Overview
ISO 22325:2016 - Security and resilience - Emergency management - Guidelines for capability assessment - provides a practical framework for assessing an organization’s emergency management capability. The standard describes an assessment model with four maturity levels, eight capability indicators, and an assessment process (plan, collect, analyse, report). ISO 22325:2016 is intended for organizations responsible for prevention, mitigation, preparedness, response and recovery activities and supports continual improvement in emergency preparedness and resilience.
Key topics and technical requirements
- Assessment model (4 levels): Classifies capability from Level 1 (basic) through Level 4 (optimal, adaptive learning and research-informed).
- Eight indicators: Used to evaluate capability across core functions:
- Leadership
- Resource management
- Information and communication
- Risk management
- Coordination and cooperation
- Emergency management planning
- Exercise programme
- Incident management system
- Assessment process: Practical steps for capability assessment - planning, collecting evidence, analysing findings, and reporting results. The standard includes an informative assessment template and guidance on tailoring context (internal/external factors).
- Integration with risk practice: Risk management is highlighted as integral to emergency management and is to be consistent with ISO 31000.
- Evidence and learning: Higher maturity levels require documented lessons learned from incidents, exercises and research, and demonstrate coordination with other organizations.
Practical applications
- Perform internal or external capability assessments to identify gaps and improvement opportunities.
- Support regulatory compliance, risk reduction and public safety objectives.
- Inform resource allocation, contingency funding, and exercise programmes.
- Guide multi-agency coordination, mutual aid agreements and interoperability testing.
- Feed organizational learning - benchmarking, lessons-learned capture and research-informed upgrades to systems and procedures.
Who should use this standard
- Emergency management agencies (local, regional, national)
- Public safety and civil protection organizations
- Large enterprises with business continuity and crisis management responsibilities
- Critical infrastructure operators, healthcare providers and emergency response partners
- Consultants and auditors conducting capability assessments or preparedness reviews
Related standards
- ISO 31000 (Risk management) - referenced for risk processes and treatment
- ISO 22300 series (security and resilience) - for terminology and broader resilience guidance
ISO 22325:2016 is a practical tool for organizations seeking a structured, evidence-based approach to emergency management capability assessment and continual improvement in security and resilience.