- What This Guide Covers (and What It Doesn't)
- The Audit Examination at a Glance
- Domains 1-3: Audit Foundations and the Standard
- Domains 4-5: Leadership, Planning, Support, Operation, and Risk
- Domains 6-8: BIA, Strategies, and Plans
- Domains 9-11: Training, Exercises, and Audit Reporting
- Sequencing the 11 Areas in Your Prep Calendar
- Fees, Course Route, and Certification Mechanics
- Frequently Asked Questions
- The CBCA is issued by DRI International; passing the 100-question audit exam alone does not confer certification.
- The exam allows 2 hours 30 minutes and requires a score of at least 75%.
- DRI has not published weighted exam domains; the 11 areas here come from the ISO 22301 audit-course outline.
- Completing the four-day BCLE AUD course (32 CEAPs) is mandatory before sitting the Audit Examination.
What This Guide Covers (and What It Doesn't)
The Certified Business Continuity Auditor (CBCA) credential is awarded by DRI International (Disaster Recovery Institute International). It is aimed at professionals who evaluate whether a continuity program actually conforms to a recognized standard, not just professionals who build one. That distinction shapes everything about how you should study the content areas below.
One point of honesty up front: DRI does not publicly publish a weighted domain blueprint for the Audit Examination. There are no official percentages, and no officially named "largest domain." What this guide does is organize your preparation around eleven substantive headings drawn from DRI's current ISO 22301 audit-course outline. These are preparation topics from the issuer's own course, not an official or exhaustive exam specification. We excluded the course's Introduction, exam preparation, and examination-event segments because they do not teach auditable subject matter.
If you are still orienting yourself to the credential, start with What Is CBCA Certification? and then return here for the content map. For the full prep plan built around these areas, see the CBCA Study Guide 2026.
The Audit Examination at a Glance
| Element | What the Public Sources Establish |
|---|---|
| Governing body | DRI International |
| Format | 100 multiple-choice questions |
| Time allowed | 2 hours 30 minutes |
| Required score | At least 75% |
| Delivery | Online through your DRI account after course registration |
| Standard version (ISO route) | Catalogued as "2023 Audit Exam - ISO 22301"; course references ISO 22301:2019 |
| Pass rate | Not publicly disclosed |
| Scored vs. unscored breakdown | Not publicly specified |
The exam is multiple choice only. The course itself includes a hypothetical-company case study and practical auditing activities, but those are classroom exercises, not a performance-based or essay portion of the exam. The five subject-matter essays belong to the separate professional certification application, not to the 100-question test.
Details such as open-book status, calculator rules, and remote-proctoring specifics could not be verified from public sources, so confirm them in your DRI account when you book. For the scoring threshold in depth, read CBCA Passing Score 2026, and for what is and isn't known about results, see CBCA Pass Rate 2026: What the Data Shows.
Domains 1-3: Audit Foundations and the Standard
The first three areas establish the frame of reference. Candidates who skip them to rush toward BIA and strategy content often struggle later, because auditor-style questions test whether you can apply audit logic to a standard's clauses.
Domain 1: Auditing basics
This is where the course teaches how an audit works regardless of subject. Expect the vocabulary of auditing to matter: objectives, scope, criteria, evidence, and conclusions.
- The difference between auditing against criteria and consulting on improvement
- How evidence is gathered, evaluated, and documented
- Auditor conduct, independence, and objectivity
- How an audit moves from planning through fieldwork to reporting
Domain 2: Understanding ISO 22301
Here the course introduces the management-system standard you will audit against. The current course page uses the heading "Understanding ISO 22301," while the linked brochure says "Introduction to ISO22301"; that is a spelling difference, not an extra topic.
- The purpose and structure of a business continuity management system
- How requirements are phrased, and what "shall" obligations mean for an auditor
- How the standard's clauses map to what you would test in an organization
- The 2019 edition referenced by the current course
Domain 3: Context of the organization
An auditor must judge whether the organization has understood its own environment before any continuity work makes sense.
- Internal and external issues affecting the continuity program
- Interested parties and their requirements
- Scope definition of the management system and whether it is justified
- Whether boundaries and exclusions are documented and defensible
A useful habit: for every concept in these three areas, ask "what evidence would prove this exists?" That question is the heart of the credential, and it separates auditor thinking from planner thinking. The CBCA Cheat Sheet condenses the vocabulary into a one-page review.
Domains 4-5: Leadership, Planning, Support, Operation, and Risk
Domain 4: Leadership, planning, support, and operation
This is a broad grouping, mirroring the course's treatment of the management-system clauses beyond context. It deals with whether governance is real or merely documented.
- Top-management commitment: policy, roles, responsibilities, and authority
- Planning for objectives and how they are measured
- Support: resources, competence, awareness, communication, and documented information
- Operational planning and control of continuity processes
Because this area spans several standard clauses, it is easy to under-study. Candidates often memorize operational content and neglect leadership evidence. Auditors, however, are routinely asked whether management commitment is demonstrated, not just claimed. Think about what a document review, interview, and observation would each reveal about leadership involvement.
Domain 5: Risk assessment
Risk assessment in a continuity audit is about whether the organization identifies, analyzes, and evaluates threats to its prioritized activities in a structured, repeatable way.
- How risks to the organization's activities and resources are identified
- The link between risk assessment and the treatment choices that follow
- Whether methodology, criteria, and review frequency are documented and consistently applied
- How risk assessment differs from, and feeds into, business impact analysis
Domains 6-8: BIA, Strategies, and Plans
These three areas form the technical core of what gets audited in most programs. They are also the areas where hands-on continuity practitioners feel most at home, which can create overconfidence. The exam asks you to audit them, not perform them.
Domain 6: Business impact analysis (BIA)
The auditor's question is whether the BIA is complete, current, and actually used.
- Identifying prioritized activities and the impacts of disruption over time
- Setting recovery time objectives and understanding how they are justified
- Dependencies: people, technology, suppliers, and facilities
- Whether results were approved by management and fed into strategy decisions
Domain 7: Continuity strategies and solutions
Strategies should be traceable back to BIA findings. A frequent audit finding in practice is a strategy that cannot be tied to documented recovery requirements.
- How strategy options are evaluated against recovery objectives
- Protecting prioritized activities and resourcing the chosen solutions
- Whether the selected strategies are proportionate and approved
- Evidence that required resources are actually available
Domain 8: Business continuity plans
Plans are where abstract requirements become procedures. Auditors test whether plans are usable, current, and consistent with the preceding analysis.
- Required plan content: activation criteria, roles, communication, and recovery steps
- Document control, versioning, and distribution
- Alignment between plans, the BIA, and chosen strategies
- Whether staff named in plans know their role
A strong mental model is a chain of traceability: context leads to risk and BIA, BIA leads to strategy, strategy leads to plans. When an exam scenario describes a break in that chain, the correct answer usually identifies the missing link. For the realistic difficulty of these scenario-style items, read How Hard Is the CBCA Exam?
Domains 9-11: Training, Exercises, and Audit Reporting
Domain 9: Education and training
This area covers competence and awareness: whether people who must act in a disruption have been prepared to do so.
- Identifying training needs by role
- Records that demonstrate training occurred and was effective
- Awareness programs for staff who hold no formal continuity role
- How competence is verified, not merely assumed
Domain 10: Exercise program
An exercise program is evidence that plans work. Auditors assess whether exercising is planned, varied, and followed by corrective action.
- Types of exercises and their appropriate use
- Defining objectives and success criteria before an exercise
- Capturing results, lessons learned, and tracking corrective actions to closure
- Whether the program addresses prioritized activities over time
Domain 11: Audit findings, recommendations, and auditor's opinion
This final area is the payoff of the whole credential: converting evidence into defensible conclusions.
- Classifying findings and judging their significance
- Writing clear, evidence-based findings and practical recommendations
- Forming and communicating the auditor's opinion
- Closing meetings, reports, and follow-up of corrective actions
Do not treat Domain 11 as an afterthought just because it comes last in the outline. It is the skill you will use daily in an audit role, and it ties back to every earlier area, since each finding must reference a requirement and supporting evidence.
Key Takeaway
Across all 11 areas, the pattern is the same: identify the requirement, identify the evidence that would demonstrate it, and judge whether the gap is significant. Practice framing every topic that way and the individual domains stop feeling like separate subjects.
Sequencing the 11 Areas in Your Prep Calendar
Because the Audit Examination follows the four-day course, your preparation is really two phases: pre-course reading and post-course consolidation. Since DRI's course descriptions say the exam is taken online after the course at your convenience, build your calendar around your own booking date, confirming the current scheduling instructions for your course (see CBCA Exam Dates 2026). A sample structure tied to the domains:
Audit logic and the standard (Domains 1-3)
- Learn audit vocabulary before opening the standard
- Read ISO 22301 clause by clause, noting what evidence each requirement implies
Governance and risk (Domains 4-5)
- Draft evidence lists for leadership, support, and operational control
- Write your own contrast between risk assessment and BIA
The traceability chain (Domains 6-8)
- Trace one fictional business activity from BIA through strategy to plan
- Note where a break in the chain would become a finding
Proof and reporting (Domains 9-11)
- Review how training and exercise records demonstrate effectiveness
- Practice phrasing findings and recommendations from a short scenario
One caution about practice material: DRI course and exam materials are confidential, so only use independently written practice questions. Our own CBCA practice tests are written independently and any topic allocations in them are editorial, not official weightings. Use them to rehearse reasoning on scenarios across all 11 areas, then revisit weak areas. You can also explore structured options under CBCA Training.
Fees, Course Route, and Certification Mechanics
The route to the credential has several separate steps, and the exam is only one of them. Understanding the mechanics helps you plan your budget and timeline realistically.
| Item | Published Amount or Requirement |
|---|---|
| Course plus first exam (BCLE AUD, ISO 22301 or NFPA 1600) | $2,950 (first exam included) |
| Certification application | $400 |
| Published subtotal (course plus application) | $3,350, before renewal, travel, taxes, or discounts |
| Audit exam retake | $250 |
| Annual renewal | $225 |
| Course length | Four full instructional days, 32 CEAPs |
DRI's Continuity Audit FAQ mentions a 10% discount for NFPA and other professional-organization members, but the qualifying organizations and final discounted total are not clearly published, so confirm eligibility directly before budgeting around it. A full breakdown is in CBCA Certification Cost 2026.
Passing the exam is necessary but not sufficient. To earn the CBCA designation, applicants need at least two years of significant practical experience in business continuity, emergency or disaster management, and/or audit within the preceding ten years. The application also requires five subject-matter essays and two validating references per subject area, potentially the same two people across all five. At least two essays must come from DRI's specified application areas covering business impact analysis, continuity strategies, plan development and implementation, and exercise, test, assessment, and maintenance. Some existing professional designations qualify for reference or experience-section waivers, but this is not a blanket waiver of the course, exam, or experience requirement. The course can be taken without a previous DRI certification. See CBCA Requirements 2026 for the full eligibility picture.
After certification, maintaining the credential means paying the annual $225 fee, earning 80 CEAPs over each two-year continuing-education period, and complying with DRI's code of ethics. It is not an unconditional two-year credential. If you are weighing the investment, Is the CBCA Certification Worth It? and the CBCA Salary Guide explore the return, and CBCA Jobs covers where the skill set is applied, such as internal audit, risk, compliance, and continuity management roles.
Frequently Asked Questions
No. DRI has not published weighted exam domains or percentages for the Audit Examination. The 11 areas in this guide come from the headings of DRI's ISO 22301 audit-course outline and serve as preparation topics, not an official exam blueprint.
No. The preparation topics here follow the ISO 22301 audit course. DRI offers a parallel NFPA 1600 audit course, but coverage of that route's content is not established in this guide, so use DRI's NFPA course materials if that is your path.
No. It consists of 100 multiple-choice questions over 2 hours 30 minutes. The classroom case study and the five application essays are separate from the exam itself; the essays are part of the professional certification application.
You need at least 75% on the examination. DRI does not publicly disclose a pass rate, so any figure you see quoted for the CBCA cohort should be treated with skepticism.
No. Completing the Business Continuity Planning for Auditors (BCLE AUD) course is required before the Audit Examination, and exam access follows course registration through your DRI account.
Mastering these 11 areas means learning to think like an auditor: requirement, evidence, judgment, report. Build that habit across the ISO 22301 clauses, confirm current logistics in your DRI account, and use independently written practice questions at the CBCA Exam Prep practice site to test your reasoning before exam day.