Purpose
Resolve backup failures, monitor SaaS dependencies, assess material change and keep the backup design proportionate and effective.
Exception Handling Procedure
If a backup download fails:
- Retry the download once.
- If failure persists:
- Notify the responsible IT/Admin.
- Log the incident.
If an upload fails:
- Retry the upload.
- Escalate if unresolved.
Limitations and Risk Acknowledgement
- Monthly backups may result in potential data gaps of up to one month.
- This risk is accepted under the proportionality principle.
- Additional backups may be triggered if the risk profile increases.
Steps
| # | Action | Details | Evidence |
|---|---|---|---|
| 1 | Retry failed operation | Retry a failed download or upload once and record the result. If the backup download fails, retry once; if failure persists, notify the responsible IT/Admin and log the incident. If the upload fails, retry the upload and escalate if unresolved | Retry and incident log |
| 2 | Escalate persistent failure | Escalate persistent failure to Technology, Operations and Compliance and assess data-loss exposure | Escalation record |
| 3 | Track issues to closure | Track missed backups, integrity failures, restore defects and provider incidents to closure | Issue tracker |
| 4 | Monitor material changes | Monitor material changes to Odoo, Microsoft 365, access, locations, sub-processors and service terms | Change monitoring record |
| 5 | Assess additional backup need | Assess whether system changes, releases or high-risk periods (high transaction periods, system changes, prior to major releases) require an additional backup | Additional-backup decision |
| 6 | Review outsourcing evidence | Review Odoo and Microsoft 365 outsourcing, continuity and exit evidence under the outsourcing framework | Outsourcing review record |
| 7 | Conduct annual review | Review backup frequency, retention, access, restore performance, accepted gaps (up to one month under proportionality) and unresolved issues annually, upon system changes and upon regulatory updates | Review record |
| 8 | Approve and update | Obtain approval for material design or risk-acceptance changes and update controlled documentation | Approval and updated documentation |
Records
- Exception and incident log (including download retries, upload retries, IT/Admin notifications, escalations)
- Vendor monitoring and change assessments (Odoo, Microsoft 365, sub-processors, service terms)
- Additional-backup decisions (triggered by high transaction periods, system changes, major releases)
- Annual review, risk acceptance and improvement plan (reviewed annually, upon system changes and upon regulatory updates)
Relationships
- Policy: POL-ODOO-001 Odoo SaaS Backup Policy
- Process: PRC-RSA-001 Resilience Systems and Assurance
- Control: CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed
History
- 2026-07-26: Created from sections 4, 11-13 and 15.4 of the final Odoo backup policy.