On September 29, 2024, Baxter International closed its North Cove plant in Marion, North Carolina, after Hurricane Helene’s flooding cut the site off, and 60% of the IV fluid used by US hospitals stopped shipping overnight. Within two weeks, 86% of surveyed providers reported shortages and hospitals postponed surgeries.
Hospitals hundreds of miles from the flood line discovered they were inside it, which is exactly the scenario a business continuation plan exists to manage. The plan is the documented playbook for keeping mission-critical work running when a disruption arrives without an invitation.
| Business Continuation Plan: Key Takeaways |
| A business continuation plan is the documented playbook that keeps mission-critical functions running during and after a disruption; Hurricane Helene’s September 2024 flooding of one Baxter plant cut 60% of US hospital IV fluid overnight. |
| The business impact analysis drives every decision: which functions are critical, what the RTO, RPO, and MTPD targets should be, and where recovery resources go first. |
| The BCP covers the whole organization; the disaster recovery plan restores technology and sits inside it. You need both, and they answer to different standards. |
| Testing is non-negotiable: an untested plan is a hypothesis. Climb the exercise ladder from annual tabletops to full-scale drills every two to three years. |
| ISO 22301:2019 sets the certifiable benchmark, FINRA Rule 4370 mandates written BCPs at US broker-dealers, and the FFIEC handbook drives bank examinations. |
| Insurance completes the plan: business interruption cover bridges the revenue gap and key person cover protects against irreplaceable people, both sized from the BIA. |
Continuity planning has hard mechanics: a business impact analysis that ranks functions, RTO and RPO targets that size the response, and exercises that prove the paper works. ISO 22301 frames all of it, and US regulators from FINRA to the FFIEC now expect to see the evidence.
What a Business Continuation Plan Is and Does
A business continuation plan, also called a business continuity plan or BCP, is a documented strategy for maintaining or rapidly resuming mission-critical functions during and after a major disruption. It assigns who does what, with which resources, and within what timeframe, before anyone has to improvise.
| Quick Definition |
| A business continuation plan outlines the procedures and instructions an organization follows when facing a disaster or disruption, ensuring personnel and assets are protected and critical functions keep operating. |
Fire, ransomware, flood, or a workforce sent home overnight: the trigger changes while the questions stay the same. A working plan behaves like a program, wiring risk management, emergency response, and recovery strategy into one framework, the shape described in the effective business continuity planning process.
Mature organizations run the plan inside a management system. A business continuity management system adds policy, governance, and audit around the plan itself, and the key elements of business continuity management map how those pieces fit together when auditors come asking.
Why the Business Continuation Plan Cannot Wait
Baxter had a continuity program and still needed every page of it. The company restarted its highest-capacity North Cove lines in early November 2024, roughly five weeks after the flood, while hospitals rationed fluids in between. Preparedness decided who kept operating through those five weeks.
The Numbers That Justify a Business Continuation Plan

Figure 1. The case for a business continuation plan in four numbers: one plant, one storm, and a national shortage inside two weeks.
The baseline is worse than most boards assume. A Mercer survey published in March 2020 found 51% of companies worldwide had no business continuity plan when COVID-19 arrived, and Uptime Institute’s outage analysis keeps finding that most significant outages now cost over $100,000.
Four returns pay for the effort. Downtime shrinks because recovery targets exist before the event, revenue and reputation survive because customers still get answers, regulators find their evidence, and planning exposes single points of failure early. FEMA’s preparedness guidance puts the share of businesses that never reopen after a disaster near 40%.
Business Continuation Plan vs. Disaster Recovery Plan
One scope question causes more confusion than any other. The business continuation plan covers the whole organization: people, premises, processes, partners, and communication. A disaster recovery plan restores the technology layer, and it sits inside the BCP, a split covered in disaster recovery vs business continuity plan, and the quickest way to end a risk-office-versus-IT turf war.
| Dimension | Business Continuation Plan (BCP) | Disaster Recovery Plan (DRP) |
| Scope | Entire organization: people, processes, technology, facilities | Technology and data systems only |
| Focus | Keeping the business running during a disruption | Restoring technology systems after an outage |
| Timeline | Before, during, and after the event | Primarily after the event |
| Includes | Communication plans, alternate sites, supply chain, staffing, the DRP | Server failover, data backups, network recovery |
| Owner | Senior management / BC coordinator | CIO / CTO / head of infrastructure |
| Standard | ISO 22301 | ISO/IEC 27031, NIST SP 800-34 |
Standards follow the same split. ISO 22301 governs the management system, while ISO/IEC 27031 and NIST SP 800-34 cover ICT readiness underneath, and incident response plan vs business continuity draws the third boundary that trips up teams during a live event.
Key Components of a Business Continuation Plan
With the scope settled, the build list comes next. Seven components appear in every plan that survives contact with a real event, and each feeds the next: the risk assessment feeds the BIA, the BIA drives recovery strategies, and the testing program validates the lot.
| Component | What it covers | Why it matters |
| Risk assessment | Threats, vulnerabilities, likelihood, and impact | You cannot protect against risks you have not identified |
| Business impact analysis | Critical functions, dependencies, RTO/RPO/MTPD targets | Drives every recovery priority and resource decision |
| Recovery strategies | Alternate sites, cloud failover, manual workarounds, vendor agreements | Turns targets into options that actually exist |
| Communication plan | Contact trees, stakeholder notifications, media protocols | Silence in a crisis destroys trust faster than the crisis |
| Roles and responsibilities | BC team structure, RACI matrix, escalation paths | Ambiguity in a crisis produces paralysis |
| Exercise and testing | Tabletops, simulations, live drills, lessons learned | Untested plans fail when needed most |
| Plan maintenance | Review schedule, change triggers, version control | An outdated plan describes a company that no longer exists |
Start the risk assessment from what already exists. A business continuity plan risk assessment reuses the ISO 31000 scoring discipline of a step-by-step risk assessment, and threats scored there, from hurricanes to the ransomware scenarios in cybersecurity risk management, flow straight into the impact analysis.
Building the Business Continuation Plan in Seven Steps
The components say what; the sequence says when. Seven steps take an organization from a blank page to a tested, maintained business continuation plan, and FEMA’s continuity guidance follows the same arc. Skipping ahead is the most common way programs quietly fail.
| Step | What you do | What it delivers |
| 1 | Secure executive sponsorship: quantify downtime cost, name a coordinator with budget | Authority and funding behind the program |
| 2 | Run a full risk assessment across natural, cyber, supply chain, and key-person threats | A scored threat inventory |
| 3 | Conduct the BIA with each business unit; set RTO, RPO, and MTPD per function | The ranked blueprint recovery follows |
| 4 | Develop recovery strategies matched to targets: alternate sites, failover, workarounds | Costed options, not theory |
| 5 | Document activation criteria, escalation paths, contact lists, recovery checklists | A plan a stressed reader can follow |
| 6 | Train staff by role and exercise the plan on a rising ladder of realism | Findings logged and tracked to closure |
| 7 | Maintain: review annually and on every trigger, with version control | A living plan that matches today’s organization |
Step one decides the fate of the other six. Quantify downtime cost and regulatory exposure for senior leadership, then name a business continuity coordinator who carries both authority and budget, because a plan owned by nobody gets maintained by nobody.
Write the documentation for a bad day. Activation criteria, escalation paths, contact trees, and recovery checklists should read cleanly to a stressed employee at 2 a.m., which is why how to build a business continuity plan keeps procedures at checklist altitude instead of policy prose.
RTO, RPO, and MTPD in the Business Continuation Plan
Three numbers from step three steer every downstream decision. RTO answers how fast a function must return, RPO answers how much data the organization can afford to lose, and MTPD marks the outer limit before damage turns existential. The difference between RPO and RTO sounds academic until it prices a backup contract.

Figure 2. The three clocks of the business continuation plan: RPO runs backward from the disruption, RTO and MTPD run forward.
| Metric | Definition | Example | Drives |
| RTO | Maximum acceptable downtime before a critical function must be restored | Online payments: RTO = 2 hours | Alternate sites, staffing, infrastructure |
| RPO | Maximum tolerable data loss, measured back from the disruption | Customer database: RPO = 15 minutes | Backup frequency, replication strategy |
| MTPD | Maximum tolerable period of disruption before existential damage | Core platform: MTPD = 24 hours | Recovery priority ranking, resource caps |
Set the targets at business-function level first, never per application. The business owns the requirement and technology delivers it, so when BIA workshops anchor an RTO to order processing rather than to a server, the plan keeps tracking what the revenue actually rides on.
The BIA That Anchors the Business Continuation Plan
Every number in the previous section comes out of one exercise. Skip the business impact analysis and the whole business continuation plan runs on guesswork; done properly, the BIA produces a ranked inventory of critical functions, their dependencies, and the cost of losing each function over time.

Figure 3. Impact over time, by function: the steepest curve earns the shortest RTO and the first claim on recovery spending.
Running the BIA Workshop for the Business Continuation Plan
Put business unit leaders in the room and keep the technology team in a supporting seat. Walk each function through one question at rising horizons: what happens when this stops for an hour, a day, a week? The answers land directly in recovery strategy design.
| BIA output | Description | How it gets used |
| Critical function ranking | Functions ordered by business impact score | Sets recovery sequence and resource allocation |
| Dependency map | Links functions to technology, people, vendors, data | Reveals hidden single points of failure |
| RTO / RPO targets | Downtime and data-loss thresholds per function | Drives infrastructure spend and vendor SLAs |
| Financial impact curve | Loss trajectory over hours, days, and weeks | Justifies budgets and insurance limits |
| Regulatory obligations | SLAs, compliance deadlines, contractual commitments | Prevents breaches and contractual penalties |
Two outputs justify the workshop by themselves. The dependency map exposes single points of failure nobody owned, including the vendors covered in how to manage third-party risk, and the financial impact curve hands the CFO a defensible basis for both budget and insurance limits.
Testing and Maintaining the Business Continuation Plan
An untested plan is a hypothesis with a logo on it. Exercises expose the stale phone number, the badge that no longer opens the recovery site, and the backup nobody ever restored, and every finding gets logged and tracked to closure like an audit item.
| Exercise type | Description | Frequency | Complexity |
| Tabletop exercise | Discussion-based walkthrough of a scenario with key stakeholders | At least annually | Low |
| Walk-through drill | Team physically walks procedures without full activation | Semi-annually | Medium |
| Simulation exercise | Realistic scenario under simulated crisis conditions and time pressure | Annually | Medium-high |
| Full-scale live drill | Actual activation, including relocation to the alternate site | Every 2-3 years | High |

Figure 4. The exercise ladder: climb it in order, and let each rung’s findings harden the plan before the next one raises the stakes.
When the Business Continuation Plan Must Be Updated
Reviews run on triggers as well as the calendar. New systems, restructures, office moves, mergers, major vendor changes, and any live incident each force an update, and how often risk assessments should run supplies the floor when nothing has changed at all. Version control keeps the history auditable.
A handful of key risk indicators cover the gap between formal reviews: exercises overdue, corrective actions aging past 90 days, and contact-list entries that bounce. Movement in any of them says the plan is quietly separating from the organization it is supposed to protect.
ISO 22301 and the Rules Behind the Business Continuation Plan
Regulators have converged on what the standard wrote down. ISO 22301:2019 defines the requirements for a certifiable business continuity management system and runs on Plan-Do-Check-Act: policy, BIA and risk assessment, strategies, response procedures, exercising, and management review. Certification signals continuity is engineered, and audited.
| Regulation | Sector | Business continuation plan requirement |
| FINRA Rule 4370 | Financial services (US) | Written BCP covering emergency contacts, data backup, alternate communications, regulatory reporting |
| OCC / FFIEC | Banking (US) | BCP with BIA, risk assessment, regular testing, and third-party resilience |
| HIPAA | Healthcare (US) | Contingency planning: data backup, disaster recovery, emergency mode operations |
| DORA | Financial services (EU) | ICT risk management and operational resilience testing for EU-facing entities |
| SOC 2 | Technology / SaaS | Availability criteria require a documented and tested BCP and DRP |
In the US, FINRA Rule 4370 requires every broker-dealer to maintain a written plan, the FFIEC business continuity handbook drives bank examinations alongside the interagency third-party guidance, and HIPAA’s security rule covers healthcare contingency planning. DORA reaches EU-facing financial entities, and SOC 2 pulls in most SaaS vendors.
Board reporting closes the loop. Continuity exposures belong among the key elements of a risk register, roll up through the enterprise risk management framework, and the risk appetite statement decides how much downtime the organization will carry before funding more resilience.
What Goes Wrong with Business Continuation Plans, and the Fixes
Six failure patterns account for most dead plans, and none of them involve the disaster itself. Each row pairs the mistake with its root cause and the fix that keeps the business continuation plan alive between crises rather than embalmed in a binder.
| Pitfall | Root cause | Remedy |
| Treated as a technology project | Only IT owns the plan | Senior management ownership, every unit contributing |
| BIA skipped | Priorities set by opinion | Evidence-based ranking before any strategy spend |
| Never tested | Paper mistaken for capability | Exercise ladder with findings tracked to closure |
| No maintenance | Plan written once and shelved | Trigger-based reviews plus a formal annual cycle |
| Third-party blindness | Internal focus, vendor dependencies unmapped | Dependency map plus contingencies in supplier contracts |
| Communication as afterthought | Contact lists stale, no media protocol | Owned contact tree, tested quarterly |
Insurance Inside the Business Continuation Plan
Operational recovery is half the answer; cash is the other half. Business interruption insurance, often sold as business continuation insurance, replaces lost income and covers continuing expenses while a covered event suspends operations, bridging the gap between disruption and full recovery.
Key person insurance protects against losing the individuals whose skills or relationships the plan cannot replace on schedule. The payout funds recruitment, covers lost revenue, or finances a buy-sell agreement among partners, and the BIA identifies which names warrant the premium.
Develop the two together. The BIA’s financial impact curve is the evidence that sizes business interruption limits, and its critical-people analysis sets key person coverage, so an insurance program built apart from the business continuation plan usually insures the wrong things.
Common Business Continuation Plan Questions Practitioners Ask
What is a business continuation plan?
A business continuation plan is a documented strategy that lets an organization maintain or quickly resume mission-critical functions after a disruptive event such as a natural disaster, cyber-attack, or supply chain failure. It covers people, processes, technology, facilities, and communication, and it is validated through regular exercises.
Is a business continuation plan the same as a business continuity plan?
Yes. Business continuation plan and business continuity plan describe the same document; continuation is older phrasing that survives in insurance products and some policy language. Both abbreviate to BCP, and ISO 22301 governs the management system behind either name, whichever one your policy uses.
How does a business continuation plan differ from a disaster recovery plan?
The business continuation plan covers the entire organization: people, processes, technology, facilities, and communication. The disaster recovery plan restores technology systems and data after an outage, and it operates as one component inside the broader BCP, alongside communication and staffing plans.
How often should a business continuation plan be tested?
Run tabletop exercises at least annually, walk-through drills semi-annually, and a full-scale live drill every two to three years. High-risk sectors such as financial services and healthcare often test quarterly, and ISO 22301 requires exercising on a planned, documented cadence.
What are RTO and RPO in a business continuation plan?
RTO, the recovery time objective, is the maximum acceptable downtime before a critical function must be restored. RPO, the recovery point objective, is the maximum tolerable data loss measured back from the disruption. Both targets are set per function during the business impact analysis.
Who owns the business continuation plan?
Ultimate accountability sits with senior management and the board, with day-to-day management delegated to a business continuity coordinator or team. Every business unit maintains and activates its own portion, and internal audit tests the program independently on a regular cycle.
Three Shifts Coming for the Business Continuation Plan: 2026-2027
Regulatory resilience testing is spreading beyond banking. DORA went live for EU financial entities in January 2025, US agencies keep sharpening operational resilience language, and the direction runs one way: regulators want demonstrated recovery, on real systems, with dated evidence attached.
Climate volatility has outrun the hazard maps plans were built on. Helene put a mission-critical pharmaceutical plant under water in the North Carolina mountains, far from any coastline, and location assumptions inherited from ten-year-old BIAs deserve a fresh look this cycle.
The third shift is concentration. Cloud regions, single-source suppliers, and shared software agents mean one event now interrupts thousands of organizations at once, so recovery strategies increasingly have to plan for shared outages in which the alternate vendor is down too.
Baxter’s five-week restart is the honest benchmark. Recovery at that speed came from a rehearsed program with pre-positioned options, and the hospitals that rationed least were the ones whose business continuation plan had already asked the IV question. The rain only graded the homework.
Put Your Business Continuation Plan to Work with Risk Publishing
Risk Publishing helps US risk and continuity teams build and pressure-test a business continuation plan that stands up to examiners and real events, from the BIA workshop to the exercise calendar. Browse our services, then contact us. A scheduled drill costs far less than an unscheduled one.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.