Risk, compliance and operational policies · 04

Business continuity and disaster recovery policy

States what the organisation will do to keep operating, and how quickly.

What it does

States what the organisation will do to keep operating, and how quickly.

How it is drafted

Identify the critical functions and their dependencies through a business impact analysis; set recovery time and recovery point objectives per function; describe the arrangements — alternate site, remote working, backup and restore, key supplier alternatives; define invocation authority and the crisis team; set the communication plan for staff, clients and regulators; and require a testing cycle with a written report.

What to look out for

Recovery objectives that have never been tested against the actual backup are aspirations. Test the restore, write down how long it took, and change the objective if the answer is inconvenient — an untested four-hour objective is worse than an honest two-day one.

The law it sits under

What governs this instrument.

Business continuity is a risk-governance obligation rather than a standalone statutory one. For a public entity it falls within the systems of risk management required by section 51(1)(a)(i) of the PFMA; for a company it falls within the directors’ duty of care, skill and diligence under section 76(3)(c) of the Companies Act 71 of 2008. In a small organisation the real exposure is key-person dependency, and a plan that does not name the person is not a plan.

Related pages, tools and documents

Where this instrument sits in the wider set, and the engagement that produces it.

Start here

Tell us the decision your organisation needs to make.

The first conversation is thirty minutes, confidential and free. You will leave it knowing which of our services you need and which you do not.