BCM Governance

BCM Metrics and Dashboard Guide

A BCM dashboard should answer a management question, not merely display activity. It connects BCM Governance with BCM Metrics and Dashboard Guide, accountable ownership and evidence that can be tested during exercises, reviews or real disruption.

A BCM dashboard should answer a management question, not merely display activity. A useful dashboard tells leaders whether critical services can recover within approved tolerances, whether dependencies are ready, whether exercises prove the plans, and where risk acceptance or investment is required.

Start with decisions, not indicators

Separate executive outcomes from programme activity. Executives need exposure, recoverability, overdue treatment and assurance trends. BCM teams need BIA freshness, plan quality, exercise completion, corrective actions and dependency gaps. Mixing both layers produces a dashboard with many green percentages but little decision value.

Core BCM metric set

MetricDefinitionEvidenceManagement use
Critical service recovery confidenceServices with tested strategies capable of meeting approved RTOExercise/test evidence and recovery resultsPrioritise resilience investment
BIA currencyCritical processes reviewed within the approved cycleApproved BIA recordsDetect stale tolerances and dependencies
Plan readinessPlans passing content, ownership and contact validationQuality review recordTarget weak plans
Exercise effectivenessExercises meeting objectives, not simply completedObjectives, observations and after-action reportMeasure demonstrated capability
Corrective-action ageingOpen findings beyond target closure dateAction registerEscalate unresolved resilience gaps
Dependency assuranceCritical suppliers, technology and sites with validated recovery evidenceContracts, tests and assurance recordsExpose concentration risk

Avoid misleading KPIs

“100% of plans completed” is weak if the plans are untested or use obsolete contacts. “100% trained” says little about response competence. Pair coverage metrics with quality and outcome measures. A mature programme distinguishes leading indicators such as overdue BIA reviews from lagging evidence such as actual recovery time achieved during a test.

Design thresholds and escalation

Every KPI needs an owner, source, calculation, review frequency, threshold and escalation rule. Red/amber/green thresholds should reflect approved risk appetite rather than arbitrary round numbers. A red metric should trigger a named action: remediation plan, risk acceptance, investment decision or executive escalation.

Worked dashboard scenario

A company reports 96% plan completion, yet only 61% of tier-one services have exercised end-to-end recovery in the last year. Three shared applications support 18 critical processes and have never been failed over. The executive dashboard should therefore show recovery assurance as amber or red despite excellent document completion. The action is to test the shared dependencies and validate achieved RTO, not to write more plans.

Implementation checklist

  • Map each metric to a BCM objective or management decision.
  • Define numerator, denominator, exclusions and authoritative data source.
  • Separate coverage, quality and demonstrated-outcome measures.
  • Trend results over time and retain prior periods.
  • Show material exceptions instead of hiding them in averages.
  • Require evidence links for reported assurance.
  • Review thresholds after exercises, incidents and major organisational change.

FAQ

How many BCM KPIs should executives see?

Usually a small set of decision-grade measures is stronger than dozens of operational counts. Use drill-down views for programme management.

What is the best BCM KPI?

No single KPI is sufficient. The strongest outcome measure is evidence that critical services and dependencies can recover within approved tolerances, supported by current BIA and exercise evidence.

Metric governance and data quality

A dashboard is only as trustworthy as the data lineage behind it. For each measure, document the source system, refresh cycle, calculation owner, exclusions and evidence location. If a percentage depends on manually maintained spreadsheets, show the last validation date and the number of records that were not independently checked. This prevents a polished dashboard from creating false confidence.

Where possible, separate reported readiness from verified readiness. A business unit may report that a plan is current, while an independent review finds obsolete contacts or unsupported recovery assumptions. Showing both values makes the assurance gap visible and gives management a concrete reason to fund remediation.

Executive review routine

Use the dashboard as an agenda for decisions. Start with deteriorating indicators, overdue corrective actions and critical services that have not demonstrated recovery. For each red or amber item, record the decision, accountable owner, due date and interim risk treatment. The following review should show whether the decision changed the exposure rather than simply repeating the same status.

A useful quarterly pack also explains material changes in scope. If a new supplier, application or site becomes critical, the denominator may increase and the percentage may temporarily fall. That can be a healthy signal because it reflects a more accurate view of the operating model.

Example metric specification

For “critical services proven within RTO,” define the numerator as critical services with an end-to-end recovery test completed within the approved review period and with achieved recovery time at or below the approved RTO. Define the denominator as all currently approved critical services. Exclude desktop walkthroughs that did not execute dependencies. This definition is auditable and prevents completion activity from being mistaken for recovery capability.

Trend and exception commentary

Every management dashboard should explain significant movement. If recovery confidence falls, state which services drove the change and whether the cause is new scope, failed testing or overdue remediation. If a metric improves, identify the evidence behind the improvement. Commentary prevents leaders from treating percentages as self-explanatory and creates a traceable link between programme activity and resilience outcomes.

Choose metrics that trigger a management decision

A useful BCM dashboard distinguishes readiness, capability, risk and improvement. Activity counts such as “number of plans reviewed” can show workload but do not prove that critical services can recover. Pair them with outcome measures: percentage of critical services with validated strategies, recovery tests meeting approved objectives, unresolved capability gaps by risk level, overdue corrective actions, supplier-assurance coverage and time since the last meaningful exercise.

Define every metric with a numerator, denominator, data owner, source, refresh frequency and interpretation rule. For example, “95% plans current” is ambiguous unless “current” means the plan was reviewed after relevant changes, approved by the owner and validated within the required period. Thresholds should be tied to action: green may require no intervention, amber may require an owner and date, and red may require risk acceptance or executive escalation.

Prevent good-looking dashboards from hiding weak capability

  • Segment results by criticality so a large number of low-impact plans cannot dilute a failure in a critical service.
  • Show trends and ageing, not only a point-in-time percentage.
  • Separate self-reported completion from independently validated recovery evidence.
  • Expose exceptions and missing data rather than excluding them from the denominator.
  • Link dashboard items to the underlying action, exercise, plan or evidence record so reviewers can drill down.

Management should be able to answer three questions from the dashboard: where continuity exposure is increasing, which commitments are not being met, and what decision is required now. If the dashboard cannot support those questions, reduce decorative measures and strengthen the connection between metrics, risk and action.

Worked example: a dashboard that drives action

A useful executive dashboard does more than report that 95% of plans are “complete.” It distinguishes coverage of critical services, overdue BIA reviews, untested recovery objectives, exercise findings by severity, actions past due, supplier dependencies without assurance and recovery tests that exceeded RTO or RPO. Trend and denominator matter: 95% plan completion can conceal the one unplanned service responsible for most revenue. Each metric should have an owner, source, calculation rule, threshold and management action so that the dashboard supports decisions rather than decoration.