This template library is designed as a connected BCM operating pack, not a collection of empty forms. Start with governance and BIA, use approved requirements to select strategies, convert those strategies into plans and runbooks, validate them through exercises, and track evidence and corrective actions. Each template explains what good information looks like and includes worked examples or review questions.
Template library by BCM lifecycle
| Stage | Template / resource | What you produce |
|---|---|---|
| Govern | BCM Policy Template | Scope, governance, minimum controls, responsibilities, assurance and exceptions |
| Analyse | 79-Question BIA Questionnaire | Impact over time, MTPD/MAO, RTO, RPO, MBCO, dependencies and gaps |
| Analyse | BIA Impact Matrix | Consistent impact categories, severity and timeframe definitions |
| Design | Continuity Strategy Guide | People, site, technology, supplier and workaround options |
| Plan | 22-Section BCP Template | Activation, roles, minimum service, workarounds, recovery and return to normal |
| Recover IT | 16-Section DRP Template | Architecture, runbooks, backup, cyber recovery, validation and failback |
| Communicate | Crisis Communication Template | Stakeholder matrix, holding messages, SITREP and approval routes |
| Validate | Exercise Plan Template | Objectives, scenarios, injects, evaluation and evidence |
| Assure suppliers | 50-Question Supplier Assessment | Supplier evidence, concentration, contracts, test and exit gaps |
| Report | BCM Reporting Guide | Coverage, quality, capability gaps, exercise and corrective-action metrics |
| Practice | BCM System Playground | A browser-based example of connected BCM records |
| Build | Interactive BCM Tools | Quick assessments and planning aids |
How the documents connect
BIA → strategy → plan → exercise → evidence → improvement. The BIA establishes business requirements. Strategy selects a feasible way to meet them. The BCP/DRP translates the selected strategy into executable procedures. Exercises show whether the capability actually works. Findings become corrective actions and management decisions. When any upstream assumption changes, downstream documents should be reviewed.
Recommended minimum data dictionary
| Data family | Key fields |
|---|---|
| Organisation / service | Service ID, service owner, customers/outcomes, locations, operating hours, peak periods, criticality |
| Impact | Impact category, timeframe, narrative consequence, severity, evidence/source |
| Recovery objectives | MTPD/MAO, RTO, RPO by data set, MBCO/minimum service, approver, rationale |
| Dependencies | Type, name, owner, required-by time, minimum capacity, alternate, evidence |
| Strategy | Scenario/resource, selected option, activation lead time, capacity, cost/risk, implementation status |
| Plan | Activation trigger, role, action, sequence, workaround, contact, communication, return-normal criterion |
| Exercise | Objective, scenario, inject, participant, evidence, observed time/capacity, finding |
| Corrective action | Gap, risk/impact, owner, due date, status, evidence, retest result |
Template quality checks
- Every recovery objective has an approver and rationale.
- Every “critical” dependency has an owner and recovery expectation.
- Every workaround has capacity, control and reconciliation rules.
- Every plan names activation authority and measurable minimum service.
- Every DR test includes business validation.
- Every exercise has objectives and observable evaluation criteria.
- Every finding becomes an owned action or explicit risk acceptance.
- Every template has a review date and material-change trigger.
- Sensitive contact or architecture data is protected; public templates use placeholders rather than live details.
For a guided example, open the BCM System Playground and move a sample service from BIA through strategy, plan, exercise and dashboard. Use the country standards hub when you need to understand how international practice intersects with national or sector-specific guidance.
Official references and further reading
- ISO 22301:2019 — BCMS requirements.
- ISO 22313:2020 — Guidance on ISO 22301.
- ISO/TS 22317:2021 — BIA guidance.
- BCI GPG 7.0 — Six professional practices from establishing a BCMS through validation.
Recommended template pack by BCM lifecycle
| Lifecycle step | Core template | Supporting records | What “complete” means |
|---|---|---|---|
| Govern | BCM policy | Scope, roles/RACI, objectives, exception register | Approved accountability and review cycle |
| Analyse | BIA questionnaire | Impact scales, dependency register, recovery objectives | Impact over time and minimum service approved |
| Design | Recovery strategy worksheet | Option appraisal, capacity, supplier/technology evidence | Chosen strategy can plausibly meet approved needs |
| Plan | 22-section BCP | Contacts, quick actions, workarounds, message templates | A duty team can activate and operate it |
| Recover technology | 16-section DRP + runbooks | Backup evidence, architecture, RTO budget, validation | Integrated technology/business recovery demonstrated |
| Exercise | Exercise plan | Injects, evaluator sheets, timeline, AAR | Objectives measured and findings retained |
| Improve | AAR / corrective action | Owner, due date, risk, retest | Material findings closed and retested |
Template anti-patterns to avoid
- Copying a 100-page plan where most sections do not apply.
- Setting RTO/RPO in the plan without an approved BIA.
- Using “work remotely” as the only continuity strategy without identity, device, capacity or connectivity evidence.
- Listing a supplier phone number without understanding the supplier recovery commitment.
- Treating successful infrastructure failover as proof the business service works.
- Closing exercise findings because a document was updated without retesting the capability.
- Putting sensitive employee/customer data into uncontrolled offline copies.
- Using the same plan for every department by changing only the title.
Choose the right template for the question you are trying to answer
| Question | Use this template |
|---|---|
| What would disruption do over time? | BIA questionnaire + impact matrix |
| How quickly must we recover and at what minimum level? | BIA recovery-objective worksheet |
| Which recovery option should we fund? | Recovery strategy worksheet |
| How will the business operate during disruption? | Business Continuity Plan |
| How will technology be restored? | Disaster Recovery Plan + technical runbooks |
| Can a supplier support our recovery requirement? | Supplier continuity assessment |
| How will we test the capability? | Exercise plan + evaluator sheet |
| What failed and what changes now? | After-action report + corrective-action register |
| How do we communicate consistently? | Crisis communication/SITREP templates |
A template is valuable when it supports a decision and retains evidence. Do not force every field into every service. Use the detailed versions as a question bank, then tailor the operational record to the risk, complexity and regulatory context of the service.
Localize the templates without creating five disconnected BCM programs
Use one enterprise BCM data model, then add jurisdiction-specific fields and annexes where needed. A service should still have one accountable owner, one approved recovery requirement set and one dependency map; country requirements should be linked as overlays rather than copied into conflicting local documents.
| Country guide | Useful template overlays to review |
|---|---|
| United States | Continuity/essential-function context, information-system contingency planning, financial-sector BCM where applicable |
| United Kingdom | Important business services, impact tolerances, mapping, scenario testing and Civil Contingencies context where applicable |
| India | Regulated IT/DR controls, recovery drills, transaction integrity, cyber crisis and sector overlays |
| Germany | BSI 200-4 terminology/method, information-security integration and DORA for in-scope financial entities |
| South Africa | Operational-resilience and banking-sector overlays alongside enterprise BCM |
Always verify the current official requirement before treating an example field or cadence as mandatory.