Overview
ISO/IEC TS 17021-6:2014 - part of the ISO/IEC 17021 series - complements ISO/IEC 17021:2011 by defining specific competence requirements for personnel involved in auditing and certification of Business Continuity Management Systems (BCMS). The Technical Specification clarifies the knowledge and capability certification bodies must ensure for auditors, reviewers and decision-makers so BCMS certification is credible and consistent.
Key topics and requirements
The Technical Specification requires certification bodies to combine the generic competencies of ISO/IEC 17021:2011 with BCMS-specific knowledge. Core competency areas include:
- BCM terminology - familiarity with terms and concepts used in business continuity and risk management (ISO 22300/22301 vocabulary).
- Context of the organization - understanding organizational environment and stakeholders relevant to continuity.
- Applicable laws and other requirements - ability to determine identification and evaluation of legal, regulatory and voluntary obligations.
- Interrelationships within the BCMS - how BCM elements interact across the lifecycle.
- Business impact analysis (BIA) and risk assessment - methodologies, activity identification, impact over time, dependencies, prioritization and risk treatment.
- Business continuity strategies - strategy development, selection, cost/benefit analysis, coordination with external stakeholders, recovery/restoration.
- Incident management - response planning, warning and communications, testing of incident response capability.
- Business continuity plans - structure, development, maintenance and procedural detail.
- Business continuity exercises - planning and evaluating exercise types, techniques and criteria to test recovery objectives.
- BCMS performance evaluation - performance indicators and metrics to assess whether objectives/targets are met.
- Application review competence - requirements for personnel determining audit team composition, required competence and audit time.
The document emphasizes that the collective competence of an audit team must meet audit objectives, even if individual auditors have different strengths.
Practical applications
ISO/IEC TS 17021-6 is used to:
- Define and document auditor competence profiles for BCMS certification.
- Select and compose audit teams with the right mix of BCMS expertise.
- Determine audit duration and scope during application reviews.
- Guide training and professional development for auditors, reviewers and certification decision-makers.
- Support accreditation assessments and improve the credibility of BCMS certification.
Who should use it
- Certification bodies issuing BCMS certificates
- BCMS auditors and lead auditors
- Personnel reviewing audit reports and making certification decisions
- Accreditation bodies and conformity assessment professionals
- Organizations preparing for BCMS certification and consultants
Related standards
Keywords: ISO/IEC TS 17021-6:2014, BCMS, business continuity management systems, competence requirements, BCMS auditors, business impact analysis, risk assessment, incident management.