ISO 22301 Maturity · Business Continuity and Financial Crisis Management
Your continuity arrangements, measured against ISO 22301 and turned into a costed action plan.
10 themes, a 5-level scale. And the action that moves each level to the next.
The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.
ISO 22301 Maturity · Business Continuity and Financial Crisis Management
10 themes, 5-level scale.
Nordhavn Industries
53 / 100
They measure their maturity with Datamensio
An example
This could be your situation.
Take one company as an example: three sites, three spreadsheets, no shared answer.
Nobody can consolidate.
Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.
Three weeks, a single base.
One ISO 22301:2019 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.
Two costs avoided before being committed.
A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.
What it saved them
- 3sites measured on the same base, instead of three questionnaires to reconcile
- 2duplicate actions caught before the spend
- 1committee report, with no manual rework
These figures are an example. They could be yours.
The standard imposes processes. Datamensio says where you stand.
01
The framework is already written
Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.
02
The score lands the same day
Online, by self-assessment link or in interview. Theme by theme, comparable over time.
03
The gap becomes a costed plan
Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.
04
Progress can be demonstrated
Campaign after campaign, against your target and against your own past. That is what your board asks for.
The maturity scale
One level, the next, and the action that links the two.
This mechanism, one level, the level above, and the action that connects them, is what turns a finding into a trajectory.
Are the maximum tolerable periods of disruption for priority activities defined, validated by the business, and consistent with the continuity solutions in place?
- N1
No maximum tolerable period of disruption is defined. Priority activities are not explicitly identified.
- N2
Periods appear in an impact analysis produced by the risk team and not validated by business managers. Their consistency with recovery arrangements is not checked.
- N3
Periods are validated by the business, documented activity by activity and checked against actual recovery capabilities. Identified gaps are tracked.
- N4
Periods are tested during exercises, gaps with recovery capabilities are subject to tracked action plans, and dependencies on critical suppliers are incorporated.
- N5
Periods are reviewed whenever the activity, the information system or the supplier portfolio changes, with a documented history of revisions and their effects on the solutions adopted.
Action to move from Level 2 to Level 3
Run a validation workshop by business area on the impact analysis, have each priority activity owner sign off the maximum tolerable periods of disruption, then check each period against existing recovery capabilities and record the gaps in the action plan presented at the management review.
« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »

Director, CCI 94CCI Île-de-France
« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »

Maja SucekChief Operating Officer, Interreg Danube
Rarely on its own
Frameworks combine. Put several together to cover your business, or have the AI write yours.
Take your first measurementon ISO 22301.
What this framework covers
ISO 22301 is the international standard for business continuity management. Published in its current version in 2019, it is certifiable by an accredited body. It requires a defined scope, a business impact analysis that identifies priority activities and their maximum tolerable periods of disruption, proportionate continuity strategies and solutions, response and crisis management procedures, an exercising and testing programme, and a management review. In the financial sector, these requirements overlap with DORA, Basel III and supervisory expectations on operational resilience.
In practice, the arrangements are difficult to steer. Documentation almost always exists, but its fidelity to how things actually run is far less certain. Have the maximum tolerable periods of disruption been validated by the business, or set by the risk team? Are dependencies on critical suppliers, market infrastructures and data providers mapped right through the chain? Did the last exercise produce corrected findings, or a filed report? These questions arise entity by entity, and the answers diverge within the same group.
A common confusion is worth clearing up: ISO 22301 is not the IT disaster recovery plan. Technical recovery, covered notably by ISO 27031, is only one component of continuity solutions. The standard covers business activities, their prioritisation, degraded operating modes and crisis management. In banking and insurance, DORA has shifted the goalposts: resilience testing, oversight of critical ICT third-party providers and incident reporting are becoming binding, and a mature ISO 22301 system provides a reusable foundation.
The maturity assessment answers a different question from the certification audit. The audit checks that requirements are present and concludes with a finding of conformity or a gap. The assessment places each practice on a progressive scale and points to the action that moves it up to the next level. Datamensio measures maturity and prepares for the audit, it does not issue any certificate. The score per theme is comparable across business units and over time, and the gap with the target generates the action plan.
The framework is ready to use and adapts to your organisation. AI adjusts the themes, questions and levels to your sector and scope, or builds a variant from your own documents: continuity policy, impact analyses, exercise reports. The models used can be selected, including from European solutions.
Reference standard: ISO 22301:2019
The themes assessed
Governance and continuity policy
Formalised and approved policy, scope of the management system, roles and responsibilities, management involvement, resources allocated.
Business impact analysis
Identification of priority activities, maximum tolerable periods of disruption, recovery objectives, validation by the business, update frequency.
Assessment of disruption risks
Scenarios selected, assessment of likelihood and impact, links with the operational risk framework, incorporation of past incidents.
Dependencies and critical suppliers
Mapping of internal and external dependencies, market infrastructures, data providers, contractual continuity clauses, exit plans.
Continuity strategies and solutions
Options chosen per priority activity, degraded operating modes, backup sites and resources, system redundancy, fit with recovery objectives.
Response procedures and crisis management
Alert and escalation arrangements, crisis unit and decision mandates, documented procedures, continuity of leadership, internal and external communication.
Communication with stakeholders
Informing customers, regulators and counterparties, incident notification within regulatory deadlines, coordination with suppliers.
Exercising and testing programme
Types and realism of exercises, coverage of priority activities and suppliers, involvement of senior management, handling of findings.
Performance and monitoring
Continuity indicators, permanent controls, internal audits, management review, follow-up of gaps through to closure.
Continual improvement and lessons learned
Analysis of real disruptions, updates to impact analyses and procedures, comparison of results over time, maturity of the arrangements themselves.
A short version of the framework is available for the online self-assessment.
Frequently asked questions
Is ISO 22301 certifiable, and does Datamensio issue the certification?
The standard is certifiable by an accredited body. Datamensio does not certify: it measures the maturity of the arrangements, documents the gaps and produces the action plan that prepares for the certification audit.
What is the difference between this assessment and a compliance audit?
The audit checks that requirements are present and concludes with a finding of conformity or a gap. The assessment places each practice on a maturity scale and points to the action that moves it up to the next level. The two are complementary: the assessment prepares, the audit validates.
How long does the assessment take?
A self-assessment run by the continuity manager can be conducted in a single working session. In collaborative mode, involving the business, IT and procurement, data collection spans one to two weeks, with most of the time spent on discussions with contributors.
Can the framework be adapted to our organisation?
Yes. The themes, questions and levels can be modified, and you can add your own internal requirements. AI adjusts the framework to your sector or builds a variant from your continuity documents.
How does this assessment fit with DORA and supervisory expectations?
DORA embodies converging principles: critical activities, resilience testing, supplier oversight, incident notification. An ISO 22301 assessment provides a reusable foundation. A cross-cutting roadmap allows several audits to be consolidated without duplicating actions.
Do respondents need technical expertise?
The questions cover continuity management practices, not technical configurations. Some points relate to IT disaster recovery or supplier contracts: collaborative mode allows these questions to be assigned to the right contributor.
Can results be compared across entities?
Yes. Assessments run on the same framework can be compared across business units, across countries and against your own past assessments. AI groups the gaps into a prioritised roadmap, with cost, timeline and expected impact on the score.
Where is the data hosted?
In France, with OVH, backed up with Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European solutions.




