Purpose

Identify, evaluate and treat disruption risks that could prevent recovery within approved impact tolerances.

Steps

#ActionDetailsEvidence
1Review current BIARecovery objectives, incidents, changes, and threat informationReview notes
2Identify disruption scenariosThreat identification: cybersecurity attacks, natural disasters, system failures, regulatory risks, operational dependenciesScenario register
3Analyze single points of failureData centers, network providers, key staff expertise, supply chainsSPOF analysis
4Identify concentration risksConcentration, interdependency, and single-point-of-failure risksRisk register
5Assess residual riskLikelihood, impact, existing controls, and residual risk per scenarioRisk assessment
6Assign treatment strategiesFor risks outside tolerance: Reduction (preventive controls), Transfer (insurance, outsourcing), Avoidance (cease risky activities), Acceptance (low-impact risks)Treatment plan
7Escalate material risksResidual risks and overdue treatments escalated to management and BoardEscalation records
8Review periodicallyAt least annually and updated when new threats or dependencies emergeReview record

Records

  • Continuity risk assessment
  • Scenario and dependency analysis
  • Treatment plan and risk acceptance
  • Escalation and closure evidence

Relationships

Assurance

Runtime effectiveness results are maintained in Odoo and assessed through the Hermes workflow tracked in ISS-HERMES-001. This note defines design, ownership, evidence expectations and testing method; it does not contain a manually maintained operation, evidence or overall effectiveness rating.

  • Frequency: annual and event-driven

History

  • 2026-07-26: Created from section 7 of the approved Business Continuity Manual.