ISO 22317
Guidelines for business impact analysis
ISO 22317 is a compliance framework from International with 15 domains and 36 controls that map to 125 other frameworks. The largest domains are ISO 22317: BCM Program Management (5 controls), ISO 22317: BCM Testing & Exercising (5 controls), ISO 22317: Business Continuity Strategy (5 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Analysis
| Code | Title |
|---|---|
| ISO22317-5.1 | Prioritized Activities Identification |
| ISO22317-5.2 | Impact Categories and Tolerances |
Assurance
| Code | Title |
|---|---|
| ISO22317-8.2 | BIA Programme Assurance |
Dependencies
| Code | Title |
|---|---|
| ISO22317-5.8 | Interdependencies and Single Points of Failure |
Execution
| Code | Title |
|---|---|
| ISO22317-6.1 | BIA Data Collection |
| ISO22317-6.2 | BIA Validation and Sign Off |
Foundation
| Code | Title |
|---|---|
| ISO22317-4.1 | BIA Programme Establishment |
ISO 22317: BCM Program Management
Establishing and managing the BCM program (ISO 22317)
| Code | Title |
|---|---|
| ISO22317-01 | Business continuity policy |
| ISO22317-02 | BCM program scope and objectives |
| ISO22317-03 | Resource allocation for BCM |
| ISO22317-04 | BCM roles and responsibilities |
| ISO22317-05 | Management commitment to BCM |
ISO 22317: BCM Testing & Exercising
Validating business continuity plans (ISO 22317)
| Code | Title |
|---|---|
| ISO22317-16 | Exercise program development |
| ISO22317-17 | Tabletop and simulation exercises |
| ISO22317-18 | Full-scale testing procedures |
| ISO22317-19 | Post-exercise review and improvement |
| ISO22317-20 | Plan maintenance and update |
ISO 22317: Business Continuity Strategy
Developing continuity and recovery strategies (ISO 22317)
| Code | Title |
|---|---|
| ISO22317-11 | Continuity strategy development |
| ISO22317-12 | Recovery strategy for critical activities |
| ISO22317-13 | Alternate site and resource planning |
| ISO22317-14 | Supply chain continuity |
| ISO22317-15 | Communication strategy during disruption |
ISO 22317: Business Impact Analysis
Understanding the impact of disruptions (ISO 22317)
| Code | Title |
|---|---|
| ISO22317-06 | Business impact analysis methodology |
| ISO22317-07 | Critical activity identification |
| ISO22317-08 | Recovery time and point objectives |
| ISO22317-09 | Resource requirements assessment |
| ISO22317-10 | Interdependency mapping |
Linkage
| Code | Title |
|---|---|
| ISO22317-7.2 | Linking BIA to Continuity Strategy |
Maintenance
| Code | Title |
|---|---|
| ISO22317-8.1 | BIA Maintenance and Refresh |
Methodology
| Code | Title |
|---|---|
| ISO22317-4.2 | BIA Methodology and Approach |
Reporting
| Code | Title |
|---|---|
| ISO22317-7.1 | BIA Outputs Reporting |
Resources
| Code | Title |
|---|---|
| ISO22317-5.7 | Resource Requirements Analysis |
Timing Parameters
| Code | Title |
|---|---|
| ISO22317-5.3 | Maximum Tolerable Period of Disruption (MTPD) |
| ISO22317-5.4 | Recovery Time Objective (RTO) |
| ISO22317-5.5 | Recovery Point Objective (RPO) |
| ISO22317-5.6 | Minimum Business Continuity Objective (MBCO) |
Your Compliance Coverage
If you comply with ISO 22317, you already cover:
PSD2 SCA
14%
5 controls mapped
Compare →OSFI B-13
14%
5 controls mapped
Compare →Open Banking Security
14%
5 controls mapped
Compare →+ 122 more: Oman National Cybersecurity Framework (14%), NIS2 Directive Implementing Acts (14%)
See all 125 mapped frameworks ↓Maps to 125 other frameworks
What is ISO 22317 and who does it apply to?
ISO 22317 is a compliance framework from International with 15 domains and 36 controls. Guidelines for business impact analysis It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does ISO 22317 actually require?
ISO 22317 has 36 controls organised across 15 domains. The largest domains are ISO 22317: BCM Program Management (5 controls), ISO 22317: BCM Testing & Exercising (5 controls), ISO 22317: Business Continuity Strategy (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of ISO 22317 do I already cover?
ISO 22317 maps to 125 other compliance frameworks. The top mapping partners are PSD2 SCA (14% coverage), OSFI B-13 (14% coverage), Open Banking Security (14% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement ISO 22317?
Start your ISO 22317 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ISO 22317 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 36 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required