What an internal audit of the BCMS checks
Three layers. Existence: policy, scope, BIA, plans, programme, records exist and are current. Operation: the BIA was reviewed on schedule, plans were exercised, actions were closed, suppliers were assessed; this is the layer of samples and dates. Effectiveness: tested recovery times meet objectives, incidents were within tolerance, management review produced decisions. Most audits stop at the first layer; reviewers and regulators are interested in the third.
Seventeen criteria by clause area
| Area | Criteria | Reference | Typical evidence |
|---|---|---|---|
| Context and leadership | 2 | ISO 22301 cl. 4-5; NCEMA 7000 cl. 4-5 | Scope statement, policy, review minutes |
| Planning and support | 3 | ISO 22301 cl. 6-7 | Objectives, training records, document register |
| Operation | 7 | ISO 22301 cl. 8; NCEMA 7000 cl. 8 | BIA, risk register, strategies, plans, exercise reports, supplier contracts |
| Performance evaluation | 3 | ISO 22301 cl. 9 | KPI dashboard, previous audits, management review |
| Improvement | 1 | ISO 22301 cl. 10 | Corrective action log with closure evidence |
| Regulatory | 1 | NCEMA, CBUAE, sector rules | Correspondence, findings, deadlines |
Download the checklist
Download the template. Audit checklist sheet with 17 criteria, evidence to request, references and columns for finding type, observation and corrective action; a summary sheet with counts; an interview guide for four roles. Xlsx.
Download xlsx (bcms-internal-audit-checklist.xlsx)
Finding types follow ISO practice: conforms, minor nonconformity, major nonconformity. Adapt references if you audit against NCEMA 7000 only. No registration, no forms. Need it adapted to your organisation or a full programme: see how we work.
Running the audit
- Plan: scope, criteria, sample sizes, interviewees; two to four weeks before fieldwork.
- Documents first: request everything in the evidence column before interviews, so that interviews test the documents rather than replace them.
- Samples: three prioritised activities end to end, from BIA line to plan to exercise report to corrective action.
- Interviews: four roles with the questions in the guide; the most revealing one for top management is "when did a BCM report last change a decision".
- Report within two weeks: findings by type, root causes, corrective actions with owners and dates, presented at management review.
Independence and competence
The auditor must not audit their own work: internal audit or risk audits a BCMS run by the BCM manager; if the organisation is too small, a peer from another unit or an external auditor. Competence means knowing the standard and the organisation; the ERGP certification covers the former in its audit and assurance module. The RACI matrix gives the auditor the list of accountable people to interview.
Frequently asked questions
Is an internal audit of the BCMS mandatory?
Yes under ISO 22301 clause 9.2 and under AE/SCNS/NCEMA 7000, which requires the organisation to conduct internal audits at planned intervals to determine whether the BCMS conforms and is effectively implemented. Reviewers ask for the audit programme and the last report.
How often should the BCMS be audited?
A full audit annually, or at least every certification cycle, plus follow-up of open findings within six months. Sector regulators may set a stricter cycle.
Who can audit the BCMS internally?
Anyone competent and independent of the activity audited: internal audit, the risk function, a trained peer from another business unit, or an external provider acting as internal auditor. The BCM manager cannot audit their own system.
What is the difference between a minor and a major nonconformity?
A minor nonconformity is an isolated lapse in an otherwise working requirement, such as one plan past its review date. A major one is a requirement absent or systematically failing, such as no exercises in the last year, and it blocks certification until closed.