Project and Processes Management

ISO 22301 Lead Auditor





Target Audience

·          Internal auditors and auditors wanting to perform and lead BCMS certification audits

·          Project managers or consultants wanting to master the BCMS audit process

·          Persons responsible for the Business continuity or conformity in an organization

·          Members of an business continuity team

·          Expert advisors in information technology

Technical experts wanting to prepare for an Business continuity audit function


·          ISO 22301 Foundation Certification or basic knowledge of ISO 27031 or BS 25999 and business continuity    concepts is recommended

Skills Gained

This course enables participants to develop the needed expertise to audit a Business Continuity Management System (BCMS) and to manage a team of auditors by applying widely recognized audit principles, procedures and techniques. During this training, the participant will acquire needed knowledge and skills to proficiently plan and perform internal and external audits in compliance with ISO 19011 the certification process according ISO 17021. Based on practical exercises, the participant will develop the skills (mastering audit techniques) and competencies (managing audit teams and audit program, communicating with customers, conflict resolution, etc.) necessary to efficiently conduct an audit. This training is compatible with BS 25999 audit (Business continuity management specification) and ISO 27031 (Guidelines for information and communication technology readiness for business continuity).

At the end of this course, the learner will gain competencies in:

·          To acquire the expertise to perform an ISO 22301 or BS 25999 internal audit following ISO 19011 guidelines

·          To acquire the expertise to perform an ISO 22301 or BS 25999 certification audit following ISO 19011 guidelines and the specifications of ISO 17021

·          To acquire  the expertise necessary to manage a BCMS audit team

·          To understand the operation of the BCMS in accordance with ISO22301, ISO 27031 or BS 25999

·          To understand the relationship between a Business Continuity Management System, including risk management, controls and compliance with the other requirements

Topics Covered

• Presentation of the standards ISO 22301, ISO 27031, ISO/PAS 22399, BS 25999 and regulatory framework
• Fundamental principles of business continuity
• ISO 22301 certification process• Business Continuity Management System (BCMS)
• Detailed presentation of the clauses 4 to 8 of ISO22301

• Fundamental audit concepts and principles
• Audit approach based on evidence and on risk
• Preparation of an ISO 22301 certification audi
• BCMS documentation audit
• Conducting an opening meeting

• Communication during the audit
• Audit procedures: observation, document review, interview, sampling techniques, technical verification, corroboration and evaluation
• Audit test plans
• Formulation of audit findings and documenting of nonconformities

• Audit documentation
• Conducting a closing meeting and conclusion of an ISO 22301 audit
• Evaluation of corrective action plans• ISO 22301 surveillance audit
• ISO 22301 internal Audit management program and second party audits

minimize course outline