ExSolution

Home / Insights / Business continuity: the decisions you make before the disruption

ContinuityGuide

Business continuity: the decisions you make before the disruption

Continuity planning is not a document exercise. It is a set of decisions about what must keep running, who decides during a disruption, and what you are willing to lose, taken in advance because they cannot be taken well under pressure.

In brief

A continuity plan is only useful if it answers four questions before anyone needs to ask them: what cannot stop, who takes charge, how people are told, and what returning to normal actually means.

ISO 22301 gives that work a recognised structure. It does not, by itself, make an organisation resilient. A certificate records that a system met the standard at the time of audit, not that the system will hold when tested.

The decisions, not the document

Most continuity work fails at the same point: the plan describes a response nobody has authority to execute, or protects activities nobody agreed were the priority. The plan is only the record of those decisions; making them is the actual work.

Four of them have to be made in advance.

What cannot stop

Not everything the organisation does is equally urgent, and treating it as though it were produces a plan that protects nothing in particular. The question is which activities, if interrupted, would cause consequences you cannot accept, whether contractual, regulatory, financial or to people, and how long you could sustain the interruption before those consequences arrive.

Who decides during a disruption

Decision rights that work in normal conditions frequently do not survive a disruption, because the people who hold them are unreachable, affected, or waiting for information that is not coming. Naming who takes charge, what they may commit without further approval, and who deputises when they are unavailable is a governance decision, not a planning detail.

How people are told

Staff, customers, suppliers and, where relevant, a regulator all need to hear something, and usually before the picture is complete. Deciding in advance who says what, through which channel, and who approves it prevents the silence that gets filled by other people's assumptions.

What recovery means

Resuming an activity is not the same as returning to normal, and organisations that have not defined the difference tend to declare victory early. Recovery should be defined as a state you can recognise, with a named person able to confirm it has been reached.

What this means for your organisation

If those four decisions are not documented and agreed, the plan is a description of intent. Testing exposes this faster than reviewing does, which is why an exercise programme, not an annual document review, is what tells you whether the capability is real.

Where ISO 22301 and NCEMA 7000 fit

ISO 22301 is the international standard for business continuity management systems.1 It provides structure: impact analysis, strategy, plans, exercises, internal audit and management review, operating as a cycle rather than a project.

NCEMA 7000 is a UAE national standard. Its application depends on the organisation's mandate, supervising authority and contractual obligations rather than the emirate in which an office is registered. It applies to UAE federal and government entities, and may extend through government or contractual requirements to suppliers, contractors and partners.

The two standards are aligned, not equivalent: they share structure and intent, but each contains requirements the other does not. ISO 22301 certification alone does not satisfy NCEMA 7000. Where both apply, the practical answer is one management system architected to produce the evidence both require, rather than two parallel programmes repeating the same analysis. Compare the two frameworks in detail.

What certification does and does not tell you

A certificate is evidence that an accredited certification body examined the management system against the standard and decided to issue it. That is worth having, and many tenders and customers require it.

It is not evidence that the organisation will recover well. It records conformity at a point in time. Whether the capability holds depends on things a certificate cannot capture: whether exercises are realistic, whether the people named in the plan still hold those roles, and whether anything material has changed since the last review.

ExSolution builds continuity capability and prepares organisations for audit. We do not issue certificates and we do not guarantee the outcome of an independent audit.

Where to start, if nothing exists yet

The first version does not need to be complete. It needs to exist and to be owned.

  • List the activities whose interruption would cause consequences you cannot accept, and how long you could sustain each interruption.
  • Name who takes charge, and who deputises.
  • Hold current contact details for key staff, suppliers and customers somewhere reachable when your systems are not.
  • Confirm that backups exist, and that someone has restored from them recently rather than assuming they would work.
  • Walk one scenario through with the people who would actually handle it, and write down what you learned.

Review it against changed circumstances rather than on a calendar alone: new activities, new dependencies, new obligations, people who have moved on.

Sources and references

All accessed 4 August 2026.

  1. International Organization for Standardization, ISO 22301, Security and resilience — Business continuity management systems — Requirements.
  2. NCEMA 7000 applicability as recorded in ExSolution's verified regulatory register and stated on the business continuity service page. Application follows mandate, supervising authority and contractual obligation, not the emirate of registration.

Read next

If a continuity obligation has landed and the scope is not yet clear, that is the conversation worth having first.

Discuss a continuity requirement