ISO 22301 defines the requirements of the BCMS being audited. ISO 19011 sets the audit methodology. ISO 17021-1 governs the conduct of certification bodies. All three apply in every professional BCMS audit.
ISO 22301 sets what the auditor audits: the requirements of a business continuity management system, its controls, its evidence and its links to governance. Without command of ISO 22301, an auditor cannot formulate substantive findings and can only verify that documents exist.
ISO 19011 sets how the audit is done: principles, management of the audit programme, planning, execution, auditor competence and professional conduct. ISO 17021-1, in turn, governs certification bodies and establishes the expectations of impartiality and rigour placed on external auditors.
The course integrates all three so that the auditor operates with judgement across internal, supplier and certification audits. In practice ISO 19011 provides the method, ISO 22301 provides the scope, and ISO 17021-1 provides the certification credibility — a competent Lead Auditor knows when to apply each.
ISO 19011 gives the method, ISO 22301 gives the scope, ISO 17021-1 gives the rules for certification bodies. A competent Lead Auditor understands when to apply each.
“Without ISO 19011 there is no method, without ISO 22301 there is no scope, without ISO 17021-1 there is no certification credibility.”
This two day foundation course introduces the structure, intent, and practical application of a Business Continuity Management System aligned with ISO 22301:2019. Participants learn how continuity requirements fit into governance, risk, and operational control without treating BCMS as a standalone.
View courseThis intensive 4-day training prepares participants to implement and manage a Business Continuity Management System (BCMS) compliant with ISO 22301:2019. It covers planning, deployment, monitoring, updates, and continual improvement, with a focus on context analysis, business impact analysis, risk.
View courseThis course prepares participants to design, implement, test, and improve an operational resilience management framework. It addresses the growing pressure to maintain critical services through cyber incidents, supplier failures, technology outages, regulatory scrutiny, and physical disruptions. Participants learn how to identify critical business services, set impact tolerances, assess risk, and coordinate response and recovery decisions. Abilene Academy teaches through consultant-led case work, realistic evidence review, and exam-focused coaching built from field practice. It is designed for resilience leaders, risk managers, business continuity professionals, internal consultants, and managers responsible for disruption readiness.
View courseIt is designed for auditors who lead BCMS certification audits, for business continuity audit managers and consultants, for BCMS compliance professionals, and for technical experts involved in audits.
The course teaches you to plan and lead BCMS certification audits under ISO 22301 and ISO 19011: scoping, evidence, interviews, formulating findings, managing the audit team and following up nonconformities.
The exam is multiple-choice, lasts three hours and requires a minimum score of 70% to pass. It covers seven domains spanning both the BCMS under ISO 22301 and the full audit lifecycle, and leads to a professional certification valid for three years.
An ISO 22301 audit verifies BCMS effectiveness and conformity. It identifies gaps and supports continual improvement.
Browse all FAQs →
Full knowledge base
Necessary cookies are always active. You can accept, reject non-essential cookies, or customize your preferences.