A post-incident review converts real disruption evidence into changes to continuity capability. It should reconstruct what happened, compare actual performance with approved objectives, explain why important gaps occurred, and assign improvements that are verified rather than merely documented.
Start with an evidence-based timeline
Build one reconciled timeline from monitoring records, service-desk tickets, crisis logs, notification platforms, system telemetry, supplier updates and interviews. Record when the disruption began, when it was detected, when escalation thresholds were met, who declared the incident, when workarounds started, when minimum service was restored and when normal service resumed. Where timestamps conflict, retain the conflict and identify the evidence used to resolve it.
Compare actual performance with continuity requirements
For each affected service, compare actual outage duration, minimum service achieved, backlog growth, data loss, customer impact and dependency availability with the approved MTPD or impact tolerance, RTO, RPO and MBCO. A plan can be followed exactly and still be ineffective; the review therefore measures outcomes, not compliance with a checklist.
Separate symptoms from causes
Use causal analysis for material failures. Ask why detection was late, why a decision was delayed, why an alternate site lacked capacity, why a supplier could not meet its commitment, or why restored data required manual reconciliation. Distinguish initiating cause, contributing conditions and control failures. Avoid conclusions such as “human error” unless the review also examines workload, authority, training, interface design and procedural conditions that made the error possible.
Review decisions and information quality
Examine the major decisions made by incident and crisis leaders: activation, prioritization, customer communication, supplier escalation, workarounds, expenditure, failover and stand-down. For each decision, record what was known at the time, what assumptions were made, whether decision rights were clear, and whether better information would have changed the outcome. This creates useful learning without judging decisions using information that became available only later.
Test the continuity chain
- People: Were critical roles available, reachable and authorized? Did succession work?
- Facilities: Could teams access alternate space and required equipment?
- Technology: Did recovery sequence, authentication, integrations and data integrity meet business need?
- Suppliers: Were notification, recovery and escalation obligations usable in practice?
- Information: Were plans, contacts, procedures and reference data available during degraded operation?
- Communications: Did stakeholders receive accurate, timely and audience-appropriate information?
Turn findings into controlled improvements
Write findings as observable capability gaps: condition, consequence, cause, required outcome, accountable owner and target date. Rank actions by exposure rather than ease of closure. Updating a document is not sufficient when the underlying problem is capacity, architecture, contract terms or authority. A material action should remain open until evidence demonstrates that the required capability exists.
Verify effectiveness
Define verification when the action is raised. Examples include a repeat restore test, a timed call-out, proof of alternate-site capacity, a revised supplier exercise, successful transaction reconciliation or a scenario demonstrating faster escalation. Where a full retest is disproportionate, document why the selected evidence is adequate.
Management questions
- Which approved recovery objective was missed and by how much?
- Which dependency created the largest delay or concentration risk?
- What decision lacked timely or reliable information?
- Which workaround created new safety, compliance, fraud or data-integrity risk?
- Could the same failure affect another service?
- Which corrective action requires investment or explicit residual-risk acceptance?
Evidence to retain
Retain the reconciled timeline, incident and decision logs, objective-versus-actual performance, relevant telemetry, communications, interview notes, causal analysis, approved findings, action owners, due dates and effectiveness evidence. The completed review should allow an independent reviewer to trace a significant lesson from observed event evidence through to a verified change in capability.
Separate event facts from hindsight
Reconstruct what participants could reasonably know at each decision point. A later-discovered fact should not be used to judge an earlier decision unless that information should have been available under the approved monitoring or escalation design. This distinction exposes genuine detection and information-flow weaknesses without turning the review into hindsight criticism.
Quantify the recovery gap
For each material service, compare approved tolerance, planned recovery objective, actual restoration time, minimum service achieved and backlog-clearance time. Record the cause of each variance and whether the same constraint could affect other services. Where the business remained within tolerance only because demand was unusually low, record that as conditional success rather than proof that the capability is adequate.
Close systemic findings across the estate
When a finding concerns a shared supplier, identity platform, network path, decision authority or recovery pattern, search for other services with the same exposure. One incident should not generate a narrowly scoped action if the underlying failure mode is enterprise-wide. The action owner should document the affected population, remediation boundary and evidence that equivalent exposures were assessed.
Operational validation checkpoint for Post Incident Review for BCM
For Post Incident Review for BCM, the most useful quality test is whether the organization can use real disruptions to test assumptions in the BIA, plans, escalation, dependencies and recovery capability, not only to review incident-response performance. A credible implementation should be supported by incident timeline, key decisions, actual recovery times, plan usage, objective breaches, dependency failures, workarounds, actions and closure evidence. Reviewers should be able to trace those artifacts to an accountable owner and to the critical service, scenario or decision they are intended to protect. If the evidence is old, generic or disconnected from the actual operating environment, treat the gap as an improvement item rather than assuming the documented approach will work during disruption.
A practical failure mode for Post Incident Review for BCM is closing the incident after service restoration without comparing actual performance with BCM objectives or updating the assumptions that proved wrong. Challenge that assumption in a walkthrough, exercise, test or evidence review that reflects realistic constraints. The corrective action is to reconcile actual RTO/RPO and decision performance with approved targets, then assign changes to plans, strategies, training or supplier arrangements. Record the decision, owner, due date and proof required for closure so the improvement can be verified instead of remaining a narrative recommendation.
- Decision: state what must be decided, triggered or recovered when this capability is used.
- Evidence: identify the current artifact or test result that proves the capability exists for Post Incident Review for BCM.
- Dependency: name the person, system, supplier, facility, data source or authority that can prevent the outcome.
- Threshold: define the point at which the current approach is no longer sufficient and escalation is required.
- Verification: specify how the owner will demonstrate that the corrective action materially improved the capability.
Connect this review to BCM Exercise After-Action Review: Evidence, Findings and Improvement so the decision does not sit in isolation. Post Incident Review for BCM should remain consistent with the wider BIA, recovery strategy, crisis governance and exercise evidence that apply to the same service.
Related BCM.Center resources: BCM Exercise After-Action Review: Evidence, Findings and Improvement.