Skip to main content
FaizZab

Readiness assessment

ISO 22301 Readiness Assessment

Determine whether your continuity programme can perform when resilience is tested.

The business problem

Why organizations bring this to us

The question that matters is not whether continuity documentation exists. It is whether the recovery objectives are achievable, whether the dependencies behind them are understood, and whether the people named in the plan know what they would do.

This assessment tests those three things against evidence. It is deliberately uncomfortable: recovery objectives are checked against actual capability, and exercise records are reviewed for whether anything was genuinely learned.

Who this is for

  • Organizations with continuity plans that have never been independently reviewed or seriously exercised.
  • Companies preparing for ISO 22301 certification or a customer resilience audit.
  • Businesses that have grown or changed materially since their continuity analysis was performed.
  • Leadership teams that need an honest answer about whether the organization could actually recover.

Service scope

Assessment areas

Every area is tested against records and against the people who would have to execute, not against the plan document alone.

Critical Activity Validation

Challenge the declared critical activities against commercial and operational reality, identifying both activities incorrectly designated critical and genuinely critical activities that were missed.

Dependency Mapping Review

Trace each critical activity to the people, systems, facilities, data and third parties it depends on, and surface single points of failure and hidden concentration.

BIA Quality Assessment

Evaluate whether the business impact analysis is current, evidence-based and time-graduated, or whether it records opinion collected once and never revisited.

Recovery Objective Coherence

Test whether stated RTOs and RPOs are internally consistent, supported by the BIA, and actually deliverable by the underlying technology and supplier arrangements.

Crisis Role Readiness

Establish whether the people named in the crisis structure know their role, have the authority the plan assumes, and are contactable and available in practice.

Escalation Effectiveness

Assess activation triggers and escalation paths for clarity and speed, including who is authorized to declare an incident and what happens outside business hours.

Exercise Evidence

Review exercise history for realism, participation, honest observation and corrective action, distinguishing genuine testing from a documented meeting.

Supplier Resilience

Evaluate continuity assurance obtained from critical suppliers, including whether their commitments are contractual, evidenced and compatible with your recovery objectives.

Recovery Documentation

Assess whether plans are usable under disruption - accessible without primary systems, current, role-based and free of dependency on a single knowledgeable individual.

BCMS Assurance Roadmap

Consolidate findings into a prioritized roadmap that addresses the gaps most likely to cause recovery failure or a certification finding.

Methodology

How the assessment runs

  1. Documentation review

    Analyse BIA output, plans, exercise records and supplier continuity evidence before fieldwork begins.

  2. Dependency tracing

    Work through critical activities with process and technology owners to build an accurate dependency picture.

  3. Objective validation

    Test recovery objectives against real technical and supplier capability rather than accepting them at face value.

  4. Crisis readiness testing

    Interview named crisis roles and run a short scenario walkthrough to establish practical readiness.

  5. Findings and roadmap

    Rate each area, present findings to leadership and deliver a prioritized assurance roadmap.

What you receive

Key deliverables

  • Continuity readiness report with area-level ratings
  • Validated critical activity list with challenge findings
  • Dependency map highlighting single points of failure and concentration risk
  • BIA quality review
  • Recovery objective coherence analysis against actual capability
  • Crisis role and escalation readiness findings
  • Exercise evidence review
  • Supplier resilience assessment
  • Prioritized BCMS assurance roadmap

Outcome

Test resilience on paper before disruption tests it in reality.

Commercial value

Why this service matters

Objectives you can defend

Committing to recovery objectives you cannot meet creates contractual and regulatory exposure. Validation removes that risk before it is tested.

Finds concentration risk

Dependency tracing routinely uncovers a single supplier, system or individual underpinning several critical activities.

Honest readiness picture

Leadership gets a defensible answer to "could we recover?" based on evidence rather than on the existence of a plan.

Questions

Common questions

Do you run a live failover test?

No. The assessment evaluates readiness, evidence and coherence, including a scenario walkthrough with the crisis team. Live technical failover testing is executed by your technology function, and we can help define and observe it.

What if our BIA is several years old?

That is a common finding and is treated as a material gap. Where the BIA no longer reflects the business, the roadmap prioritizes refreshing it before any other continuity investment.

Can this cover our critical suppliers directly?

The assessment reviews the continuity assurance you hold over suppliers. Direct supplier assessment is available through our third-party risk service.

Related

Related services

View all services
ImplementationAVAILABLE NOW

ISO 22301 Implementation

Implementation of a Business Continuity Management System aligned to the current edition of ISO 22301 - BCMS governance, business impact analysis, recovery requirements, continuity strategy, crisis management, plans, exercising and supplier continuity.

Explore this service
AdvisoryAVAILABLE NOW

Third-Party Risk

Design and operation of third-party risk management - supplier due diligence, criticality tiering, risk assessment, contractual controls, ongoing monitoring and periodic review.

Explore this service
AdvisoryAVAILABLE NOW

Risk Management

Design and operation of a practical risk management process - identification, assessment, treatment, ownership, monitoring and reporting - connected to the controls and decisions it is meant to influence.

Explore this service
Readiness assessmentAVAILABLE NOW

ISO 27001 Readiness Assessment

An evidence-based benchmark of your existing ISMS against ISO/IEC 27001:2022 certification expectations - clause and Annex A readiness, documentation sufficiency, evidence sampling, and a prioritized 30/60/90-day remediation roadmap.

Explore this service

Important

Readiness and advisory support only. FaizZab does not issue ISO certification, and this assessment does not guarantee a certification outcome or the success of any actual recovery.

Find out where you actually stand

Tell us your obligation, your timeline and where you are today. We will confirm whether this is the right engagement for you.