What is a business continuity plan and how to write one
A business continuity plan is the difference between a bad week and an existential threat. What a plan actually needs to contain, and how to write one that works under pressure.
Most organisations believe they have continuity covered because a plan exists somewhere on the shared drive. Then a supplier collapses, a flood closes a building or a ransomware incident takes out core systems, and the plan turns out to be a contents page with no answers underneath it. Understanding what a business continuity plan actually is, and writing one properly, is one of the highest-return exercises any organisation can undertake.
What a business continuity plan actually is
A business continuity plan sets out how your organisation keeps delivering its critical products and services during a disruption, and how it recovers afterwards. It is not an IT document and it is not an insurance schedule. It starts from a simple question. If this building, system, supplier or team became unavailable at short notice, which activities would we need to protect first, how long could we tolerate losing them, and how would we bring them back?
How it differs from the plans next to it
Continuity planning gets confused with its neighbours more often than any other discipline. An emergency plan covers the immediate safety of people at the scene of an incident. A crisis management plan covers the decisions and communications when the organisation itself is under strain. Disaster recovery covers restoring technology. Business continuity sits above all of them and answers the commercial question, which is how the organisation keeps functioning while the specialists do their work. The plans should reference each other, but they are not interchangeable.
The components every plan needs
A usable plan is shorter than most people expect. It needs a clear statement of your important products and services, ranked by how badly the organisation suffers when each is interrupted. It needs recovery time objectives for each of those activities, agreed by the people who own them rather than guessed by a consultant. It needs named roles with deputies, because the person who wrote the plan will not always be available. It needs contact details that are checked, escalation thresholds that remove hesitation, and workarounds recorded in enough detail that someone who does not normally do the job could follow them at two in the morning.
How to write one, step by step
Start with a business impact analysis to identify what is genuinely critical and how long you can function without it. Map the dependencies behind those activities, including people, systems, suppliers and premises. Agree recovery objectives with the owners of each service rather than imposing them. Draft response actions for the most likely disruption scenarios, keeping them as checklists rather than essays. Assign every role a primary and a deputy. Then walk the plan with the people who would actually use it, and rewrite anything they do not understand. The writing is the easy part. The analysis and the agreement are where the value sits.
The part most plans skip
A plan that has never been exercised is a theory. The organisations that respond well are the ones that rehearse regularly, find the gaps in a controlled setting and fix them before a real disruption exposes the same weaknesses. We set out the patterns behind plans that look solid and fail anyway in a separate briefing, and our crisis exercising service exists precisely to stress-test plans under realistic pressure.
Building the capability in-house
Continuity planning is a learnable discipline with established methods behind it. The Certified Operational Resilience Manager (CORM®) gives individuals the framework, from impact analysis through to testing and maintenance, through distance learning that fits around a full-time role. For organisations that want the plan built and embedded properly, our operational resilience consulting works alongside your teams to produce something your people will actually use rather than file.
Related services
More insights
Keep reading.
Related thinking from the Oakwood team.
Operational resilience: what 'beyond March 2025' actually looks like
The FCA's transitional period has closed. The interesting question now isn't whether you're compliant — it's whether the framework you built is doing any real work.
Supply chain resilience: five lessons from a disruptive 2025
From Red Sea disruption to concentrated cloud outages, last year was an unusually clean test of how resilient your suppliers really are. The results were not flattering.
Why most business continuity plans fail under pressure
The plan is rarely the problem. The problem is the gap between the document and the organisation's ability to operate it.
