ISO Spaghetti: Making Sense of the Standards You Keep Hearing About
If you work in any kind of professional role, you have probably come across ISO standards. They get mentioned in tender documents, supplier questionnaires, job adverts, and LinkedIn profiles. ISO 27001. ISO 22301. ISO 31000. Sometimes all three in the same sentence.
But what do they actually mean? And do you need all of them?
The short answer is: probably not. And the slightly longer answer is what this post is about.
There are five main standards in the risk and resilience space
When it comes to risk, resilience, business continuity and information security, five ISO standards come up most often:
- ISO 22301 — Business Continuity Management
- ISO 27001 — Information Security Management
- ISO 22361 — Crisis Management
- ISO 31000 — Risk Management
- ISO 22316 — Organisational Resilience
They sound similar. They overlap in places. And they are frequently listed together as though they are all the same kind of thing.
They are not.
The most important thing to understand first
Of those five standards, only two can be certified to: ISO 22301 and ISO 27001.
The other three — ISO 22361, ISO 31000 and ISO 22316 — are guidance standards. That means there is no audit, no certificate, and no renewal process. They exist to help organisations improve their practice, not to provide third-party assurance.
This matters more than you might think. If you ever see a tender document or a job specification asking for “ISO 31000 certification,” it has been written by someone who does not understand the standard. ISO 31000 certification does not exist. Neither does ISO 22361 or ISO 22316 certification.
So what does each one actually do?
ISO 22301 is about keeping your organisation running when something goes wrong — a flood, a cyber attack, a key supplier failing, a critical member of staff being unavailable. It requires you to work out which activities are most important, plan how you would keep them going, and — this is the part people often skip — actually test those plans through exercises.
ISO 27001 is about protecting your information. That means making sure the right people can access it, that it hasn’t been tampered with, and that it’s available when you need it. It covers everything from how you manage passwords and devices to how you respond to a security incident.
ISO 22361 steps in when a situation escalates beyond your normal plans — when the media are involved, when your board needs to make decisions without all the facts, or when the organisation’s reputation is on the line. It is about crisis leadership rather than crisis planning.
ISO 31000 is the framework that sits underneath everything else. It gives organisations a common language and approach for managing risk — thinking about risk appetite, assessing threats, and making risk-informed decisions at every level.
ISO 22316 takes the widest view of all, looking at organisational resilience as a whole — the culture, leadership behaviours, and adaptability that allow an organisation to absorb disruption and keep moving forward..

Which one do you actually need?
That depends on your organisation, but here are some simple starting points.
If you handle personal data or sensitive information, ISO 27001 is likely to be the most relevant — and increasingly it is expected by clients and required in contracts.
If your clients depend on you to keep operating even when things go wrong, ISO 22301 is the standard that gives them that assurance.
If your organisation has a high public profile and a serious incident could put you in the media spotlight, ISO 22361 is worth understanding even though you cannot certify to it.
If you want to build a more structured approach to risk management across the whole organisation, ISO 31000 gives you the framework to do that.
They are not a checklist
The temptation, especially in procurement, is to treat these standards as boxes to tick. The more you have, the safer you are. But that is not how resilience works in practice.
The organisations that handle disruption well are not necessarily the ones with the most certificates. They are the ones that have implemented the right frameworks for their context, taken them seriously, and tested them before they were needed.
If you want to understand more about how these standards relate to each other — including a plain-English comparison table and a guide to which ones are right for different types of organisation — the full guide is available as a free download from Cambridge Risk Solutions.





