Skip to main content
Category: Business Continuity

Business Continuity Policy

Also known as: BCP, Business Continuity and Disaster Recovery Policy, Business Continuity Plan Policy
Simply put

A Business Continuity Policy is a formal document that sets out how an organization will keep its most important business activities running during and after a disruptive event. It establishes the organization's overall approach and expectations for planning ahead, so that critical functions can continue or be quickly restored while losses are minimized. The policy typically directs the creation of more detailed continuity and recovery plans and procedures.

Formal definition

A Business Continuity Policy is a governing document that defines the organization's objectives, scope, roles, and acceptable methods for sustaining critical business processes through and after a disruption, generally leveraging a risk-based analysis to prioritize functions and drive preparedness. It typically establishes the framework under which a Business Continuity Plan (the documented set of predetermined instructions or procedures for maintaining mission/business processes) and related disaster recovery planning are developed, maintained, and tested. In a compliance context, such a policy commonly supports evidence of resilience-related controls; under SOC 2, availability and related continuity concerns are addressed within the Trust Services Criteria when that category is in scope, while under ISO/IEC 27001 continuity of information security is addressed through the ISMS requirements and applicable Annex A reference controls selected via the Statement of Applicability. The specific policy content, tested scope, and required plans vary depending on the organization, its risk assessment, and the applicable criteria or standard.

Why it matters

A Business Continuity Policy matters because disruptions, whether from natural disasters, technology failures, or other events, can interrupt the critical business processes an organization depends on. Without a formal policy establishing objectives, scope, and responsibilities ahead of time, organizations are forced to improvise during a crisis, which typically increases both the duration of an outage and the associated losses. A resiliency strategy set out before an event is what allows critical functions to continue or be quickly restored while minimizing loss of life, property, and assets.

In a compliance context, a Business Continuity Policy commonly supports evidence of resilience-related controls. Under SOC 2, availability and related continuity concerns are addressed within the Trust Services Criteria when the Availability category is included in scope; a Business Continuity Policy can therefore contribute to the evidence a service auditor examines during a SOC 2 examination. Under ISO/IEC 27001, continuity of information security is addressed through the ISMS requirements and any applicable Annex A reference controls selected via the Statement of Applicability, so the policy can help demonstrate that continuity has been considered as part of the management system.

It is important to recognize the boundaries of what such a policy provides. A Business Continuity Policy sets the framework and expectations; it does not by itself guarantee that operations will continue uninterrupted. The specific policy content, the scope of what is tested, and the plans that flow from it vary depending on the organization, its risk assessment, and the applicable criteria or standard, and the effectiveness of continuity arrangements ultimately depends on how well the resulting plans are maintained and exercised.

Who it's relevant to

Compliance and GRC Managers
Those responsible for governance and compliance rely on the Business Continuity Policy as a governing document that establishes objectives, scope, and roles for resilience. It commonly supports evidence of resilience-related controls and helps demonstrate that continuity has been formally considered and assigned within the organization.
SOC 2 Practitioners and Auditors
When the Availability category is in scope for a SOC 2 examination, availability and related continuity concerns are addressed within the Trust Services Criteria. A Business Continuity Policy can form part of the evidence a service auditor examines, though it attests only to the controls and period covered rather than guaranteeing uninterrupted operations.
ISO/IEC 27001 ISMS Owners
For organizations pursuing or maintaining ISO/IEC 27001 certification, continuity of information security is addressed through the ISMS requirements and applicable Annex A reference controls selected via the Statement of Applicability. A Business Continuity Policy helps show that continuity has been evaluated as part of the management system, within the defined scope of the ISMS.
Business and Operational Leaders
Leaders accountable for critical functions use the policy to ensure the organization can continue or quickly resume performing its most important business processes. The risk-based prioritization it directs helps focus preparedness efforts on the functions whose disruption would cause the greatest loss.

Inside BCP

Purpose and Scope Statement
Defines why the policy exists and the boundaries it covers, such as which business units, locations, processes, and systems fall within the continuity program. In an ISO 27001 context, the scope should align with the defined ISMS boundaries rather than assuming enterprise-wide coverage.
Roles and Responsibilities
Identifies the individuals or teams accountable for continuity planning, activation, and recovery, including management commitment. Assignment of responsibilities supports the ISMS requirements in clauses 4 through 10, though the specific roles vary by organization.
Business Impact Analysis (BIA) Reference
Points to the process for identifying critical processes and the potential impact of disruption over time. The BIA typically informs recovery priorities and objectives, though its depth and method depend on organizational scope and risk assessment outcomes.
Recovery Objectives
Describes targets such as recovery time and recovery point objectives for critical processes. These values are set through scoping and risk decisions and are not fixed across engagements.
Plan Activation and Response Procedures
Outlines how and when continuity plans are invoked, including escalation, communication, and decision authority. The specifics typically depend on the organization's structure and identified disruption scenarios.
Testing and Maintenance Provisions
Establishes how continuity arrangements are exercised, reviewed, and updated. Under ISO 27001, continual improvement and evaluation are part of the ISMS requirements, though the frequency and format of testing vary by organization.
Relationship to Applicable Controls
Where relevant, references the reference controls selected via the Statement of Applicability in ISO 27001 and, for a SOC 2 examination, the Availability category of the Trust Services Criteria, which is optional and selected based on scope. The policy alone does not demonstrate control effectiveness.

Common questions

Answers to the questions practitioners most commonly ask about BCP.

Does a business continuity policy earn you an ISO 27001 certification or a SOC 2 certification?
Neither framework issues a certification based on a single policy, and the two frameworks produce different outcomes. ISO/IEC 27001 results in a certification issued by an accredited certification body against the ISMS requirements, while SOC 2 results in an attestation report produced by a licensed CPA firm under the AICPA SSAE 18 standard. A business continuity policy is one input into the broader body of evidence an auditor or certification body evaluates; it does not, on its own, produce either outcome. Additionally, the ISO 27001 certificate covers only the defined scope of the ISMS, and a SOC 2 report attests only to the controls and period covered.
Is a business continuity policy a mandatory control that every organization must implement in the same way?
Requirements depend on the framework, scope, and applicable criteria rather than a single universal rule. Under ISO 27001, controls are selected via a Statement of Applicability informed by a risk assessment, so the applicability and depth of business continuity provisions depend on scoping and risk decisions. Under SOC 2, the relevant expectations flow from the Trust Services Criteria in scope, with Availability being an optional category selected based on scope. In most engagements the specifics vary by the auditor, certification body, and defined scope, so it is better to describe business continuity as typically expected where relevant rather than uniformly mandatory.
Who should own and approve the business continuity policy?
Ownership and approval arrangements vary by organization, but in most engagements the policy is formally approved by leadership or management with authority over the relevant scope, and assigned an accountable owner responsible for maintenance. Both frameworks value evidence of management commitment and clear responsibility; the exact roles depend on the organization's structure and the scope defined for the ISMS or the SOC 2 examination.
How often should the business continuity policy be reviewed and updated?
Review frequency is set by the organization and typically documented within the policy or a governing procedure. Many organizations perform reviews on a defined periodic cycle and after significant changes or incidents, but the specific interval varies and is not fixed by either framework. Auditors and certification bodies generally look for evidence that reviews occur consistently with the organization's stated cadence.
What evidence do assessors typically look for related to a business continuity policy?
Assessors typically look for a documented, approved policy, evidence that it is communicated to relevant personnel, and records demonstrating that associated activities occur as described, depending on scope. For a SOC 2 Type II examination, evidence may need to demonstrate operating effectiveness over the defined review period, whereas a Type I assessment addresses suitability of design at a point in time. Under ISO 27001, related evidence supports the ISMS requirements in clauses 4 through 10 and any applicable reference controls selected in the Statement of Applicability.
How does a business continuity policy relate to broader recovery and resilience documentation?
A business continuity policy generally sets the high-level intent, scope, and responsibilities, while more detailed plans and procedures describe how activities are carried out. The precise document structure varies by organization. It is worth noting that a policy or supporting plan attests only to the intended approach and does not guarantee freedom from disruption or breaches; both the ISO 27001 certificate and the SOC 2 report are bounded by the defined scope and, for SOC 2, the period covered.

Common misconceptions

Having a Business Continuity Policy means an organization has satisfied continuity requirements for both SOC 2 and ISO 27001.
A policy is a documented intent, not evidence of operating controls. A SOC 2 Type II examination assesses whether controls operated effectively over a defined review period, and ISO 27001 certification depends on implementation and evidence within the defined ISMS scope. Satisfying one framework does not automatically satisfy the other, as mapping between them is only partial.
A Business Continuity Policy guarantees the organization will not experience disruption or breaches.
The policy describes an approach to preparedness, but it does not eliminate risk. A SOC 2 report attests only to the controls and period covered and does not guarantee freedom from disruption, and an ISO 27001 certificate covers only the defined scope of the ISMS.
The Business Continuity Policy is a mandatory standalone control identical across both frameworks.
Continuity relates to the optional Availability category of the SOC 2 Trust Services Criteria, selected based on scope, and to ISO 27001 reference controls chosen through the Statement of Applicability informed by risk assessment. Whether and how continuity is addressed depends on scope, applicable criteria, and risk decisions.

Best practices

Align the policy scope with the defined ISMS boundaries for ISO 27001 and with the criteria selected for a SOC 2 examination, rather than assuming universal coverage.
Reference a business impact analysis and risk assessment so that recovery priorities and objectives are justified rather than arbitrary, recognizing that specific targets vary by scoping decisions.
Assign clear roles, responsibilities, and management accountability to support the ISMS requirements in clauses 4 through 10.
Establish provisions for regular testing, review, and update of continuity arrangements so the policy is supported by evidence of operating effectiveness, which is what a SOC 2 Type II examination evaluates over its review period.
Maintain the policy consistently with the Statement of Applicability and any selected reference controls, documenting how continuity requirements are met within scope.
Retain records of activation, testing, and improvements so that both auditors and certification bodies can assess implementation, remembering that a policy alone does not demonstrate control effectiveness.