Skip to content

Business Continuity Plan

Operating plan — instantiates Resilience Capacity Building

A standing, activatable document that says which functions must keep running through a disruption, at what minimum level, who invokes the response, and who talks to whom.

Once a system knows which functions must survive, it needs a playbook for keeping them alive while the disruption is still happening. Business Continuity Plan is that operating document: for each critical function it fixes a minimum acceptable level of service, an alternate way to deliver it, a rule for when and by whom the response is switched on, and the channels through which everyone will coordinate. Its defining idea is continuity during the shock — holding the line, not rebuilding it. That single word "during" is what separates it from the Disaster Recovery Plan, its nearest sibling, which is about restoration after. A continuity plan is written to be grabbed and invoked mid-crisis, so its virtues are the opposite of a strategy document's: it is short, current, and unambiguous about who does what the moment things go wrong.

Example

A regional credit union writes a continuity plan for the case where its core banking system goes down or a branch becomes inaccessible. For each member-facing function it sets a continuity threshold: members must still be able to withdraw up to a set daily limit and payroll direct-deposits must post within four hours, even if account histories are temporarily read-only. It sets an activation rule: if the core is unreachable for more than thirty minutes, the on-call operations manager — named, with a backup named — declares a continuity event and no one waits for a committee. And it documents a communication channel plan: an internal staff hotline, a scripted member-facing message for branch doors and the website, and the notification path to the state regulator.

When an ice storm closes three branches and knocks out a data link, the on-call manager hits the thirty-minute trigger, work reroutes to the backup call center, and the scripted notice goes up within the hour. Members keep basic access; nobody spends the first frantic half-hour arguing about who is allowed to decide.

How it works

  • Set a floor per function. For each critical function, state the minimum service that still counts as "continuing" and the alternate route that delivers it under degraded conditions.
  • Pre-decide activation. Write the trigger condition and name the person with authority to invoke — and their backup — so the confusing calls are made in advance, not mid-crisis.
  • Wire the coordination. Lay out the internal and external communication channels: who is called, who speaks to regulators, customers, and staff, and through what medium.
  • Keep it invocable. Optimize for grab-and-go: concise, versioned, with contact lists that are actually current.

Tuning parameters

  • Threshold height — how much service the plan guarantees to hold. A high floor protects more but demands costly standby capacity; a low floor is cheap but concedes more degradation.
  • Activation sensitivity — a hair-trigger that invokes early versus a high bar that waits for certainty. Early invocation buys reaction time but cries wolf; a high bar avoids false alarms but can lose the crucial first minutes.
  • Authority centralization — one named decider versus distributed local authority to invoke. Central alignment keeps priorities coherent; local authority reacts faster when information is on the ground.
  • Communication breadth — internal-only versus a full external-stakeholder tree including regulators and the public. Wider coverage prevents information vacuums but multiplies what must be kept current.
  • Maintenance cadence — how often contacts and alternates are re-verified. Continuity plans rot silently; a stale call tree fails at exactly the wrong moment.

When it helps, and when it misleads

Its strength is that it converts intent into an invokable response: the moment a disruption hits, the plan has already made the decisions that would otherwise be improvised under stress — who decides, what minimum to hold, whom to call. It removes the first, most expensive source of delay.

Its central failure mode is the shelf document: a plan that is written, filed, and never rehearsed, so it describes a capability the organization does not actually have. A binder is not a behavior. This is the honest edge of Eisenhower's line that plans are worthless, but planning is indispensable — the artifact matters far less than the shared readiness that only comes from working through and rehearsing it.[n1] The classic misuse is producing the plan to satisfy an auditor and treating its existence as evidence of resilience. The discipline that guards against this is to hand the plan to the Emergency Preparedness Drill for real rehearsal, keep the contact lists live, and judge the plan on how invocable it proves under test rather than on its page count.

How it implements the components

Business Continuity Plan fills the during-disruption operating components — the machinery for holding the line while the shock is live:

  • continuity_threshold — for each critical function it fixes the minimum acceptable service level that separates tolerable degradation from unacceptable failure.
  • activation_rule — it encodes the trigger condition and the named authority to switch the response on, so invocation does not wait on deliberation.
  • communication_channel_plan — it lays out the internal and external channels through which the response is coordinated during the event.

It holds function through the shock but does not bring it back afterward: it does not stage the resources or encode the restoration order to rebuild lost function (recovery_resource, dependency_map — the Disaster Recovery Plan, its nearest twin — where this plan keeps critical functions running during the disruption, the recovery plan restores them once it has passed). It also does not map what matters (critical_function_map, shock_scenario — the Resilience Planning Workshop) or rehearse, own, and harvest lessons from the response (adaptive_capacity, resilience_governance_owner, incident_learning_loop).

Editorial Notes

Form Classification

Form family: Representation, Specification & Plan

Rationale: A standing, activatable document that says which functions must keep running through a disruption, at what minimum level, who invokes the response, and who talks to whom, making its operative form a non-executable information artifact that externalizes static or prospective structure.

Independent corroboration: The frozen evidence defines Business Continuity Plan as 'A standing, activatable document that says which functions must keep running through a disruption, at what minimum level, who invokes the response, and who talks to whom', so its operative form is Representation, Specification & Plan.

Review outcome: Independent reviewer agreement; high confidence.

Origin Attribution

Primary origin: Disaster Management & Risk Reduction

Origin pattern: Single lineage

Present-day reach: Multi-domain

Rationale: Emergency and disaster-management practice established business continuity planning as the standing method for sustaining critical functions during disruption.

Related originating lineages:

Review resolution: Disaster management is the agreed primary lineage because continuity planning is an established preparedness discipline for sustaining critical functions during disruption. Organizational management contributes service ownership, minimum-service definitions, exercises, and communication responsibilities.

Review outcome: Reconciled after independent review; high confidence.

Notes

[n1] The aphorism attributed to Dwight D. Eisenhower — "Plans are worthless, but planning is indispensable" — captures why a continuity plan's value is in the shared readiness the plan-making produces, not in the document itself. An unrehearsed plan is precisely the "worthless plan" without the indispensable planning behind it.