How do you know whether a business continuity consultant can keep your organisation running during a crisis, rather than simply produce a handsome document that sits unread in a shared folder?
That is the uncomfortable question to ask before you hire anyone. Business continuity work can look deceptively tidy from the outside: a few interviews, a risk workshop, a thick plan and a presentation full of reassuring arrows. But a real programme has to survive pressure. It must show what happens when systems fail, suppliers stop answering, staff cannot reach the workplace and senior managers have incomplete information.
A consultant worth hiring should be able to move comfortably between strategy and awkward operational detail. They should ask which processes must continue, how long each one can be unavailable, who makes decisions when normal authority is disrupted and whether the organisation has actually practised its response. If the conversation stays at the level of templates, you may be buying paperwork rather than resilience.
Start with standards, then test the consultant’s depth
Ask the candidate to explain how they use ISO 22301:2019, not merely whether they have heard of it. The standard is only 21 pages long, so a consultant should be able to discuss its requirements clearly without hiding behind jargon. It has also been amended by Amd 1:2024 and is currently under revision, which makes up-to-date knowledge especially relevant.
A strong candidate should know that the work is moving towards ISO/CD 22301, edition 3. The working draft was registered on March 12, 2026, and the comment period closed on May 10, 2026. You do not need a consultant to predict every change in the final edition. You do need them to understand where the standard is heading and to explain how today’s decisions could affect a future transition.
Try a practical question: “Which parts of ISO 22301 would shape your first month with us?” A thoughtful answer might cover leadership involvement, the business impact analysis, continuity strategies, documented information, exercising and continual improvement. A vague answer about “aligning the business with best practice” tells you very little.
Standards knowledge is useful, but it should not be confused with certification. A consultant may have attended training without having led a continuity programme. Ask for examples of work they personally delivered, the size and complexity of the organisations involved, and what happened after the plans were written. Were exercises run? Were weaknesses recorded? Did the client update its procedures? Could the consultant describe a failed assumption they found and corrected?
Professional credentials can help you screen candidates, provided you check what they actually mean. For a DRI CBCP credential, ask whether the person has more than two years of experience, practical experience across five areas and has passed the qualifying examination. Those requirements matter because they point to applied competence rather than a certificate collected after a short introductory course. The current DRI CBCP certification fee is listed as $400, or $225 for members, but the fee itself tells you nothing about the consultant’s ability. Verify the credential and focus the interview on the work behind it.
The same caution applies to BCI CBCI 7.0. If a candidate lists it, ask whether they completed the required three- to five-day course with a licensed BCI training partner. A credential written on a proposal is not proof of current status, and a course certificate is not evidence that someone can design, exercise and maintain a business continuity management system in your environment.
You can make this concrete with a short scenario. Tell the consultant that your payroll system is unavailable, the main office cannot be entered and a key outsourced provider has suffered a cyber incident. Then ask what they would want to know in the first hour, who should be involved, and how they would decide which services receive limited resources. You are not testing whether they can perform a perfect emergency response on the spot. You are watching how they think. Do they ask about dependencies, tolerances, communications and authority, or do they immediately offer a generic recovery checklist?
Experience in your sector also deserves careful handling. A consultant does not need to have worked for an identical organisation, but they should understand your regulatory exposure, customer expectations, technology dependencies and supplier landscape. A continuity specialist from manufacturing may bring excellent methods to a professional services firm, yet the two environments will not share the same recovery priorities. Ask what they would need to learn before recommending a strategy.
Pay attention to how the consultant talks about your people. Business continuity is not a document exercise conducted by one specialist in isolation. It involves executives, process owners, technology teams, facilities, communications, procurement and often external partners. If the consultant promises to “take the burden off everyone” by completing the whole programme alone, be cautious. They may make the process feel easy, but they cannot create ownership without involving the people who will have to use the arrangements.
Put the real work in the contract
The proposal should describe outputs in language you can inspect. Do not settle for “business continuity plan” as the only deliverable. A plan without testing is not equivalent to a certified business continuity management system aligned with ISO 22301.
Your contract should require a business impact analysis that identifies critical activities, impacts over time, recovery priorities, dependencies and suitable recovery objectives. It should explain how information will be gathered, who will validate the findings and how disagreements between departments will be resolved. A spreadsheet full of recovery times is not enough if nobody responsible for the process recognises the figures.
The contract should also require a continuity and recovery strategy. That strategy might address alternate facilities, manual workarounds, technology recovery, staffing arrangements, data access, supplier alternatives and communications. The correct choices will vary by organisation. A consultant who recommends the same solution to every client is not offering strategy; they are offering a favourite template.
Testing needs its own line of responsibility. Specify the exercises to be designed and delivered, the participants, the scenarios, the expected evidence and the method for recording lessons. A discussion-based workshop can reveal confusion about roles. A technical recovery test can expose a dependency that nobody documented. A full simulation may show that senior decisions take too long when several teams are under pressure. These are different tests, and a credible programme uses them deliberately rather than labelling every meeting an exercise.
Ask how findings will be tracked after an exercise. Will the consultant produce an improvement register? Who owns each action? What is the target date? How will unresolved risks be reported to leadership? A glossy after-action report is easy to produce. Following an uncomfortable issue until someone fixes it is the part that proves value.
Make updating the BCMS an explicit deliverable as well. Organisational changes, new suppliers, software migrations, office moves and staff turnover can quietly invalidate a plan. The consultant should define how documents, contact details, recovery procedures, training records and exercise schedules will be maintained. If they are leaving after a one-off project, your team should still know how to run the next review without starting from zero.
The proposal should name the people doing the work. Some firms sell a senior consultant’s experience and then assign the project to someone else. Ask who will conduct interviews, lead workshops, write the analysis, design exercises and present findings to executives. If subcontractors are involved, the contract should say so.
Price matters, but it is rarely the best first filter. Compare the scope, consultant time, level of client involvement, number of processes covered, exercises included and post-project support. A low quote may cover one plan and a brief handover, while a higher quote includes analysis, strategy, testing and several rounds of revision. They are not comparable services.
Before signing, speak with at least one recent client if possible. Ask what the consultant did when stakeholders disagreed, whether the project stayed grounded in operational reality and what remained useful six months later. The most revealing question may be: “What did the consultant fail to do?” A client who cannot mention any limitation may be giving a polite reference rather than an honest one.
Trust your reaction to the consultant’s questions. The best ones often make the project sound slightly more complicated at first because they uncover dependencies you had not considered. I once heard a continuity manager describe a supposedly simple process that depended on one person’s inbox, a supplier’s spreadsheet and a printer in a locked room. That kind of detail is where continuity work becomes real.
Choose someone who can explain standards without reciting them, challenge assumptions without performing expertise and turn findings into tested arrangements. The right consultant will not promise that disruption can be eliminated. They will help you see exactly what would fail, what must be protected first and how your organisation will respond when the neat version of the plan meets an untidy Tuesday morning.
