article
Our continuity plans run to sixty pages. Is that wrong?
By Maximilian Bazzi · Published 6 October 2026
- BCM
- operational resilience
- FINMA
Continuity plans running to fifty pages and beyond are common in regulated institutions, and the instinct that something is wrong with them is correct. The usual diagnosis, that they are too long, is not quite right, and acting on it produces a different failure.
What the evidence says about long plans
The most useful criticism comes from the profession itself rather than from vendors selling an alternative. The Business Continuity Institute has described the traditional continuity plan as the War and Peace of disaster recovery documents, ring-bound and covered in dust because it typically goes unread, observing that it is unlikely to be the document anyone reaches for during an actual emergency (Preen, 2021).
ISO guidance points the same way, holding that quickly understood, user-focused documents are more suitable than the large unwieldy documents suited to auditors, and that smaller plans are therefore more likely to be needed than one large plan (International Organization for Standardization, 2020).
The behavioural basis is well established. Research on emergency checklists in aviation and medicine holds that procedural memory is less affected by acute stress than declarative memory, which is why time-critical emergency actions are kept as short memorised items while long reference material is deliberately separated out.
Real incidents bear this out. During an extended healthcare systems outage in 2024, providers reverted to manual workarounds, and the subsequent review found that many continuity plans lacked a paper downtime procedure for a disruption of that duration (American Hospital Association, 2024). Following the global operating system outage of July 2024, the Financial Conduct Authority found that what separated firms which coped was mapped services, pre-defined and tested communications, and prior testing of severe but plausible scenarios (Financial Conduct Authority, 2024). None of those advantages is a function of documentation length.
The actual diagnosis
A sixty-page plan is usually two documents that have been merged.
One of them is a reference artefact. It records the impact analysis, the dependency data, the recovery strategies and the rationale, and it exists so that a supervisor, an auditor or a successor can understand how the organisation reached its conclusions. This document should be comprehensive, and regulatory frameworks require it to exist.
The other is an execution aid. It is opened during an incident by someone under pressure who needs to know what to do and in what order. It should be short, role-based, and organised so that the reader sees only what applies to the situation they are in.
These have different readers, different purposes and different optimal lengths. Merging them produces a document that serves neither, and the merged version fails in the direction of the auditor, because that is the reader who complains.
The strongest objection
A three-page playbook will not survive a supervisory review. ISO 22301, DORA, FINMA Circular 2023/1 and the Basel operational resilience principles all require documented impact analysis, dependencies and recovery strategies. A firm that arrives with a short playbook and nothing behind it will be found wanting, and rightly.
There is a second objection with real force. Some recovery genuinely requires detailed technical sequences. A database failover or a controlled switchover cannot be reduced to bullet points without losing the precision that makes it work.
The answer to it
Neither argues for one merged document. The first argues for keeping the detail, which is exactly what separation does; the reference library is not deleted, it is stopped from pretending to be an operational tool. The second argues for referenced runbooks, which are detailed by necessity and pointed to from the playbook rather than pasted into it.
The position is therefore narrower than the usual advice. Do not shorten your plans. Split them, and be honest about which document is being written for which reader.
The test to apply
Open your continuity plan and find the point at which someone acting during an incident would stop reading. In most documents it arrives within the first few pages, and everything after it is reference material.
Then ask a different question, which is more uncomfortable. When was this plan last executed against a scenario that was allowed to hurt, rather than reviewed? Survey work suggests a majority of organisations never perform a full simulation (Disaster Recovery Journal, 2023). A plan of any length that has never been executed is a document about recovery rather than a capability for it.
References
American Hospital Association (2024) Lessons learned from the Change Healthcare cyberattack. Chicago, IL: American Hospital Association.
Disaster Recovery Journal (2023) The state of business continuity preparedness. Produced with Forrester Research.
Financial Conduct Authority (2024) Global technology outage: lessons for firms. London: Financial Conduct Authority.
International Organization for Standardization (2020) ISO 22313:2020 Security and resilience: business continuity management systems: guidance on the use of ISO 22301. Geneva: ISO.
Preen, J. (2021) Playbooks are the future, business continuity plans are the past. Caversham: The Business Continuity Institute.