Business Continuity Policy Template (ISO 22301 + DORA + ISO 27001)

UK Business Continuity policy template aligned to ISO 22301, ISO 27001:2022 Annex A 5.29-30, UK Operational Resilience and EU DORA. RTO/RPO with tested DR plan.

Single policy template

£49.99

One-off purchase · lifetime access · no renewal

Get this template — £49.99

Or save with the ISO 27001 Core Set (16 policies for £400)

What is the Business Continuity (BCP) Policy?

Quick answer. UK Business Continuity policy template aligned to ISO 22301, ISO 27001:2022 Annex A 5.29-30, UK Operational Resilience and EU DORA. RTO/RPO with tested DR plan. Single document satisfies ISO 22301, ISO 27001 Annex A.5.29-30, UK FCA SYSC 15A and EU DORA Article 11.

The Business Continuity (BCP) Policy is one of 988 single-policy templates available on PolicySuite. Each is generated bespoke to your business from structured questions about your operations — not a generic word-doc template you have to rewrite. Buy this single policy at £49.99, or get the complete ISO 27001 Core Set (16 policies for £400) if you need the surrounding policies too.

What’s included in the template

  • Business impact analysis methodology
  • Recovery Time Objectives + Recovery Point Objectives by service
  • DR plan + tested-restore evidence requirement
  • Crisis-management roles + decision authority matrix
  • Customer + regulator communications playbooks
  • Supplier & sub-processor BC dependencies
  • Annual exercise programme (tabletop, walkthrough, full-scale)
  • Lessons-learned + management review loop

Statutory and framework references

The template is drafted with explicit citations to the following anchors so your auditor, tribunal or ICO inspector can verify alignment. Every reference resolves to a primary-source link — legislation.gov.uk for UK statute, iso.org for ISO standards, ico.org.uk for ICO codes, acas.org.uk for ACAS Codes, and legislation.gov.uk for UK Acts and Regulations.

  • ISO 22301:2019 (BCMS)
  • ISO 27001:2022 Annex A 5.29-5.30
  • EU DORA Article 11 (BCP)
  • FCA SYSC 15A (UK Operational Resilience)
  • Civil Contingencies Act 2004 (where applicable)

Why this policy matters

In 2024 alone, UK regulators and tribunals continued to test the documentation behind ISO 22301:2019 (BCMS). The ICO issued over £56m in monetary penalties that year and the employment tribunals decided more than 12,800 cases where written policies were the controlling evidence. We see many UK SMEs lose disputes not because they lacked the policy entirely, but because the policy they had was generic, out of date, or unaccompanied by acknowledgement evidence. In our experience, a bespoke Business Continuity (BCP) Policy sized to your business is the cheapest single line of defence against that outcome.

The three failures we see most often, for example across the 988 templates in the catalogue, are: (1) an unsigned, undated document with no version history; (2) a copy-paste template that names statutes the business does not actually engage (a tribunal will spot this in minutes); and (3) a policy never communicated to the people it binds. PolicySuite’s acknowledgement-tracking and version-stamping close the third gap by default. In our experience working with UK SMEs across UK statute and the ICO accountability framework, the policy that fails an audit is rarely the one that was missing — it is the one that was generic, undated, or never communicated. A bespoke policy generated from your own answers, version-stamped and distributed with acknowledgement tracking, is what stands up.

How PolicySuite generates this template for you

Buying the £49.99 single policy unlocks PolicySuite’s structured-question flow for the Business Continuity (BCP) Policy. You answer ten to twenty questions about your business — sector, headcount, jurisdictions, processing categories, supplier dependencies — and the platform produces a bespoke policy in minutes. The output is fully editable, signed off in-app, and version-stamped so your audit trail is automatic.

Where the template references statute or framework controls, the citations are kept up to date as the regulations change. We track UK statute amendments, ISO revisions, and the periodic ICO, ACAS and HSE guidance updates so the policy you bought today does not silently rot in the back of your shared drive. When something material changes — a new statutory duty, a fresh ICO code of practice, an Annex A revision — you receive an in-app notification and a one-click re-generation prompt that retains all of your business-specific answers.

Single policy versus the full pack

A single £49.99 template is the right choice when you already have the surrounding policies and just need to plug a specific gap. If you need the complete framework set, the ISO 27001 Core Set (16 policies for £400) bundles the related policies at a lower per-policy cost, with a pack-level audit-mapping table included.

Further reading

Read the in-depth Business Continuity library page for context on why the policy matters and what auditors and tribunals look for. The framework pages ISO 27001, DORA explain how this policy fits the wider compliance picture.