Professional track

ISO 22301 Auditor

Develop the skills to plan, conduct and evaluate audits against ISO 22301 in real organisational contexts

AuditorBusiness ContinuityISO 22301
ISO 22301 auditor conducting a site inspection with a guide and operational expert, assessing business continuity capabilities in an industrial environment.

Auditing business continuity beyond documented plans

By focusing on critical activities, recovery capabilities and evidence from exercises and operations, this track builds the capability to assess whether a BCMS will actually perform under disruption.

Overview

What this track is about

A modular training programme for business continuity auditors. Learn to audit ISO 22301 Business Continuity Management Systems by evaluating preparedness, recovery capability and organisational resilience.

The ISO 22301 Auditor Track is designed for professionals who audit Business Continuity Management Systems (BCMS) in different organisational and audit contexts. Rather than approaching audits as a review of documented plans alone, the programme focuses on evaluating preparedness, prioritisation and the organisation’s ability to respond to and recover from disruption.

The track covers the full audit life cycle and enables effective BCMS audits in internal auditing, supplier auditing as well as third-party auditing contexts.

Audience

Who it is for

The ISO 22301 Auditor Track equips professionals to plan, conduct, and report audits of Business Continuity Management Systems (BCMS) against the requirements of ISO 22301.

Current or aspiring internal, supplier, or third-party auditors who want to audit business continuity management systems against ISO 22301

Business continuity, resilience, or risk professionals seeking to transition into BCM auditing roles

Auditors from other management system domains who want to extend their audit competence to business continuity

Practising ISO 22301 auditors who want to improve audit effectiveness in complex, risk-driven, or regulated environments

Outcomes

Learning outcomes

4 capability areas. Each is assessed on the case organisation before the credential is issued, not on a multiple-choice paper.

01

Understand and interpret ISO 22301 requirements reliably

Interpret ISO 22301 requirements consistently across different organisational contexts

Understand the structure and practical application of BCMS

02

Plan and conduct audits in a structured manner

Plan and perform internal, supplier and third-party BCMS audits in accordance with ISO 19011

Apply appropriate audit techniques to obtain objective and verifiable audit evidence

03

Evaluate conformity and audit findings professionally

Evaluate conformity of a BCMS against ISO 22301 requirements and defined audit criteria

Formulate clear, well-founded audit findings and nonconformities

04

Communicate audit results and support improvement

Communicate audit results professionally to auditees and management

Support improvement of business continuity governance and controls through clear, actionable audit feedback

Professional positioning

Build a recognised competence profile as an auditor for ISO 22301 across different organisational contexts

Assess business continuity management systems in a structured, independent and standard-compliant manner, and substantiate audit findings professionally

Act as a competent professional counterpart to organisations, management, certification bodies and other auditors

Credentials

Scalable credential model

Halderstone tracks follow a two-credential model that mirrors their modular structure. Both are awarded without expiry.

Core credential

Diploma in Management System Auditing

Cross-domain management system foundation: the 17 core modules

Applicable across every ISO standard we teach

Reusable across every further specialisation in the same role

Specialisation credential

Halderstone Certified ISO 22301 Auditor

Fundamentals of business continuity management

Ability to audit ISO 22301-specific requirements

Registered credentials

Once the specialisation credential is held, a Registered credential can be applied for. These confirm verified professional experience alongside the qualification, and keep it current through periodic reassessment.

How registered credentials work →
Registered credentials: Halderstone Certified ISO 22301 Auditor

The following Registered credentials can be applied for:

Registered Associate Auditor in ISO 22301 Auditing

Registered Professional Auditor in ISO 22301 Auditing

Registered Lead Auditor in ISO 22301 Auditing

Registered Senior Lead Auditor in ISO 22301 Auditing

Application requires meeting the experience requirements for the respective level.

For employers

How Halderstone credentials translate into capability signals in hiring, role design and professional practice, including what each one does and does not evidence.

View the credential framework →

Track price

CHF 7,500

All 19 modules, the capstone and the examination

approx. €7,890 · invoiced in CHFapprox. £6,590 · invoiced in CHFapprox. US$9,320 · invoiced in CHF

No VAT is charged.

Start with a single module at any time · credited in full if you continue

Bought from us before? Sign in to see the modules you already hold.

Track facts

Track ID
HAT-BC-A
ISO standard
ISO 22301

Modular approach

The core carries into every discipline

The 17 core modules are the same in every auditor track. Completing them here means they are never repeated, never re-assessed and never paid for again, which is what makes a second track short and why most of this one is not about business continuity.

Core modules

Auditor capabilities across disciplines

17 modules · shared by every auditor track

Awarded as the Diploma in Management System Auditing: the credential you keep whichever discipline you specialise in.

A second auditor track is 2–4 modules, not 19

Its specialisation modules, a capstone and an exam, whenever you want them, with no time limit on the core you completed here.

Compare the auditor tracks →

Curriculum

How the modules fit together

Every module is self-contained. There is no fixed order and no schedule: take them in whatever sequence your work makes useful, at whatever pace you can sustain. The grouping below is how we would sequence them if you have no reason to do otherwise.

Core

Shared with every auditor track. Complete them once and they count towards any further qualification in the same role.

Any order
Management system core
HAM-AG-C-07Risk ManagementBuild the capability to surface, structure and act on risk while action is still possible
Audit core
HAM-AG-AC-01Audit PrinciplesApply evidence-based audit reasoning, materiality-focused prioritisation and structured audit test planningHAM-AG-AC-02Audit Communication & InterviewingPlan and conduct effective audit interviews, use structured questioning, and guide conversations to obtain reliable audit evidenceHAM-AG-AC-03Audit Reporting & Follow-upFormulate evidence-based audit findings, structure clear audit reports, and verify the effective closure of agreed actionsHAM-AG-AC-04Audit Programme ManagementDesign and govern risk-informed audit programmes across standards, group structures and programme-level reportingHAM-AG-AC-05Supplier AuditingPlan and conduct supplier audits using contract-based criteria, defined evidence targets and disciplined audit documentationHAM-AG-AC-06Third-Party AuditingNavigate accreditation, the certification ecosystem, the audit lifecycle, impartiality boundaries and certification decision interfaces
Management system auditing core
HAM-AG-A-01Auditing Context & ScopeAssess whether organisational context, interested parties, scope and system boundaries credibly reflect how the organisation operatesHAM-AG-A-02Auditing Leadership & GovernanceAssess whether leadership commitment, policy direction and governance structures credibly steer the management systemHAM-AG-A-03Auditing Risk & Opportunity ManagementAssess whether risk and opportunity management credibly informs organisational decisions and prioritiesHAM-AG-A-04Auditing Documented InformationAssess whether documented information is fit for use, internally consistent and credible as audit evidenceHAM-AG-A-05Auditing Objectives & Performance EvaluationAssess whether objectives and KPIs credibly measure and steer organisational performanceHAM-AG-A-06Auditing Operational ControlAssess whether operational controls and process interactions work reliably in day-to-day practiceHAM-AG-A-07Auditing Supplier & Outsourcing ManagementAssess whether supplier and outsourced process controls manage risk effectively and achieve intended outcomes across organisational boundariesHAM-AG-A-08Auditing Internal Audit & AssuranceAssess whether internal audit and related assurance mechanisms cover risk credibly and provide meaningful assuranceHAM-AG-A-09Auditing Management ReviewAssess whether management review credibly steers organisational priorities, risks and improvementHAM-AG-A-10Auditing Improvement ManagementAssess whether corrective action addresses nonconformities effectively and whether continual improvement strengthens performance beyond nonconformity response

ISO 22301 Auditing

These modules carry the same audit work into ISO 22301. The method does not change; the material does. What counts as evidence, which controls are worth sampling and where a system of this kind usually fails are specific to the standard. The aim is an audit of the system as it operates, not of the system as it is documented.

Any order

The capstone engagement

Practical application of the acquired auditing competencies

Demonstrates ability to audit a BCMS according to ISO 22301 in a real-world scenario

Based on case proposed by the candidate or provided by Halderstone

The final examination

Confirms solid and actionable understanding of business continuity management principles an d ability to audit a BCMS based on ISO 22301

Covers all core and specialization modules of the track

Method

How you learn it

Two things separate knowing a standard from being able to audit a management system against it: what is trained, and what it is trained on.

Practical reflexes, not topics covered

Every module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next review, the next escalation and the next signature. Each one is developed in the written module, practised on the case organisation’s own material, and assessed in graded exercises that must be passed before the certificate is issued.

Three examples from this track’s modules:

Real ownership and escalation

Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.

Residual exposure and explicit acceptance

See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.

Risk criteria and acceptance authority

Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.

Trained on one organisation

Exercises run on Northstar Integrated Services AG, a Zurich company that provides digital operations platforms and managed operational services to organisations in healthcare, the public sector, industry and energy.

One organisation, carried across modules

Northstar has a management system with the wear of a real one. Authority is not always where the org chart puts it. The founder stepped off the board years ago and teams still seek his signal on the calls that matter. The decision log he kept personally faded out during a growth phase and nothing replaced it. You work that organisation rather than a tidy example, and the exercises are marked on what you did with it.

It has a timeline
Governance changes as the company grows, suppliers move through their lifecycle, and modules travel into earlier windows as well as later ones

Nothing resets between modules
The state you leave the organisation in is the state the next module finds it in

Why it matters

Judgement cannot be trained on tidy examples, and it cannot be trained on a fresh one each week. Because the modules work the same organisation, they compound into one continuous engagement rather than a series of disconnected courses.

How we teach →

Related track

The same discipline, the other role

The same discipline is taught from the manager’s side as well. That track rests on a different core and carries its own specialisation modules, capstone and examination, so the two qualifications are earned separately.

Track price

CHF 7,500

19 modules, the capstone and the examination

Getting it signed off

Most people pay for this from a training budget. This page is written to be forwarded to whoever approves it: what the qualification covers, what it costs and what it changes in the role are all on it. If your approver needs something the page does not answer, ask us.

Not sure this is the one?

Start with a single module and have it credited in full later. If the work is running and improving your own management system rather than assessing other people’s, the manager track is the one. Tell us the situation and we will say which, honestly.

Browse the modules →

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this track is the right one, or point you at a better fit.
About ISO 22301 Auditor Track · HAT-BC-A

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.