Blog
Business Continuity Plans: What the Board Should Review Yearly
At a glance
- The board should review the business continuity plan annually against critical processes, recovery time targets, dependencies, test evidence, and named accountability.
- Treat the annual review as a documented exercise with prerequisites, ordered steps, and a stated expected outcome for each step.
- Scenario coverage must now include cyber, war, pandemic, supplier failure, and AI-dependent processes, not natural disaster alone.
- Untested plans are the most common failure: demand exercise results, gap lists, and closure dates, not the plan document.
- LT Risk Management advises regulated financial institutions, boards, and internal audit on operational, fraud, cyber, continuity, and AI risk.
LT RISKMGMT
Published: 2026-09-08
Every year the board of directors should review five things in the business continuity plan (BCP) — the plan for keeping the organization running through emergencies such as war, earthquake, pandemic, supplier collapse, or a cyber incident: the map of critical business processes and their recovery time objectives; the dependency chain behind them, including outsourced and cloud providers; the evidence from actual exercises rather than the plan document itself; the gaps those exercises exposed, with owners and closure dates; and the scenario list, which in 2026 must account for AI-dependent processes that did not exist when many plans were first written. This is a governance act with personal accountability attached, not an operational formality, and it is discharged through review of tested evidence. The steps below set out how to run that annual review in order — what to have in hand before you start, what to ask at each stage, and what a satisfactory answer looks like. LT Risk Management, the boutique consultancy led by Lea Tzur, works with boards, risk managers, and internal auditors in supervised financial institutions on exactly this class of non-financial risk.
What should the board review in the business continuity plan every year?
This section addresses the annual board-level review of the business continuity plan (BCP) — the plan mapping critical systems, processes and recovery timelines for emergencies such as war, earthquake, pandemic or cyber events. Below are minimum attributes a board or risk committee should inspect, question and minute annually.
- Component — What it must state — Why the board should care
- Business Impact Analysis (BIA) — Ranked list of business processes with financial, regulatory and reputational impact per hour or day of outage — Without a BIA, recovery priorities are guesswork rather than a risk decision
- RTO (Recovery Time Objective) — Maximum tolerable downtime per critical process, stated in hours or days — Sets the spend on redundancy; an unfunded RTO is an unmet commitment
- RPO (Recovery Point Objective) — Maximum tolerable data loss, stated as a time window — Drives backup frequency and reconciliation effort after an event
- Critical process list — Explicitly named processes, systems, suppliers and their dependencies — Boards should confirm outsourced and third-party dependencies are inside the scope
- Succession and authority — Named deputies and decision rights when a key manager is unreachable — Prevents paralysis during the first hours of an incident
- Plan owner — A single accountable role, not a committee — Ownership is the difference between a living plan and a shelf document
- Version date and approval trail — Last revision, approving forum, next scheduled review — A stale version date is itself an audit finding
Recovery targets stated on paper should be checked against what the organisation actually achieves under pressure. In LT Risk Management's work reshaping fraud risk management at a large Israeli financial institution, the firm's own account is that the time to disconnect a suspicious client from the business platform fell from an average of two to five days to no more than two hours, alongside an estimated saving of roughly five staff positions — figures the company presents as its own estimate rather than externally verified measurements. That gap between documented target and measured reality is what yearly review exists to expose.
Which questions should directors ask about testing, recovery times, and third-party dependencies?
Directors get better oversight when questions force evidence rather than assurance — a Business Continuity Plan (BCP) is only as good as its last honest test. The table below pairs the question to ask with the trap that answer often hides.
- Ask management this — But watch out for
- What did the last exercise actually break, and who signed off on the findings? — Tabletop-only walkthroughs presented as a full test; no failed scenario means the scenario was too easy.
- Are Recovery Time Objectives (RTO — maximum tolerable downtime) and Recovery Point Objectives (RPO — tolerable data loss) validated by measurement, not assumption? — Paper RTOs inherited from old documents and never re-measured after systems changed.
- Which single vendors, cloud regions or clearing counterparties would halt a critical process if they failed? — Concentration hidden one layer down — several suppliers resting on the same underlying provider.
- Which gaps from the previous review are still open, with owner and due date? — A remediation list that rolls forward untouched year after year.
What else should the board probe?
Ask who has authority to declare a crisis and activate the plan out of hours — ambiguity there costs more than any technical gap. Ask whether the BCP covers ransomware-driven outages, where restoring from backup may reintroduce the attacker, not only physical disruption. Ask whether critical suppliers test their own continuity arrangements, and whether the organisation has seen the results.
The highest-impact risk is a plan validated only against scenarios the organisation already knows how to survive. Mitigate it by commissioning one exercise a year designed by someone outside the process owners' reporting line. Leading bodies in Israel's financial and public sector — including Bank Discount, Bank Leumi, Bank of Israel, Menora Mivtachim, Visa Cal and the Ministry of Justice — attest to LT Risk Management's consulting, training and lectures in this territory.
How does a business continuity plan differ from disaster recovery and crisis management plans?
A business continuity plan (BCP) is the organization-wide document that keeps critical processes running during disruptions—war, earthquake, pandemic, or cyber events—while disaster recovery, incident response, and crisis communication are narrower plans underneath it. Directors who conflate the four may approve a single document while assuming it covers all four failure modes.
Four criteria separate them:
- Trigger — what event activates the plan. A plan with an undefined trigger is never invoked in time.
- Owner — the accountable executive. Weight this highest: an unowned plan is unrehearsed.
- Scope of recovery — whether the plan restores technology, a business process, or public trust.
- Success measure — the recovery time or response target the board can test against.
- Plan — Trigger — Typical owner — Scope — Success measure
- Business continuity plan (BCP) — Any disruption to critical processes — COO / risk function — Processes, people, sites, suppliers — Recovery time for each critical process
- IT disaster recovery plan (DRP) — Loss of systems, data centre or data — CIO / infrastructure — Systems, data, restoration order — Restoration time and data-loss tolerance
- Incident response plan (IRP) — Detected cyber or fraud incident — CISO — Containment, forensics, eradication — Time to detect, contain and disconnect
- Crisis communication plan — Reputational or regulatory exposure — CEO / company secretary — Messaging to regulators, customers, media — Time to first approved statement
The verdict: the BCP is the parent framework and should be reviewed as a whole; the other three are annexes the board reviews for consistency with it—same critical-process list, same recovery clocks, no contradictions.
Directors who want to interrogate these documents credibly need the vocabulary. LT Risk Management runs a certification course for operational risk, cyber and AI risk managers of roughly 40 academic hours, built as experiential learning with workshops, hands-on exercises and a SOC visit, alongside guest lecturers from major organizations.
Which regulations, standards, and recent risk shifts shape board-level continuity oversight today?
Regulations and standards have shifted faster than most continuity plans, so a board-level review in 2026 should open with a current map of which rules actually bind the organization. A Business Continuity Plan (BCP) — the plan that maps critical systems, processes, and recovery times for emergencies such as war, earthquake, pandemic, or cyber event — is now judged against a layered set of obligations rather than a single standard.
- Framework or rule — What it governs — What the board should confirm
- ISO 22301 — Business continuity management systems — Scope, recovery objectives, and exercise evidence are documented
- ISO 31000 / ISO 27001 — Risk management and information security controls — Continuity risks are registered inside the enterprise risk framework
- DORA (EU) — Digital operational resilience for financial entities — Third-party ICT dependencies and testing regime are mapped
- SEC cyber disclosure rules — Materiality assessment and incident reporting — A defined path from incident to disclosure decision exists
- FFIEC resilience guidance — Examiner expectations for financial institutions — Recovery capability matches examiner-tested scenarios
- Bank of Israel Proper Conduct of Banking Business directives (including 355 and 361) — Supervised operational and cyber risk requirements — Local supervisory requirements are reconciled with global standards
- EU AI Act — Governance of AI systems by risk tier — AI dependencies appear in the continuity and risk map
Two recent movements deserve explicit board attention. First, operational resilience guidance increasingly frames continuity around critical business services and impact tolerances rather than IT recovery alone. Second, AI and third-party services may be entering critical processes faster than governance catches up; the AI risk map belongs on the same agenda as the recovery plan.
How should the board schedule, document, and follow up on the annual review cycle?
Boards that schedule business continuity oversight as a fixed calendar item—rather than ad-hoc—document decisions cleanly and close findings on time. This section addresses the decision point: you have the material and need a cycle you can approve, minute, and defend to regulators or auditors.
Follow these steps to build the annual cycle:
- Fix the slot. Place the Business Continuity Plan (BCP)—mapping critical systems, processes, and recovery times for emergencies such as war, earthquake, pandemic, or cyber events—on one named board or risk-committee meeting annually, with the exercise report tabled a quarter earlier. Expected outcome: a dated slot in the annual work plan, not a floating item.
- Circulate the pack in advance. Require the recovery-objective table, exercise findings, and management's remediation status to reach directors before the meeting. Expected outcome: discussion time spent on gaps, not briefing.
- Document the decision, not the discussion. Record in minutes what was approved, which assumptions were challenged, what was rejected, and the named owner and due date for each gap. Expected outcome: minutes that evidence oversight to auditors.
- Approve explicitly. Pass a resolution approving the plan version and any accepted residual risk. Expected outcome: version-stamped approval on record.
- Track remediation between cycles. Put open items on the quarterly risk report until closed and re-tested. Expected outcome: no finding survives two annual cycles unchallenged.
Continuity failures usually surface first as governance-cadence failures: a plan reviewed late, approved without a version, or closed on paper before re-testing. LT Risk Management brings risk specialists with decades of experience in regulated organizations, providing consulting, training, workshops, and lectures across AI governance, cyber, operational risk management, fraud prevention, and business continuity—including facilitating this review cycle for boards wanting independent challenge.
Frequently Asked Questions
What should the board of directors review in the business continuity plan each year?
An annual review by the board of directors should cover five concrete items: the map of critical business processes and their recovery time objectives (RTO — the maximum tolerable outage before a process must be restored); the results of the most recent continuity exercise, including failures and open gaps; dependencies on third parties and cloud or outsourcing providers; the crisis command structure, including named deputies and decision authority; and the scenario set itself — war, earthquake, pandemic, and cyber incidents such as ransomware. A BCP (Business Continuity Plan) that has not been re-mapped against changes in systems, suppliers, and headcount over the past year is a document, not a control.
How is a business continuity plan different from a disaster recovery plan?
A business continuity plan governs how the organization keeps delivering critical services during a disruption; disaster recovery (DR) is the narrower technical discipline of restoring IT systems, data, and infrastructure. DR is a component of continuity, not a substitute for it. A bank can restore its core systems and still fail continuity if the trading desk has no alternate site, no manual fallback procedure, and no authorized signatory reachable in the middle of the night. International practice — the ISO 22301 continuity management standard and the ISO 31000 risk management framework — treats the two as related but distinct layers, and directors should ask for both.
What evidence of BCP testing should reach board level?
Directors should receive exercise evidence, not exercise announcements. Useful reporting includes the scenario tested, whether it was a tabletop or a live failover, which processes were exercised, measured recovery times against declared RTO targets, the gaps found, and the owner and due date for each corrective action. Unresolved findings carried over from the prior year deserve explicit discussion, because repeat findings are the pattern internal audit and supervisors probe first. In supervised financial institutions in Israel, this documentation also supports the evidence trail expected under the Proper Conduct of Banking Business directives.
What is BPT (Business Penetration Test) and how does it relate to continuity?
BPT — Business Penetration Test — is a method developed exclusively by Lea Tzur at LT Risk Management that examines weaknesses in the business process itself rather than in technology. It is not a technical penetration test of networks or applications; it is a structured analysis of how a workflow can be exploited, producing a holistic view of cyber risk, embezzlement and fraud risk, and human error in one pass. Its relevance to continuity is direct: continuity plans assume that processes behave as documented, and a process-level review tests whether that assumption survives contact with a real disruption.
Which training helps directors and risk managers read a continuity plan critically?
LT Risk Management runs a certification course for operational risk, cyber and AI managers of approximately 40 academic hours, built as experiential learning with workshops, hands-on exercises, and a visit to a leading SOC, with guest lecturers from major organizations in Israel and abroad; the course is recognized by IRM (Institute of Risk Management). For directors, the aim of any such learning is the ability to challenge a plan critically rather than to write one. LT's consulting, training, and lectures are used by leading organizations in the Israeli financial and public sectors, including Bank Discount, Bank Leumi, Bank of Israel, Menora Mivtachim, Visa Cal, and the Ministry of Justice.
About this article
LT RISKMGMT publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by LT RISKMGMT before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-09-08
Related- What Is a Business Penetration Test (BPT) and When to Use It
- When Government Bodies Should Outsource the Risk Manager Role
- Who Owns Audit Finding Remediation — Board or Management? A Guide for Supervised Financial Institutions and Fintechs in Israel
Ready to get started?
See how LT RISKMGMT can help.
צרו קשר