Business Continuity Management System Consultants in Dubai, Abu Dhabi & Saudi Arabia
Nathan ISO Consulting builds and certifies ISO 22301:2019 Business Continuity Management Systems for financial institutions, data centres, logistics operators, healthcare providers and critical infrastructure suppliers across the UAE, Saudi Arabia and the wider GCC.
A fire in a Ras Al Khaimah warehouse. A ransomware attack locking a Dubai logistics company out of its booking system for four days. A supplier collapse leaving an Abu Dhabi contractor without critical material mid-project. Regional flooding closing roads and stranding staff. None of these wait for a convenient time, and none of them are rare anymore. ISO 22301 exists for the moment operations stop and someone has to decide, in real time, what happens next.
What Is ISO 22301:2019?
ISO 22301:2019 is the international standard for Business Continuity Management Systems. It specifies requirements for planning, establishing, operating and improving a documented capability to respond to disruption and resume critical activities within defined timeframes.
It follows the Annex SL high-level structure shared with ISO 9001, ISO 14001, ISO 45001 and ISO 27001, so organisations already certified to any of those recognise the shape immediately. What is specific to ISO 22301 sits in three technical clauses that most organisations have never formally addressed.
| Requirement | What it asks | Common gap |
|---|---|---|
| Business impact analysis (8.2) | Impact of disruption over time per activity, with maximum tolerable period of disruption, recovery time objectives and minimum resources | Recovery times declared by wishful thinking rather than tested evidence |
| Risk assessment (8.2) | What could cause an activity to stop — fire, flood, cyber, supplier failure, utility outage, pandemic, civil disruption | Regional extreme weather risk omitted despite recent flooding history |
| Continuity strategies and plans (8.3, 8.4) | Documented response, communication and recovery plans naming people, not just roles | Plans assume the usual decision-maker is available, with no named deputy |
| Exercising and testing (8.5) | Periodic exercising of continuity procedures with documented results and lessons learned | Plans never exercised, so gaps surface during a real incident instead |
| Performance evaluation (9) | Monitoring, internal audit and management review of the BCMS | Plans reviewed only when the auditor is due |
These are distinct and auditors examine them separately. The BIA asks what happens, and how badly, if a given activity stops — regardless of cause. The risk assessment asks what could cause it to stop. Both are required, both inform each other, and organisations that conflate them typically produce a document that satisfies neither requirement properly.
The BIA process also forces some uncomfortable but valuable conversations. Most organisations initially claim more of their operation is critical than survives scrutiny, and working through the impact-over-time analysis is what separates genuinely time-critical activities from those that could pause for a week without material consequence.
Clause 8.5 requires the organisation to exercise and test its continuity procedures periodically, and this is where paper-only programmes get exposed. A plan that has never been exercised is a hypothesis, not a capability. We have sat in more than one post-incident review where a well-written recovery plan named a server decommissioned two years earlier, or listed an emergency contact who had left the company.
| Exercise type | What it tests | Typical frequency |
|---|---|---|
| Tabletop walkthrough | Plan logic, decision authority, communication chain | Annually, per critical plan |
| Call tree / notification test | Whether emergency contact details actually work | Quarterly to semi-annually |
| Partial simulation | A specific recovery procedure such as IT failover or site relocation | Annually for critical systems |
| Full-scale exercise | End-to-end recovery under realistic conditions | Every one to three years, risk-based |
Why ISO 22301 Certification Matters in the UAE and GCC
The Central Bank of the UAE and equivalent regional regulators expect licensed institutions to maintain a tested business continuity capability as part of operational resilience supervision. ISO 22301 is the most widely accepted way of demonstrating that capability in a structured, auditable form. In Saudi Arabia, SAMA-regulated institutions face comparable expectations, and organisations licensed in DIFC, ADGM, the Qatar Financial Centre or under the Central Bank of Bahrain encounter similar supervisory interest.
Business continuity is increasingly listed as a pre-qualification item for critical infrastructure, utilities, healthcare, telecoms and logistics contracts across the region. For organisations delivering services classified as critical national infrastructure, an uncertified continuity capability is a growing competitive disadvantage.
Large enterprises now write continuity clauses into vendor contracts, particularly where the supplier represents a single point of failure — a sole-source component manufacturer, a managed IT provider, a facilities contractor running a critical site. Recovery time objectives are increasingly contractual commitments rather than internal aspirations.
Insurers underwriting business interruption cover increasingly ask about certified continuity programmes before quoting favourable terms, because a faster operational recovery directly reduces the claim. Insurance addresses financial consequence after a loss; a BCMS addresses whether you actually recover operationally, and how fast.
The BIA process routinely surfaces dependencies that had nothing to do with disaster planning — a sole-source supplier nobody flagged as a risk, institutional knowledge living in one person’s head, a system with no documented recovery procedure. Several clients have told us the BIA interviews alone justified the project, independent of the certificate.
Nathan ISO Consulting’s ISO 22301 Services
We define which sites, activities and services are in scope, and identify interested parties and their continuity expectations — regulators, key clients, insurers and your own board.
Structured interviews conducted personally with your process owners, not a questionnaire issued for self-completion. The most useful information in a BIA usually emerges from a follow-up question. Output is a defensible set of recovery time objectives, maximum tolerable periods of disruption and minimum resource requirements.
Threats mapped against your actual sites and operations — including regional extreme weather, utility interruption, cyber incident, supplier failure and workforce unavailability — with treatment options assessed against your recovery objectives.
Response, communication and recovery plans written in language your team will actually use under pressure. Plans name people and deputies, define activation triggers, and specify where authority sits if the usual chain of command is unavailable.
Internal and external communication protocols covering staff, clients, regulators, suppliers and media — because reputational damage from a badly handled announcement frequently outlasts the operational disruption itself.
A realistic, risk-based schedule of tabletop, notification, partial and full-scale exercises, sized to your actual criticality profile. We facilitate the first exercises, score them honestly, and document lessons learned.
Everyone named in a plan trained on their role before they are asked to perform it under stress, plus internal auditor qualification for your nominated staff.
Full BCMS internal audit with genuine findings, followed by a properly minuted management review covering every Clause 9.3 input.
Certification body selection, Stage 1 and Stage 2 audit attendance, and nonconformity closure handled by us.
Where ISO 27001 exists, information security incident response and the Annex A control on ICT readiness for business continuity share substantial ground with ISO 22301 — we extend rather than duplicate. Where ISO 45001 exists, emergency preparedness provides a foundation for physical incident response.
Our ISO 22301 Certification Process
Consultation and fixed proposal. Discussion of your services, regulatory exposure, client commitments and deadlines, followed by a fixed written quotation.
Scope and context definition. Sites, activities and services in scope, plus interested party continuity expectations.
Business impact analysis. Process owner interviews establishing recovery time objectives and minimum resource requirements.
Risk assessment. Threat identification mapped to your sites, with treatment planning.
Strategy selection. Continuity strategies chosen to meet the recovery objectives the BIA established.
Plan development. Response, communication and recovery plans naming people and deputies, with defined activation triggers.
Exercise programme design. Risk-based schedule established, with the first tabletop exercise facilitated by us.
Awareness and training. Role-based training for everyone named in a plan, plus internal auditor qualification.
Internal audit. Full BCMS audit with genuine findings and verified corrective action.
Management review. Structured review covering every required input, properly minuted.
Stage 1 and Stage 2 audits. Documentation review then full implementation audit, with our consultant on site.
Certification and surveillance support. Nonconformity closure, certificate issue and ongoing support across the three-year cycle.
Why Choose Nathan ISO Consulting
BIA interviews conducted personally. Not a self-completion questionnaire. The follow-up question is where the useful information lives.
Plans designed to survive a real incident. Built around your actual recovery objectives, supplier dependencies and staffing gaps, not a generic industry template.
Exercise programmes you can realistically run. Sized to your risk profile rather than copied from a much larger organisation’s programme.
Regulatory awareness. Familiarity with Central Bank of the UAE operational resilience expectations, SAMA requirements in Saudi Arabia, and DIFC, ADGM and QFC supervisory contexts.
One dedicated lead consultant throughout. Continuity from scoping through surveillance audits.
Integration with existing certifications. Where ISO 27001 or ISO 45001 exist, we extend rather than build a parallel structure.
Honest exercise scoring. An exercise that everyone passes taught you nothing. We score realistically and document what actually needs fixing.
Full audit attendance. On site for Stage 1 and Stage 2, managing auditor liaison and findings.
Fixed written pricing. Agreed upfront with audit attendance included.
Independent of certification bodies. Certification is issued independently under ISO/IEC 17021, which is what makes it credible to regulators and clients.
Industries We Serve
Banking, insurance and payment providers. Regulatory continuity expectations, payment system resilience and customer-facing service recovery.
Data centres, cloud and managed service providers. Client-contracted recovery time objectives, failover capability and multi-tenant continuity assurance.
Logistics, freight and supply chain. Node disruption cascading across client networks, warehouse and fleet continuity, customs and port dependency.
Healthcare providers. Continuity of care, clinical system availability, critical supply and pharmaceutical chain resilience.
Manufacturing with single-site production. Facility loss recovery, equipment redundancy and alternative production arrangements.
Telecoms and utilities. Network resilience, distributed asset recovery and critical national infrastructure obligations.
Government and semi-government entities. Public service continuity and critical infrastructure classification requirements.
Oil, gas and petrochemicals. Production interruption, supply chain disruption and emergency response integration with client facilities.
Locations We Serve
ISO 22301 consultants across Dubai — Business Bay, Deira, Jebel Ali, Dubai Investment Park and Dubai South — plus DIFC, DMCC, JAFZA, DAFZA, Dubai Internet City, Dubai Silicon Oasis and Dubai Production City, and organisations under Trakhees and the Dubai Development Authority.
Abu Dhabi city, Mussafah, ICAD, KEZAD, Khalifa Port, Masdar City, Abu Dhabi Global Market (ADGM), Hub71 and Al Ain — including ADNOC group suppliers and government-linked entities.
Sharjah city, Hamriyah Free Zone and SAIF Zone; Ajman and Ajman Free Zone; Ras Al Khaimah, RAKEZ and RAK Maritime City; Umm Al Quwain Free Trade Zone; Fujairah and Fujairah Free Zone.
Riyadh, Jeddah, Dammam, Al Khobar, Dhahran, Jubail, Yanbu, Mecca, Medina and Tabuk — including King Abdullah Economic City, NEOM, SPARK, MODON industrial cities, and SAMA-regulated financial institutions.
Qatar — Doha, Lusail, Ras Laffan, and the Qatar Financial Centre and Qatar Free Zones. Kuwait — Kuwait City, Shuwaikh and Ahmadi. Oman — Muscat, Sohar, Salalah and Duqm. Bahrain — Manama, Seef, Sitra and Bahrain International Investment Park.
What Determines the Cost of ISO 22301 Certification?
Certification body audit fees follow mandatory audit-day tables based on headcount, number of sites and the complexity of the activities within scope. Our consultancy fee is separate and fixed in writing before engagement.
The main cost drivers are the number of critical activities requiring business impact analysis, the number of sites and jurisdictions, the depth of the exercise programme you need, and whether the BCMS is being built standalone or extended from an existing ISO 27001 or ISO 45001 system. Standalone implementations for organisations with no prior management system take longer, since document control and internal audit capability must be built alongside the continuity content.
Get Started with ISO 22301 Certification
For ISO 22301 certification in Dubai, Abu Dhabi, Sharjah, Saudi Arabia, Qatar, Kuwait, Oman or Bahrain, call +971 50 258 5024, email info@nathanisoconsulting.com, or visit our contact page. We start with a business impact analysis workshop run on your own site with your process owners, and provide a fixed written proposal before you commit further.
Frequently Asked Questions About ISO 22301 Certification
No. Disaster recovery, particularly IT disaster recovery, is typically a subset focused on restoring systems. ISO 22301 covers the whole organisation — people, premises, suppliers, communication and reputation — not only technology. A strong DR plan is one input into a BCMS, not a substitute for it.
Yes. The Central Bank of the UAE and equivalent regional regulators expect licensed institutions to maintain a tested business continuity capability as part of operational resilience supervision. ISO 22301 is widely accepted as evidence of that capability, though the regulatory requirement itself sits separately from ISO certification.
The BIA asks what happens, and how badly, if an activity stops — regardless of cause. The risk assessment asks what could cause it to stop. Both are required, they inform each other, and auditors examine them separately.
The standard requires periodic exercising without fixing a frequency — you determine it based on risk and criticality. In practice, an annual tabletop exercise for each critical plan with more frequent notification testing is the baseline we recommend and what certification bodies expect to see evidenced.
Smaller organisations are often more exposed to disruption, not less, because they typically lack redundancy — one site, one key supplier, one system. The standard scales down easily, and the discipline is arguably more valuable for a business with fewer fallback options.
ISO 27001 Annex A includes a control on ICT readiness for business continuity, focused specifically on technology recovery. ISO 22301 is broader and covers the entire organisation. Many clients implement both together, using the ISMS incident response process as the technology-recovery layer inside the wider BCMS.
The standard is scenario-agnostic by design — it requires planning for loss of people, premises, systems, suppliers or utilities regardless of cause. A well-built BCMS covers a pandemic, a flood, a cyberattack and a key-supplier failure using the same underlying strategy structure rather than a separate plan for each named threat.
Three years, with annual surveillance audits. Surveillance typically samples your exercise records and checks that plans reflect organisational changes since the last visit — a static, unexercised BCMS is a common surveillance finding.
Insurance addresses financial consequence after a loss. A BCMS addresses whether you actually recover operationally, and how fast. Insurers increasingly recognise the difference, and several UAE brokers now ask about certified continuity programmes when quoting business interruption cover.
Yes, scope is a deliberate decision. Many organisations start with the most critical service or site and expand over subsequent cycles. What matters is that the scope statement accurately reflects what is covered, since clients and regulators read it closely.
The RTO is the target time within which an activity must be resumed after disruption to avoid unacceptable consequences. It should be derived from the business impact analysis — how quickly impact becomes intolerable — not declared by aspiration. An RTO you have never tested is an assumption, and auditors probe how it was established.
Accountability sits with top management, since continuity strategy involves resource commitment decisions. Coordination typically sits with a risk, compliance, operations or IT leader. What matters is that the coordinator has authority to convene across departments and direct access to leadership.
Not necessarily, but you must assess supplier-related disruption risk and address it. For a critical single-source supplier, that may mean requiring evidence of their continuity arrangements, holding buffer stock, or qualifying an alternative. Supplier continuity is one of the most common gaps we find during BIA work.
Extreme weather is treated like any other disruption source in the risk assessment — flooding, sandstorms, extreme heat affecting outdoor work and equipment, and the road closures and staff access problems that follow. Recent regional flooding events have made this a topic auditors ask about more directly than they did previously.
Look for accreditation from a recognised IAF member — EIAC, ENAS, GAC in Saudi Arabia, UKAS or ANAB — with ISO 22301 in the accreditation scope. We are independent of all certification bodies and will recommend one appropriate to your sector.
Yes. All follow the Annex SL structure, sharing context, leadership, competence, documented information, internal audit and management review. Integration reduces both implementation effort and ongoing audit days through combined certification visits.
The business impact analysis and how recovery objectives were derived, the risk assessment, the plans themselves and whether they name real people, exercise records and lessons learned, incident logs if any incidents occurred, internal audit findings, and management review minutes. Exercise evidence receives particular attention.
No. The standard requires you to have strategies that meet your recovery objectives, and those strategies vary — remote working arrangements, reciprocal agreements, cloud-based systems, third-party recovery services, or simply accepting a longer recovery for less critical activities. A dedicated standby site is one option among several, not a requirement.
Yes, included in our full implementation programmes and available standalone. We also deliver crisis response team training and exercise facilitation training, which are often the more valuable in-house capabilities to retain.
By running the exercise programme, updating plans when people, systems, suppliers or sites change, maintaining contact lists, reviewing the BIA when the business changes materially, and holding management review on schedule. Plans that were accurate at certification and never updated are the most common surveillance finding.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving