Browse all questions
Business continuity
- How detailed should a business impact analysis be?
- Should a business impact analysis be scoped at business service or business process level?
- At what level should a multi-site organisation write its continuity plans, site or function?
- What is the minimum viable company, and how do you find it?
- How do you set a disruption tolerance that is not just a description of current recovery capability?
- Should recovery time and recovery point objectives be set at process level or application level?
- Who should review and approve a continuity plan?
- Our continuity plans are sixty pages long. Is that wrong?
Risk management
Regulatory compliance
Technology and platforms
Running the programme
AI governance
Knowledge base
Evergreen positions, no dates, revised when the position changes. For dated writing, see Insights.
Direct answers to the questions this work actually turns on. Each one states its answer first, then works through where it gets difficult. Choose a question below, or from the list on the left.
Business continuity
Business impact analysis, continuity plans, recovery objectives and disruption tolerance.
- How detailed should a business impact analysis be?
- Should a business impact analysis be scoped at business service or business process level?
- At what level should a multi-site organisation write its continuity plans, site or function?
- What is the minimum viable company, and how do you find it?
- How do you set a disruption tolerance that is not just a description of current recovery capability?
- Should recovery time and recovery point objectives be set at process level or application level?
- Who should review and approve a continuity plan?
- Our continuity plans are sixty pages long. Is that wrong?
Risk management
Taxonomy design, assessment method and how risk maps to controls.
Regulatory compliance
What FINMA, DORA, NIS2 and the CER Directive actually require, and where they overlap.
Technology and platforms
Platform data models, build versus buy, and reporting on your own data.
Running the programme
Why implementations stall, and what a programme actually takes.
AI governance
Governing the AI tools already in use, approved or not.