BCMS internal audit checklist: ISO 22301 and NCEMA 7000 criteria (Excel)

Template · Excel · Audit

BCMS internal audit checklist: seventeen criteria and the evidence for each

Internal audit is where a BCMS stops being a set of documents and becomes a system with findings. Both ISO 22301 and AE/SCNS/NCEMA 7000 require it, and NCEMA reviewers ask for the audit report before they ask for the plans. Here is a seventeen-criterion checklist that records evidence seen rather than statements heard, with an interview guide and the Excel file.

What an internal audit of the BCMS checks

Three layers. Existence: policy, scope, BIA, plans, programme, records exist and are current. Operation: the BIA was reviewed on schedule, plans were exercised, actions were closed, suppliers were assessed; this is the layer of samples and dates. Effectiveness: tested recovery times meet objectives, incidents were within tolerance, management review produced decisions. Most audits stop at the first layer; reviewers and regulators are interested in the third.

Seventeen criteria by clause area

AreaCriteriaReferenceTypical evidence
Context and leadership2ISO 22301 cl. 4-5; NCEMA 7000 cl. 4-5Scope statement, policy, review minutes
Planning and support3ISO 22301 cl. 6-7Objectives, training records, document register
Operation7ISO 22301 cl. 8; NCEMA 7000 cl. 8BIA, risk register, strategies, plans, exercise reports, supplier contracts
Performance evaluation3ISO 22301 cl. 9KPI dashboard, previous audits, management review
Improvement1ISO 22301 cl. 10Corrective action log with closure evidence
Regulatory1NCEMA, CBUAE, sector rulesCorrespondence, findings, deadlines

Download the checklist

Download the template. Audit checklist sheet with 17 criteria, evidence to request, references and columns for finding type, observation and corrective action; a summary sheet with counts; an interview guide for four roles. Xlsx.

Download xlsx (bcms-internal-audit-checklist.xlsx)

Finding types follow ISO practice: conforms, minor nonconformity, major nonconformity. Adapt references if you audit against NCEMA 7000 only. No registration, no forms. Need it adapted to your organisation or a full programme: see how we work.

Running the audit

  1. Plan: scope, criteria, sample sizes, interviewees; two to four weeks before fieldwork.
  2. Documents first: request everything in the evidence column before interviews, so that interviews test the documents rather than replace them.
  3. Samples: three prioritised activities end to end, from BIA line to plan to exercise report to corrective action.
  4. Interviews: four roles with the questions in the guide; the most revealing one for top management is "when did a BCM report last change a decision".
  5. Report within two weeks: findings by type, root causes, corrective actions with owners and dates, presented at management review.

Independence and competence

The auditor must not audit their own work: internal audit or risk audits a BCMS run by the BCM manager; if the organisation is too small, a peer from another unit or an external auditor. Competence means knowing the standard and the organisation; the ERGP certification covers the former in its audit and assurance module. The RACI matrix gives the auditor the list of accountable people to interview.

Frequently asked questions

Is an internal audit of the BCMS mandatory?

Yes under ISO 22301 clause 9.2 and under AE/SCNS/NCEMA 7000, which requires the organisation to conduct internal audits at planned intervals to determine whether the BCMS conforms and is effectively implemented. Reviewers ask for the audit programme and the last report.

How often should the BCMS be audited?

A full audit annually, or at least every certification cycle, plus follow-up of open findings within six months. Sector regulators may set a stricter cycle.

Who can audit the BCMS internally?

Anyone competent and independent of the activity audited: internal audit, the risk function, a trained peer from another business unit, or an external provider acting as internal auditor. The BCM manager cannot audit their own system.

What is the difference between a minor and a major nonconformity?

A minor nonconformity is an isolated lapse in an otherwise working requirement, such as one plan past its review date. A major one is a requirement absent or systematically failing, such as no exercises in the last year, and it blocks certification until closed.

More on assurance and governance

Audit due and the evidence folder thin? A gap assessment is the dress rehearsal.

Request a gap assessmentTake the free readiness check
NCEMA-ready gap assessment
Learn this properlyERGP — the Executive Certificate in Enterprise Resilience Governance

Six modules, 94 chapters, a capstone defended before the examiner and a certificate anyone can verify. The first resilience governance certification fully available in Arabic, also in English. The AE/SCNS/NCEMA 7000 module is inside.

Explore the ERGP certification →