What the policy has to do
A BCM policy answers four questions for the whole organisation: what we protect (scope and prioritised activities), how much disruption we tolerate (objectives and tolerances), who decides (roles and authority) and how we prove it works (exercising, audit, review). Procedures do not belong here; they live in plans. Clause 5 of AE/SCNS/NCEMA 7000 expects top management to establish the policy, make it available and review it, and auditors check exactly that: a signed document, a date, evidence of communication.
Ten sections, what each one is for
| Section | Content | What the reviewer looks for |
|---|---|---|
| 1 Purpose and scope | Units, sites, subsidiaries, critical suppliers; prioritised activities in Appendix A | Scope matches the BIA |
| 2 Policy statement | One paragraph on what continues, at what level, and who comes first | Signed by top management |
| 3 Objectives | Five measurable objectives: BIA currency, plans exercised, escalation time, suppliers, compliance | Numbers, not adjectives |
| 4 Principles | Ownership, service view, evidence over intention, proportionality, improvement | Applied in decisions, not copied from a standard |
| 5 Roles | Board, accountable executive, BCM manager, activity owners, IT, procurement, audit, staff | One accountable executive named |
| 6 BCMS framework | PDCA cycle, document control | Consistent with ISO 22301 structure |
| 7 Exercising | Programme, frequencies, records | Frequencies as numbers |
| 8 Suppliers | Contract clauses, right to review, concentration | Clauses actually in contracts |
| 9 Communication | Spokesperson, regulator notification timelines | Timelines match regulation |
| 10 Review | Periodicity and triggers | Date of next review |
Three mistakes that make reviewers write findings
- Scope by omission. The policy covers "the organisation" and the BIA covers three departments; the reviewer asks about the other seven.
- Objectives without numbers. "Plans are exercised regularly" is a finding; "every prioritised activity is exercised at least annually, records kept" is evidence.
- Accountability spread thin. "Management is responsible for BCM" names nobody. One named executive, with deputies in the plans.
Download the template
Download the template. Ten sections with a roles table, measurable objectives, exercising frequencies, supplier clauses and Appendix A for prioritised activities and recovery objectives. Docx, five pages.
Download docx (bcm-policy-template-uae.docx)
Aligned with AE/SCNS/NCEMA 7000:2021 and ISO 22301:2019; add CBUAE or sector-specific requirements in section 1. No registration, no forms. Need it adapted to your organisation or a full programme: see how we work.
From policy to evidence
The policy is the top of a chain: BIA with numbers, plans per prioritised activity, an exercise programme with reports, an audit, a management review. The NCEMA 7000 self-assessment shows which links of the chain exist; the BCP template and the BIA template fill the two largest gaps.
Frequently asked questions
Is a BCM policy mandatory under NCEMA 7000?
Yes. Clause 5 requires top management to establish a business continuity policy appropriate to the organisation, communicate it and keep it under review. Reviewers ask for the signed document and evidence of communication.
How long should a BCM policy be?
Three to six pages. Procedures, contact lists and scenarios belong in plans and appendices; a policy longer than ten pages is usually a plan with the wrong title.
Who signs the BCM policy?
The accountable executive at the top of the organisation: CEO, general manager or board chair, depending on structure. A policy signed by the BCM manager alone carries no authority with reviewers.
Does the same policy work for ISO 22301 certification?
Yes. The template follows the ISO 22301 clause logic, and NCEMA 7000 is built on the same high-level structure; the UAE-specific elements are regulator notification and the NCEMA relationship.