Australia does disruption on a scale that surprises people who have not worked here. Flood, cyclone and bushfire arrive on a seasonal cycle rather than as freak events. Supply chains run down single highways for thousands of kilometres. A telecommunications outage or a faulty software update can take out payment systems across the country in an afternoon.
ISO 22301:2019 is the international standard for business continuity management systems. It asks you to work out which of your operations genuinely cannot stop, how long they can be interrupted before the consequences become unacceptable, and what you will actually do when that happens. Then it asks you to test it.
Nathan ISO Consulting builds business continuity management systems for Australian organisations, with particular focus on those carrying regulatory obligations under APRA CPS 230 or the Security of Critical Infrastructure Act.
What a BCMS produces, in the language auditors and regulators use
| Term | What it means | Why it matters |
|---|---|---|
| Business impact analysis (BIA) | Structured assessment of which activities support your most important products and services, and the consequences of interrupting them | Everything else in the system derives from it. A weak BIA produces a plan that protects the wrong things |
| Maximum tolerable period of disruption (MTPD) | The point beyond which interruption causes unacceptable harm | Sets the outer boundary for every recovery target you set |
| Recovery time objective (RTO) | The target time to resume an activity after disruption | Must sit inside the MTPD, and must be achievable with resources you actually have |
| Recovery point objective (RPO) | The maximum data loss you can tolerate, expressed as time | Drives backup frequency and replication design, and is where IT and business assumptions most often diverge |
| Minimum business continuity objective (MBCO) | The reduced level of service you must sustain during disruption | Turns continuity from all-or-nothing into something operationally realistic |
APRA CPS 230 is the strongest driver in the Australian market
CPS 230 commenced on 1 July 2025 for APRA-regulated entities, with a twelve-month extension for non-significant financial institutions on the business continuity and scenario analysis elements. It requires regulated entities to manage operational risk, maintain critical operations through severe disruption, and manage the risks arising from service providers.
The standard does not name ISO 22301. It does, however, ask for exactly the things a BCMS produces, and it flows down to material service providers who are not themselves regulated entities. A lot of technology vendors have discovered CPS 230 obligations arriving through a customer contract rather than a regulator.
| CPS 230 requirement | Where ISO 22301 delivers it |
|---|---|
| Identify critical operations | Business impact analysis, Clause 8.2 |
| Set tolerance levels for disruption | MTPD and RTO determination, Clause 8.2 |
| Maintain a credible business continuity plan | Continuity strategies and plans, Clauses 8.3 and 8.4 |
| Systematic testing including an annual exercise | Exercising and testing program, Clause 8.5 |
| Board oversight and clear senior accountability | Leadership and governance, Clause 5 |
| Manage material service provider risk | Supply chain continuity requirements within Clauses 8.2 and 8.3 |
| Incident escalation and notification | Incident response structure, Clause 8.4 |
| Review and continual improvement | Performance evaluation and improvement, Clauses 9 and 10 |
Mapping is not equivalence. CPS 230 imposes obligations ISO 22301 does not cover, including specific service provider register and notification requirements. We build the BCMS so it satisfies the standard and evidences the prudential requirement in the same set of records.
Critical infrastructure and the SOCI Act
The Security of Critical Infrastructure Act 2018 requires responsible entities in declared sectors to maintain a critical infrastructure risk management program covering all hazards that could affect the availability of the asset. Declared sectors span energy, water, transport, communications, health care, data storage and processing, food and grocery, financial services and defence industry.
All hazards means what it says. Cyber is one hazard category among several, sitting alongside physical, personnel and supply chain hazards, plus natural events. A business continuity management system is the operational machinery behind the availability side of that program, and organisations that already run one find the CIRMP obligation considerably less daunting.
Australia's disruption profile is regional, and your plan should be too
A continuity plan written in a Sydney head office and applied unchanged to a Cairns depot is not a plan. The hazards differ, the recovery timeframes differ, and the practical constraints differ enormously.
| Region | Dominant disruption exposure | What that means for the BCMS |
|---|---|---|
| Sydney and Melbourne | Concentration risk in financial services, data centres and transport nodes; cyber and third-party outage | CPS 230 driven; heavy focus on service provider dependency mapping |
| Brisbane, Gold Coast, Sunshine Coast | Flooding, severe storms, occasional cyclone reach | Seasonal readiness cycles; site relocation and staff access planning |
| Cairns, Townsville, Darwin | Cyclone season, storm surge, extended isolation | Pre-season activation triggers; realistic MTPDs that account for access delays |
| Perth, Pilbara, Goldfields | Extreme remoteness, single-route supply chains, heat, fire | Stock and spares strategy; recovery targets that reflect travel realities |
| Regional NSW, Victoria, South Australia | Bushfire, flood, extended power interruption | Manual workaround procedures; communication when networks are down |
| Canberra | Government service continuity, cyber, smoke and air quality events | PSPF interaction; continuity of services to agencies |
| Tasmania | Storm, power interruption, freight dependency across Bass Strait | Freight contingency and inventory buffers |
| Nationwide | Telecommunications outage, cloud provider failure, software update failure, cyber incident | Third-party dependency register; scenarios that assume your provider, not you, is the point of failure |
The exercise program most organisations skip
More than any other management system standard, ISO 22301 is undone by documentation that has never been tested. A plan nobody has rehearsed is a hypothesis.
Clause 8.5 requires an exercising and testing program, and CPS 230 goes further by requiring an annual business continuity exercise covering critical operations under severe but plausible scenarios. That word plausible does a lot of work. A scenario in which everything fails at once teaches nothing. A scenario in which your primary cloud region is unavailable for eleven hours during end-of-month processing teaches a great deal.
We design and facilitate exercises, and we write them so they surface problems rather than confirming that the plan reads well. The measure of a good exercise is the length of the findings list.
How Nathan ISO Consulting assists
Why organisations choose Nathan
| Common approach | Our approach |
|---|---|
| A BIA run as a survey emailed to department heads | A facilitated BIA where dependencies get argued about in the room, because that is where the real answers surface |
| Recovery objectives set by the business and never checked against IT capability | RTOs and RPOs tested against what your infrastructure can actually deliver before they are signed off |
| One continuity plan applied nationally | Plans that reflect regional hazard exposure, because cyclone season in Cairns is not a Sydney risk register entry |
| Exercises designed to be passed | Exercises designed to find problems, measured by the length of the findings list |
| CPS 230 and ISO 22301 run as two separate projects | One system, one set of evidence, satisfying both the standard and the prudential requirement |
| Third-party risk treated as a procurement issue | Service provider dependency mapped into the BCMS, with scenarios where the provider fails and you do not |
| A plan delivered and never revisited | Annual exercise cycles and BIA refresh, because dependencies change faster than documents do |
Sectors and locations we serve
Business continuity work needs presence at the sites that carry the risk. We attend those, run workshops and exercises in person where it materially improves the outcome, and deliver the rest remotely.
| Sector | Where we typically work |
|---|---|
| Banking, insurance and superannuation | Sydney, Melbourne, Brisbane, Perth — CPS 230 driven |
| Energy, water and utilities | Perth, Brisbane, Gladstone, Newcastle, Latrobe Valley, Adelaide, Darwin |
| Transport, ports and logistics | Sydney, Melbourne, Brisbane, Fremantle, Port Hedland, Townsville, Darwin |
| Health and aged care | All capital cities and major regional centres |
| Telecommunications and data centres | Sydney, Melbourne, Canberra, Brisbane, Perth |
| Government and government suppliers | Canberra, and state capitals |
| Manufacturing and food processing | Melbourne, Geelong, Shepparton, Toowoomba, Adelaide, Bendigo |
| Mining and resources | Perth, Karratha, Port Hedland, Kalgoorlie, Mackay, Mount Isa, Roxby Downs |
| Professional and financial services | Sydney, Melbourne, Brisbane, Adelaide, Perth, Canberra, Hobart |
FAQ'S
No. There is no legal requirement to certify. It becomes a practical requirement when it appears in tender prequalification criteria, which is increasingly common in civil construction, infrastructure and government contracts, or when a head contractor requires it of subcontractors.
Not automatically. ISO 14001 requires you to identify your compliance obligations and evaluate performance against them, which makes compliance far more likely and much easier to demonstrate. The legal obligations themselves sit with your state environmental legislation, not the standard.
It is a proactive duty under Victoria's Environment Protection Act 2017 to eliminate or minimise risks of environmental harm so far as reasonably practicable. It applies to any Victorian operation regardless of whether you hold a permit, and EPA Victoria can act without a pollution event occurring.
They are separate obligations. NGER and the Safeguard Mechanism are Commonwealth schemes with their own thresholds. An ISO 14001 system provides the data collection discipline and operational control that makes those obligations far easier to meet accurately.
All states and territories. We work across Sydney, Melbourne, Brisbane, Perth, Adelaide, Canberra, Hobart and Darwin, and through industrial regional centres including Gladstone, Kwinana, the Hunter Valley, the Latrobe Valley, Kalgoorlie and Port Hedland.
Yes, and it usually should be. The three standards share a common high-level structure, so a single integrated system with combined audits means one set of internal audits and one management review instead of three separate cycles.
Generally 12 to 20 weeks. The aspects and impacts assessment takes real time to do properly, and you need operational records plus one internal audit and management review cycle before a Stage 2 audit can proceed.
Sometimes. Contaminated land, complex licence conditions, and air, noise or water monitoring sit outside management system consultancy. We will tell you where that line falls rather than quoting for work we should not be doing.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving