Skip to content

Audit & Assurance

Business Continuity and Disaster Recovery Audit

Most continuity plans are documents that have never been invoked. We test whether yours would actually work — and whether the recovery objectives it promises are achievable in practice.

What we test

  • Business impact analysis — whether it exists, whether the criticality ratings are justified, and whether it has been refreshed since the business changed.
  • Recovery objectives — whether RTO and RPO are defined per process and system, agreed by the business rather than set by IT, and technically achievable with the infrastructure in place.
  • Continuity strategy — whether the chosen strategy actually delivers the stated objectives, or whether there is a gap nobody has priced.
  • Plan content and currency — call trees, escalation criteria, invocation authority, alternate site arrangements, and whether contact details are current.
  • IT disaster recovery capability — replication configuration, backup coverage and integrity, restoration testing evidence, and DR site readiness.
  • Testing regime — the type, frequency and realism of exercises, and whether findings from previous tests were closed.
  • Governance — management review, resourcing, and reporting to the board.

The gap we most often find

A documented RTO of four hours, a backup regime that produces a recoverable copy once every twenty-four hours, and no one has reconciled the two. The plan promises something the infrastructure cannot deliver, and this is only discovered during an actual incident.

The second most common: restoration has never been tested. Backups complete successfully every night and no one has ever proved a restore works. A backup you have not restored from is a hypothesis, not a control.

RPO and RTO, and the gap between promise and capability

Incident Last good backup RPO — data you lose Service restored RTO — time you are down THE GAP WE MOST OFTEN FIND A documented 4-hour RTO sitting above a backup cycle that produces onerecoverable copy every 24 hours.

Live exercise observation

Where scope allows, we observe an actual invocation exercise rather than relying on the test report. Observed exercises consistently reveal issues that written reports omit — dependencies nobody documented, access nobody could obtain out of hours, and recovery sequences that assumed staff who were not available.

How the engagement runs

  1. 1

    Scope and criticality

    Agree which processes and systems are in scope, weighted by business criticality.

  2. 2

    BIA validation

    Test whether the impact analysis is current, evidenced and consistently applied.

  3. 3

    Capability assessment

    Compare stated recovery objectives against actual technical capability. This is where most gaps surface.

  4. 4

    Plan review

    Assess plan completeness, currency and usability under stress by someone who did not write it.

  5. 5

    Test evidence review

    Review exercise records, scope and realism, and confirm previous findings were closed.

  6. 6

    Observation and reporting

    Observe a live exercise where possible, then report against ISO 22301 with a prioritised gap list.

What you receive

Assessment against ISO 22301:2019 clauses
BIA validation with challenge on criticality ratings
RTO and RPO achievability analysis — stated versus demonstrable
Backup and restoration testing assessment
Exercise observation report where a live test is in scope
Prioritised remediation plan with realistic cost and effort indications

Frequently asked questions

Because the test scope is usually set by the team being tested. Common limitations: testing a single system rather than an integrated recovery, testing during business hours with full staff available, recovering to a clean environment rather than a degraded one, and excluding the dependencies that would actually cause the failure. An independent audit challenges the scope, not just the result.

It can, and increasingly it should. Recovery from ransomware differs materially from recovery from a hardware failure — the backups may be encrypted or deleted, the recovery environment may be compromised, and there is a forensic preservation obligation that conflicts with speed. If that scenario matters to you, we scope it explicitly.

We can, on a separate engagement. But not the plans we then audit — the independence principle applies here as everywhere else in our practice.

Related services

Related regulatory frameworks

Need an independent view?

Tell us the scope, the regulator and the deadline. We will come back with an approach, a team and a fee estimate.

Request a proposal
Top