International (ISO/TC 292); adopted as EN ISO 22313:2020 and nationally (BS EN, DIN EN, UNE-EN, SIST EN, I.S. EN, AS ISO, DSTU EN ISO 22313:2021 and others)

ISO 22313:2020

163 controls. 160 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

163 controls 160 frameworks share controls with it International (ISO/TC 292); adopted as EN ISO 22313:2020 and nationally (BS EN, DIN EN, UNE-EN, SIST EN, I.S. EN, AS ISO, DSTU EN ISO 22313:2021 and others) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
ISO-22313-10.1Nonconformity and corrective action11
ISO-22313-10.2Continual improvement16
ISO-22313-4.1Understanding the organization and its context14
ISO-22313-4.2Understanding the needs and expectations of interested parties10
ISO-22313-4.3Determining the scope of the BCMS0
ISO-22313-4.4Business continuity management system0
ISO-22313-5.1Leadership and commitment15
ISO-22313-5.2Policy27
ISO-22313-5.3Organizational roles, responsibilities and authorities12
ISO-22313-6.1Actions to address risks and opportunities11
ISO-22313-6.2Business continuity objectives and plans to achieve them27
ISO-22313-6.3Planning changes to the BCMS27
ISO-22313-7.1Resources1
ISO-22313-7.2Competence0
ISO-22313-7.3Awareness1
ISO-22313-7.4Communication5
ISO-22313-7.5Documented information14
ISO-22313-8.1Operational planning and control12
ISO-22313-8.2Business impact analysis and risk assessment124
ISO-22313-8.3Business continuity strategies and solutions1
ISO-22313-8.4Business continuity plans and procedures1
ISO-22313-8.5Exercise programme1
ISO-22313-9.1Monitoring, measurement, analysis and evaluation11
ISO-22313-9.2Internal audit14
ISO-22313-9.3Management review15
ISO22313-10.1Guidance on nonconformity and corrective action10
ISO22313-10.2Guidance on continual improvement0
ISO22313-4.1Guidance on understanding context0
ISO22313-4.2Guidance on interested parties0
ISO22313-4.3Guidance on BCMS scope0
ISO22313-5.1Guidance on leadership and commitment0
ISO22313-5.2Guidance on BC policy0
ISO22313-5.3Guidance on roles and authorities0
ISO22313-6.1Guidance on risks and opportunities0
ISO22313-6.2Guidance on BC objectives0
ISO22313-7.2Guidance on competence0
ISO22313-7.4Guidance on communication0
ISO22313-7.5Guidance on documented information0
ISO22313-8.1Guidance on operational planning and control12
ISO22313-8.2Guidance on BIA and risk assessment0
ISO22313-8.3Guidance on BC strategies and solutions0
ISO22313-8.4Guidance on BC plans and procedures0
ISO22313-8.5Guidance on exercising and testing0
ISO22313-8.6Guidance on evaluation of BC documentation and capability0
ISO22313-9.1Guidance on monitoring and evaluation0
ISO22313-9.2Guidance on internal audit0
ISO22313-9.3Guidance on management review0
1010 Improvement0
10.110.1 Nonconformity and corrective action0
10.1.110.1.1 Nonconformity and corrective action: general0
10.1.210.1.2 Occurrence of nonconformity0
10.1.310.1.3 Retention of documented information0
10.210.2 Continual improvement0
44 Context of the organization0
4.14.1 Understanding the organization and its context0
4.24.2 Understanding the needs and expectations of interested parties0
4.2.14.2.1 Understanding the needs and expectations of interested parties: general0
4.2.24.2.2 Legal and regulatory requirements0
4.34.3 Determining the scope of the business continuity management system0
4.3.14.3.1 Determining the scope of the BCMS: general0
4.3.24.3.2 Scope of the business continuity management system0
4.3.34.3.3 Exclusions to scope0
4.44.4 Business continuity management system0
55 Leadership0
5.15.1 Leadership and commitment0
5.1.25.1.2 Top management0
5.1.35.1.3 Other managerial roles0
5.25.2 Policy0
5.2.15.2.1 Establishing the business continuity policy0
5.2.25.2.2 Communicating the business continuity policy0
5.35.3 Roles, responsibilities and authorities0
66 Planning0
6.16.1 Actions to address risks and opportunities0
6.1.16.1.1 Determining risks and opportunities0
6.1.26.1.2 Addressing risks and opportunities0
6.26.2 Business continuity objectives and planning to achieve them0
6.2.16.2.1 Establishing business continuity objectives0
6.2.26.2.2 Determining business continuity objectives0
6.36.3 Planning changes to the business continuity management system0
77 Support0
7.17.1 Resources0
7.1.17.1.1 Resources: general0
7.1.27.1.2 BCMS resources0
7.27.2 Competence0
7.37.3 Awareness0
7.47.4 Communication0
7.57.5 Documented information0
7.5.17.5.1 Documented information: general0
7.5.27.5.2 Creating and updating0
7.5.37.5.3 Control of documented information0
7.5.3.17.5.3.1 Access to documented information0
7.5.3.27.5.3.2 Types of control0
88 Operation0
8.18.1 Operational planning and control0
8.1.18.1.1 Operational planning and control: general0
8.1.28.1.2 Business continuity management0
8.1.38.1.3 Maintaining business continuity0
8.28.2 Business impact analysis and risk assessment0
8.2.18.2.1 Business impact analysis and risk assessment: general0
8.2.28.2.2 Business impact analysis0
8.2.38.2.3 Risk assessment0
8.38.3 Business continuity strategies and solutions0
8.3.18.3.1 Business continuity strategies and solutions: general0
8.3.28.3.2 Identification of strategies and solutions0
8.3.2.18.3.2.1 Determination of strategies and solutions: general0
8.3.2.28.3.2.2 Protection of prioritized activities0
8.3.2.38.3.2.3 Stabilization, continuation, resumption and recovery of prioritized activities0
8.3.2.48.3.2.4 Mitigating, responding to and managing impacts0
8.3.38.3.3 Selection of strategies and solutions0
8.3.48.3.4 Resource requirements0
8.3.4.18.3.4.1 Resource requirements: general0
8.3.4.28.3.4.2 People0
8.3.4.38.3.4.3 Information and data0
8.3.4.48.3.4.4 Buildings, work sites and associated utilities0
8.3.4.58.3.4.5 Equipment and consumables0
8.3.4.68.3.4.6 ICT systems0
8.3.4.78.3.4.7 Transportation and logistics0
8.3.4.88.3.4.8 Finance0
8.3.4.98.3.4.9 Partners and supply chain0
8.3.58.3.5 Implementation of solutions0
8.48.4 Business continuity plans and procedures0
8.4.18.4.1 Business continuity plans and procedures: general0
8.4.28.4.2 Response structure0
8.4.2.18.4.2.1 Response structure: purpose0
8.4.2.28.4.2.2 Response structure: design0
8.4.2.38.4.2.3 Team capabilities0
8.4.2.48.4.2.4 Team composition and guidance0
8.4.38.4.3 Warning and communication0
8.4.3.18.4.3.1 Warning and communication: general0
8.4.3.28.4.3.2 Alerting interested parties0
8.4.48.4.4 Business continuity plans0
8.4.4.28.4.4.2 Business continuity plans: coverage and incident response0
8.4.4.38.4.4.3 Content, guidance and usability0
8.4.4.48.4.4.4 Incident management and strategic management0
8.4.4.58.4.4.5 Communication0
8.4.4.68.4.4.6 Safety and welfare0
8.4.4.78.4.4.7 Salvage and security0
8.4.4.88.4.4.8 Resumption of prioritized activities0
8.4.4.98.4.4.9 ICT systems0
8.4.58.4.5 Recovery0
8.58.5 Exercise programme0
8.5.18.5.1 Exercise programme: general0
8.5.28.5.2 Design of the exercise programme0
8.5.38.5.3 Exercising business continuity plans0
8.68.6 Evaluation of business continuity documentation and capabilities0
8.6.18.6.1 Evaluation of business continuity documentation and capabilities: general0
8.6.28.6.2 Measuring effectiveness0
8.6.38.6.3 Outcomes0
99 Performance evaluation0
9.19.1 Monitoring, measurement, analysis and evaluation0
9.1.19.1.1 Monitoring, measurement, analysis and evaluation: general0
9.1.29.1.2 Retention of evidence0
9.1.39.1.3 Performance evaluation0
9.29.2 Internal audit0
9.2.19.2.1 Internal audit: general0
9.2.29.2.2 Audit programme(s)0
9.39.3 Management review0
9.3.19.3.1 Management review: general0
9.3.29.3.2 Management review input0
9.3.39.3.3 Management review outputs0
STANDARDISO 22313:2020: the standard, its scope and what is held0
STATUSEdition status: the 2020 second edition is current; guidance on ISO 22301, not certifiable0
SUPPORT_NOTEEvery guidance leaf names the ISO 22301:2019 clause it supports0

Tell me when ISO 22313:2020 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Trend and foresight scan report
  • IMS scope statement signed by leadership
  • Innovation context register
  • Innovation maturity baseline assessment
  • Strategic intelligence brief
  • Stakeholder map with innovation interests
  • PESTEL/SWOT analysis covering innovation landscape
  • IP register and assignment agreements
  • Time-allocation policy (e.g., 10% innovation time)
  • Document control register for IMS

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for ISO 22313:2020, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition