outages, quarterly governance reports to the Board).
  3. With whom to communicate (With Whom): Segmenting internal audiences (executive leadership, operational recovery teams, general workforce) and external audiences (customers, Tier-1 suppliers, regulators, emergency services, media, shareholders, local community).
  4. How to communicate (How): Selecting robust, redundant channels (enterprise mass notification systems [ENS], encrypted mobile messaging, satellite phones, emergency conference bridges, public dark websites, press releases).
  5. Who communicates (Who): Identifying and authorizing official spokespersons (e.g., Crisis Communications Director, Chief Executive Officer, Corporate PR Lead, Facilities Safety Marshal).

2. Routine Governance vs. Disruption / Emergency Communications

A critical requirement tested in the Lead Implementer syllabus is the operational distinction between Routine BCMS Communications and Disruption / Emergency Communications (linking Clause 7.4 to Clause 8.4.3 and ISO 22320).

+-------------------------------------------------------------------------+
|                 ROUTINE VS. EMERGENCY COMMUNICATIONS                    |
+-------------------------------------------------------------------------+
|  ROUTINE GOVERNANCE (Clause 7.4)                                        |
|  • Cadence: Scheduled (Monthly, Quarterly, Annual).                     |
|  • Purpose: Awareness, policy rollout, BIA workshops, audit findings.   |
|  • Tone: Informative, collaborative, instructional.                     |
|  • Primary Channels: Corporate email, intranet, LMS, town halls.        |
+-------------------------------------------------------------------------+
|  EMERGENCY & DISRUPTION (Clauses 7.4 & 8.4.3)                           |
|  • Cadence: Trigger-based, immediate (Minutes / Hours).                 |
|  • Purpose: Life safety alerts, crisis coordination, media control.     |
|  • Tone: Directive, clear, concise, authoritative.                      |
|  • Primary Channels: Automated ENS, SMS broadcast, out-of-band comms.  |
+-------------------------------------------------------------------------+

Inbound and Outbound Crisis Communication Protocols

Under Clause 7.4 and Clause 8.4.3, the organization must establish structured mechanisms to manage both inward and outward information flows during a crisis:

  • Inbound Communication Protocols:
    • Dedicated emergency telephone hotlines and incident reporting mobile apps for employees.
    • Structured monitoring of incoming emergency service directives, meteorological warnings, and cyber threat intelligence feeds.
    • Active social media listening to track rumors, customer sentiment, and unverified leaks.
  • Outbound Communication Protocols:
    • Pre-scripted, pre-approved "Holding Statements" for immediate release to media within 30–60 minutes of a major incident.
    • Mandatory Single Point of Contact (SPOC) rules: Strict prohibition against unauthorized employees speaking to journalists or posting on social media during an active crisis.
    • Regulatory Breach Reporting: Formal procedures to notify supervisory authorities within mandatory statutory timelines (e.g., 72 hours for GDPR personal data breaches; immediate notification under central bank or healthcare resilience rules).

3. ISO 22301 Clause 7.5: Documented Information Fundamentals

In ISO 22301:2019, the term "Documented Information" replaces the legacy terms "documents" (procedures, policies, guidelines) and "records" (logs, audit reports, exercise results). Documented information represents information required to be controlled and maintained by the organization and the medium on which it is contained.

The Documented Information Lifecycle

+-------------------------------------------------------------------------+
|                DOCUMENTED INFORMATION LIFECYCLE (Clause 7.5)            |
+-------------------------------------------------------------------------+
| 1. CREATING & UPDATING (7.5.2)                                          |
|    • Identification (Title, Ref #, Date, Author)                        |
|    • Format & Media (Language, Software, Graphics, Web/PDF)             |
|    • Review & Approval (Formal Sign-off for Suitability & Adequacy)     |
+-------------------------------------------------------------------------+
| 2. CONTROLLING (7.5.3)                                                  |
|    • Availability & Suitability (Available where & when needed)         |
|    • Protection (Confidentiality, Integrity, Loss Prevention)           |
|    • Distribution, Access & Retrieval (Role-based access controls)      |
|    • Storage & Preservation (Backups, Legibility, Longevity)            |
|    • Version Control & Change History (Change tracking, Redlines)       |
|    • Retention & Disposition (Archival schedules, Secure destruction)   |
+-------------------------------------------------------------------------+

Creating and Updating Controls (Clause 7.5.2)

When creating and updating documented information, the Lead Implementer must enforce three non-negotiable rules:

  1. Identification and Description (7.5.2a): Every document must feature unique metadata, including document title, unique reference code (e.g., BCP-FIN-004), publication date, author name, and designated document owner.
  2. Format and Media (7.5.2b): Standardized typography, corporate templates, clear diagrammatic conventions, and appropriate media (electronic cloud repository, encrypted USB tokens, laminated physical binders).
  3. Review and Approval for Suitability and Adequacy (7.5.2c): Formal governance review workflow. A draft document cannot be published without formal, dated sign-off by designated authorities (e.g., Business Continuity Policy signed by CEO; IT Disaster Recovery Plan signed by CIO/CISO).

Control of Documented Information (Clause 7.5.3)

Clause 7.5.3 mandates that documented information required by the BCMS must be controlled to ensure:

  • Availability and Suitability (7.5.3.1a): Documents must be accessible where and when they are needed. If recovery teams cannot access the BCP because the corporate intranet is down during a cyberattack, the organization is noncompliant with Clause 7.5.3.
  • Adequate Protection (7.5.3.1b): Safeguarded against loss of confidentiality (e.g., unredacted staff home addresses leaked), improper use, or loss of integrity (e.g., unauthorized editing of recovery RTOs).
  • Control of Changes (7.5.3.2c): Maintaining clear version histories (e.g., v1.0 Draft, v1.1 Revised, v2.0 Approved) detailing exact changes made, reasons for revision, and authorizing manager.
  • Retention and Disposition (7.5.3.2d): Establishing clear retention schedules based on legal and regulatory requirements (e.g., retaining management review minutes for 7 years; exercise debrief logs for 5 years) followed by certified secure disposal (shredding or cryptographic data wiping).
  • Control of External Documents: Managing third-party standards, regulatory guidelines, and vendor service level agreements with formal cataloging and review.

4. Master Inventory: Mandatory Documented Information in ISO 22301:2019

During an accredited ISO 22301 Stage 1 and Stage 2 certification audit, the Lead Auditor will methodically inspect every mandatory document and record required by the standard. Lead Implementers must maintain this complete master inventory:

ISO 22301 ClauseMandatory Documented Information RequiredDocument TypeRetention & Control Recommendation
Clause 4.3Scope of the BCMS & justification for any exclusionsMandatory DocumentControlled living document; reviewed annually.
Clause 5.2Business Continuity Policy signed by Top ManagementMandatory DocumentStrategic apex document; published and controlled.
Clause 6.2Business continuity objectives and plans to achieve themMandatory RecordAnnual action plans; updated upon review.
Clause 7.2Evidence of competence (CVs, training records, certifications)Mandatory RecordHR / BCMS records; retained throughout employment + 3 yrs.
Clause 7.4Documented communication procedures (routine & emergency)Mandatory DocumentOperational protocols; verified in drills.
Clause 8.2.1BIA and Risk Assessment methodology / processMandatory DocumentFormal framework; approved by BCSC.
Clause 8.2.2Business Impact Analysis (BIA) context, priorities, & resultsMandatory RecordDetailed process reports, MTPD, RTO, RPO metrics.
Clause 8.2.3Disruption Risk Assessment results & treatment evaluationsMandatory RecordThreat register, risk scores, chosen treatment options.
Clause 8.4.1Business continuity plans and incident response proceduresMandatory DocumentStep-by-step operational action plans (BCPs/DRPs).
Clause 8.4.3.1Procedures for warning, alerting, and internal/external commsMandatory DocumentEmergency call trees, holding statements, ENS runbooks.
Clause 8.4.5Procedures for restoring and returning to normal operationsMandatory DocumentPost-incident recovery, demobilization, and rebuilding.
Clause 8.5Exercise programme, exercise plans, and post-exercise reportsMandatory RecordMulti-year exercise schedule, scenario scripts, debriefs.
Clause 9.1.1Evidence of monitoring and measurement results & metricsMandatory RecordKPI dashboards, SLA compliance reports.
Clause 9.2.1Internal audit programme, audit plans, and audit reportsMandatory RecordFormal audit reports, findings, evidence sampled.
Clause 9.3.1Evidence of Top Management Review results and decisionsMandatory RecordSigned executive minutes, resource decisions, action items.
Clause 10.1Evidence of nonconformities, corrective actions, and resultsMandatory RecordCAPA logs, root cause analysis, verification notes.

5. Worked Scenario: CloudMatrix Enterprise SaaS

Context

CloudMatrix provides multi-tenant ERP software to 1,200 enterprise clients. During an unannounced ransomware attack that encrypted all internal Active Directory and file server environments, the Crisis Management Team assembled to execute the Business Continuity Plan.

The Support Breakdown

When the incident occurred, the response collapsed due to severe Clause 7.4 and 7.5 failures:

  • Documentation Inaccessibility (7.5.3.1): All 48 Business Continuity Plans and technical runbooks were stored solely on the internal SharePoint network, which was encrypted by the ransomware. No team member had offline access.
  • Version Confusion (7.5.2): A local backup copy found on a laptop contained outdated 2022 server IP addresses and defunct vendor phone numbers.
  • Communication Chaos (7.4): The Crisis Communications Lead had no out-of-band contact directory. Panicked junior engineers posted conflicting updates on public Twitter/X accounts, causing three major clients to threaten breach-of-contract lawsuits.

Remediation Action Plan

The newly appointed Lead Implementer redesigned the communication and documentation infrastructure:

  1. High-Availability Document Vault (7.5.3): Deployed an out-of-band, air-gapped, zero-trust cloud documentation portal accessible via biometric authentication on mobile devices, with automated offline caching.
  2. Cryptographic Version Control (7.5.2): Implemented automated metadata headers, quarterly review sign-offs, and an automated script that deletes cached copies exceeding 90 days.
  3. Emergency Communication Overhaul (7.4): Deployed an enterprise SaaS Emergency Notification System (ENS) with multi-modal alerting (SMS, voice call, push notification). Authored pre-approved crisis holding statements and established strict SPOC rules binding all personnel.

Outcome

Twelve months later, during a simulated ransomware and data center power outage exercise, CloudMatrix teams accessed their runbooks on mobile devices within 90 seconds, initiated encrypted emergency conference calls, broadcast client notifications within 15 minutes, and restored critical services within the 1-hour RTO. The ISO 22301 Stage 2 auditor awarded CloudMatrix zero nonconformities and commended the resilient support architecture.


6. Exam Warning Traps & Auditing Pitfalls

[!WARNING] PECB Exam Trap 1 (Single Point of Storage Failure): In audit scenarios, having detailed, beautifully written BCPs that are stored exclusively on primary corporate networks or shared drives represents a Major Nonconformity against Clause 7.5.3.1a (Availability). If primary systems fail, documentation must remain immediately retrievable via redundant, offline, or out-of-band channels.

[!CAUTION] PECB Exam Trap 2 (The Missing Mandatory Record): Exam questions frequently test which items are mandatory under ISO 22301. Be vigilant: While an organization has flexibility in how it formats documents, it cannot omit mandatory records such as competence evidence (7.2), exercise reports (8.5), monitoring results (9.1), internal audit reports (9.2), or management review minutes (9.3).

[!NOTE] Auditing External Communication Protocols: Lead Auditors will always inspect Clause 7.4 holding statements and regulatory notification procedures. If an organization lacks predefined templates for notifying regulators or the press during a disruption, the auditor will note a gap in crisis communication readiness.

Loading diagram...
ISO 22301 Communication Matrix and Document Control Architecture
Test Your Knowledge

An ISO 22301-certified company maintains all of its Business Continuity Plans, disaster recovery runbooks, and emergency contact lists exclusively on a local SharePoint server. During a cyberattack, the SharePoint server is encrypted and inaccessible. Which clause of ISO 22301:2019 has the organization failed to satisfy?

A
B
C
D
Test Your Knowledge

Which of the following represents a mandatory item of documented information explicitly required to be retained as evidence under ISO 22301:2019?

A
B
C
D
Test Your Knowledge

In the event of a critical operational disruption involving a cyber breach and data leak, which communication protocol must an organization follow to ensure compliance with ISO 22301:2019 Clause 7.4 and Clause 8.4.3?

A
B
C
D