Business Continuity Plan Template
Five documents and five sheets built around what is unavailable rather than what went wrong, with every recovery target traced to a deadline somebody else set.
Free download · No account needed
Critical Process Register
Bellhaven Logistics, 180 staff, two warehouses
| Organising axis | Unavailability class, not scenario |
| Dependencies mapped | 14, of which 6 are single points of failure |
| Open gaps | 4, one with no date because the decision is unmade |
Where each hour figure comes from
| Process | Deadline it feeds | Worst moment | Tolerance | Target | Verdict |
|---|---|---|---|---|---|
| Carrier tendering | Tender cutoff 15:00, a miss rolls the load | 14:40 weekdays | 20 min | 15 min | Met |
| Payroll | Bank cutoff, 3 working days out | 16:00 on the 24th | 90 min | 60 min | Met |
| Wave release and picking | Same-day dispatch, orders before 13:00 | 11:00 Friday | 2 h | 90 min | Unmeasured |
| Customs entry filing | Filed before the vessel discharges | Filer absent | 4 h | 4 h | Gap |
| Month-end billing | Customer portal closes, 5th working day | 12:00 on the 5th | 3 h | 2 h | Met |
| Proof of delivery | Unposted PODs cannot be billed at all | 4th working day | 8 h | 4 h | Untested |
| Stock accuracy report | No hard external deadline | Month end | 72 h | 72 h | Met |
The two columns no other template has
Deadline it feeds is where the tolerance comes from, so the number is checkable against a contract instead of trusted. Worst moment is why payroll has ninety minutes rather than three weeks.
Stock accuracy earns a row precisely because it has no hard deadline. Seventy-two hours of slack, written down, is the process not to spend money protecting.
Every template in this genre makes you pick disasters. Flood, fire, ransomware, supplier failure, pandemic, key-person loss, and the same content written once per scenario with a hole wherever imagination ran out. There are only four classes of unavailability: a system, a site, a person, a supplier. Ransomware, a billing dispute and a data centre fire all ask the same question about your warehouse system, and it has the same answer in all three cases. Four columns, no hole.
Then the recovery target, which every template asks you to assign and none of them tells you where to get. It is downstream of a tolerance, and NIST says so directly: because the objective must ensure the tolerable downtime is not exceeded, it must normally be shorter than it. The tolerance is the interval to the first hard external deadline the process feeds. A carrier cutoff at three, a bank submission window, a portal that closes on the fifth working day.
And tolerance depends on when the outage starts, which nothing else in this genre carries. Payroll has three weeks of slack on the fifth and ninety minutes at four o'clock on the twenty-fourth. Every row carries the worst moment instead of the average one. Send River the system inventory and the org chart, or take the documents and CSV sheets blank, beside the procedures the plan depends on existing and the audit that ranks what only one person knows.
What's in the pack
Single Point of Failure Map
One row per dependency across all four unavailability classes, with qualified alternates counted and a separate column for whether the alternate has actually performed the work. Those two disagree constantly, and the disagreement is the finding worth having.
Critical Process Register
The deadline each process feeds, the worst moment in the week, the tolerance measured from there, the target set inside it, and the honest estimate of recovery today. Four verdicts rather than two, because Unmeasured ranks below Gap.
Degraded Mode Playbook
What the business does while the thing is still down, which is a different document from how to restore it. Each row carries how long the workaround holds, what accumulates while it runs, and what has to be reconciled afterwards.
Contact Tree
An out-of-band channel on every row, staff and customer notification kept as separate trees, decision authority recorded next to reachability, and at least one branch that reaches somebody outside the company entirely.
Exercise Log
One dependency made unavailable against the clock, never a simulated disaster. The column that matters most records what broke that nobody predicted, which is never in the step the plan describes.
Where Recovery Targets Come From
The reference behind every hour figure. It keeps the tolerance and target vocabulary straight, lists the seven kinds of hard external deadline worth hunting for, and explains why the same process has two tolerances. Plus what to do when the estimate is worse than the target.
Continuity Standard and Continuity Plan
Four rules on one page, plus a filled plan for a fictional logistics business so the format is arguable against something real. It carries four open gaps, one of them with no date at all because the decision has not been made.
Key Person Risk Note and Recovery Runbook
The class that actually happens, since most companies see more resignations in three years than system outages, written up with its three failure modes separated. A resignation is this class with notice attached, which is where the handover itself picks it up.
How to use it
- 1
Open in River, or take it blank
Install the pack in River and hand it your inventory, or download the five documents and five CSV sheets and work them yourself.
- 2
Send the inventory and org chart
A list of the tools you pay for and who does what. An export of who holds administrator rights is the single best evidence of where work concentrates.
- 3
Answer the deadline question
For each critical process, the first hard external cutoff it feeds. You are looking that up in a contract or a tariff rather than deciding it.
- 4
Exercise one dependency
Make one thing unavailable for two hours and run the workaround against the clock. Record what broke that nobody predicted, because something always does.
Frequently asked questions
Is this free, and what do I get?
Free, and there is no signup gate on the download. Five documents and five spreadsheets. The AI half is optional: send a system inventory and an org chart, and River maps the dependencies, finds the ones with a single person or account behind them, and works out what stops. More in the template library.
Why not organise the plan by disaster scenario?
Because it makes you write the same thing repeatedly and still misses whatever you failed to imagine. A vendor outage, a ransomware event and a billing dispute all take the same system away, so they all get the same answer. Four unavailability classes cover every scenario anybody names and the ones nobody does.
Where does the recovery time objective actually come from?
The first hard external deadline the process feeds. A carrier tender cutoff at three in the afternoon, a bank submission window three working days out, a customer portal that stops accepting invoices on the fifth working day. Those are written in contracts and tariffs already, so the tolerance is checkable rather than negotiated.
What if we cannot meet the target we derived?
Write the gap down with an owner and a date. Do not loosen the target until the two agree, which is how these documents become fiction and leaves no trace on the page. NIST prescribes the honest version: document the situation and plan its mitigation when the tolerance is inflexible.
What is a degraded mode playbook, and why is it separate?
Restoring the system ends the outage; degraded mode is what the business does during it, and where the system is vendor hosted the restore is not yours anyway. The health information security rules make an emergency mode operation plan required while leaving the criticality analysis merely addressable.
Does the contact list really need somebody outside the company?
Yes, and a regulator wrote it down. FINRA requires two emergency contacts, and a firm with only one associated person must name a second from outside the firm entirely: their attorney, accountant or clearing contact. A tree that only reaches inside has no branch surviving the company being unreachable.
How do we test this without running a full disaster exercise?
Make one thing unavailable and run the workaround against the clock. Two hours, one dependency, unannounced where it is safe. Every exercise in the log found something nobody predicted, and it was never in the step the plan described: a locked whiteboard, a lapsed retainer, a stock extract thirty-one hours old.
Stop picking disasters
Take the documents and CSV sheets blank, or install this pack in River and send it a system inventory and an org chart.
Edit with AI