Business continuity reporting should answer a simple leadership question: where could we fail to meet an important recovery requirement, and what are we doing about it? A dashboard that only shows “97% of plans complete” may look healthy while critical services still depend on untested technology or a supplier with no recovery evidence.
Five layers of BCM metrics
| Layer | Example metrics | What it tells you |
|---|---|---|
| Coverage | % critical services with approved BIA; % plans current | Has required work been completed? |
| Capability | RTO vs demonstrated recovery time; workaround capacity vs MBCO | Can we meet the requirement? |
| Assurance | Exercise coverage; DR test success; call-tree reach rate | Has capability been validated? |
| Exposure | Single points of failure; unsupported systems; supplier gaps | Where are the material weaknesses? |
| Improvement | Overdue actions; repeat findings; average closure age | Are known weaknesses actually closing? |
Executive dashboard: keep it decision-oriented
An executive BCM dashboard should usually fit on one screen. Show a small number of high-value measures, trend, target and the top exceptions. Useful cards include critical services with unmet RTO, critical services not exercised within the required cycle, high-severity overdue actions, supplier continuity exceptions, BIAs affected by recent change, and current program maturity trend. Every red number should lead to an owner and a decision path.
Operational dashboard: give BCM teams the work queue
Operational teams need more detail: BIAs due in the next 30/60/90 days, plans awaiting approval, services with missing owners, exercises scheduled, DR tests without business validation, dependencies without recovery evidence, expiring supplier assurance, open findings and actions nearing breach. This turns reporting into work management rather than a presentation exercise.
Useful formulas
- BIA freshness: current approved BIAs ÷ in-scope BIAs × 100.
- Exercise coverage: critical services exercised within required cycle ÷ critical services × 100.
- RTO capability match: services where demonstrated recovery time ≤ approved RTO ÷ services with validated tests × 100.
- Action breach rate: overdue actions ÷ open actions × 100.
- Supplier assurance coverage: critical suppliers with current continuity evidence ÷ critical suppliers × 100.
Do not hide small denominators. “100% RTO compliance” based on one tested service can mislead. Show both percentage and count, for example 1/1 tested, 24 not yet tested.
Example monthly BCM report structure
- Executive summary: three changes that matter.
- Critical recovery gaps and accepted risks.
- Coverage and freshness of BIA/plans.
- Exercise and test results, including failures and lessons.
- Technology and supplier recovery gaps.
- Corrective-action ageing and escalations.
- Upcoming major changes or events affecting continuity.
- Decisions required from leadership.
Metrics that often create false confidence
- Number of documents created without checking whether they are usable.
- Training attendance without testing whether people understand activation and roles.
- Exercise count without measuring scenario coverage or closed findings.
- Plan approval percentage without freshness or change triggers.
- RTO values without comparison to demonstrated technology and resource capability.
The BCM System Playground includes a demo dashboard where BIA, plan, exercise and incident records change readiness metrics in real time.
Board pack narrative example
Instead of writing “BCM compliance is 92%,” say: “Twenty-four of twenty-six critical services have approved BIAs. Four services have recovery targets that have not yet been demonstrated in an exercise or DR test. Two depend on the same network component, creating a concentration risk. Remediation owners are assigned; one action is overdue and requires funding approval.” The second version gives leadership a decision, not just a score.
Frequently asked questions
What are the best BCM KPIs?
Use a balanced set covering scope/coverage, demonstrated recovery capability, exercise assurance, material exposure and corrective-action closure.
Should BCM dashboards show only percentages?
No. Include counts, denominator, trend and material exceptions so percentages cannot hide untested or out-of-scope items.
How often should BCM be reported?
Cadence should match governance and risk. Operational dashboards can be continuous; leadership reporting is often monthly or quarterly, with immediate escalation for material recovery gaps.
Metric catalogue with formulas
| Metric | Formula / method | What it measures |
|---|---|---|
| BIA coverage | Approved in-scope BIAs ÷ required in-scope BIAs × 100 | Coverage only; does not prove recovery |
| Plan validation coverage | Critical services with exercised current plan ÷ critical services × 100 | Assurance coverage |
| RTO capability attainment | Services with demonstrated recovery ≤ approved RTO ÷ tested services × 100 | Recovery capability |
| RTO gap hours | Demonstrated recovery time − approved RTO | Magnitude of missed target |
| RPO attainment | Tests where observed data loss ≤ RPO ÷ applicable tests × 100 | Data recovery |
| MBCO attainment | Demonstrated minimum throughput ÷ required MBCO throughput × 100 | Degraded-operation capacity |
| Critical supplier evidence | Critical suppliers with current service-specific resilience evidence ÷ critical suppliers × 100 | Third-party assurance |
| Single-point concentration | Count of material dependencies without viable alternate/mitigation | Exposure |
| Exercise finding closure | Findings closed with evidence ÷ findings due × 100 | Improvement |
| Overdue high-risk actions | Count and age of overdue high-priority BCM actions | Risk backlog |
| Call-tree reachability | Confirmed reachable priority contacts ÷ priority contacts attempted × 100 | Emergency communications |
| Plan change latency | Median days from material change to plan/BIA update | Maintenance responsiveness |
Thresholds should be risk-based and organisation-specific. Avoid publishing arbitrary “industry benchmark” percentages unless a reliable source actually supports them. A useful dashboard shows target, current result, trend, data freshness and owner so management can act on the result.
Executive dashboard example
| Signal | Illustrative result | Interpretation / action |
|---|---|---|
| Critical services tested this year | 18 of 22 | Four services still lack current assurance; two are high priority |
| RTO gaps | 5 services | Largest gap: 3.6 hours; remediation funded for three, two await risk decision |
| MBCO gaps | 2 services | Workaround capacity lower than approved minimum |
| Critical supplier evidence | 31 of 38 current | Seven assessments expired or lack service-specific test evidence |
| High-risk actions overdue | 4 | Oldest 73 days; escalate owners and funding blockers |
| Recent actual disruption | 1 major / 3 minor | Lessons mapped to two plan changes and one architecture action |
Dashboard anti-patterns
- Green status based only on document review date.
- A single composite maturity score that hides a failed critical-service RTO.
- Counting exercises without measuring objectives.
- Reporting supplier questionnaires received without judging evidence quality.
- Showing average RTO across unrelated services.
- Closing actions because a policy was updated when technical/workaround capability remains untested.
- No data freshness timestamp or accountable owner.