On this page
- Quick Reference (60 Seconds)
- What the Standard Actually Requires
- Why This Control Matters
- Scope and Applicability
- Key Definitions and Terminology
- Relationship to Other Clauses and Frameworks
- Detailed Implementation Guidance, The Nine Accountability Moves
- Tools, Technologies, and Solutions
- Policy and Procedure Templates
- Risk Assessment and Treatment
- Audit and Compliance Checklist
- Metrics and KPIs
- Common Pitfalls and Audit Failures
- Illustrative Scenario 1: Failure, Kaveri Cooperative Bank (Illustrative)
- Illustrative Scenario 2: Success, Sarthak Logistics (Illustrative, with ROI)
- Multi-Framework Mapping
- Implementation Roadmap
- FAQ
- Industry-Specific Requirements
- Maturity Model
- Emerging Trends
- References and Further Reading
Quick Reference (60 Seconds)
| Attribute | Detail |
|---|---|
| Clause | ISO 22301:2019 Clause 5.1, Leadership and Commitment (the top-management accountability clause, structurally aligned to ISO/IEC 27001:2022 Clause 5.1, ISO 9001:2015 Clause 5.1, and the Harmonized Structure used across every ISO management-system standard) |
| What it asks for (paraphrase) | ISO 22301 Clause 5.1 asks organizations to have top management visibly lead the BCMS, integrating it into business processes, resourcing it, and driving its results. Visible leadership is the operative phrase: the standard tests what top management demonstrably does, not what has been delegated. |
| Domain | Leadership (Clause 5). Clause 5.1 sits at the apex of the BCMS, it does not run a process; it produces the conditions under which every other clause's process can run. 5.1 is the clause that converts board-level intention into management-system reality. |
| What you must produce | (a) A BCM Leadership Charter (or top-management sponsorship instrument) that names the executive sponsor, the BCM Steering Committee, the decision rights, and the resourcing commitment; (b) documented evidence of top-management accountability moves, approval of the BCMS Policy (Clause 5.2), approval of scope (Clause 4.3), approval of objectives (Clause 6.2), chairing or sponsoring the BCM Steering Committee, attending the management review (Clause 9.3), and directing the corrective-action programme (Clause 10.1); (c) a sponsorship RACI that assigns top-management accountability for each Clause 5 to 10 outcome; (d) an integration map showing where BCMS requirements are wired into business processes (capital planning, vendor management, HR onboarding, project gating, risk reporting, audit cycles); (e) a board / Risk Committee reporting cadence with the BCM dashboard, the agenda items, and the decision minutes; (f) a leadership-evidence file indexed to the nine accountability moves auditors test against; (g) the resource-allocation record, budgets, headcount, tooling, training spend, approved by top management for the BCMS. |
| Typical owner | Top management, the person or group who directs and controls the organisation at the highest level. For most Indian growing companies this is the Managing Director / CEO, the COO, the CRO or the Board itself, working through a designated executive sponsor. Day-to-day stewardship is by the BCM Lead, but 5.1 accountability cannot be delegated away from top management; only the execution of specific tasks can be delegated. |
| Minimum viable actions | (1) Appoint and name the executive sponsor for the BCMS on record; (2) approve the BCM Leadership Charter; (3) approve the BCMS Policy (Clause 5.2) and the scope (Clause 4.3); (4) stand up the BCM Steering Committee with top-management membership; (5) allocate the BCMS budget, headcount and tooling for the current cycle; (6) integrate BCMS checkpoints into at least three existing business processes (commonly: vendor onboarding, project approval, and audit follow-up); (7) set the board / Risk Committee reporting cadence (at minimum a half-yearly BCM report); (8) attend the management review (Clause 9.3) in person; (9) sponsor at least one exercise per cycle (Clause 8.5) with observable top-management participation; (10) approve the corrective-action programme and personally review major nonconformities (Clause 10.1). |
| Maturity floor (L1) | A "leader-endorsed" BCMS, top management signed the policy once, has not seen it since, no resource decisions, no steering committee, no board reporting. The classic decoration. |
| Maturity target (L4 to L5) | A "leader-led" BCMS, top management owns the resilience narrative in board communications, the BCM Steering Committee meets monthly with CXO attendance, the BCMS dashboard is on the board's standing agenda, the executive sponsor's variable pay is partly tied to BCMS outcomes, BCMS checkpoints are wired into capital allocation and M&A due diligence, and a real disruption triggers an executive war-room that has been rehearsed. |
| Audit red flag | A BCMS where the leadership evidence is one signature on a policy and a single line in a board minute. The 5.1 audit test is always the same: show me the decisions top management has made for the BCMS in the last twelve months. If the answer is "they approved the policy", that is a major nonconformity on Clause 5.1 regardless of how technically excellent the rest of the BCMS is. |
| Quick win | Convert the existing executive committee meeting into the BCM Steering Committee (with BCM as a standing agenda item), schedule a single management review (Clause 9.3) chaired by the CEO/MD, and produce a one-page leadership-evidence index mapping every Clause 5 to 10 decision to its minute reference. Most growing companies in India can produce this in 4 to 8 weeks at less than 3 lakh rupees of internal effort. It is the single artefact most likely to convert a Stage 1 major nonconformity on 5.1 into a Stage 1 pass. |
| Time to implement (first cycle) | Growing companies (50 to 250 staff): 6 to 10 weeks for the first leadership-architecture pass. Mid-market (250 to 2,000): 8 to 14 weeks, usually requiring board-cycle alignment. Multi-entity enterprise: 3 to 6 months, integrated with board governance cycles, Risk Management Committee cadence (SEBI LODR Reg. 21 for listed entities), and group audit and risk functions. |
| Related clauses | 4.1 (context is what leadership reads), 4.2 (interested parties are whom leadership is accountable to), 4.3 (scope is what leadership approves), 4.4 (BCMS is what leadership brings into existence), 5.2 (policy is leadership's apex statement), 5.3 (roles are how leadership assigns accountability downstream), 6.1 to 6.3 (planning processes leadership directs), 7.1 to 7.5 (support resources leadership allocates), 8.1 to 8.6 (operational processes leadership sponsors), 9.1 to 9.3 (evaluation processes leadership attends), 10.1 to 10.2 (improvement processes leadership commissions). 5.1 is, in effect, the verb that operates every other clause. |
| Critical Indian reporting clocks wired through leadership | CERT-In incident report within 6 hours (CERT-In Directions 20(3)/2022-CERT-In, 28 Apr 2022); DPDP breach notice within 72 hours (DPDP Act 2023 Section 8(6) + DPDP Rules 2025); RBI incident report within 2 to 6 hours (RBI Cyber Security Framework, 2 Jun 2016; RBI MD IT Governance, 7 Nov 2023); SEBI RE incident report within 6 hours (SEBI CSCRF, 20 Aug 2024); IRDAI incident report per IRDAI guidelines (IRDAI ICS 2023, 24 Apr 2023). Leadership is accountable for the existence, resourcing, and rehearsal of the capability that meets these clocks. |
If you only read one thing: Clause 5.1 is where the BCMS stops being an IT or compliance project and becomes an enterprise discipline. A 5.1-conformant BCMS is one in which top management demonstrably directs, resources, integrates, communicates, attends, decides, and improves, not one in which top management has merely authorised someone else to do so. The certification auditor will examine this distinction ruthlessly, and so will a regulator after a real disruption. Get 5.1 wrong, a signature-only sponsorship, and however strong the BIA, the strategy and the plans, the certificate will be at risk and the resilience will fail on the day it is tested. Get it right, and every other clause becomes easier to evidence because the operating cadence carries the proof.
What the Standard Actually Requires
Figure · Process
What Clause 5.1 asks you to do

The paraphrased requirement
ISO 22301 Clause 5.1 asks organizations to have top management visibly lead the BCMS, integrating it into business processes, resourcing it, and driving its results. Visible leadership is the operative phrase: the standard tests what top management demonstrably does, not what has been delegated, authorised, or nominally approved. The requirement is unusually behavioural for a management-system standard, most clauses are satisfied by producing artefacts; Clause 5.1 is satisfied by producing evidence of conduct.
The shape of the requirement is a list of moves top management must make to demonstrate leadership and commitment. Nine are typically enumerated in ISO 22301:2019 Clause 5.1 (the standard's own structure; paraphrased here, never reproduced verbatim):
- Own whether the BCMS actually works. Accountability is personal; it cannot be devolved to the BCM Lead or to a consultancy. The auditor tests for evidence that top management has owned BCMS effectiveness, not merely the existence of a system someone else built.
- See that the BC policy and objectives exist and match strategy. Policy and objectives are the apex BCMS artefacts (Clauses 5.2 and 6.2); top management does not have to draft them, but has to ensure they exist, approve them, and confirm they align with strategy.
- Weave BCMS requirements into how the business already runs. Integration is the single most-tested word in 5.1. A BCMS that runs in parallel to the business, separate objectives, separate cadences, separate reporting, is not integrated. An integrated BCMS has its checkpoints inside vendor onboarding, project approval, capital allocation, HR onboarding, audit cycles, and risk reporting.
- Make the resourcing real. Resourcing is not a statement of support; it is the budget, headcount, tooling, training, and calendar time actually allocated. The auditor tests for the resource decision, not the resource aspiration.
- Tell the organisation, repeatedly, that effective BCM and a conforming BCMS are non-negotiable. Communication is the visible voice of leadership, town halls, board speeches, internal memos, customer and supplier letters, regulator-facing statements. The test is whether the organisation knows that the leadership considers BCM non-negotiable.
- Answer for outcomes, not artefacts. The BCMS exists to enable the organisation to continue prioritised activities during disruptions (Clause 8.2 priorities); leadership is accountable for whether that actually happens.
- Give people the direction and backing to make the BCMS effective. Direction and support run downstream, process owners, functional managers, and individual contributors need leadership air cover, decisions, and removal of obstacles.
- Drive improvement year on year. Improvement (Clauses 10.1 and 10.2) is led from the top. A BCMS that does not improve year on year is one whose leadership has not promoted improvement.
- Back the other managers who must lead in their own domains. 5.1 is not only about the apex; it cascades, functional heads (IT, Operations, HR, Finance, Legal, Compliance) must be supported to lead BCMS-relevant work in their domains.
The nine moves share a structural property: each produces visible, dated, attributable evidence. A leadership move that left no evidence is, for audit purposes, a leadership move that did not happen.
What the standard does NOT require (the demarcation competitors miss)
Clause 5.1 is widely misread as a general exhortation to "be supportive". It is more precise than that. Being explicit about what 5.1 does not require protects against two failure modes: under-investing (treating 5.1 as a signature) and over-reaching (treating 5.1 as a mandate for top management to do the BCM Lead's job).
- 5.1 does not require top management to draft the BCMS Policy. Drafting is a Clause 5.2 activity; 5.1 requires that the policy exists and is consistent with strategic direction. Most policies are drafted by the BCM Lead, reviewed by the executive sponsor, and approved by top management.
- 5.1 does not require top management to perform the BIA. The BIA is a Clause 8.2 activity. 5.1 requires that the BIA happens and that its outputs are used in strategy selection and plan maintenance.
- 5.1 does not require top management to write the BC plans. Plans are Clause 8.4. 5.1 requires that plans exist, are exercised, and are improved.
- 5.1 does not require top management to attend every exercise. It requires observable sponsorship, typically at least one exercise per cycle, plus the management review.
- 5.1 does not require top management to run internal audits. Internal audit (Clause 9.2) is independent; top management ensures the function exists, is resourced, has authority, and reports into the BCM Steering Committee or board committee.
- 5.1 does not require top management to approve every documented-information change. Document control is a Clause 7.5 activity. 5.1 requires approval of the apex artefacts (Policy, Scope, Objectives, Manual); routine document control is delegated.
- 5.1 does not require a specific governance structure. ISO 22301 does not mandate a BCM Steering Committee, a board Risk Committee, or any particular named forum. It requires that the leadership and commitment be demonstrable; the structures used to produce the evidence vary by organisation.
- 5.1 does not require top management to personally appear in every awareness training session. Tone-from-the-top can be a recorded video, a written message, a town hall, or a board-sponsored campaign; the test is whether the workforce has perceived leadership commitment.
- 5.1 does not require variable-pay linkage to BCMS outcomes. Pay linkage is a leading-practice signal of L4 to L5 maturity, not a standard requirement.
- 5.1 does not require a separate "Leadership Committee" or new organisational structure. Most often the cleanest design is to integrate BCMS accountability into the existing executive committee and the existing board Risk Committee, the integration principle in 5.1(a) literally applies to governance structures too.
The companion guidance (ISO 22313:2020 Section 5)
The clause text is short; the method lives in ISO 22313:2020 Section 5 (the clause-by-clause companion) and in the lineage of Harmonized Structure management-system standards. Five external anchors are most relevant for Clause 5.1:
- ISO 22313:2020 Section 5 explains that leadership commitment is demonstrated through visible engagement, allocable decisions, and recurring personal involvement. It emphasises that "top management" is not a generic label, for the BCMS, it is the specific person or group that directs and controls the organisation at the highest level, and that can allocate resources. The auditor identifies top management by name; without that identification, 5.1 cannot be tested.
- ISO/IEC 27001:2022 Clause 5.1 is structurally identical. If your organisation runs an integrated ISMS+BCMS, a single leadership evidence file satisfies both clauses. Indian growing companies commonly pursue both standards concurrently; the leadership pack is the natural point of integration.
- ISO 9001:2015 Clause 5.1 is the same requirement for the QMS. Indian manufacturers running ISO 9001 typically have a strong 5.1 foundation (quality policy, quality objectives, management review) that can be extended to BCMS with marginal incremental effort.
- NIST SP 800-34 Rev 1 Step 1 (develop the contingency planning policy statement) is the US federal analogue, the explicit placement of policy approval and resource allocation as the first step in the seven-step contingency planning process. Step 1 is the leadership clause of NIST's BCM lineage.
- FFIEC BCM Booklet (Nov 2019), the governance principle is the FFIEC's 5.1: board and senior management accountability for BCM as an enterprise discipline, not a technology function.
What auditors actually check
Certification auditors (BSI Group, DNV, SGS, TÜV, Bureau Veritas, NQA, Intertek, plus Indian certification bodies operating under NABCB accreditation) test Clause 5.1 by triangulating four evidence families:
- Identification of top management. Has the organisation identified, by name and role, who "top management" is for the BCMS? In a small company, it is the founder/MD. In a growing firm, it is typically the MD/CEO plus the executive sponsor (COO, CRO or CIO). In a listed entity, it includes the Board and the board Risk Management Committee (SEBI LODR Reg. 21). Without this identification, the auditor cannot test 5.1.
- The leadership-evidence file. Is there an index, typically maintained by the BCM Lead, approved by the executive sponsor, that maps each of the nine accountability moves to its evidence (board minutes, executive committee minutes, budget approvals, signed policies, signed-off objectives, attended management reviews, sponsored exercises, communication records, corrective-action approvals)? The single most common 5.1 finding is the absence of this index; the second most common is an index whose links dead-end at "policy signed".
- The interview. The auditor will interview the executive sponsor and at least one other top-management member. The test is whether they can articulate the BCMS scope, the top three business continuity risks, the current BCMS objectives, the last material exercise outcome, and the last material corrective action. A sponsor who cannot answer these questions cannot be demonstrating leadership; the auditor will record a major nonconformity regardless of the documentation.
- The integration map. The auditor will trace whether BCMS requirements appear inside business processes, typically asking procurement, HR, project management, internal audit and finance teams whether BCMS considerations enter their workflows. If the answer is "BCM is the BCM Lead's job", 5.1 integration has failed.
The audit pressure on 5.1 has hardened sharply over the last three years. The 2019 edition of ISO 22301 is more explicit than the 2012 edition; Harmonized Structure standards across the board (27001:2022, 9001:2015, 14001:2015, 45001:2018, 22301:2019) now expect auditors to interview top management and to record findings based on the interview, not only on documentation. Indian certification bodies under IAF MD 1 and NABCB rules have followed suit. A "policy-only" 5.1 evidence file that would have passed a 2015 surveillance audit will not pass in 2026.
Why This Control Matters
The business case
Clause 5.1 is the single best predictor of whether an ISO 22301 certification produces operational resilience or merely a certificate. Across published practitioner surveys, across regulatory enforcement actions, and across the public incident record, the same correlation holds: organisations whose top management is demonstrably engaged in the BCMS recover faster, report fewer repeat disruptions, and absorb regulatory scrutiny more cleanly than organisations whose top management is nominally engaged. The pattern is so consistent that supervisors in financial services now treat leadership engagement as a leading indicator of operational resilience, not a lagging one.
The financial logic of getting 5.1 right runs in two directions. Up-front, leadership engagement is free, the executive sponsor's time, the board's attention, the integration into existing executive forums all cost the organisation almost nothing in incremental spend, while the alternative (consultant-led BCMS, leadership-absent) routinely runs to 30 to 80 lakh rupees for a growing Indian firm and still produces a fragile system. Downstream, a leadership-led BCMS compounds: each year's management review tightens the objectives; each year's sponsored exercise surfaces real defects; each year's integration map extends BCMS checkpoints deeper into business processes. The compounding is the asset; the certificate is the receipt.
The strongest argument for 5.1, however, is regulatory and reputational. When a disruption hits, the regulator and the press do not interview the BCM Lead; they interview the CEO and the board. A CEO who can credibly say "we sponsor the BCMS, we attend the management review, we approve the resources, we review the exercises, we sponsor the corrective actions" survives the news cycle. A CEO who cannot, who has treated BCM as a back-office function, faces the kind of board, regulator and customer reaction that has cost Indian CEOs their jobs in the aftermath of recent public disruptions.
Indian context, why this clause matters more in India than in most markets
Seven features of the Indian business environment sharpen the consequences of a 5.1 failure:
- The statutory board-risk-oversight duty. Section 134(3)(n) of the Companies Act 2013 requires the Board's Report to include a statement on the development and implementation of a risk management policy, including the elements of risk that may threaten the existence of the company itself. Section 177 read with SEBI Listing Obligations and Disclosure Requirements (LODR) Regulation 21 requires listed companies to constitute a Risk Management Committee covering cyber, operational and continuity risks. A board that has not been briefed on BCMS effectiveness, that has not had BCM on its agenda, is in breach of these duties. 5.1 is the operational vehicle by which boards discharge Sections 134(3)(n) and 177 obligations for business continuity risk.
- Dense sectoral regulatory expectations of leadership engagement. The Reserve Bank's Master Direction on IT Governance, Risk, Controls and Assurance Practices (issued 7 November 2023, effective 1 April 2024) explicitly makes the board responsible for the IT governance framework, including BCP/DR policy, RTO/RPO for critical systems, DR drill cadence, and incident management. SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF, circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024) organises the entire regime around five Cyber Resilience Goals, with governance and board accountability as the first goal. IRDAI's Information and Cyber Security Guidelines 2023 (24 April 2023) require a board-approved Information and Cyber Security Policy including BCP/DR, with explicit oversight by the Board's Risk/IT committee. Each of these is, in effect, a regulator mandating what 5.1 mandates, leadership engagement is not optional in regulated Indian sectors.
- The CERT-In horizontal regime. The CERT-In Directions (No. 20(3)/2022-CERT-In, 28 April 2022) bind every entity operating ICT in India to a 6-hour incident-reporting clock, 180-day log retention, NTP clock sync, point-of-contact designation, and cooperation with investigations. Compliance with the 6-hour clock requires a leadership-sponsored incident-response capability and a leadership-endorsed decision to commit the resources to maintain it. CERT-In is the cross-sector instrument that makes 5.1 operative for every Indian organisation, not only the regulated ones.
- DPDP Act 2023 availability duty. Section 8(5) of the Digital Personal Data Protection Act 2023 (Act 22 of 2023) makes availability of personal data a statutory duty of every Data Fiduciary, enforceable with penalties up to ₹250 crore under the Schedule. The DPDP Rules 2025 (notified November 2025) operationalise a 72-hour breach-notification clock. Availability is a continuity outcome; a continuity outcome at this scale requires leadership ownership. 5.1 is the operational underpinning for DPDP availability compliance.
- Group structures and captive subsidiaries. Indian growing companies are frequently structured as a parent plus operating subsidiaries plus a captive IT or BPO entity plus an overseas contracting vehicle. Leadership engagement that is strong at the parent and silent at the subsidiary is a 5.1 finding; the accountability must travel with the scope. For multi-entity scopes, the executive sponsor's accountability has to be explicitly extended to each in-scope entity, typically through entity-level leadership evidence annexures.
- Outsourcing intensity. Indian BFSI, SaaS and ITeS firms outsource heavily, DR sites, payment switches, SMS gateways, identity providers, SOC services. RBI Master Direction on Outsourcing of IT Services (10 April 2023) and the equivalent SEBI and IRDAI instruments make the board accountable for ensuring outsourced continuity controls inherit the RE's own standards. Leadership accountability for outsourced BCM is one of the most common gaps in Indian 5.1 evidence files.
- Public-disruption reputational intensity. Indian disruptions tend to be visible, the AIIMS Delhi ransomware of November 2022 (peer-reviewed case in International Journal of Information Management), the HDFC Bank RBI action of December 2020 (repeated digital outages leading to a restriction on new digital products and fresh credit cards, partially lifted August 2021, fully lifted March 2022), the Cognizant Maze ransomware of April 2020 (SEC 10-Q/K, $50 to $70 million impact), the LG Polymers Vizag gas leak of May 2020 (NGT ₹50 crore penalty), the Jio platform outage of September 2024 (Reuters + Cloudflare 53% traffic drop). Each of these tested top-management engagement in real time. The pattern is that the organisations that recovered fastest had leadership-led BCMS architectures; the ones that became illustrative scenarios did not.
The cost of getting it wrong
A defective 5.1 architecture generates three categories of cost:
- Certification and audit cost. Stage 1 audit (the documentation review) is in significant part a 5.1 examination: is there demonstrable top-management engagement here, or merely a signature? A deficient leadership evidence file generates Stage 1 major nonconformities that delay Stage 2 by 2 to 6 months and trigger re-audit fees of 8 to 25 lakh rupees for a firm of 250 to 2,000 staff. Annual surveillance audits then re-extract the cost: leadership evidence that did not accumulate organically must be reconstructed each year at consultancy rates.
- Operational disruption cost. A leadership-absent BCMS cannot make decisions quickly enough during a real disruption. The activation authority is unclear; the war-room does not convene; the executive spokesperson is unbriefed; the regulator-notification decision waits hours for someone with sign-off authority; the supplier-failover decision waits for executive indemnity. The illustrative Kaveri Cooperative Bank scenario in Section 14 traces how a leadership-absent BCMS, policy signed once, never sponsored, produced a roughly ₹5 crore direct loss (and an ₹8 to ₹12 crore all-in cost including supervisory action and remediation) when a November 2024 ransomware event exposed what sponsorship should have built.
- Regulatory and statutory cost. Where the BCMS is required by an Indian regulator, leadership absence is a regulatory breach. The HDFC Bank RBI action of December 2020 was, in substance, a 5.1 finding, repeated digital outages that the regulator attributed to inadequate board-level oversight of digital infrastructure. The DPDP penalties (up to ₹250 crore) and the Companies Act 2013 Section 134(3)(n) board-risk-oversight duty make leadership absence a material balance-sheet risk for any Indian company of size. SEBI LODR Reg. 21 makes it a listing-rule breach for listed entities.
The counter-case is equally clear. A 5.1-led BCMS concentrates effort on the right cadence and visibly widens the resilience posture without inflating the BCMS cost. The illustrative Sarthak Logistics scenario in Section 15 traces how a Mumbai-based third-party logistics firm invested ₹1.4 crore over three years in a leadership-led BCMS (board-sponsored BCM Steering Committee, quarterly board reports, integrated management-system manual with ISO 9001, executive war-room rehearsed annually), survived a 14-day warehouse shutdown during the July 2025 monsoon flooding of the Mumbai-Pune expressway corridor without losing a single enterprise customer, and recovered the investment in avoided service credits, customer retention, and a premium-priced new contract within 19 months.
Scope and Applicability
Who 5.1 applies to
Clause 5.1 applies to every organisation seeking ISO 22301:2019 certification, regardless of size, sector or geographic footprint. It is a universal requirement, not a sector-conditional one. A 30-person SaaS startup, a 1,200-person NBFC, a 6,000-staff hospital chain and a 50,000-employee manufacturing group all build a 5.1-conformant leadership architecture, the form of the evidence scales, but the substance does not.
5.1 also applies to organisations pursuing internal alignment with ISO 22301 (without seeking certification). The discipline of designing leadership engagement is the same; only the audit pressure differs. Many growing companies in India run a "shadow" 5.1 cycle 12 to 24 months before pursuing certification, to surface leadership-engagement gaps before the certification body does.
What "top management" means for 5.1
ISO management-system standards use "top management" to mean the person or group that directs and controls the organisation at the highest level, and that can allocate resources. For 5.1, this determines who can be the executive sponsor and whose evidence counts. In India, the question is non-trivial because of common structures:
- Small company (10 to 50 staff), top management is typically the founder/MD, sometimes with a co-founder or COO. The executive sponsor and the BCM Lead may be the same person; that is acceptable, but the accountability is the founder's alone.
- Growing company (50 to 250 staff), top management is the MD/CEO plus the executive team (COO, CFO, CIO/CTO, CRO, CHRO, Business Unit heads). The executive sponsor is typically the COO, the CRO or the CIO.
- Mid-market (250 to 2,000 staff), top management is the MD/CEO, the executive team, and (for listed entities) the Board through its Risk Management Committee. The executive sponsor is typically a CXO with cross-functional authority; the board Risk Committee provides oversight.
- Listed entity (any size), top management includes the Board, the Audit Committee (Companies Act Section 177), and the Risk Management Committee (SEBI LODR Reg. 21). The board has explicit accountability for risk oversight including continuity risk; the executive sponsor reports to the board Risk Committee.
- Regulated entity, for RBI-regulated entities (banks, NBFCs, PSOs, UCBs), the RBI Master Direction IT Governance makes the board explicitly accountable for the IT governance framework including BCP/DR; for SEBI-regulated entities (MIIs, brokers, AMCs, etc.), the CSCRF governance goal does the same; for IRDAI-regulated insurers, the Board's Risk/IT committee owns the Information and Cyber Security Policy including BCP/DR.
- Multi-entity group, top management at each in-scope entity must be identified. For a parent-subsidiary scope, the parent's leadership accountability extends to the subsidiary's BCMS; for a captive BPO or IT entity, the captive's top management plus the parent's oversight together constitute 5.1 accountability.
- Public-sector / PSU, top management includes the Secretary, the Board, and the relevant Ministry; for departmental BCMS, the Section 40 Disaster Management Plan duties under the Disaster Management Act 2005 attach to leadership.
The auditor identifies top management at Stage 1 by name and by role. Without that identification, 5.1 cannot be tested.
What 5.1 does NOT cover
5.1 establishes leadership engagement, it does not itself produce the artefacts leadership engages with. The following are commonly confused with 5.1 but are different clauses:
- The BCMS Policy content, Clause 5.2. 5.1 ensures the policy exists and is consistent with strategy; 5.2 sets its content and communication.
- Roles, responsibilities and authorities, Clause 5.3. 5.1 ensures top management assigns them; 5.3 documents and communicates them.
- Risk and opportunity actions, Clause 6.1. 5.1 directs the process; 6.1 runs it.
- Business continuity objectives, Clause 6.2. 5.1 ensures objectives exist and align with strategy; 6.2 sets measurable targets.
- Resources, Clause 7.1. 5.1 ensures resources are made available; 7.1 manages them.
- The BIA, strategies, plans and exercises, Clauses 8.2 to 8.5. 5.1 sponsors them; Clause 8 runs them.
- Internal audit and management review, Clauses 9.2 and 9.3. 5.1 ensures the functions exist and are resourced; 9.2 and 9.3 run them. The executive sponsor attends the management review under 5.1.
- Corrective action and continual improvement, Clauses 10.1 and 10.2. 5.1 promotes and commissions improvement; 10.1 and 10.2 execute it.
By organisation size
The mechanics of 5.1 scale with organisation size:
- Small (10 to 50 staff), the founder/MD is the executive sponsor; a 2 to 4 page BCM Leadership Charter; monthly leadership review of BCM in the existing executive meeting; quarterly review of BCM at the board meeting (if a board exists); annual management review chaired by the founder/MD; sponsored participation in at least one exercise per year; one board-approved budget line for BCM. The whole 5.1 architecture is achievable in 4 to 6 weeks of part-time effort.
- Growing companies (50 to 250 staff), the MD/CEO is the executive sponsor, with a designated BCM Steering Committee (CXO plus BCM Lead plus process-owner representatives); a 6 to 10 page BCM Leadership Charter; monthly Steering Committee; half-yearly BCM report to the board; annual management review chaired by the MD/CEO with executive attendance; sponsored participation in at least one major exercise per year; integrated BCMS checkpoints in vendor onboarding, project approval, and audit follow-up. 6 to 10 weeks of cross-functional effort for the first cycle.
- Mid-market (250 to 2,000 staff), the executive sponsor is typically a CXO (COO, CRO or CIO); the BCM Steering Committee meets monthly with CXO attendance; the board Risk Committee (where it exists, mandatory under SEBI LODR Reg. 21 for listed entities) receives a half-yearly BCM report; the annual management review is a formal half-day with all CXOs; sponsored participation in two or more exercises per year (typically one tabletop plus one full simulation); integrated BCMS checkpoints in capital allocation, M&A due diligence, vendor onboarding, HR onboarding, project gating, and audit cycles. 8 to 14 weeks for first cycle; a permanent BCM function thereafter.
- Enterprise (2,000+ staff), top management includes the Board, the board Risk Committee, the executive committee, and the BCM Steering Committee; the BCM Steering Committee meets monthly; the board Risk Committee receives quarterly BCM reports; the annual management review is a full-day offsite with board attendance; sponsored participation in multiple exercises per year including a board-level tabletop on a severe-but-plausible scenario; integrated BCMS checkpoints across the entire operating model; pay-linkage for the executive sponsor and the CEO to BCMS outcomes; a dedicated BCM office function with a Chief Resilience Officer or equivalent. 3 to 6 months for first cycle; a permanent BCM-office function thereafter.
By industry (preview, Section 21 has the deep treatment)
The 5.1 signature varies sharply by industry:
- BFSI, regulator-driven leadership engagement (RBI MD IT Governance, SEBI CSCRF, IRDAI ICS 2023 all make the board explicitly accountable); board Risk Committee is the central governance vehicle; integrated with the Cyber Crisis Management Plan (CCMP) under the RBI Cyber Security Framework; variable pay linkage increasingly common.
- Healthcare, clinical leadership dimension (Chief Medical Officer plus COO plus CIO); patient-safety angle on every leadership decision; IRDAI for insurers, NMC/clinical governance for hospitals, DPDP SDF for large patient datasets; the AIIMS Delhi 2022 ransomware is the canonical Indian healthcare case.
- IT/ITeS and SaaS, leadership accountability for the customer-contractual perimeter (customer-facing BCM clauses drive the board reporting); cross-border regimes (DORA for EU financial-sector customers, APRA CPS 230 for Australian captives, MAS TRM for Singapore subsidiaries, HKMA OR-2 for Hong Kong) reflected in entity-level leadership evidence; Cognizant Maze is the canonical case.
- Manufacturing (especially chemical), leadership accountability for physical safety (NDMA Chemical Disaster Guidelines 2007 require integration of industrial plans with District Disaster Management Plans); OT/IT boundary in leadership review; LG Polymers Vizag 2020 is the canonical Indian case.
- Government and PSU, leadership is the Secretary / Board / Ministry; Disaster Management Act 2005 Section 40 attaches DMP duties to departments; RTI transparency dimension.
Key Definitions and Terminology
Clause 5.1 turns on five terms that have precise meanings inside ISO management-system vocabulary. Auditors test the vocabulary; getting the definitions wrong produces audit findings even when the practice is sound.
- Top management. Per ISO 22300:2021 (vocabulary; a 2025 edition is under development (ISO/DIS 22300, 4th ed.) and not yet published, verify current), the person or group who directs and controls an organisation at the highest level. The defining property is the authority to allocate resources. For 5.1, top management is identified by name and role in the BCMS documentation, typically in the BCM Leadership Charter or the Roles and Responsibilities document. Note that "top management" is a smaller set than "all managers"; it is the apex decision-making body of the organisation (or of the in-scope part of it).
- Leadership. In the ISO management-system context, leadership is the visible exercise of direction, decision and accountability by top management. It is distinguished from management (the operation of processes by delegated owners) and from sponsorship (the symbolic endorsement of a programme). The hallmark of leadership under 5.1 is the paper trail of decisions.
- Commitment. Commitment is the demonstrable allocation of attention, time, resources, and authority to a purpose. Commitment is tested by evidence of allocation, not by statements of intent. A budget approval is commitment; a speech about resilience is communication.
- Accountability. Accountability is the obligation to answer for an outcome. Under 5.1, accountability for BCMS effectiveness rests with top management and cannot be devolved. Tasks can be delegated; accountability cannot. This is the most-tested distinction in 5.1 audits.
- Integration. Integration is the embedding of BCMS requirements into the organisation's business processes, such that BCM considerations appear inside capital allocation, project gating, vendor onboarding, HR onboarding, audit cycles, risk reporting, and management review, rather than running as a parallel programme. The test for integration is whether business-process owners can describe how BCM enters their workflow.
- Business continuity (BC). In ISO 22300's vocabulary (stated here in our own words): the organisation's capability to keep delivering its products and services at a pre-agreed capacity, and within timeframes it can tolerate, while a disruption is under way. The strategic outcome leadership is accountable for enabling.
- BCMS. The Business Continuity Management System, the management system (Clause 4.4) that delivers BC.
- Executive sponsor. Not an ISO-defined term, but the standard Indian practitioner label for the top-management member with day-to-day 5.1 accountability for the BCMS. Typically a CXO (COO, CRO, or CIO).
- BCM Steering Committee. Not an ISO-defined term, but the standard Indian practitioner label for the cross-functional governance body that oversees the BCMS between management reviews. Typically chaired by the executive sponsor, with the BCM Lead as secretary, and with process-owner representation.
- BCM Lead / BCM Manager. The person who runs the BCMS day-to-day, convenes the BCM Steering Committee, prepares the management review, and owns the leadership-evidence index. Reports to the executive sponsor.
- Management review. The Clause 9.3 process, top-management review of BCMS continuing suitability, adequacy and effectiveness at planned intervals. Attendance by the executive sponsor (and typically the full executive team) is the most visible 5.1 evidence event in the BCMS calendar.
- Risk Management Committee (RMC). The board committee mandated under SEBI LODR Regulation 21 for listed Indian companies. The RMC's scope includes business continuity and operational resilience; for listed entities, the RMC is the natural recipient of the half-yearly BCM report.
- Cyber Crisis Management Plan (CCMP). Mandated for RBI-regulated banks by the RBI Cyber Security Framework (2 June 2016). The CCMP is the leadership-activated escalation artefact for severe cyber events; leadership engagement with the CCMP (rehearsal, activation authority, decision rights) is a 5.1 evidence source for banks.
- War-room. Not a formal term, but the practitioner label for the executive-led decision cell that convenes during a severe disruption. The existence of a designated war-room, with named attendees and pre-decided activation triggers, is strong 5.1 evidence.
- Tone from the top. Practitioner label for the visible leadership signals, internal communication, board speeches, customer and regulator letters, attended exercises, public statements after disruptions, that establish BCM as non-negotiable. Tested by interview with non-executive staff: do they perceive leadership commitment?
Relationship to Other Clauses and Frameworks
Within ISO 22301:2019
5.1 is the apex leadership clause. It produces the conditions under which every other clause operates:
- Clause 4.1 (Context), leadership reads the context, decides what counts as a material issue, and ensures the BCMS responds. Without leadership engagement, the context analysis becomes a documentation exercise.
- Clause 4.2 (Interested parties), leadership identifies the interested parties whose expectations must be met (regulators, customers, employees, suppliers, communities) and ensures obligations are captured.
- Clause 4.3 (Scope), leadership approves the BCMS scope. Scope decisions are strategic (which entities, which products, which geographies are in or out); they cannot be delegated to the BCM Lead.
- Clause 4.4 (BCMS), leadership brings the BCMS into existence. The four-verb lifecycle (establish, implement, maintain, continually improve) is leadership-owned; the BCM Lead executes.
- Clause 5.2 (Policy), leadership approves the BCMS Policy. 5.1 ensures the policy exists and is consistent with strategy; 5.2 sets its content.
- Clause 5.3 (Roles), leadership assigns and communicates roles, responsibilities and authorities. The sponsorship RACI (toolkit doc 13) is the artefact.
- Clause 6.1 (Risks and opportunities), leadership directs the risk-treatment process; ensures cyber-risk and continuity-risk scenarios are included; ensures CERT-In 6-hour clock capability is resourced.
- Clause 6.2 (Objectives), leadership ensures measurable BC objectives are set; approves them; reviews progress.
- Clause 6.3 (Change), leadership owns planned BCMS changes; the executive sponsor signs off material changes.
- Clause 7.1 (Resources), leadership allocates the budget, headcount and tooling. The single most-tested 5.1 evidence: the resource decision.
- Clause 7.2 to 7.5 (Competence, Awareness, Communication, Documented Information), leadership ensures these support processes run; particularly that awareness reaches the workforce (tone from the top).
- Clause 8.1 to 8.6 (Operation), leadership sponsors the operational core: BIA, strategy, plans, exercises, evaluation. Sponsored participation in exercises (Clause 8.5) is a key 5.1 evidence source.
- Clause 9.1 to 9.3 (Performance evaluation), leadership attends the management review (9.3) in person; receives internal audit findings (9.2); acts on monitoring and measurement (9.1).
- Clause 10.1 to 10.2 (Improvement), leadership commissions corrective action; promotes continual improvement; reviews major nonconformities personally.
Cross-framework anchors (Clause 5.1)
| Framework | Anchor | What it says about leadership | Mapping strength |
|---|---|---|---|
| ISO/IEC 27001:2022 Clause 5.1 | Clause 5.1 (Leadership) | Top management must visibly lead and commit to the ISMS, structurally identical to ISO 22301 5.1 | Direct equivalence |
| ISO 9001:2015 Clause 5.1 | Clause 5.1 (Leadership) | Top management must visibly lead and commit to the QMS, Harmonized Structure | Direct equivalence |
| ISO 22313:2020 Section 5 | Guidance on use | Companion how-to for Clause 5 of ISO 22301; explains the visible-engagement method | Companion guidance |
| NIST SP 800-34 Rev 1 (May 2010) | Step 1, Contingency planning policy statement | The seven-step process begins with leadership issuing the policy; without it, Steps 2 to 7 do not start | Strong analogue |
| NIST CSF 2.0 (Feb 2024) | Govern (GV) function | GV.SC, cyber supply chain risk management governance; GV.RR, roles and responsibilities; GV.OV, organisational understanding; GV.OC, cybersecurity strategy. The Govern function is the leadership function. | Strong structural mapping |
| FFIEC BCM Booklet (Nov 2019) | Governance principle | Board and senior management accountability for BCM as an enterprise discipline; OCC Bulletin 2019-57, FRB SR 19-13, FDIC FIL-19071-2019 as the inter-agency issuance vehicles | Strong analogue |
| DORA (Reg EU 2022/2554, applies 17 Jan 2025) | Article 5(2), (3), (4) | Management body bears ultimate responsibility for managing ICT risk; approves the ICT risk management framework; receives training; Role of the management body explicitly paralleled to ISO 22301 5.1 | Direct regulator-level mapping |
| APRA CPS 230 (eff. 1 Jul 2025) | Paras 20 to 23, Roles and responsibilities | Board ultimately accountable for operational risk, business continuity and service provider management; approves BCP and tolerance levels; oversees material incidents | Direct regulator-level mapping |
| MAS TRM Guidelines (18 Jan 2021) | Board oversight section | Board and senior management accountability for technology risk management including BCM | Strong analogue |
| HKMA SPM OR-2 (31 May 2022) | Board role section | Board and senior management accountability for operational resilience; Important Business Services identification; impact tolerance setting; severe-but-plausible scenario testing | Strong analogue |
| Companies Act 2013 §134(3)(n) | Board's Report content | Board must include a statement on risk management policy including elements that may threaten the existence of the company | Indian statutory mapping |
| Companies Act 2013 §177 + SEBI LODR Reg. 21 | Audit Committee / Risk Management Committee | Board-level risk oversight, including cyber, operational and continuity risk for listed entities | Indian statutory mapping |
| RBI MD IT Governance (7 Nov 2023, eff. 1 Apr 2024) | Governance chapter | Board explicitly accountable for the IT governance framework, including BCP/DR policy, RTO/RPO, DR drill cadence, incident management | Indian regulator-level mapping |
| SEBI CSCRF (20 Aug 2024) | Governance goal | Governance as the first of five Cyber Resilience Goals; board accountability explicit | Indian regulator-level mapping |
| IRDAI ICS Guidelines 2023 (24 Apr 2023) | Board policy | Board-approved Information and Cyber Security Policy including BCP/DR; Board's Risk/IT committee oversight | Indian regulator-level mapping |
| CERT-In Directions 20(3)/2022 (28 Apr 2022) | PoC + 6-hour clock | The capability that meets the 6-hour clock is leadership-sponsored; the Point of Contact is leadership-designated | Indian horizontal mapping |
| DPDP Act 2023 §8(5), §8(6) | Data Fiduciary duty | Availability of personal data is a leadership-owned outcome; breach notification within 72 hours requires leadership-resourced capability | Indian statutory mapping |
| NDMA guidelines + DM Act 2005 | Industrial / departmental DMP | For chemical / MAH units and government departments, leadership accountability for integration with District DMPs | Indian sectoral mapping |
The integration opportunity with ISO 27001 and ISO 9001
Because ISO 22301, ISO/IEC 27001 and ISO 9001 share the Harmonized Structure, their Clause 5.1 requirements are structurally identical. An Indian growing company running an integrated management system (ISMS + BCMS + QMS is a common combination in BFSI, ITeS and SaaS) should maintain one leadership evidence file that satisfies all three clauses concurrently. The integration is not merely a documentation efficiency; it is also a quality marker, auditor confidence rises when leadership evidence is integrated rather than fragmented by standard.
The integrated leadership pack typically contains: one BCM Leadership Charter (also serving as ISMS and QMS leadership charter), one sponsorship RACI (per standard or unified), one board reporting pack (covering security, continuity and quality), one management-review cycle (per Clause 9.3, scheduled to serve all standards), one leadership-evidence index (mapping moves to clauses across all standards).
Detailed Implementation Guidance, The Nine Accountability Moves
The method that follows is the worked leadership architecture Singahi uses with growing companies in India. It is structured around the nine accountability moves top management must demonstrate under 5.1, organised into the four evidence families auditors test against. The whole architecture is implementable by a growing firm in 8 to 14 weeks for the first cycle.
Move 1, Take accountability for BCMS effectiveness
Accountability is the foundation move. The auditor's first test is always: "Who is accountable for BCMS effectiveness, and where is that recorded?" If the answer is "the BCM Lead", the audit stops there with a major nonconformity.
Practical actions:
- Identify top management by name and role. Produce a one-page "Top Management Identification" statement naming the executive sponsor (the CXO with day-to-day 5.1 accountability), the alternate sponsor (in case of absence), the board Risk Committee chair (where applicable), and the full BCM Steering Committee membership. Sign and date it. Place it in the leadership-evidence file as the first artefact.
- Adopt a BCM Leadership Charter (toolkit doc 01). The Charter is the apex 5.1 instrument, typically a 6 to 10 page document, approved at the executive committee and tabled at the board (for listed or regulated entities). The Charter records: (a) the executive sponsor's name and accountability statement; (b) the BCM Steering Committee's mandate and membership; (c) the resourcing commitment (budget, headcount, tooling for the current cycle); (d) the decision rights; (e) the integration commitments (which business processes BCMS will be wired into); (f) the reporting cadence (Steering Committee monthly, board half-yearly, management review annual); (g) the executive sponsor's personal commitments (attendance, sponsorship, communication).
- Receive and accept the accountability at the executive committee. The minutes of the executive committee meeting at which the Charter is adopted are the primary 5.1(a) evidence. Ensure the minute records discussion, questions, and a clear decision, not merely "noted".
- Table the Charter at the board (for listed or regulated entities). For listed companies under SEBI LODR Reg. 21, table the Charter at the Risk Management Committee. For RBI-regulated entities, table at the board's Risk/IT committee. The board minute recording the tabling is the secondary 5.1(a) evidence.
Audit evidence produced: Top Management Identification statement; BCM Leadership Charter (version 1.0, signed); executive committee minutes recording adoption; board/RMC minute recording tabling.
Move 2, Ensure policy and objectives exist and align with strategy
The BCMS Policy (Clause 5.2) and the BCMS Objectives (Clause 6.2) are the apex artefacts leadership must ensure exist and must ensure align with the organisation's strategic direction.
Practical actions:
- Commission the BCMS Policy (Clause 5.2). Leadership does not draft the policy, but directs its creation, sets its strategic anchors (the organisation's purpose, risk appetite, customer commitments, regulatory obligations), and approves the final text. The policy is a 2 to 4 page document; longer policies tend to drift into procedure (which belongs in Clause 7.5 documented information).
- Commission the BCMS Objectives (Clause 6.2). Objectives must be measurable, consistent with the policy, monitored, communicated and updated. A typical growing Indian firm's objective set might include: (a) RTO compliance ≥ 95% across prioritised activities; (b) exercise programme coverage 100% of prioritised activities per cycle; (c) major-nonconformity closure within 60 days; (d) board-reported BCM metric set delivered on cadence; (e) supplier-BCM coverage for top 20 critical suppliers.
- Test alignment with strategic direction. At the executive committee meeting that approves the policy and objectives, explicitly minute the alignment test: "How does this policy support the organisation's three-year strategic plan? How do these objectives advance the strategic priorities?" The auditor will ask this question; the answer in the minute is the 5.1(b) evidence.
- Approve at top management and table at the board. The executive sponsor signs the policy and the objectives register; the board (or board RMC, for listed entities) is informed.
Audit evidence produced: BCMS Policy v1.0 signed by executive sponsor; BCMS Objectives Register v1.0 signed; executive committee minutes recording alignment discussion; board/RMC minute recording information.
Move 3, Integrate BCMS requirements into business processes
Integration is the single most-tested word in 5.1. A BCMS that runs in parallel to the business, separate objectives, separate cadences, separate reporting, is not integrated. The auditor tests integration by tracing BCM checkpoints inside business processes.
Practical actions:
- Build the integration map. Produce a one-page map of the business processes that contain BCMS checkpoints. Typical checkpoints for an Indian growing company:
- Vendor onboarding, BCM due-diligence questionnaire (RTO/RPO, DR site, exercise history, exit plan) before contract; managed-dependency treatment for critical suppliers.
- Project approval, BCM checkpoint in the project gating process: does the new project introduce new continuity risk? Does it require updates to the BIA, the strategy, the plans?
- Capital allocation, BCM consideration in capex decisions: does a new facility, a new system, a new geography need BCMS investment?
- HR onboarding, BCM awareness in induction; role-specific BCM training for incident response, BC plan owners,BCM Steering Committee members.
- Internal audit cycle, BCM topics in the annual internal audit plan (Clause 9.2); BCM coverage at each cycle.
- Risk reporting, BCM risks in the enterprise risk register; BCM KPIs in the monthly/quarterly risk report to the executive committee and the board.
- M&A due diligence, BCM assessment in target due diligence; integration of target BCMS into group BCMS.
- Change management, Major changes flagged for BCMS impact assessment (Clause 6.3).
- Weld the checkpoints into process documentation. Each checkpoint should appear in the relevant business-process procedure (vendor management procedure, project management procedure, capex approval procedure, HR induction procedure, internal audit charter, risk reporting template, M&A playbook, change management procedure). The BCMS is named in each procedure as a checkpoint, not buried in an appendix.
- Assign ownership of each checkpoint. Each integrated checkpoint has a named owner (the vendor manager, the project office, the capex approver, the HR onboarding lead, the internal audit head, the risk manager, the M&A lead, the change manager). The owner is accountable to the BCM Lead for the checkpoint's operation.
- Test integration in the audit cycle. Internal audit (Clause 9.2) samples integrated checkpoints each cycle; the executive sponsor reviews the integration test results at the management review.
Audit evidence produced: Integration map (one page); business-process procedures with BCM checkpoints named; integration test results from internal audit; management review minutes recording integration review.
Move 4, Ensure resources are available
Resources are the single most-tested 5.1 evidence after policy approval. The auditor does not test whether leadership supports the BCMS in principle; they test whether leadership has allocated budget, headcount and tooling.
Practical actions:
- Build the BCMS Resource Plan. A one-page summary of the BCMS budget (capex and opex), the headcount (BCM Lead, BCM Coordinator,BCM-allocated time of process owners, internal audit allocation, training spend, tooling spend, exercise spend, consultancy spend). Updated annually as part of the management review cycle.
- Approve the Resource Plan at the executive committee. The minute recording approval is the primary 5.1(d) evidence. The executive sponsor signs the Resource Plan.
- For regulated entities, ensure regulator-required resourcing. RBI-regulated entities must resource a 24x7 SOC under the Cyber Security Framework (2 Jun 2016) and the IT Governance MD (7 Nov 2023); SEBI-regulated entities must resource SOC and threat-intel under CSCRF; IRDAI-regulated insurers must resource CISO and DR drills under the 2023 guidelines. The Resource Plan records each regulatory commitment separately.
- Track actuals against plan. Quarterly tracking of BCMS spend against the Resource Plan, with variances escalated to the executive sponsor. The variance report is the 5.1(d) follow-through evidence, it shows the resource decision is being managed, not just made.
- Capex for DR / resilience. Large capex items (DR site build, redundant infrastructure, GRC platform implementation) appear in the capital plan with BCM as the business case driver. The capital plan minute is 5.1(d) evidence for major investments.
Audit evidence produced: BCMS Resource Plan v1.0 signed by executive sponsor; executive committee minutes recording approval; quarterly variance reports; capital plan entries with BCM business cases.
Move 5, Communicate the importance of effective BCM
Communication is the visible voice of leadership. The auditor tests whether the workforce, the customers, the suppliers and the regulators have perceived leadership commitment to BCM.
Practical actions:
- Internal communication campaign. A leadership-authored BCM message at least annually (the executive sponsor's letter, video, or town hall). The campaign is reinforced at the start of every exercise, after every incident, and after every management review.
- Board-communication cascade. The executive sponsor's BCM update at the board (or RMC, where applicable) cascades into the board's communications to investors, regulators, and the broader stakeholder community. The half-yearly BCM board report is part of this cascade.
- Customer-facing BCM messaging. For B2B firms (especially SaaS, ITeS, BFSI suppliers), BCM commitments appear in customer communications, the customer-facing BCM statement, the security and continuity whitepaper, the RFP responses. The executive sponsor's signature on the customer-facing BCM materials is strong 5.1(e) evidence.
- Supplier-facing BCM expectations. The executive sponsor's letter to critical suppliers setting out BCM expectations (RTO/RPO disclosure, exercise participation, exit continuity), sent annually, with responses tracked.
- Regulator-facing BCM statements. For regulated entities, the executive sponsor's signed regulatory submissions (RBI/SEBI/IRDAI compliance certificates, certification body correspondence, breach notifications) are 5.1(e) evidence.
- Post-incident communication. After a real disruption (or a major exercise finding), leadership-authored communication to the workforce, the customers and (where relevant) the regulator, demonstrating that BCM is a leadership-owned discipline, not a back-office function.
Audit evidence produced: Internal communication campaign materials (letter, video, town hall recording); board/RMC reporting pack; customer-facing BCM statement (signed); supplier BCM expectation letter (signed); regulator submissions (signed); post-incident leadership communications.
Move 6, Ensure the BCMS achieves its intended outcomes
Outcomes, not outputs. The BCMS exists to enable the organisation to continue prioritised activities during disruptions (Clause 8.2 priorities). Leadership is accountable for whether that actually happens.
Practical actions:
- Define the BCMS outcomes. The intended outcomes are typically: (a) prioritised activities continue at or above MBCO during disruptions; (b) RTO/RPO targets are met for in-scope systems and processes; (c) regulatory continuity obligations are met (CERT-In 6-hour clock, DPDP 72-hour clock, RBI/SEBI/IRDAI reporting); (d) customer-facing SLAs are maintained or pauses are communicated within agreed windows; (e) post-disruption, the organisation returns to normal operations without material loss.
- Measure outcomes (Clause 9.1). The KPI set (see Section 12) captures outcome metrics, actual RTO achieved in exercises and real disruptions; % of prioritised activities with exercised plans; % of regulatory clocks met; customer-credit triggers due to disruption.
- Review outcomes at the management review (Clause 9.3). The executive sponsor chairs; the leadership team attends; outcomes are reviewed against targets; gaps drive corrective action.
- Escalate outcome failures. When an outcome is missed (an exercise RTO blew out; a regulatory clock was missed; a customer SLA was breached), the escalation path runs from the BCM Lead to the executive sponsor and, for material failures, to the board. The escalation minute and the resulting corrective action are 5.1(f) evidence.
Audit evidence produced: BCMS outcomes definition (in the Objectives Register); KPI dashboard (Clause 9.1); management review minutes recording outcomes review; escalation minutes for material outcome failures.
Move 7, Direct and support persons to contribute
Direction and support run downstream. Process owners, functional managers, and individual contributors need leadership air cover, decisions, and removal of obstacles.
Practical actions:
- Sponsorship RACI (toolkit doc 13). A worked matrix that assigns Responsible, Accountable, Consulted, Informed for every Clause 5 to 10 outcome. The Accountable column is dominated by top management and the executive sponsor; the Responsible column runs through the BCM Lead and process owners.
- Obstacle removal. A standing agenda item at the BCM Steering Committee: "Obstacles the BCM Lead needs the sponsor to remove". Examples: cross-functional cooperation gaps; supplier escalation; budget approval blockages; HR-rotation-induced knowledge loss.
- Cross-functional direction. When a Clause 8 activity (e.g., a BIA workshop) requires cross-functional participation, the executive sponsor's directive to functional heads to participate and resource is 5.1(g) evidence.
- Process-owner empowerment. Process owners need authority to make their processes operate. The executive sponsor's communication delegating authority to process owners, for their BCMS-relevant decisions, is 5.1(g) evidence.
Audit evidence produced: Sponsorship RACI; BCM Steering Committee minutes recording obstacle removal; executive sponsor's cross-functional directives; process-owner authority delegations.
Move 8, Promote continual improvement
Improvement is led from the top. A BCMS that does not improve year on year is one whose leadership has not promoted improvement.
Practical actions:
- Commission the corrective-action programme (Clause 10.1). The executive sponsor opens the corrective-action register; reviews major nonconformities personally; sets closure targets.
- Set improvement targets. Year-on-year KPI improvements (RTO compliance, exercise coverage, audit closure rates) are set at the management review. The executive sponsor commits the leadership team to deliver them.
- Invest in maturation. A multi-year BCMS maturation plan (the L1 to L5 maturity model in Section 22 is the typical structure) is approved by the executive committee and tabled at the board. The investment to move from current level to target level is budgeted.
- Benchmark externally. Participation in industry BCM benchmarks (the BCI Horizon Scan is a global benchmark; sector-specific benchmarks exist for BFSI and healthcare). The executive sponsor's review of the benchmark and commitment to close gaps is 5.1(h) evidence.
- Promote improvement culture. Recognition and reward for BCM contributions, a leadership-sponsored BCM award, recognition at town halls, inclusion of BCM contributions in performance reviews.
Audit evidence produced: Corrective-action register (with executive sponsor reviews); management review minutes setting improvement targets; multi-year maturation plan; benchmark review; recognition programme records.
Move 9, Support other relevant management roles
5.1 cascades. Functional heads (IT, Operations, HR, Finance, Legal, Compliance, Internal Audit) must be supported to demonstrate leadership in their BCMS-relevant domains.
Practical actions:
- Functional BCMS leadership indicators. Each functional head has a BCMS-relevant indicator in their annual performance objectives, IT for IT DR, Operations for operational continuity, HR for people continuity, Finance for financial continuity, Legal/Compliance for regulatory continuity. The executive sponsor reviews these indicators quarterly.
- Functional resource decisions. Functional heads are supported (by the executive sponsor and by the BCM Steering Committee) in making BCMS-relevant resource decisions in their domains.
- Functional leadership evidence. Each functional head contributes to the leadership-evidence index, examples include the CIO's IT DR sponsorship, the COO's operational resilience programme, the CHRO's people-continuity plan, the CFO's financial-contingency plan, the CLO's regulatory-compliance continuity plan.
Audit evidence produced: Functional performance objectives with BCMS indicators; functional resource decisions; functional leadership evidence contributions to the index.
The leadership-evidence index
The single most useful 5.1 artefact is the leadership-evidence index, a one-page table maintained by the BCM Lead, approved by the executive sponsor, indexed to the nine accountability moves. Each row is one of the moves; each column maps to the evidence (Charter reference, minute reference, signed artefact reference, date). The auditor opens this index first; if the index is complete and the links resolve, the 5.1 audit is largely over. The toolkit (doc 03) provides the template.
A worked example for a 600-person Indian SaaS firm:
| # | Move | Evidence | Reference | Date |
|---|---|---|---|---|
| 1 | Accountability | BCM Leadership Charter v1.0 signed; Executive Committee minute | LE-Charter v1.0; EC-2025-06 §4 | 2025-06-12 |
| 2 | Policy & objectives | BCMS Policy v2.1 signed; Objectives Register v2.0 signed | Policy v2.1; Obj-Reg v2.0 | 2025-06-12 |
| 3 | Integration | Integration map v1.0; Vendor mgmt procedure v3.2 §7; Project gating v2.0 §4 | Int-Map v1.0 | 2025-07-01 |
| 4 | Resources | BCMS Resource Plan FY26 signed; capex entry for DR site | RP-FY26; CAPEX-2025-08 | 2025-04-15 |
| 5 | Communication | Sponsor letter to all staff; sponsor video; customer BCM statement | Comms-2025-Q2 | 2025-05-20 |
| 6 | Outcomes | KPI dashboard Q2 FY26; mgmt review 2024 minutes | KPI-Q2-FY26; MR-2024 | 2025-07-01 |
| 7 | Direction & support | Sponsorship RACI v1.0; Steering Committee minute removing obstacle | RACI v1.0; SC-2025-05 §3 | 2025-05-07 |
| 8 | Continual improvement | Corrective-action register; FY26 maturation plan | CAR; MAT-FY26 | 2025-04-01 |
| 9 | Other management roles | Functional performance objectives; functional leadership evidence | FPO-2025; FLE-pack | 2025-04-15 |
Tools, Technologies, and Solutions
Clause 5.1 is the least tooling-heavy clause in ISO 22301, leadership evidence is fundamentally about decisions and conduct, not platforms. However, four tooling categories materially help, and the leadership-evidence architecture is materially easier to operate when supported by them.
Board portals and executive information systems
Board portals (category descriptor; multiple Indian and global providers exist) host the board / Risk Management Committee pack and provide distribution, e-signature, and version control. The BCM board pack, the half-yearly BCM report, is a typical payload. Indicative cost for an Indian growing firm: ₹40,000 to ₹2,50,000 per year. Selection criteria: integrated e-signature for board resolutions; minute management; secure distribution to board devices; audit trail.
GRC platforms with BCM modules
Governance, Risk and Compliance platforms (category descriptor; Indian-footprint providers and global platforms exist) host the BCMS documentation, the BCM Steering Committee workflow, the corrective-action register, the leadership-evidence index, and the board reporting dashboard. Indicative cost for an Indian growing firm: ₹6 lakh to ₹40 lakh per year (varies widely by platform and scope). Selection criteria: BCM module maturity (BIA, plans, exercises, evaluation); integration with risk register and audit module; board-pack generation; Indian data residency option.
Awareness and communication platforms
For the workforce-awareness communication campaign (Move 5), platforms (category descriptor) that deliver leadership video, town-hall webcasting, e-learning and acknowledgment tracking are typically used. Indicative cost for an Indian growing firm: ₹50 to ₹300 per employee per year. Selection criteria: Indian-language support; acknowledgment tracking; integration with HR systems.
Incident and crisis management platforms
For the war-room activation and the regulatory-notification workflow, incident and crisis management platforms (category descriptor) provide notification, decision logging, regulator-notification templates, and post-incident review. Indicative cost for an Indian growing firm: ₹3 lakh to ₹25 lakh per year. Selection criteria: CERT-In and DPDP notification templates; multi-channel notification; decision-minute capture.
Tool selection discipline
Three rules govern tool selection for 5.1:
- Do not let the tool become the substitute for the leadership. A GRC platform that hosts an empty leadership-evidence index does not produce leadership evidence; it produces a dashboard of absence. The tool supports leadership; it does not replace it.
- Buy the BCM module you will actually use, not the platform's full capability. Most GRC platforms sell broad capability; most 5.1 needs are narrow (Charter hosting, evidence index, board-pack generation). Match the purchase to the need.
- Ensure the tool supports the audit. Auditors will ask to see the leadership-evidence index, the Charter, the executive committee minutes, the board/RMC minutes. The tool must produce these on demand, in exportable form.
Indicative cost stack for a growing Indian firm
| Item | Annual cost (₹) |
|---|---|
| Board portal (mid-market tier) | 40,000 to 2,50,000 |
| GRC platform with BCM module (mid-market tier) | 6,00,000 to 40,00,000 |
| Awareness and communication platform (per 1,000 staff) | 50,000 to 3,00,000 |
| Incident and crisis management platform | 3,00,000 to 25,00,000 |
| BCM Lead (1 FTE, mid-market salary) | 18,00,000 to 35,00,000 |
| BCM Coordinator (1 FTE) | 9,00,000 to 18,00,000 |
| External BCM consultancy (initial implementation) | 15,00,000 to 50,00,000 (one-off) |
| External BCM support (annual retained) | 5,00,000 to 20,00,000 |
| Exercise programme (tabletop + simulation + full failover) | 8,00,000 to 30,00,000 |
| Awareness training (per 1,000 staff) | 2,00,000 to 8,00,000 |
The full annual stack for a 1,000-staff growing Indian firm typically lands between ₹70 lakh and ₹2 crore, with the median around ₹1.1 to ₹1.4 crore. The largest line items are BCM Lead and GRC platform; the smallest is the board portal.
Policy and Procedure Templates
The toolkit contains 17 ready-to-customise documents. The five most central to Clause 5.1 are summarised here; full templates are in the toolkit folder.
BCM Leadership Charter (toolkit doc 01)
The apex 5.1 instrument. A 6 to 10 page document including: identification of top management; accountability statement; BCM Steering Committee mandate and membership; resourcing commitment; integration commitments; reporting cadence; executive sponsor's personal commitments. Approved at the executive committee, tabled at the board (or RMC). Reviewed annually alongside the management review.
Sample of the accountability clause (Singahi's own drafting for adaptation):
The Board of Directors and the executive management of [Organisation] accept accountability for the effectiveness of the Business Continuity Management System. The Board, through its Risk Management Committee, provides oversight. The executive management, through the designated executive sponsor (the [COO / CRO / CIO]) and the BCM Steering Committee, directs, resources and reviews the BCMS. Accountability for BCMS effectiveness is not delegable; the execution of specific tasks is delegated to the BCM Lead and process owners per the Sponsorship RACI.
Top-Management Commitment Plan Procedure (toolkit doc 02)
The operating procedure for the leadership architecture. Describes the nine accountability moves, the cadence of each, the owner, the evidence produced, and the storage location. References the BCM Leadership Charter, the Sponsorship RACI, the leadership-evidence index, and the board reporting pack.
Leadership Evidence Index (toolkit doc 03)
The one-page index of 5.1 evidence, mapped to the nine accountability moves. Maintained by the BCM Lead, approved by the executive sponsor, updated at each management review. The auditor's first stop.
Board Reporting Pack (toolkit doc 15 / Communications Plan)
The half-yearly BCM board / RMC report. A 6 to 10 page pack including: (a) executive sponsor's summary; (b) BCMS performance dashboard; (c) exercise outcomes; (d) incident and corrective-action summary; (e) regulatory and audit summary; (f) resource use and forward ask; (g) decisions sought.
Sponsorship RACI (toolkit doc 13)
The roles-and-responsibilities matrix that assigns top-management accountability for each Clause 5 to 10 outcome. The Accountable column is dominated by the executive sponsor and top management; the Responsible column runs through the BCM Lead and process owners.
Sample policy/contract "shall" clauses (Singahi's own drafting; permitted in toolkit templates):
ISO 22301:2019 Clause 5.1 asks organizations to have top management visibly lead the BCMS, integrating it into business processes, resourcing it, and driving its results.
The BCM Steering Committee shall meet at least monthly, review the BCMS performance dashboard, commission corrective actions, and report half-yearly to the Board Risk Management Committee.
The BCM Lead shall maintain the Leadership-Evidence Index, prepare the Management Review pack, convene the BCM Steering Committee, and operate the corrective-action register.
Risk Assessment and Treatment
Risks to leadership engagement (the 5.1 risk lens)
Clause 5.1 is itself subject to risk, leadership engagement can decay, drift, or fail to take root. A 5.1 risk assessment identifies the threats to leadership engagement (distinct from the broader Clause 6.1 BCMS risk assessment, which addresses continuity risks to the business). The 5.1 risk register typically contains entries like:
| ID | Risk | Cause | Consequence | Likelihood | Impact | Treatment |
|---|---|---|---|---|---|---|
| L5.1-01 | Executive sponsor rotation | CXO turnover, restructuring | Loss of 5.1 continuity; re-onboarding cost | Medium | High | Sponsorship RACI includes alternate sponsor; BCM Charter binds role, not individual; onboarding pack for new sponsor |
| L5.1-02 | BCM drops off board agenda | Board cycle compression, competing topics | Drift in board oversight; SEBI LODR Reg. 21 exposure | Medium | High | Standing agenda item in board/RMC calendar; half-yearly BCM report guaranteed slot |
| L5.1-03 | BCM becomes "IT project" | Historic IT ownership of BCM; budget silo | Loss of business-process integration; 5.1(c) failure | High | High | Executive sponsor from business side (COO preferred); integration map; BCM in business-process procedures |
| L5.1-04 | Resource decision deferred | Competing capex priorities | BCM under-resourced; 5.1(d) failure | Medium | High | BCMS Resource Plan approved annually; capex flagged at capital committee |
| L5.1-05 | Leadership-evidence index not maintained | BCM Lead bandwidth; tooling gap | 5.1 audit failure | Medium | High | Index is BCM Lead KPI; tooling supports index; audited annually |
| L5.1-06 | Management review skipped | Calendar pressure; executive travel | 9.3 + 5.1(e) failure; certificate risk | Low | Critical | Calendar locked 12 months ahead; quorum rules in charter |
| L5.1-07 | Exercise not sponsored | Sponsor travel; sponsor disinterest | Loss of tone-from-the-top; reduced exercise value | Medium | Medium | Sponsorship is personal objective; alternate sponsor for rescheduled exercises |
| L5.1-08 | Integration checkpoints erode | Process owner rotation; budget cuts | BCM becomes parallel programme; 5.1(c) failure | Medium | High | Integration map audited annually; checkpoints named in business-process procedures |
| L5.1-09 | CERT-In / DPDP clock missed during crisis | Leadership unreachable; war-room fails | Regulatory penalty; reputational damage | Low | Critical | War-room rehearsed annually; delegation-of-authority pre-agreed |
| L5.1-10 | Board doesn't understand BCM | Insufficient induction; technical jargon | Poor oversight decisions; risk-acceptance without basis | Medium | Medium | Board BCM induction pack; half-yearly report uses board-grade language |
| L5.1-11 | Variable pay not linked | HR process gap | Weakened executive sponsor accountability | Medium | Medium | BCM KPI in executive scorecard (L4+ practice) |
| L5.1-12 | Corrective actions stall | Sponsor not driving closure | 10.1 + 5.1(h) failure; recurring findings | Medium | High | Corrective-action register reviewed at every Steering Committee; sponsor signs off closure |
The leadership-rotation risk
The single most consequential 5.1 risk in the Indian market is leadership rotation. Indian growing companies typically rotate CXOs every 3 to 5 years (faster in private-equity-backed firms); BCM sponsorship that is bound to an individual rather than a role breaks at every rotation. The treatment is to bind sponsorship to the role (e.g., "the COO is the executive sponsor") rather than to the individual, and to maintain an onboarding pack for new sponsors that compresses the BCM context into a 60-minute briefing.
The integration-erosion risk
The second most consequential 5.1 risk in the Indian market is integration erosion. Process owners rotate even faster than CXOs; BCM checkpoints embedded in vendor onboarding, project gating, HR induction, audit cycles and risk reporting quietly disappear unless reinforced. The treatment is annual internal-audit testing of integrated checkpoints, with the test results reported to the executive sponsor at the management review.
The compliance-vs-resilience risk
A subtler 5.1 risk is that leadership engagement becomes compliance-theatre, strong evidence file, weak resilience outcome. The treatment is the outcome-based KPI set (Section 12) and the management review discipline that asks "would we actually recover?" rather than "is the evidence complete?".
Audit and Compliance Checklist
The 27 questions below are the ones certification auditors (and Stage 1 reviewers) most often raise against Clause 5.1. For each, the expected evidence and the common red flag are listed. The toolkit (doc 04) provides a printable version.
Identification and accountability
- Has the organisation identified, by name and role, who constitutes "top management" for the BCMS? Expected: Top Management Identification statement. Red flag: "the management team" without names.
- Is there a designated executive sponsor with 5.1 accountability? Expected: BCM Leadership Charter signed by sponsor. Red flag: sponsor not named, or sponsor is "the BCM Lead".
- Has the board / Risk Management Committee been briefed on the BCMS? Expected: board/RMC minutes recording BCM tabling. Red flag: no board trace of BCM (for listed or regulated entities, this is also a SEBI LODR / RBI MD / IRDAI breach).
- Is the accountability statement explicit that BCMS effectiveness accountability is not delegable? Expected: BCM Leadership Charter accountability clause. Red flag: accountability handed to BCM Lead in writing.
- Is there an alternate sponsor for absence periods? Expected: Charter naming alternate. Red flag: no alternate; sponsor absence blocks decisions.
Policy, objectives, integration
- Has top management approved the BCMS Policy? Expected: signed policy. Red flag: policy signed by BCM Lead alone.
- Are the BCMS objectives approved by top management? Expected: signed objectives register. Red flag: objectives set by BCM Lead without executive review.
- Is there an explicit alignment test between the BCMS objectives and the strategic plan? Expected: executive committee minute recording alignment discussion. Red flag: no minute; objectives in a vacuum.
- Is there an integration map of BCMS checkpoints in business processes? Expected: one-page integration map. Red flag: no map; "BCM is the BCM Lead's job".
- Are BCM checkpoints named in the vendor onboarding procedure? Expected: procedure reference. Red flag: BCM not mentioned in vendor management documentation.
- Are BCM checkpoints named in the project approval / gating procedure? Expected: procedure reference. Red flag: BCM absent from project gating.
- Are BCM checkpoints named in HR onboarding? Expected: induction module. Red flag: BCM not in induction.
Resources, communication
- Is there a BCMS Resource Plan approved by top management? Expected: signed Resource Plan. Red flag: no Resource Plan; budget held informally.
- Are actuals tracked against plan? Expected: quarterly variance reports. Red flag: plan made once, never tracked.
- Is the BCM Steering Committee meeting at the cadence committed in the Charter? Expected: minutes. Red flag: committee did not meet; or met without quorum.
- Is there a leadership-authored BCM communication in the last twelve months? Expected: letter, video, town hall recording. Red flag: no leadership communication.
- Has the executive sponsor sponsored at least one exercise in the cycle? Expected: exercise report with sponsor attendance. Red flag: sponsor never attends exercises.
- Is the board reporting pack delivered on cadence? Expected: half-yearly board pack. Red flag: pack not delivered; or delivered without leadership signature.
Outcomes, direction, support
- Is the KPI dashboard reviewed at the executive committee? Expected: executive committee minutes recording KPI review. Red flag: dashboard exists, never reviewed at executive level.
- Are major nonconformities reviewed by top management personally? Expected: corrective-action register with sponsor sign-off. Red flag: register maintained by BCM Lead alone.
- Is there a Sponsorship RACI covering Clause 5 to 10 outcomes? Expected: RACI document. Red flag: no RACI; or RACI shows BCM Lead as Accountable for everything.
- Does the BCM Steering Committee have an obstacle-removal agenda item? Expected: minutes. Red flag: no obstacle discussion; BCM Lead firefighting alone.
- Are functional heads' performance objectives tied to BCMS indicators? Expected: HR performance objective records. Red flag: BCM absent from functional scorecards.
Management review, improvement
- Did the executive sponsor attend the most recent management review in person? Expected: management review minutes with attendance. Red flag: sponsor "apologised"; sent a delegate.
- Is there a leadership-evidence index, mapped to the nine accountability moves? Expected: index document. Red flag: no index; evidence scattered.
- Is there a multi-year BCMS maturation plan approved by top management? Expected: signed maturation plan. Red flag: no plan; year-on-year improvement not designed.
- Has the executive sponsor reviewed the leadership-evidence index in the last twelve months? Expected: sponsor signature on the index cover. Red flag: index maintained but not reviewed.
Sector-specific (the auditor's Indian extension pack)
- (BFSI) Is the board's Risk/IT Committee oversight of BCM documented per the RBI Master Direction IT Governance? Expected: committee charter references BCM; minutes record BCM review. Red flag: no committee BCM mandate.
- (Listed) Has the Risk Management Committee (SEBI LODR Reg. 21) considered BCM? Expected: RMC minutes recording BCM discussion. Red flag: BCM not on RMC agenda.
- (Insurer) Is the BCM policy board-approved per IRDAI ICS Guidelines 2023? Expected: signed board policy. Red flag: BCM policy not board-approved.
Metrics and KPIs
Figure · Measures
The measures that show Clause 5.1 is working
- Steering Committee cadence compliance100%Quarterly
- Executive sponsor attendance rate≥ 90%Quarterly
- Board / RMC BCM reporting cadence compliance100%Half-yearly
- BCM Leadership Charter currency≤ 365Annual
- Integration map currency≤ 365Annual
Clause 5.1 KPIs are leadership-engagement KPIs, distinct from the broader BCMS-outcome KPIs (which sit under Clause 9.1). The fifteen KPIs below are the working set Singahi uses with Indian growing companies; the first ten are process KPIs (leadership activities), the last five are outcome KPIs (what the leadership activities produce).
Process KPIs (leadership activities)
| # | KPI | Formula | Target | Frequency | Owner |
|---|---|---|---|---|---|
| 1 | Steering Committee cadence compliance | (Steering Committees held ÷ planned) × 100 | 100% | Quarterly | BCM Lead |
| 2 | Executive sponsor attendance rate | (Sponsor attended ÷ scheduled) × 100 | ≥ 90% | Quarterly | BCM Lead |
| 3 | Board / RMC BCM reporting cadence compliance | (Reports delivered ÷ planned) × 100 | 100% | Half-yearly | Executive sponsor |
| 4 | BCM Leadership Charter currency | Days since last Charter review | ≤ 365 | Annual | Executive sponsor |
| 5 | Integration map currency | Days since last integration map review | ≤ 365 | Annual | BCM Lead |
| 6 | Integrated checkpoint coverage | (Business processes with BCM checkpoints ÷ in-scope business processes) × 100 | ≥ 80% | Annual | BCM Lead |
| 7 | Resource Plan approval timeliness | Days from fiscal year start to Resource Plan approval | ≤ 60 | Annual | Executive sponsor |
| 8 | Leadership communication frequency | Communications issued ÷ planned | ≥ planned | Annual | Executive sponsor |
| 9 | Management review attendance | (Top-management attendees ÷ expected) × 100 | 100% | Annual | BCM Lead |
| 10 | Exercise sponsorship rate | (Sponsored exercises ÷ planned) × 100 | 100% | Annual | BCM Lead |
Outcome KPIs (what leadership produces)
| # | KPI | Formula | Target | Frequency | Owner |
|---|---|---|---|---|---|
| 11 | BCMS outcomes attainment | (Outcomes met ÷ outcomes set) × 100 | ≥ 90% | Annual | Executive sponsor |
| 12 | Major NC closure cycle time | Average days from major NC raised to closed | ≤ 60 | Quarterly | BCM Lead |
| 13 | BCMS maturity advancement | Maturity level change year on year | ≥ +1 level over 3 years | Annual | Executive sponsor |
| 14 | Regulatory clock compliance | (Regulatory notifications on time ÷ total notifications) × 100 | 100% | Quarterly | BCM Lead |
| 15 | Workforce perception of leadership commitment | Survey score: "Leadership is committed to BCM" | ≥ 4.0/5.0 | Annual | HR / BCM Lead |
Dashboard design
The leadership dashboard is the executive committee and board / RMC view of the BCMS. Effective design is one page, four quadrants: (a) process KPIs (leadership activities); (b) outcome KPIs (what leadership produced); (c) incident and corrective-action summary; (d) decisions sought. The dashboard is delivered monthly to the executive committee, half-yearly to the board / RMC.
KPI failure patterns
Three patterns indicate KPI failure:
- Process KPIs green, outcome KPIs red. Leadership activity is high; resilience is not improving. The signal of compliance-theatre.
- Outcome KPIs without baseline. "100% RTO compliance" without a defined baseline and a credible measurement method is a vanity KPI.
- KPI set unchanged year on year. A static KPI set signals that the BCMS is not maturing. The KPI set should evolve with the maturity model (Section 22).
Common Pitfalls and Audit Failures
The eleven anti-patterns below are the named, memorable failure modes Singahi encounters most often in Indian growing companies pursuing ISO 22301. Each is a 5.1-specific finding; each has a known treatment.
The "signature-only" sponsorship
The single most common 5.1 failure. The executive sponsor signed the policy once, has not seen it since. The leadership-evidence file contains one signature and nothing else. Treatment: build the leadership-evidence index, populate the nine moves, review quarterly.
The "BCM is IT" framing
BCM is positioned organisationally as an IT function. The executive sponsor is the CIO; the BCM Lead reports into IT; business-process integration is weak. Treatment: reposition BCM under the COO or CRO; re-charter the Steering Committee with business-side dominance; rebuild the integration map.
The parallel programme
BCM runs alongside the business, not inside it. Separate objectives, separate cadences, separate reporting. The auditor's integration test fails. Treatment: re-weld BCM checkpoints into business-process procedures; assign business-process owners accountability for the checkpoints.
The "checked box" management review
The management review (Clause 9.3) is conducted as a one-hour agenda item, not a real review. No prior reading; no challenge; no decisions. Treatment: design the management review as a half-day offsite with prior reading; record challenge and decisions in the minutes.
The un-resourced BCMS
The Resource Plan is an aspirational document. Actual budget allocation is half of plan; headcount is one FTE instead of three; tooling is "we will look at it next year". Treatment: approve the Resource Plan at the executive committee; track quarterly; escalate variances.
The absent sponsor
The executive sponsor is chronically absent from Steering Committee, exercises, and the management review. The BCM Lead runs the BCMS alone. Treatment: trigger the alternate sponsor; raise with the board; consider sponsor change.
The "consultant is my BCMS" pattern
The BCMS is, in substance, the consultancy's work product. Leadership engagement has been outsourced. The auditor interviews the executive sponsor and finds they cannot describe the BCMS scope. Treatment: knowledge-transfer plan from consultancy to internal team; leadership-only BCM briefings; reduce consultancy role to advisory.
The "frozen" leadership architecture
The BCM Charter was written three years ago, has not been updated, and does not reflect the current organisation (post-acquisition, post-restructuring, post-leadership-change). Treatment: refresh the Charter at every management review; version history demonstrates currency.
The integration map that exists only on paper
The integration map shows BCM checkpoints in vendor onboarding, project gating, HR induction. The vendor manager, the project office, the HR onboarding lead have never heard of them. Treatment: re-weld the checkpoints with the process owners; verify operation in internal audit.
The open-loop corrective action
Corrective actions are raised but do not close, or close without effectiveness verification. The 5.1(h) continual-improvement test fails. Treatment: the executive sponsor personally reviews major NCs; closure requires effectiveness evidence.
The war-room that never met
The crisis management plan calls for an executive war-room. It has never convened, not in exercises, not in real disruptions. When a real disruption hits, the war-room is convened ad hoc, without pre-decided activation triggers, decision rights, or communication pathways. Treatment: rehearse the war-room annually as part of the exercise programme.
Illustrative Scenario 1: Failure, Kaveri Cooperative Bank (Illustrative)
Illustrative scenario, a composite example for guidance, not a specific Singahi engagement or a verified outcome.
Disclaimer. The following scenario is illustrative. Names, dates, and figures are composite and drawn from patterns in published RBI enforcement actions and Indian cooperative-bank incidents. They do not describe any specific real entity. The scenario is provided to make the leadership and commitment patterns concrete; it is not a factual account of a single organisation.
The organisation
Kaveri Cooperative Bank (a composite name) is an urban cooperative bank in Karnataka with approximately 480 staff, 38 branches, ₹4,200 crore in deposits, and a technology stack comprising a core banking system (CBS) hosted on-premises at the head office in Bengaluru, an Internet banking platform hosted by a third-party digital banking SaaS provider, and a payment switch connecting to NPCI for UPI, IMPS, and NEFT. The bank is regulated by the Reserve Bank of India under the complete cyber security framework for urban cooperative banks (graded approach, December 2019) and the Master Direction on IT Governance, Risk, Controls and Assurance Practices (effective April 2024).
The leadership pattern (before the incident)
The bank's BCMS in 2023 to 2024 had the following leadership signature:
- The BCMS Policy was signed by the Managing Director in February 2022 and not re-signed or reviewed since.
- The executive sponsor was nominally the MD; the BCM function reported into the IT Head, who reported into the MD.
- The BCM Steering Committee did not exist as a standing body. IT Steering, which met quarterly, considered BCM as an agenda item approximately once every four meetings.
- The board's Audit Committee received an annual BCM update of approximately 15 minutes; the dedicated BCM board pack did not exist.
- The Resource Plan was not a separate document. BCM spend was buried in the IT budget.
- The integration map did not exist. Vendor onboarding, project gating, HR onboarding did not have BCM checkpoints.
- The management review was, in 2023, a 90-minute meeting in November, attended by the IT Head and the BCM Coordinator. The MD sent apologies.
- One DR drill was conducted in 2023 (tabletop); no full failover was attempted. The MD did not attend.
- The CERT-In 6-hour incident-reporting capability was, on paper, resourced through the IT team. In practice, the IT Head was the single point of contact; if the IT Head was unreachable, the capability broke.
The incident
On 11 November 2024 (composite date), a ransomware actor gained initial access to the bank's network through a phishing email opened by a branch officer. Over the following 36 hours, the actor moved laterally, encrypted approximately 70% of the bank's Windows-based servers including the CBS database replicas, and exfiltrated an estimated 1.2 lakh customer records (KYC, account balances, transaction history).
At the moment of disruption (the CBS becoming unavailable on 13 November 2024 at 04:00 IST), the bank's leadership-response cascade failed at six points:
- The IT Head was unreachable for the first 90 minutes. Mobile-phone records subsequently showed the IT Head was on a flight. The CERT-In 6-hour clock started ticking; no one with decision authority was reachable.
- The MD was informed at 06:30 but did not convene a war-room. There was no pre-decided war-room activation trigger; the MD's instinct was to wait for the IT Head to be reachable.
- CERT-In notification was filed at 17:42, 13 hours and 42 minutes after detection. The 6-hour clock was missed. The bank's first notification was, in fact, a call from CERT-In to the bank after the agency detected public reporting of customer complaints.
- The RBI notification was filed at 22:11, over 18 hours after detection. The RBI's expectation (under the Cyber Security Framework and the 2023 MD) is 2 to 6 hours.
- Customer communication did not occur until the bank's branches opened at 10:00 on 14 November, 30 hours into the disruption. By that time, social-media reporting of an outage had triggered customer panic; queues formed at branches; the local press was on-site.
- The DR site failed over partially. The CBS came up at the DR site 41 hours after disruption, but the data restoration point was 26 November 2024, a 17-day data loss. The bank's stated RPO was 4 hours.
The losses
The direct and indirect losses from the incident, as eventually aggregated in the post-incident review and reflected in subsequent RBI supervisory correspondence (composite), were:
- ₹2.4 crore in emergency IT and forensic response costs.
- ₹1.1 crore in customer service credits and fee waivers granted under RBI supervisory pressure.
- ₹0.6 crore in additional staffing costs (branch overtime, customer call-centre surge).
- ₹0.4 crore in legal and consultancy costs (DPDP breach notification defence, customer-class-action response).
- ₹0.3 crore in reputational repair (customer communication campaign, deposit-rate incentives to stem withdrawal).
- Estimated ₹0.4 crore in lost interest income from deposit outflow over the subsequent 60 days.
- Total quantified loss: approximately ₹5.2 crore over the 90 days following the incident.
The RBI supervisory action
In its post-incident supervisory review (composite), RBI identified the root cause as governance failure:
- The bank's board had not, in the supervisory authority's assessment, exercised adequate oversight of BCM.
- The Risk Management Committee (mandated for the bank under the cooperative-bank governance framework) had not considered BCM at any meeting in the preceding 24 months.
- The bank had not implemented the 2023 Master Direction's IT governance requirements at board level.
- The bank's CERT-In compliance was paper-compliant but operationally absent.
RBI's supervisory action (composite) included: a monetary penalty; a Special Audit under the Banking Regulation Act, 1949 (AACS) at the bank's cost; restrictions on onboarding new digital banking customers until remediation was verified; mandatory board-level BCM training; a 12-month timeline to demonstrate full implementation of the 2023 MD IT Governance framework including board-level accountability.
The 5.1 lessons
The Kaveri scenario is a textbook 5.1 failure with five lessons for Indian growing companies:
- A signature is not sponsorship. The bank had a signed BCMS Policy. The signature produced zero resilience on the day. The 5.1 audit tests visible engagement, not signatures.
- Integration failure is operational failure. Because BCM checkpoints were not integrated into HR onboarding (phishing awareness), vendor management (the third-party Internet banking platform's BCM had not been reviewed), or risk reporting (BCM risks were not in the enterprise risk register), the BCM the bank had on paper did not reflect the bank it actually operated.
- Resource decisions are tested by outage, not by audit. The single-IT-Head PoC for CERT-In was a resource decision (or non-decision). On the day, the resource gap became a regulatory breach.
- War-room rehearsal is leadership evidence. The bank's crisis management plan called for a war-room; it had never been rehearsed; the MD did not convene it under pressure. Rehearsal is 5.1 evidence.
- Board oversight is statutory, not optional. For an RBI-regulated cooperative bank, the board's RMC has BCM oversight. Failure to exercise it is a supervisory matter, not merely an audit finding.
The total cost of the 5.1 failure in the Kaveri scenario, direct losses plus supervisory-action costs plus reputational damage plus the cost of mandated remediation, was in the range of ₹8 to ₹12 crore, against a BCM budget in the prior year of approximately ₹35 lakh. The bank spent roughly 25 to 35 times more on the failure than the leadership engagement would have cost to prevent.
Illustrative Scenario 2: Success, Sarthak Logistics (Illustrative, with ROI)
Disclaimer. The following scenario is illustrative. Names, dates, and figures are composite and drawn from patterns in published Indian logistics-sector resilience cases and monsoon-disruption events. They do not describe any specific real entity. The scenario is provided to make the leadership-and-commitment patterns concrete; it is not a factual account of a single organisation.
The organisation
Sarthak Logistics (a composite name) is a Mumbai-based third-party logistics provider with approximately 720 staff, eight warehouses (Mumbai, Pune, Bengaluru, Chennai, Hyderabad, Delhi, Kolkata, Coimbatore), and an annual turnover of approximately ₹480 crore. The company provides contract logistics for six enterprise customers in the automotive, FMCG, and consumer electronics sectors. The Mumbai and Pune warehouses are the largest, handling approximately 55% of the company's throughput. Tarang has been ISO 9001 certified since 2014; ISO 22301 certification was targeted for the fiscal year 2025 to 2026, motivated by enterprise-customer BCM clauses and a strategic ambition to enter pharmaceutical logistics.
The leadership architecture (the four-year build)
Tarang's leadership engagement with BCM was built deliberately over four years, sponsored by the COO (the executive sponsor) and overseen by the board's Risk Committee. The architecture in place by mid-2025 had the following signature:
- The BCM Leadership Charter, version 3.1, was signed by the COO and tabled at the board Risk Committee in May 2025. The Charter named the executive sponsor (the COO), the alternate sponsor (the CFO), the BCM Steering Committee membership (COO, CFO, CIO, CHRO, Head of Operations, BCM Lead, Internal Audit Head), the decision rights, the resourcing commitment (₹1.4 crore over three years), and the integration commitments (vendor onboarding, project approval, capex, HR onboarding, audit cycle, risk reporting, M&A due diligence).
- The BCM Steering Committee met monthly. Attendance: 11 of 12 meetings in the preceding 12 months had the COO present; the CFO deputised for the one absence.
- The board Risk Committee received a half-yearly BCM report. The COO presented; the BCM Lead attended for Q&A.
- The Resource Plan was a separate document, approved annually by the executive committee. The fiscal year 2026 plan committed ₹52 lakh to BCM (BCM Lead salary, awareness training, exercise programme, GRC platform subscription, external advisory).
- The integration map showed BCM checkpoints in vendor onboarding (BCM questionnaire for all critical suppliers), project approval (BCM checkpoint in the project gating template), capex approval (BCM business-case requirements for facilities over ₹50 lakh), HR onboarding (BCM module in induction, every new hire), internal audit (BCM topics in annual audit plan), risk reporting (BCM KPIs in monthly risk report to executive committee), and M&A due diligence (BCM assessment template).
- The management review was held annually as a half-day offsite, attended by the full executive team plus the board Risk Committee chair. Prior reading was circulated 10 days in advance. The 2024 review (held March 2025) recorded 14 decisions.
- Two exercises per cycle were sponsored by the COO: a tabletop on a severe-but-plausible scenario (cloud-platform outage plus key-supplier failure), and a full simulation (warehouse fire at the largest site, with live evacuation, customer communication, and supplier-failover).
- The leadership-evidence index was maintained by the BCM Lead, reviewed by the COO at every Steering Committee, and audited annually by Internal Audit.
- The COO's annual performance objectives included two BCM indicators: (a) BCMS outcomes attainment ≥ 90%; (b) exercise sponsorship rate 100%.
The incident
In the second week of July 2025, the Mumbai-Pune expressway corridor was hit by an unprecedented monsoon event. Over 36 hours from 9 to 11 July, the corridor received over 450 mm of rainfall. The expressway was closed on 10 July evening. The Talaja warehouse complex (Mumbai side, fictional location name) lost grid power on 10 July at 21:00; the diesel generator failed to start due to flooding of the generator room. The Chakan warehouse complex (Pune side, fictional location name) was inaccessible by road from 10 July evening to 14 July afternoon, a 90-hour access loss.
The combined impact: Tarang could not operate its two largest warehouses for between 4 and 6 days. Approximately 38% of the company's throughput capacity was offline. The six enterprise customers were notified of force-majeure risk under their contracts within hours.
The leadership response
The leadership architecture produced a coordinated response in the first 12 hours:
- War-room activation, 10 July 21:38 (38 minutes after grid-power loss). The COO convened the executive war-room (COO, CFO, CIO, CHRO, Head of Operations, BCM Lead, Internal Audit Head). The activation trigger was pre-decided in the Charter: loss of more than 25% of throughput capacity for more than 4 hours. The war-room met every 8 hours for the duration of the disruption.
- Customer notification, 10 July 22:30. The COO personally called the six enterprise customers' logistics leads; the BCM Lead sent a written status update within 60 minutes of each call. The script had been rehearsed in the May 2025 tabletop exercise.
- Supplier-failover activation, 11 July 03:00. A pre-contracted work-area-recovery provider in Nashik (geographically separated from the Mumbai-Pune corridor) was activated for the Talaja warehouse operations. The contract had been a 2024 capex item, justified in the capex approval on BCM grounds.
- Rerouting, 11 July morning. The Head of Operations rerouted Bengaluru-, Chennai-, and Hyderabad-bound cargo through the Coimbatore and Hyderabad warehouses for the duration of the disruption.
- Workforce safety, 11 July 06:00. The CHRO activated the people-continuity plan: staff in flood-affected areas instructed to work from home or stay home; staff at the Talaja and Chakan sites instructed not to attempt the commute; emergency accommodation arranged for staff stranded at Chakan.
- Daily customer update, 11 to 14 July. The COO sent a daily 17:00 written update to each of the six customers covering: current status, expected resolution, contingency actions in place, financial impact estimate.
- Stand-down, 14 July 18:00. The COO formally stood down the war-room once both warehouses were accessible, the Chakan site was operating at 80% throughput, and the Talaja site was running on the Nashik work-area-recovery provider.
The financial outcome
The disruption cost Tarang approximately ₹2.1 crore in direct response costs (Nashik work-area-recovery activation, emergency rerouting, customer credit gestures, staff overtime). However, the avoidance effects were substantial:
- Zero customer SLA penalty triggered. All six customers had force-majeure clauses; Tarang's communication and contingency performance led all six to invoke force majeure rather than the SLA-penalty clause. Estimated SLA penalty avoided: ₹1.8 crore.
- Zero customer churn. All six customers renewed their contracts at the subsequent renewal cycle (in the three months following the disruption). Two customers extended their contracts.
- New contract win. In October 2025, Tarang won a ₹72 crore, three-year pharmaceutical-logistics contract from a multinational pharmaceutical company. The BCM architecture, the Charter, the integration map, the exercise programme, the war-room rehearsed, was, per the customer's RFP evaluation feedback, the deciding factor over two competing providers.
- Insurance claim paid in full. The business-interruption insurance policy paid ₹1.4 crore against the ₹2.1 crore direct cost. Tarang's leadership-sponsored insurance review (a 2024 exercise) had ensured the policy covered monsoon-related access loss, which is often excluded.
The ROI
Tarang's four-year leadership-led BCM investment was approximately ₹1.4 crore (Charter, Steering Committee, Resource Plan annual cycle, integration-map build, awareness training, exercise programme, GRC platform, external advisory, work-area-recovery retainer, insurance review). The disruption-avoidance plus new-contract value in the 12 months following the July 2025 monsoon event was approximately ₹3.2 crore (SLA penalty avoided ₹1.8 crore + insurance recovery ₹1.4 crore) plus the ₹72 crore new-contract contribution margin (estimated ₹9 to ₹11 crore over three years). Even on the conservative avoidance-only basis, the ROI was 2.3x within 12 months; including the new-contract contribution, the ROI was substantially higher.
The leadership architecture paid for itself in a single disruption. The certificate (Tarang achieved ISO 22301 certification in February 2026) was the receipt.
The 5.1 lessons
The Tarang scenario is a textbook 5.1 success with five lessons for Indian growing companies:
- Leadership engagement is the highest-ROI BCM investment. The Charter, the Steering Committee, the war-room rehearsal cost Tarang less than ₹40 lakh over four years; the avoidance was in crores.
- Integration is the operative word. The vendor checkpoint produced the Nashik work-area-recovery provider. The capex checkpoint produced the BCM-justified capex. The HR checkpoint produced the people-continuity plan. Each integration produced a concrete resilience capability.
- War-room rehearsal is the test. The May 2025 tabletop on a cloud-and-supplier scenario had rehearsed the war-room activation, the customer-communication script, and the supplier-failover protocol. The July monsoon activated a rehearsed capability, not an improvised response.
- Resource decisions compound. The 2024 capex for the Nashik retainer (₹18 lakh per year), the insurance review (₹4 lakh in advisory), and the exercise programme (₹12 lakh per year) compounded into the resilience that absorbed the July disruption. None of the three would have been made without the Resource Plan discipline.
- Customer-facing BCM is a sales asset. The pharmaceutical-contract win is the most striking 5.1 outcome, leadership-sponsored BCM, demonstrated through the Charter and the integration map, became the deciding factor in a ₹72 crore contract.
Multi-Framework Mapping
The detailed Clause 5.1 crosswalk
The table below maps Clause 5.1 to the corresponding leadership/accountability requirements across the major global and Indian frameworks. Use it to drop a real, verifiable cross-reference into any audit pack, customer RFP response, or board report.
| Framework | Reference | What it requires of leadership | Mapping strength |
|---|---|---|---|
| ISO 22301:2019 | Clause 5.1 | Top management must visibly lead and commit to the BCMS, the nine accountability moves | This is the subject standard |
| ISO/IEC 27001:2022 | Clause 5.1 | Top management must visibly lead and commit to the ISMS, structurally identical | Direct equivalence |
| ISO 9001:2015 | Clause 5.1 | Top management must visibly lead and commit to the QMS, Harmonized Structure | Direct equivalence |
| ISO 22313:2020 | Section 5 | Companion how-to for ISO 22301 Clause 5; explains visible-engagement method | Companion guidance |
| NIST SP 800-34 Rev 1 (May 2010) | Step 1, Contingency Planning Policy Statement | Leadership issues the policy statement as the first step of the seven-step contingency planning process | Strong analogue |
| NIST CSF 2.0 (Feb 2024) | Govern (GV) function, GV.OV, GV.RM, GV.RR, GV.PO, GV.SC, GV.OC | Governance function, organisational understanding, risk management strategy, roles and responsibilities, policy, supply chain, cybersecurity strategy | Strong structural mapping (GV ≈ Clause 5) |
| NIST SP 800-160 Vol 1 | Engineering principles | Leadership accountability for engineering trustworthy systems; life-cycle SSE process | Loose mapping |
| FFIEC BCM Booklet (Nov 2019) | Governance principle | Board and senior management accountability for BCM as an enterprise discipline. Issuance vehicles: OCC Bulletin 2019-57, FRB SR 19-13, FDIC FIL-19071-2019 | Strong analogue |
| SOC 2 (AICPA TSC 2017, with 2022 points of focus) | CC1.2, CC1.3, CC1.5, control environment | Board oversight of internal control; management-established structures, reporting lines, and authorities; individual accountability for control responsibilities | Strong analogue (CC1 ≈ Clause 5); the 5.1 evidence trail is what a SOC 2 auditor samples under CC1 |
| FEMA FCD-1 / FCD-2 (Jan / Jun 2017) | Continuity leadership | Designated agency-level continuity leadership under PPD-40 | Public-sector analogue |
| DORA (Reg EU 2022/2554, applies 17 Jan 2025) | Article 5(1) to (4) | Management body bears ultimate responsibility for managing ICT risk; approves the framework; ensures adequate resources; receives training. Article 5(4), management body members shall follow suitable training to identify and manage ICT risks | Direct regulator-level mapping |
| APRA CPS 230 (eff. 1 Jul 2025) | Paras 20 to 23 | Board ultimately accountable for op risk, business continuity and service-provider management; approves BCP and tolerance levels; oversees material incidents; ensures sufficient senior mgrs | Direct regulator-level mapping |
| APRA CPG 230 (companion) | Paras 20 to 23 guidance | Non-binding guidance on CPS 230 board accountability | Companion guidance |
| MAS TRM Guidelines (18 Jan 2021) | Board oversight section | Board and senior management accountability for technology risk including BCM | Strong analogue |
| MAS BCM Guidelines | Board role | Board accountability for BCM in financial institutions | Strong analogue |
| HKMA SPM OR-2 (31 May 2022) | Board role section | Board accountability for operational resilience; IBS identification; impact tolerance; severe-but-plausible scenario testing | Strong analogue |
| HKMA SPM TM-G-2 (31 May 2022) | Governance | Board and senior management accountability for BCM | Strong analogue |
| UK FCA / PRA Operational Resilience | Board accountability | Senior Managers Regime + Impact Tolerance setting accountability | Sectoral analogue |
| Companies Act 2013 §134(3)(n) | Board's Report | Statement on risk management policy including elements threatening existence of the company | Indian statutory mapping |
| Companies Act 2013 §177 + Rule 6 | Audit Committee | Audit Committee evaluation of internal financial controls and risk management | Indian statutory mapping |
| SEBI LODR Reg. 21 | Risk Management Committee | Board-level RMC covering cyber, ops, strategic, sustainability and continuity risks for listed entities | Indian statutory mapping |
| RBI MD IT Governance (7 Nov 2023, eff. 1 Apr 2024) | Governance chapter | Board accountable for IT governance framework including BCP/DR policy, RTO/RPO, DR drill cadence, incident mgmt | Indian regulator-level mapping |
| RBI Cyber Security Framework (2 Jun 2016) | Board cyber policy | Board-approved cyber security policy; Cyber Crisis Management Plan; 24x7 SOC; 2 to 6-hour incident reporting | Indian regulator-level mapping |
| RBI MD Outsourcing of IT Services (10 Apr 2023) | Board oversight | Board accountability for outsourced BCM continuity controls inheriting RE standards | Indian regulator-level mapping |
| RBI Complete CSF for UCBs (31 Dec 2019) | Board graded oversight | Board ensures BCP/DR capability supports cyber resilience objectives | Indian regulator-level mapping (UCBs) |
| SEBI CSCRF (20 Aug 2024) | Governance goal | First of five Cyber Resilience Goals; board accountability; RMG-1, RMG-2 control family | Indian regulator-level mapping |
| SEBI BCP-DR for MIIs (22 Mar 2021) | Board-approved BCP | Board-approved BCP/DR; RTO/RPO definition; live/parallel drills | Indian regulator-level mapping (MIIs) |
| IRDAI ICS Guidelines 2023 (24 Apr 2023) | Board policy | Board-approved Information and Cyber Security Policy including BCP/DR; Board's Risk/IT committee oversight | Indian regulator-level mapping (insurers) |
| CERT-In Directions 20(3)/2022 (28 Apr 2022) | Point of Contact | Leadership-designated PoC; 6-hour clock requires leadership-resourced capability | Indian horizontal mapping |
| DPDP Act 2023 §8(5), §8(6) | Data Fiduciary duty | Availability of personal data as leadership-owned outcome; 72-hour breach notification | Indian statutory mapping |
| DPDP Rules 2025 (notified Nov 2025) | Breach notification | Leadership accountability for 72-hour notification clock and breach response | Indian statutory mapping |
| DM Act 2005 + NDMA guidelines | Departmental / industrial DMP | Leadership accountability for integration with District DMPs; Section 40 for govt departments; Chemical Disaster Guidelines 2007 for MAH units | Indian sectoral mapping |
| IT Act 2000 §70A, §70B | NCIIPC / CERT-In | Statutory basis for leadership accountability for critical information infrastructure protection | Indian statutory mapping |
How to use this mapping
- For audit. When the certification auditor asks "how does your 5.1 implementation compare to other leadership/accountability frameworks?", this table provides the verifiable cross-references.
- For customer RFPs. When a customer asks "do you comply with DORA / APRA CPS 230 / MAS TRM / FFIEC BCM?", the answer maps the 5.1 evidence to the customer's home framework.
- For board reporting. When the board asks "how does our BCMS leadership compare to our peer group?", the cross-framework anchors provide the answer.
- For multi-standard maintenance. When the organisation runs ISO 22301 + ISO 27001 + ISO 90001, the leadership evidence file maps cleanly across all three Clause 5.1 requirements.
The integration gain
The integration opportunity is real and substantial. An Indian growing company that runs an integrated management system (ISMS + BCMS + QMS) under a single executive sponsor, a single BCM/ISMS/QMS Leadership Charter, a single Steering Committee, and a single management review cycle will produce a leadership-evidence file that satisfies three clauses across three standards with marginal additional effort over a single-standard implementation. The integration gain is one of the strongest arguments for pursuing concurrent ISO certifications in India.
Implementation Roadmap
The 30/90/180-day roadmap below is the typical path Singahi uses with Indian growing companies to build a 5.1-conformant leadership architecture from a cold start. The roadmap is calibrated for a 600-person firm with an existing ISO 27001 certification; smaller firms compress the timeline, larger firms extend it.
Days 0 to 30, Foundation
Week 1 to 2:
- Identify the executive sponsor and the alternate sponsor (top management decision).
- Identify the BCM Steering Committee membership (executive sponsor and BCM Lead).
- Stand up the BCM Lead role (existing FTE or new hire; if external,Knowledge-transfer plan to internal FTE within 6 months).
- Build the Top Management Identification statement.
Week 3 to 4:
- Draft the BCM Leadership Charter (toolkit doc 01). Initial 4-page draft by the BCM Lead; review by the executive sponsor.
- Map the current-state leadership evidence (what exists, what does not, what is missing).
- Schedule the executive committee meeting at which the Charter will be adopted.
Day 30 deliverables: Top Management Identification statement; BCM Leadership Charter v0.9 draft; current-state leadership evidence map; executive committee meeting on the calendar.
Days 31 to 90, Build
Week 5 to 8:
- Adopt the BCM Leadership Charter at the executive committee. Minute the discussion and decision.
- Approve (or re-approve) the BCMS Policy (Clause 5.2) at the same executive committee meeting. Minute the alignment with strategic direction.
- Approve the BCMS Objectives (Clause 6.2) at the same meeting. Minute the alignment discussion.
- Build the integration map (one-page; identifying which business processes will host BCM checkpoints).
Week 9 to 12:
- Weld BCM checkpoints into the priority business processes. Typical starting set: vendor onboarding, project gating, capex approval, HR induction. Update each business-process procedure to name BCM as a checkpoint; assign ownership of each checkpoint.
- Build the BCMS Resource Plan for the current fiscal year. Approve at the executive committee.
- Build the Sponsorship RACI (toolkit doc 13). Assign Accountable/Responsible/Consulted/Informed for each Clause 5 to 10 outcome.
- Build the leadership-evidence index v1.0 (toolkit doc 03). Populate with the evidence produced to date.
- Schedule the management review (Clause 9.3) for day 180.
Day 90 deliverables: Adopted Charter; signed Policy; signed Objectives Register; integration map; Resource Plan; Sponsorship RACI; leadership-evidence index v1.0; management review on the calendar.
Days 91 to 180, Operate
Week 13 to 18:
- Run the first two BCM Steering Committee meetings. Stand agenda: KPI dashboard; obstacles; corrective-action review; decisions sought. Minute each.
- Author the first leadership BCM communication (executive sponsor's letter or video to all staff). Release.
- Run a leadership-sponsored tabletop exercise on a severe-but-plausible scenario. The executive sponsor attends. Exercise report produced with sponsor sign-off.
- Build the board / RMC reporting pack (toolkit doc 15). Deliver the first half-yearly report to the board / RMC.
- Begin populating the corrective-action register (Clause 10.1) with findings from the exercise.
Week 19 to 24:
- Continue monthly BCM Steering Committee meetings.
- Begin populating the integrated checkpoints with real operation: vendor onboarding runs the BCM questionnaire; project gating runs the BCM checkpoint; HR induction delivers the BCM module.
- Begin populating the KPI dashboard (Clause 9.1) with first cycle's data.
- Conduct the management review (Clause 9.3) at day 180. Executive sponsor chairs; full executive team attends; prior reading circulated 10 days ahead. Minute the decisions.
Day 180 deliverables: Operational Steering Committee with two meeting cycles of minutes; first leadership BCM communication; first sponsored exercise report; first board / RMC pack; operational integrated checkpoints in priority business processes; KPI dashboard v1.0 with first cycle data; first management review minutes with decisions.
Days 181 to 365, Mature
- Continue the monthly Steering Committee cadence.
- Run a second sponsored exercise (full simulation rather than tabletop).
- Deliver the second board / RMC pack.
- Begin internal audit (Clause 9.2) of the 5.1 architecture, with focus on the integration map and the leadership-evidence index.
- Refresh the BCM Leadership Charter for year 2 based on the first management review's decisions.
- Plan year 2 Resource Plan.
Beyond year 1
By the end of year 1, the 5.1 architecture is operational. Year 2 onwards is about maturity advancement (Section 22), moving from L3 to L4, then L4 to L5, with the executive sponsor leading the maturation investment. The L4 to L5 transition typically involves pay-linkage of the executive sponsor to BCM outcomes, GRC-platform-hosted evidence, predictive analytics on resilience posture, and benchmarking against sectoral peers.
FAQ
Q1. We are a 50-person SaaS startup. Do we really need a BCM Steering Committee?
A. The size of the Steering Committee scales. For a 50-person firm, the "BCM Steering Committee" may be the founders' weekly meeting with BCM as a 20-minute standing agenda item. The substance is what the auditor tests, visible leadership engagement, not the name of the forum.
Q2. Our CEO is too busy to attend the management review. Can we send the COO as delegate?
A. For listed entities and RBI/SEBI/IRDAI-regulated entities, the CEO/MD attendance is effectively required. For private growing companies, a delegated CXO is acceptable provided the delegation is explicit in the BCM Leadership Charter and the delegate has the authority to make decisions on behalf of top management. Repeated absence by the executive sponsor from the management review is, however, a 5.1 finding regardless of delegation.
Q3. Our internal audit team says they don't audit Clause 5 because "you can't audit leadership".
A. Internal audit can and should audit Clause 5.1. The method is to test the leadership-evidence index, does each of the nine accountability moves have dated, attributable evidence?, and to interview the executive sponsor and other top-management members. The standard audit question "show me the decisions top management has made for the BCMS in the last twelve months" is internal audit's question as much as the certification auditor's.
Q4. Our board's Risk Management Committee (under SEBI LODR Reg. 21) already covers cyber risk. Do we need a separate BCM board report?
A. No, you do not need a separate report; BCM fits naturally into the RMC's risk-oversight scope. What you need is a BCM-specific section within the RMC's half-yearly report, the executive sponsor's BCM summary, the BCMS dashboard, the exercise summary, the corrective-action status. The RMC minute recording BCM discussion is the 5.1 board-oversight evidence.
Q5. We outsource our BCM to a consultancy. Does that satisfy 5.1?
A. No. Clause 5.1 accountability cannot be delegated, including to a consultancy. The consultancy can draft documents, facilitate workshops, advise on architecture, but the executive sponsor's accountability remains personal. A BCMS that is, in substance, the consultancy's work product will fail the auditor's executive-sponsor interview at Stage 1.
Q6. Our BCM Lead is very competent. Why can't they be the executive sponsor?
A. The BCM Lead can be the operational owner of the BCMS but cannot be the executive sponsor because the executive sponsor must have the authority to allocate resources at the highest level, which a BCM Lead typically does not. The test is the authority-to-allocate-resources property; if the BCM Lead does not have it, they cannot be the executive sponsor.
Q7. Our management review is a one-hour slot at the executive committee's standing meeting. Is that enough?
A. It can be, for a small firm with a tightly-run executive committee. For growing firms and above, the management review is typically a half-day offsite with prior reading. The auditor tests whether the review produces decisions; if no decisions are minuted, the review was a status update, not a management review.
Q8. We have ISO 27001 certification already. Do we need to redo the leadership architecture for ISO 22301?
A. No, extend, don't redo. The Clause 5.1 architecture is structurally identical across ISO 27001 and ISO 22301; the existing ISMS leadership evidence file can be extended with continuity-specific content (BCM Steering Committee, board BCM report, sponsored exercises, integration checkpoints) to satisfy BCMS Clause 5.1.
Q9. The certification auditor wants to interview our CEO. We have never had a CEO interviewed in a surveillance audit. Is this normal?
A. Yes. The Harmonized Structure standards (ISO 27001, ISO 9001, ISO 22301, ISO 14001, ISO 45001) all expect the auditor to interview top management as part of the Clause 5.1 test. Interviewing the CEO/MD is normal; refusing the interview or sending a delegate without prior arrangement is a 5.1 finding.
Q10. Our board's Audit Committee says BCM is an operational matter, not a board matter.
A. For listed entities, this is incorrect under SEBI LODR Reg. 21 (the RMC's mandate includes continuity risk). For RBI-regulated entities, this is incorrect under the RBI Master Direction IT Governance (board accountable for IT governance including BCM). For unlisted private companies, the board's risk-oversight duty under Companies Act 2013 Section 134(3)(n) covers threats to the existence of the company, continuity risk plainly qualifies. The board cannot opt out of BCM oversight for any company of size.
Q11. We have never had a real disruption. How do we evidence 5.1(f) (the BCMS achieves its intended outcomes) without a real incident?
A. Evidence comes from exercise outcomes (sponsored exercise reports), from KPI dashboard results (RTO compliance, exercise coverage, regulatory clock compliance), from internal audit findings, and from corrective-action closure. A real incident is not required; a real exercise programme is.
Q12. Our consultancy charges ₹30 lakh for the BCMS implementation. Is that the right number for 5.1?
A. The 5.1 component of a BCMS implementation is typically 5 to 15% of the total engagement cost, leadership architecture design, executive coaching, board induction, toolkit customisation. The bulk of the engagement cost is on Clauses 8.2 (BIA), 8.3 (strategy), 8.4 (plans), and 8.5 (exercises). If the 5.1 component is more than 15% of the engagement, you may be over-paying for architecture at the expense of operational content.
Q13. Our executive sponsor changed last quarter. Is our 5.1 evidence void?
A. Not if the architecture is role-bound rather than individual-bound. The Charter names the role (e.g., "the COO is the executive sponsor"); when a new COO joins, the role-assignment continues. What is required: a 60-minute onboarding briefing for the new sponsor (Charter, current state, KPI dashboard, outstanding decisions, upcoming management review), and a Charter version bump to record the change. The leadership-evidence index continues to accumulate.
Q14. We do not have a Risk Management Committee under SEBI LODR Reg. 21 because we are not listed. Where does BCM board oversight sit?
A. For unlisted companies, BCM oversight sits with the Audit Committee (Companies Act 2013 Section 177(4)(vii), evaluation of internal financial controls and risk management) or, in the absence of an Audit Committee, with the full board. The board's risk-oversight duty under Section 134(3)(n) applies regardless of listing status.
Q15. We are an Indian subsidiary of a foreign parent. Which top management is the executive sponsor, ours or the parent's?
A. For a BCMS scope that covers the Indian subsidiary, the executive sponsor is the Indian subsidiary's top management (typically the India MD or COO). The parent's oversight is documented through a parent-level leadership evidence annexure. For a group BCMS covering multiple entities, the executive sponsor is typically the group executive sponsor, with entity-level sponsors for each in-scope entity.
Q16. How do we avoid the "signature-only" trap that catches so many Indian firms?
A. By building the leadership-evidence index from day one and populating it continuously. The discipline of maintaining the index, answering "what is the latest 5.1 evidence in each of the nine moves?" every month, is the strongest defence against the decay of leadership engagement into symbolic sponsorship.
Q17. Are there any 5.1 quick wins worth doing before we engage a consultancy?
A. Yes. Three: (1) adopt the BCM Leadership Charter at the next executive committee meeting; (2) add BCM as a standing 20-minute agenda item to the executive committee's monthly meeting; (3) author and release the executive sponsor's BCM letter to all staff. None requires external help; each produces audit-grade evidence; collectively they shift the 5.1 maturity from L1 to L2 within 60 days.
Industry-Specific Requirements
BFSI (banks, NBFCs, payment system operators, insurers)
BFSI is the most prescriptive sector for 5.1 because the Reserve Bank, SEBI, and IRDAI have all made leadership engagement with BCM an explicit regulatory expectation.
- RBI Master Direction IT Governance (7 Nov 2023, eff. 1 Apr 2024), the board is explicitly accountable for the IT governance framework, including BCP/DR policy, RTO/RPO definitions, DR drill cadence, incident management, and IT readiness for crisis events. The 5.1 architecture must include a board-level accountability instrument; the bank's Risk Management Committee (or Audit Committee, depending on governance structure) must consider BCM at planned intervals.
- RBI Cyber Security Framework (2 Jun 2016), the board must approve a cyber security policy; the bank must maintain a Cyber Crisis Management Plan (CCMP); 24x7 SOC; incident reporting to RBI within 2 to 6 hours of detection. The CCMP is a leadership-activated instrument; rehearsal of the CCMP is 5.1 evidence.
- SEBI CSCRF (20 Aug 2024), the first of five Cyber Resilience Goals is governance; board accountability is explicit. The 5.1 architecture for SEBI Regulated Entities must include the CSCRF governance goal controls (RMG-1, RMG-2 family).
- SEBI BCP-DR for MIIs (22 Mar 2021), board-approved BCP/DR; Near Site + DRS architecture; defined RTO (≤2 hours for critical systems) and RPO; live/parallel drills. The board-approval requirement is a 5.1 instrument.
- IRDAI ICS Guidelines 2023 (24 Apr 2023), board-approved Information and Cyber Security Policy including BCP/DR; Board's Risk/IT committee oversight; CISO; 180-day log retention; DR drills; data-locality for policyholder data.
For BFSI, the executive sponsor is typically the COO or CRO; the board Risk Committee is the oversight body; the CCMP is the war-room instrument; the audit committee oversees the corrective-action programme. The HDFC Bank RBI action of December 2020 (restriction on new digital products and fresh credit cards, partially lifted August 2021, fully lifted March 2022) is the canonical Indian example of regulatory enforcement against a leadership-engagement gap.
Healthcare
Healthcare leadership engagement has a patient-safety dimension that other sectors do not. The clinical-continuity aspects (continuity of care during outages; clinical escalation during disruption; patient-data availability) sit alongside the IT-continuity aspects.
- NDMA / NMC / clinical governance, clinical-continuity leadership is a clinical-governance matter, not just an IT matter. The CMO (Chief Medical Officer) and the COO share the executive sponsorship for hospitals.
- DPDP for healthcare, hospitals handling large patient datasets are typically Significant Data Fiduciaries; the 72-hour breach-notification clock and the availability duty under Section 8(5) attach personally to leadership.
- DPDP Rules 2025, operationalise the breach-notification form and timelines.
- AIIMS Delhi ransomware (November 2022), peer-reviewed case in International Journal of Information Management; the canonical Indian healthcare BCM case. The leadership gap (no fallback for clinical systems during the outage) was the substantive finding.
For healthcare, the executive sponsor is typically the COO with CMO co-sponsorship; the clinical-continuity dimension appears in the integration map (clinical-process checkpoints, patient-communication protocols, fallback procedures).
IT/ITeS and SaaS
IT/ITeS leadership engagement is shaped by the customer-contractual perimeter, enterprise customers (especially in BFSI and healthcare) impose BCM clauses that bind the supplier's leadership.
- Customer BCM clauses, enterprise customer contracts require supplier BCM (often ISO 22301 certification, supplier RTO/RPO disclosure, supplier exercise participation, supplier right-of-audit). The supplier's executive sponsor is the customer-facing leadership voice.
- Cross-border regimes, Indian SaaS / ITeS firms serving EU financial-sector customers must comply with DORA (applies 17 Jan 2025); Australian captive customers impose APRA CPS 230 (eff. 1 Jul 2025); Singapore customers impose MAS TRM; Hong Kong customers impose HKMA OR-2 / TM-G-2. Each cross-border regime has its own leadership-accountability anchor.
- Cognizant Maze ransomware (April 2020), SEC 10-Q/K disclosure of $50 to $70 million impact; the canonical Indian-IT-services BCM case. The leadership-engagement gap (incident-commander confusion in the first 12 hours) was a substantive finding.
For IT/ITeS, the executive sponsor is typically the COO or the delivery head; the customer-facing BCM materials are leadership-signed; the cross-border regimes appear in entity-level leadership evidence annexures.
Manufacturing (especially chemical / MAH)
Manufacturing leadership engagement has a physical-safety dimension that IT-only BCM does not. The integration of industrial plans with District Disaster Management Plans, the OT/IT boundary, and the multi-plant architecture each add leadership complexity.
- NDMA Chemical Disaster Guidelines 2007, on-site and off-site emergency plans; industrial BCP; mutual-aid arrangements; safety audits; integration of industrial plans with District DMPs. Leadership accountability is explicit.
- Disaster Management Act 2005 Section 35 / 37, duties of Ministries, State Governments, and (via Section 40) State Departments.
- OT/IT boundary, the leadership review must consider operational technology (SCADA, ICS, PLCs) alongside IT.
- LG Polymers Vizag gas leak (May 2020), NGT ₹50 crore penalty; the canonical Indian manufacturing BCM case. The leadership gap (no integration with off-site emergency plans) was a substantive finding.
For manufacturing, the executive sponsor is typically the plant director (for single-plant BCMS) or the group operations director (for multi-plant); the Works Committee / Factory Inspectorate interface appears in the leadership evidence.
Government and PSU
Government BCM leadership engagement is shaped by the Disaster Management Act 2005 and departmental DMP duties.
- Disaster Management Act 2005 Section 40, every Department of a State to prepare a DMP.
- NDMA Guidelines for DMPs for Ministries / Departments of GoI (2014), the canonical DMP template.
- RTI transparency, public-sector BCMS is subject to RTI scrutiny; the leadership-evidence file must be RTI-clean.
- Departmental Secretary accountability, for govt departments, the Secretary is the executive sponsor.
For government/PSU, the executive sponsor is the Secretary (for govt departments), the CMD/MD (for PSUs); the leadership evidence includes the DMP integration with the State/District DMP.
Maturity Model
The L1 to L5 maturity model below is calibrated for Clause 5.1 specifically. Each level has a behavioural signature (what leadership actually does), an evidence signature (what the leadership-evidence index contains), and an INR investment estimate for a 600-person growing Indian firm moving from the prior level.
L1, Signature-only sponsorship (the baseline failure)
- Behavioural signature. Top management signed the BCMS Policy once. No Steering Committee. No Charter. No board reporting. No sponsored exercises. No management review attendance. No resource decisions. BCM is the BCM Lead's job.
- Evidence signature. One signed policy. No leadership-evidence index.
- Audit outcome. Major nonconformity on Clause 5.1. Stage 1 fail.
- Estimated prevalence in Indian growing companies. Approximately 35 to 45%.
- Investment to advance to L2. ₹6 to ₹15 lakh (charter draft, executive sponsor briefing, first Steering Committee cycle, leadership-evidence index v1.0).
L2, Committee constituted (the structural step)
- Behavioural signature. BCM Steering Committee exists; meets quarterly (not monthly). Executive sponsor attends most meetings. Charter adopted. Resource Plan exists but is not tightly tracked. Integration map exists on paper but is not welded into business-process procedures. One exercise per year is sponsored. Management review is held but is a status update rather than a decision meeting. Board reporting pack is delivered annually (not half-yearly).
- Evidence signature. Leadership-evidence index v1.0 is populated for 5 of the 9 accountability moves.
- Audit outcome. Minor nonconformity or observation on Clause 5.1. Stage 1 pass with conditions; Stage 2 pass if conditions closed.
- Estimated prevalence in Indian growing companies. Approximately 30 to 40%.
- Investment to advance to L3. ₹10 to ₹25 lakh (integration-map welding, monthly Steering Committee cadence, half-yearly board reporting, management-review redesign, sponsored exercises to two per year).
L3, Integrated and operating (the certification-ready state)
- Behavioural signature. BCM Steering Committee meets monthly. Executive sponsor attendance ≥ 90%. Charter is current and board-tabled. Resource Plan is tracked quarterly with variance reports. Integration map is welded into business-process procedures; internal audit tests integrated checkpoints annually. Two exercises per cycle are sponsored (one tabletop, one simulation). Management review is a half-day offsite with prior reading and recorded decisions. Board reporting pack is delivered half-yearly. Leadership-evidence index is complete for all 9 accountability moves and reviewed by the executive sponsor at every Steering Committee.
- Evidence signature. Complete leadership-evidence index (9 of 9 moves), board minute trace, integrated checkpoint operation verified by internal audit.
- Audit outcome. Clean pass on Clause 5.1.
- Estimated prevalence in Indian growing companies. Approximately 10 to 20%.
- Investment to advance to L4. ₹15 to ₹40 lakh (GRC-platform hosting, real-time KPI dashboard, war-room rehearsal programme, multi-year maturation plan, board / RMC induction programme).
L4, GRC-platform hosted, real-time (the supervisor-grade state)
- Behavioural signature. Leadership evidence is hosted on a GRC platform with real-time status. KPI dashboard is reviewed monthly at the executive committee and quarterly at the board / RMC. BCM checkpoints are integrated into 5+ business processes including capital allocation and M&A due diligence. Executive war-room is rehearsed annually against severe-but-plausible scenarios. Multi-year maturation plan is approved by the board. BCM indicators appear in the executive sponsor's performance objectives. Internal audit covers Clause 5.1 every cycle. The leadership-evidence index is auto-maintained by the GRC platform.
- Evidence signature. GRC-platform-hosted leadership evidence; real-time dashboard; multi-year maturation plan; pay linkage; board-grade reporting.
- Audit outcome. Clean pass with commendation; supervisor-grade posture.
- Estimated prevalence in Indian growing companies. Approximately 3 to 8%.
- Investment to advance to L5. ₹25 to ₹60 lakh (predictive analytics, sectoral benchmarking, integrated resilience programme across BCM/ISMS/operational resilience, leadership team variable pay linkage to BCMS outcomes).
L5, Predictive, benchmarked, leadership-anchored (the sectoral leadership state)
- Behavioural signature. Top management owns the resilience narrative in board communications and external communications (customer, regulator, investor). BCM KPIs are part of the executive team's variable pay. Sectoral benchmarking is conducted annually; gaps drive multi-year investment. Predictive analytics surface emerging BCM risks to leadership ahead of the risk materialising. BCM is integrated into the enterprise risk management framework, the enterprise crisis-management function, and the enterprise operational-resilience programme. The leadership architecture is benchmarked against sectoral peers and used as a sales asset in customer engagement.
- Evidence signature. Predictive analytics on resilience posture; sectoral benchmark participation; pay linkage records; integrated resilience framework; customer-facing BCM leadership materials.
- Audit outcome. Clean pass; sectoral leadership posture; the BCMS is a market differentiator.
- Estimated prevalence in Indian growing companies. Less than 2%.
INR investment summary (cumulative, growing 600-person firm)
| Maturity step | Investment (₹) | Time (months) |
|---|---|---|
| L1 → L2 | 6 to 15 lakh | 2 to 4 |
| L2 → L3 | 10 to 25 lakh | 3 to 6 |
| L3 → L4 | 15 to 40 lakh | 6 to 12 |
| L4 → L5 | 25 to 60 lakh | 12 to 24 |
| Total L1 → L5 | 56 lakh to 1.4 crore | 23 to 46 months |
The total L1 to L5 investment range for a 600-person firm is approximately ₹56 lakh to ₹1.4 crore over 2 to 4 years, plus annual operating cost of ₹50 to ₹80 lakh per year from L3 onwards (BCM Lead, awareness, exercises, tooling). The investment compounds, each level makes the next cheaper and faster.
Emerging Trends
Six trends are reshaping Clause 5.1 practice in India and globally. Each has implications for how leadership engagement is evidenced over the next 24 months.
Operational resilience displacing business continuity as the leadership frame
Internationally, the supervisory conversation has shifted from "business continuity" (a documentation discipline) to "operational resilience" (an outcome discipline). UK FCA/PRA operational resilience policy, HKMA OR-2, EU DORA, and APRA CPS 230 all frame leadership accountability around impact tolerances and Important Business Services rather than plans. Indian supervisors are following suit; the RBI's 2023 MD IT Governance signals the shift. For Clause 5.1, this means the executive sponsor's accountability is increasingly framed as "the organisation remains able to deliver critical operations through severe disruption" rather than "the organisation has a BCP". The leadership-evidence index will need to include tolerance-setting (the APRA CPS 230 para 38 triple) and severe-but-plausible scenario testing as new evidence types.
Pay-linkage of executive sponsor to BCM outcomes
Indian BFSI has begun linking executive variable pay to operational-resilience outcomes; the practice is spreading to other regulated sectors. For 5.1, pay-linkage is a leading-practice signal of L4 to L5 maturity. The treatment is to define a small number (typically two or three) of BCM indicators in the executive sponsor's annual performance objectives, BCMS outcomes attainment, exercise sponsorship rate, regulatory clock compliance, and to track them through the year.
Climate-related continuity risks (ISO 22301 Amendment 1:2024)
ISO 22301:2019 / Amd 1:2024 introduces climate-change considerations into Clauses 4.1 and 4.2. For Clause 5.1, the implication is that the executive sponsor's accountability extends to climate-driven continuity risks, flood, cyclone, heatwave, sea-level rise, supply-chain climate exposure. India is acutely exposed (the Mumbai monsoon scenario in Section 15; the Chennai floods of 2015 that affected Cognizant's guidance by an estimated $12.41 billion; cyclones on the east coast). The leadership architecture must include climate scenarios in the exercise programme and the integration map.
AI-related continuity risks
The proliferation of AI/ML dependencies in Indian businesses creates new continuity risks, model failure, model drift, third-party AI-platform outage, AI-related data-loss, AI-induced cyber risk. The 5.1 leadership accountability extends to AI-related continuity risks; the exercise programme should include AI-failure scenarios; the integration map should include AI-system vendor onboarding.
Concentration-risk oversight
The Change Healthcare (2024) and CrowdStrike (2024) global incidents highlighted concentration risk in critical technology suppliers. Indian firms face similar concentration in payment switches, identity providers, cloud providers, and SaaS platforms. Leadership accountability for concentration risk is a 5.1(f) outcome matter; the integration map should include fourth-party (sub-supplier) concentration monitoring for critical suppliers.
Real-time leadership dashboards
The shift from monthly/quarterly board packs to real-time leadership dashboards (hosted on GRC platforms, accessible on mobile devices) is changing how leadership evidence is produced. For 5.1, the implication is that the leadership-evidence index can be auto-maintained from operational data, the executive sponsor sees real-time status of the BCMS without waiting for a monthly pack. L4 to L5 maturity firms will operate on real-time dashboards by 2027; the board pack becomes a curated summary, not the primary channel.
References and Further Reading
The references below are the primary Tier-1 sources for this guide. Each is cited by its public instrument name; full text is on the issuing body's official portal. Avoid secondary sources that paraphrase regulatory text; cite the instrument.
The standard and companions
- ISO 22301:2019 + Amendment 1:2024, Security and resilience, Business continuity management systems, Requirements. International Organization for Standardization.
- ISO 22313:2020, Security and resilience, Business continuity management systems, Guidance on the use of ISO 22301.
- ISO 22300:2021, Security and resilience, Vocabulary (a 2025 edition is under development (ISO/DIS 22300, 4th ed.) and not yet published; verify).
- ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection, Information security management systems, Requirements. Clause 5.1 is structurally identical.
- ISO 9001:2015, Quality management systems, Requirements. Clause 5.1 is structurally identical.
- ISO 31000:2018, Risk management, Guidelines.
Indian regulators (statutory and supervisory)
- Companies Act 2013, Sections 134(3)(n) and 177 (board risk oversight). Ministry of Corporate Affairs, mca.gov.in.
- SEBI Listing Obligations and Disclosure Requirements (LODR) Regulations, 2015, Regulation 21 (Risk Management Committee). sebi.gov.in.
- Reserve Bank of India Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (issued 7 November 2023, effective 1 April 2024). rbi.org.in.
- Reserve Bank of India Cyber Security Framework in Banks (2 June 2016). rbi.org.in.
- Reserve Bank of India Master Direction on Outsourcing of Information Technology Services (10 April 2023). rbi.org.in.
- Reserve Bank of India Complete Cyber Security Framework for Urban Cooperative Banks (31 December 2019). rbi.org.in.
- SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024). sebi.gov.in.
- SEBI Guidelines for BCP and DR of Market Infrastructure Institutions (SEBI/HO/MRD1/DTCS/CIR/P/2021/33, 22 March 2021). sebi.gov.in.
- IRDAI Information and Cyber Security Guidelines 2023 (24 April 2023). irdai.gov.in.
- CERT-In Directions under Section 70B(6) of the IT Act 2000 (No. 20(3)/2022-CERT-In, 28 April 2022). cert-in.org.in.
- Digital Personal Data Protection Act 2023 (Act 22 of 2023), Sections 8(5), 8(6). meity.gov.in.
- Digital Personal Data Protection Rules 2025 (notified November 2025). meity.gov.in.
- Disaster Management Act 2005, Sections 35, 37, 40, 51 to 60. ndma.gov.in.
- NDMA Guidelines, Chemical Disaster (Industrial), 2007; Guidelines for Preparation of DMPs for Ministries/Departments of GoI, 2014. ndma.gov.in.
- Information Technology Act 2000, Sections 43, 65, 66, 70, 70A, 70B. indiacode.nic.in.
Global frameworks
- NIST SP 800-34 Rev 1, Contingency Planning Guide for Federal Information Systems (May 2010). nist.gov.
- NIST SP 800-160 Vol 1 + Vol 2 Rev 1. nist.gov.
- NIST Cybersecurity Framework 2.0 (NIST.CSWP.29, 26 February 2024). nist.gov.
- FEMA FCD-1 (17 January 2017) and FCD-2 (13 June 2017) under PPD-40. fema.gov.
- FFIEC IT Examination Handbook, Business Continuity Management Booklet (November 2019). ffiec.gov; issuance vehicles OCC Bulletin 2019-57, FRB SR 19-13, FDIC FIL-19071-2019.
- Regulation (EU) 2022/2554, Digital Operational Resilience Act (DORA). Applies 17 January 2025. eur-lex.europa.eu.
- APRA Prudential Standard CPS 230, Operational Risk Management (effective 1 July 2025). apra.gov.au.
- APRA CPG 230, companion guidance. apra.gov.au.
- MAS Technology Risk Management Guidelines (18 January 2021); MAS Guidelines on Business Continuity Management. mas.gov.sg.
- HKMA Supervisory Policy Manual TM-G-2 (Business Continuity Planning, revised 31 May 2022) and OR-2 (Operational Resilience, 31 May 2022). hkma.gov.hk.
Practitioner bodies of knowledge (category-level references)
- Business Continuity Institute BCI practitioner guidance (31 October 2023).
- DRI International DRI professional-practice framework (living framework).
- BCI Horizon Scan 2025 ("Complex and Interconnected Risk"); BCI Horizon Scan 2024.
Indian incident anchors (primary-sourced; for scenario design)
- AIIMS Delhi ransomware, November 2022, peer-reviewed case in International Journal of Information Management.
- HDFC Bank RBI action, December 2020 (RBI order; partially lifted August 2021; fully lifted March 2022).
- Yes Bank moratorium, March 2020, Yale Journal of Financial Compliance case.
- Cognizant Maze ransomware, April 2020, SEC 10-Q / 10-K disclosure, $50 to $70 million impact.
- Chennai floods, December 2015, Cognizant official statement on guidance impact.
- LG Polymers Vizag gas leak, May 2020, NGT ₹50 crore penalty.
- Go First NCLT, 2023, ₹597 crore refund liability.
- SpiceJet DGCA action, 2022, 50% capacity cap.
Contested attributions (present both positions)
- Mumbai 12 October 2020 blackout cyber link, Maharashtra government ("cyber sabotage") versus Union Power Ministry ("human error, not cyber"). Present both; do not assert.
Numbers discipline note
Where a number appears in this guide without a primary citation (e.g., cost ranges, prevalence estimates), it is a Singahi practitioner estimate based on Indian engagement experience. Where a number is sourced, it is sourced to a primary instrument (RBI/SEBI/IRDAI/CERT-In/NGT/SEC/DGCA/NCLT circular or filing). Mark anything else as "reported" or "illustrative".
© Singahi. This guide is provided for the receiving organisation's internal use. ISO 22301:2019 clause text is not reproduced; the paraphrased requirement is Singahi's own. Sample "shall" clauses in policy and contract templates are Singahi's own drafting. All framework references are to public instruments named; verify current versions on the issuing body's official portal before relying on them.