How to use this checklist
Answer each question with one of three honest options: yes with evidence (a document, a record, a test report), on paper only, or no. Auditors accept only the first. “On paper only” is where most organisations live — and where audits hurt.
Governance and system (clauses 3-7)
- Does a named member of top management personally own business continuity — with accountability in writing?
- Is there an implementation plan with target dates approved by leadership?
- Have you mapped the context: dependencies, stakeholders, regulatory requirements that apply to you?
- Is there a signed BCM policy with a defined scope — which facilities, activities and threats it covers?
- Are the people running the BCMS demonstrably competent (training records, experience)?
- Are criteria defined for selecting critical external providers — and applied?
- Does documented information exist for every clause that requires it — and is it current?
Operations (clause 8)
- Have you identified prioritised activities and the impact of their disruption over time (BIA)?
- Do you know the cost of one lost day for each critical facility or process — as a number?
- Are recovery time objectives set — and are they achievable with current arrangements, not aspirational?
- Are single points of failure identified: one supplier, one route, one system, one person?
- Have you evaluated the continuity arrangements of critical suppliers against your dependency on them?
- Do continuity strategies exist: alternate facilities, routes, workarounds, technology recovery?
- Is there a response structure with named roles and written authority for the first hours — including who can stop operations?
- Are communication procedures ready: staff, clients, authorities, media?
- Has the plan been exercised in the last 12 months on a realistic scenario — and did the exercise produce findings?
Review and improvement (clauses 9-10)
- Are performance indicators defined and measured for the compliance elements of clause 9?
- Has an internal audit of the BCMS been performed — by someone independent of its operation?
- Has top management formally reviewed the system in the last year?
- Do findings from exercises, audits and incidents actually change the system — with a traceable record?
Count your honest answers. 20 «yes with evidence» — you are audit-ready. 15+ — close the gaps in a focused quarter. Below 12 — you need a structured programme, and the good news is that 3-6 months of honest work gets a mid-size organisation there.
Frequently asked questions
Is this the official NCEMA checklist?
No — it is a practitioner's checklist mapped to the clauses of the official standard. The official document is free at ncema.gov.ae; this page turns its requirements into questions you can answer honestly in an hour.
What counts as “evidence” for an auditor?
Records, not intentions: a signed policy, BIA outputs with numbers, an exercise report with findings, training records, supplier evaluations, KPI dashboards. If it is not written down and dated, it did not happen.
We scored badly. What is the fastest path?
A gap assessment first — 2-3 weeks, every gap priced in downtime terms, a 90-day plan. Fixing gaps in priority order beats fixing them in clause order.