Audit & Assurance
Business Continuity and Disaster Recovery Audit
Most continuity plans are documents that have never been invoked. We test whether yours would actually work — and whether the recovery objectives it promises are achievable in practice.
What we test
- Business impact analysis — whether it exists, whether the criticality ratings are justified, and whether it has been refreshed since the business changed.
- Recovery objectives — whether RTO and RPO are defined per process and system, agreed by the business rather than set by IT, and technically achievable with the infrastructure in place.
- Continuity strategy — whether the chosen strategy actually delivers the stated objectives, or whether there is a gap nobody has priced.
- Plan content and currency — call trees, escalation criteria, invocation authority, alternate site arrangements, and whether contact details are current.
- IT disaster recovery capability — replication configuration, backup coverage and integrity, restoration testing evidence, and DR site readiness.
- Testing regime — the type, frequency and realism of exercises, and whether findings from previous tests were closed.
- Governance — management review, resourcing, and reporting to the board.
The gap we most often find
A documented RTO of four hours, a backup regime that produces a recoverable copy once every twenty-four hours, and no one has reconciled the two. The plan promises something the infrastructure cannot deliver, and this is only discovered during an actual incident.
The second most common: restoration has never been tested. Backups complete successfully every night and no one has ever proved a restore works. A backup you have not restored from is a hypothesis, not a control.
RPO and RTO, and the gap between promise and capability
Live exercise observation
Where scope allows, we observe an actual invocation exercise rather than relying on the test report. Observed exercises consistently reveal issues that written reports omit — dependencies nobody documented, access nobody could obtain out of hours, and recovery sequences that assumed staff who were not available.
How the engagement runs
-
1
Scope and criticality
Agree which processes and systems are in scope, weighted by business criticality.
-
2
BIA validation
Test whether the impact analysis is current, evidenced and consistently applied.
-
3
Capability assessment
Compare stated recovery objectives against actual technical capability. This is where most gaps surface.
-
4
Plan review
Assess plan completeness, currency and usability under stress by someone who did not write it.
-
5
Test evidence review
Review exercise records, scope and realism, and confirm previous findings were closed.
-
6
Observation and reporting
Observe a live exercise where possible, then report against ISO 22301 with a prioritised gap list.
What you receive
Frequently asked questions
Related services
Related regulatory frameworks
Need an independent view?
Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.
Request a proposal