Purpose

Resolve backup failures, monitor SaaS dependencies, assess material change and keep the backup design proportionate and effective.

Exception Handling Procedure

If a backup download fails:

  • Retry the download once.
  • If failure persists:
    • Notify the responsible IT/Admin.
    • Log the incident.

If an upload fails:

  • Retry the upload.
  • Escalate if unresolved.

Limitations and Risk Acknowledgement

  • Monthly backups may result in potential data gaps of up to one month.
  • This risk is accepted under the proportionality principle.
  • Additional backups may be triggered if the risk profile increases.

Steps

#ActionDetailsEvidence
1Retry failed operationRetry a failed download or upload once and record the result. If the backup download fails, retry once; if failure persists, notify the responsible IT/Admin and log the incident. If the upload fails, retry the upload and escalate if unresolvedRetry and incident log
2Escalate persistent failureEscalate persistent failure to Technology, Operations and Compliance and assess data-loss exposureEscalation record
3Track issues to closureTrack missed backups, integrity failures, restore defects and provider incidents to closureIssue tracker
4Monitor material changesMonitor material changes to Odoo, Microsoft 365, access, locations, sub-processors and service termsChange monitoring record
5Assess additional backup needAssess whether system changes, releases or high-risk periods (high transaction periods, system changes, prior to major releases) require an additional backupAdditional-backup decision
6Review outsourcing evidenceReview Odoo and Microsoft 365 outsourcing, continuity and exit evidence under the outsourcing frameworkOutsourcing review record
7Conduct annual reviewReview backup frequency, retention, access, restore performance, accepted gaps (up to one month under proportionality) and unresolved issues annually, upon system changes and upon regulatory updatesReview record
8Approve and updateObtain approval for material design or risk-acceptance changes and update controlled documentationApproval and updated documentation

Records

  • Exception and incident log (including download retries, upload retries, IT/Admin notifications, escalations)
  • Vendor monitoring and change assessments (Odoo, Microsoft 365, sub-processors, service terms)
  • Additional-backup decisions (triggered by high transaction periods, system changes, major releases)
  • Annual review, risk acceptance and improvement plan (reviewed annually, upon system changes and upon regulatory updates)

Relationships

History

  • 2026-07-26: Created from sections 4, 11-13 and 15.4 of the final Odoo backup policy.