Business Continuity Planning • FCA SYSC 15A Compliance • Disaster Recovery
List all business functions and assess their criticality. Functions supporting Important Business Services (IBS) under FCA SYSC 15A should be marked accordingly.
| Business Function | Department | Criticality | Supports Important Business Service (IBS)? | Recovery Time Objective (RTO) | Recovery Point Objective (RPO) | Impact if Disrupted | Actions |
|---|
Set maximum tolerable disruption levels for each Important Business Service (IBS). Impact tolerances define the point at which disruption causes intolerable harm to consumers.
| Important Business Service (IBS) | Consumer Impact | Max Tolerable Duration | Max Data Loss | Impact Tolerance Set | Within Tolerance? | Actions |
|---|
For each Important Business Service (IBS), map the resources required to deliver it. Identify single points of failure and concentration risks.
| Important Business Service (IBS) / Function | People (Key Roles) | Technology | Facilities | Third Parties | Single Point of Failure? | Actions |
|---|
Assess each threat by likelihood and impact. The risk score determines priority for mitigation.
| Threat | Category | Likelihood | Impact | Risk Score | Risk Appetite | Existing Controls | Residual Risk | Owner | Actions |
|---|
Test resilience against severe but plausible scenarios. The FCA requires firms to test their ability to remain within impact tolerances under stress conditions.
| Risk Category | Stress Test | Date Tested | Result | Actions / Comments | Actions |
|---|
The Crisis Management Team is activated when a BCP incident is declared. All members must be contactable 24/7.
| Name | Role / Title | CMT Role | Office Phone | Mobile | Personal Email | Deputy | Actions |
|---|
Complete directory of emergency contacts. Keep in Recovery Box and accessible offline.
| Service / Category | Provider / Company | Contact Name | Telephone | Reference / Policy No. | Actions |
|---|
| System | Vendor | Hosting | Recovery Time Objective (RTO) | Recovery Point Objective (RPO) | Backup Frequency | Failover Type | Last Disaster Recovery (DR) Test | Result | Actions |
|---|
Maintain a complete register of all insurance policies relevant to business continuity.
| Insurance Type | Insurer | Policy Number | Cover Level | Excess | Expiry Date | Broker | Actions |
|---|
Maintain a Recovery Box at an offsite location containing these essential items. Review contents quarterly.
Track critical third-party dependencies and their business continuity arrangements.
| Supplier | Service Provided | Criticality | BCP Received? | BCP Adequate? | Alternative Supplier | Contract Expiry | Actions |
|---|