Assess, do not read
A business continuity plan is a set of decisions made in advance so that nobody has to make them under pressure. The assessment therefore asks one question twelve times, from twelve angles: has this decision actually been made, and would the person who needs it find it in time? A plan can be long, formatted and approved, and fail every one of the twelve. Reviews that read the document end to end tend to miss that, because the document is coherent; it is the incident that is not.
The twelve questions
Score each as pass, weak or fail. A weak answer exists on paper but has not been tested or has no name against it.
- Activation. Is there a written, measurable trigger, and is one named person, with a named deputy, authorised to declare? «In case of a serious disruption» is a fail; «any outage of payments longer than 30 minutes, declared by the duty manager» is a pass.
- First thirty minutes. Can a person opening the plan for the first time find what to do in the first half hour within ninety seconds? If the answer is on page 14, it is a fail regardless of its quality.
- Authority before the crisis team convenes. What may the first responder decide and spend alone? A plan that requires the crisis team for every decision loses the first hour by design.
- Scope from the customer side. Are the activities defined as services the outside world receives, with the recovery order justified, or as departments in the order of the organisation chart?
- Recovery targets with arithmetic. Is there a recovery time objective per activity, and can anyone show where the number came from? A target without arithmetic is a wish.
- Workarounds. For each critical activity, is there a way to operate without the primary system, described in enough detail to start, and has it been tried at least once?
- Dependencies named. People, suppliers, sites, systems, data: is the single point of failure in each list identified, and does the plan say what replaces it?
- Contacts current. Pick five names at random. Are the people still in the roles, and do the numbers work? Two failures out of five is a fail for the whole section.
- Communication. Who speaks to staff, customers, regulator and media, in that order, and are the first three messages pre-approved so that nobody drafts under pressure?
- Availability of the plan itself. Where is it when the network is encrypted and the building is closed? Printed copies, an offline copy, a cloud copy independent of the primary infrastructure. A plan inside the compromised system is a hostage.
- Evidence of testing. When was it last exercised, what was found, and are the findings closed? A test with no findings is a walkthrough, not a test.
- Ownership and review. Who owns the plan by name, when was it last reviewed, and what event triggers a review outside the calendar? A plan reviewed only annually is out of date after every real incident and every system change.
How to run the session
Two hours, three people: the plan owner, someone who would execute it on a night shift, and the assessor. The assessor asks, the executor answers without opening the plan first, then the plan is opened to see whether it says the same thing. The distance between the two answers is the finding. Score, record, and close with the three actions that move the most questions from fail to pass; usually those are activation, workarounds and contacts.
The three findings that appear almost every time
- Authority is missing. The plan describes what to do and is silent on who may decide to do it before the meeting. This one finding explains most of the four-hour delays in real incidents.
- Workarounds exist as a heading. The section is present and reads «switch to manual procedures». Nobody has written the manual procedure, and nobody has tried it.
- The test proved nothing. The last exercise was a walkthrough with no timings and no findings, so the plan has never met resistance. The next exercise should be designed so that it can fail.
What a passing plan looks like
Short, with names, dated, tested within the year, and findable in the dark. It pairs with a structure built for the worst hour, a business impact analysis that justifies the targets, and an exercise programme that keeps finding things. If the assessment is part of a regulatory or standards review, the NCEMA 7000 checklist and the CBUAE checklist map the same questions to clauses.
Frequently asked questions
Can we assess our own plan, or does it need an external reviewer?
You can, if the executor in the session is someone who did not write the plan. The assessor role needs distance from the document, not necessarily from the organisation. An external review adds value when the result goes to a regulator, a client or an insurer.
How long does a plan assessment take?
Two hours for the session and half a day to write it up. A plan that fails more than six of the twelve questions needs a rebuild rather than a fix list, which is a different piece of work.
What score is acceptable?
No fails on activation, first thirty minutes, authority and plan availability; at most two weak answers elsewhere. Those four questions decide whether the plan works at all; the rest decide how well.
How is this different from an ISO 22301 or NCEMA 7000 audit?
An audit checks conformity with clauses and produces findings against the standard. This assessment checks whether the plan would work and produces actions. Done first, it makes the audit shorter and its findings smaller.