Page 25 - Insurance Times February 2023
P. 25
information from the BIA and risk assessment, organizations strategy is kept consistent with the latest changes to the
determine which business functions are "core" or "mission- enterprise. Education is ongoing to maintain awareness of
critical" and determine a strategy to manage the risks responsibilities when an emergency strikes.
identified in the risk assessment process (address, mitigate,
Elements of Business Continuity
or accept). The critical time frames and impacts from the
BIA are used to determine which contingency strategies are Management (BCM)
viable. The strategy alternatives must satisfy the BIA for both
Business Continuity Management is an ongoing process with
cost effectiveness and response times. The planners usually
several different but complementary elements mentioned
present three to four alternatives to management with the
below:
most cost effective alternative as the recommendation.
Risk Mitigation Plan: Organizations, today, are taking a
comprehensive and methodical approach to risk
Phase IV- Business Continuity Plan Development: On the
mitigation to ensure their business continuity. By
basis of phases I, II and III, the Business Continuity plan is
developing, implementing and testing risk mitigation
created. Being the main deliverable of the project, the BC
strategies, they provide their business with a level of
plan includes department level DR plans, external supplier
resiliency and operational insurance which positions their
response plans, and the like. The BC Plan is updated regularly.
business to continue, perform and succeed against
The primary components of the BCP include, but are not
unexpected threats. A viable Business Continuity plan
limited to:
involves a detailed plan for risk identification,
Communication/ Coordination Plan: Communication
prioritization, monitoring, and mitigation as a part of
is the key in any crisis. The Communication and
project planning. It covers all business units, verticals,
Coordination plan establishes the communication
service offerings, support groups and subsidiaries; and
channels to be used during the execution of a BCP;
offer a deeper, more diverse, and quantified feedback
determines a chain of command for coordination of the
on risks. This enables organizations to address the actual
BC effort; defines authorized media contacts; and
and the potential risk events in a systematic manner.
includes notification procedures for key suppliers,
Business Continuity Plan: The value of a business
vendors and clients.
continuity plan can never be exaggerated. Business
Emergency Response Plan: The Emergency Response
Continuity plan is one of the pillars in the overall
Plan specifies responses to the emergency situations,
framework of Project Business Continuity Management.
which are defined as risks that pose a danger to life,
Organization should develop a comprehensive BCP based
property, or the environment. This includes Emergency
on the size and complexity of the institution. The goal of
Notification tools like Email, Phone, SMS, FAX or Pager.
the BCP should be to minimize losses to the institution,
serve customers with minimal disruptions, and mitigate
Phase V - Business Continuity Plan Testing: In a quest to
the negative effects of disruptions on business
know whether their BCP is viable and usable, planners conduct
operations.
thorough functional testing of their mission-critical
Pandemic Plan: BCP planning cannot be restricted only
applications and personnel to verify that all business processes
to breakdown of critical operations and controls. Business
work as expected. Plan testing is a regulatory requirement
can also get hampered in the event of a pandemic, which
as well. It defines the methodology used to test the BCP,
leads to human-resource disruption. An absence of staff
deciding on "how often do we test?", "how much do we
can result in stalling of key functionalists which are
test?", and "how do we judge the success or failure of the
important to keep an organization functional. It thus
test?". Once the test methodology is decided upon, business
becomes important to prepare your company for
continuity plan is tested as an iterative task, at least twice
organizational downtime during the health crisis; by
annually.
considering the risk of pandemic outbreak while planning
for business continuity.
Phase VI - Plan Maintenance: An outdated plan is as good as
no plan. Most organizations strive to keep their Business Contingency Plan: The key to attain and sustain success
Continuity Plans up to date with the latest and most efficient is by being prepared for the unexpected. Contingency
recovery processes. Elements regarding Recovery time planning is thus imperative for every organization so that
objectives, Recovery Point Objectives, are evaluated and they can have advance plans and strategies ready, to
included in the plan. Testing and managing of the recovery effectively handle unexpected problems, emergencies
The Insurance Times January 2023 23