Course Introduction
The course focuses on the ISO 22301:2019 Business Continuity Management System (BCMS) standard. Based on business operation resilience building in various industries, it systematically interprets the core clauses, implementation logic and compliance requirements of the system standard to carry out internal auditor job skills training. At the same time, it helps enterprises standardize business continuity management processes, identify and prevent various business interruption risks (such as natural disasters, cyber attacks, supply chain interruptions, epidemics, etc.), formulate scientific business continuity strategies and emergency plans, ensure that core businesses can recover quickly in emergencies, reduce interruption losses, improve enterprise operational resilience and market competitiveness, and achieve sustainable development.
Training Benefits
- Master standard clauses, terminology, PDCA logic, BIA, risk assessment, emergency plans, compliance requirements
- Understand the internal audit process and the coordination between internal audit and management review
- Be able to prepare audit plans, checklists and reports
- Identify nonconformities and propose corrective recommendations
- Conduct risk assessment and business impact analysis
- Formulate business continuity strategies
- Establish awareness of "prevention first, rapid response, continuous improvement"
- Strengthen internal auditor responsibility and professionalism
- Promote senior management support and resource investment
- Improve compliance and risk prevention awareness
Target Participants
- Business continuity, emergency, quality, IT, operations, supply chain and other personnel; internal auditors, management, system promotion heads; personnel related to risk assessment, emergency plans, drill organization and business recovery; practitioners in high-risk, highly regulated, supply chain-dependent industries
Course Outline
- Part 1: Basic cognition
- Origin of the system
- Changes in the 2019 version
- Core terminology (RTO/RPO/BIA, etc.), principles, laws and regulations, common risk types (natural disasters/cyber attacks/supply chain interruptions, etc.)
- Part 2: Interpretation of standard clauses
- Chapter-by-chapter interpretation of Chapters 1-10 (scope, organizational context, leadership, planning, support, operation, evaluation, improvement), combined with multi-industry case analysis (finance/manufacturing/medical/IT)
- Part 3: Theoretical basis of internal audit
- Definition, principles (independence/objectivity/evidence-based), organizational responsibilities, documentation requirements (plan/checklist/report), differences and coordination between internal audit and management review
- Part 4: Internal audit practical process
- Full process: planning → preparation → on-site audit → report → corrective action tracking; checklist preparation techniques, on-site audit techniques, nonconformity determination and grading, report writing
- Part 5: Case analysis and assessment