How to Create a Business Continuity Management Plan That Works

A solid business continuity management plan keeps your critical operations running when disruption hits, whether that’s a cyberattack, a power outage, or a key staff member suddenly unavailable. For small and medium-sized businesses in New Zealand, the stakes are real. Client deadlines don’t pause, regulators don’t wait, and cashflow gaps appear fast.

Most businesses know they need a business continuity plan, but struggle to build one that staff can actually use under pressure. A document that sits in a folder and never gets tested is not a plan. It’s a liability.

This post walks you through how to write a business continuity management plan from scope to sign-off, covering people, processes, technology, work sites, and suppliers. You will also find a practical template structure, a business continuity plan checklist, and guidance on how to keep the plan current through regular testing and reviews.

What is a business continuity management plan in practice

A business continuity management plan combines two things. The BCM framework sets direction, assigns ownership, and drives improvement over time. The business continuity plan is the document that your team uses when an incident hits. One governs. The other guides action.

In practice, the scope should cover four activity types.

  • Incident response covers the first hours of a disruption
  • Crisis communications keeps staff, clients, and regulators informed
  • Continuity actions keep priority services available during the event
  • Recovery activities return operations to normal levels

The disaster recovery plan vs business continuity plan distinction matters for NZ SMBs. An IT disaster recovery plan restores systems. A business continuity plan covers the whole business, including people, sites, suppliers, and workflows.

Use the five Ps to define your scope clearly.

  • People
  • Places
  • Providers
  • Processes
  • Programs

Common triggers include ransomware, power or ISP outage, flood, sudden staff loss, office inaccessibility, and supplier failure. Your plan should name each one and assign a response path.

Set outcomes and success measures for a NZ SMB

Start with what your business must protect. For most NZ SMBs in legal, finance, accounting, or insurance, the answer is consistent. Serve clients, meet deadlines, protect cash flow, and stay compliant.

Your plan targets should reflect real duties. Under the Privacy Act 2020, a notifiable breach requires a prompt, coordinated response. Contracts may set service levels. Regulators may expect timely notification. Each obligation becomes a measurable target in your plan. The FMA’s guidance on operational resilience makes clear that your BCP should be reviewed, tested and updated on a regular basis to align with emerging risks or changes in the threat landscape, and at least annually.

Define acceptable downtime for each service. Include peak periods such as month-end, tax deadlines, payroll runs, and daily cut-off times. Choose measures that reflect real recovery performance.

Metric What it measures
Downtime minutes by service Total unavailability per function
Recovery time objective (RTO) How fast a service must return
Recovery point objective (RPO) How much data loss is acceptable
Backup restore success rate Reliability of your recovery process
Client notification time Speed of external communication

Decide what good enough looks like for each group. Staff may manage manual steps for one business day. Clients may accept a slower response for a few hours. Owners may tolerate limited reporting briefly, but not missed payments or a privacy breach.

Step-by-step write your business continuity management plan

Step 1: Set scope and owners

Name the plan owner, executive approver, and a deputy for each role before you write anything else. Set decision rights clearly. Who can declare an incident? Who can approve emergency spend, office closure, or alternate supplier use? Clear authority prevents delay when pressure is high.

Step 2: Map critical business functions and dependencies

List every function your business must protect first. For a legal or accounting firm, that may include client communication, file access, document production, billing, trust accounting, payroll, and payment approval. For each function, map its dependencies.

  • Key staff and backups
  • Business applications and data sets
  • Devices, internet, and telephony
  • Suppliers and third-party platforms

This step reveals single points of failure before an incident does.

Step 3: Run a business impact analysis

A business impact analysis (BIA) quantifies what an outage costs your business over time. Measure impact at one hour, four hours, one day, and one week. Cover client service loss, revenue impact, compliance exposure, and workload backlog. The scale of that exposure is real: the NCSC recorded a $7.8 million loss from cyber incidents in Q1 2025 alone, a 14.7% increase on the previous quarter. Keep the BIA worksheet short. A simple table with functions, dependencies, and impact scores works better than a long document for most NZ SMBs.

Step 4: Do a risk assessment for business continuity

Assess your most likely disruption scenarios. Rate each one for likelihood, current controls, and remaining gaps. For NZ businesses, common scenarios include ransomware, M365 outage, ISP failure, severe weather, office loss, and sudden staff absence. This risk assessment for business continuity shows where extra controls or workarounds will reduce real exposure.

Step 5: Set recovery priorities, RTO, and RPO

Use BIA results to rank services in restore order. Then set a recovery time objective (RTO) and recovery point objective (RPO) for each. RTO defines how fast a service must return. RPO defines how much data loss is acceptable. If your backup runs once daily, a one-hour RPO is not achievable. Set targets your infrastructure can actually meet.

Step 6: Choose continuity actions, approve, and publish

For each critical function, document the workaround if normal tools fail. Options include remote work, mobile hotspot, manual forms, phone diversion, or temporary service reduction. Write short, role-specific procedures with a call tree and escalation path. Get sign-off from the executive approver, then publish the plan so that staff can reach it from any device. Store an offline copy as a PDF with version number, owner name, and next review date on the first page.

Build the plan sections your team will rely on during an incident

Your plan needs sections that work under pressure, not just in a review meeting. Each section should be short, specific, and easy to act on.

Roles, escalation, and authority

Document the incident lead, technical lead, communications owner, and finance authority. Include a call tree with mobile numbers, on-call cover, and deputy assignments. State clearly who can approve spend, who can communicate externally, and who can make service reduction decisions.

A business continuity communication plan sets message paths for each audience. Staff need early, factual updates. Clients need to know what is affected and when to expect resolution. Regulators may need formal notification under the Privacy Act 2020. Define who approves each message and which channel each audience receives.

Remote work, workarounds, and systems

A remote work continuity plan should document laptop access, cloud or VPN access, MFA methods, spare device options, and home internet limitations. Note what staff cannot do remotely and provide alternatives for each gap.

For each critical workflow, include a manual form, approval checklist, and reconciliation step. If staff must use paper or spreadsheets, note how data returns to core systems once access is restored.

List key accounts, backup scope, admin access paths, software licences, and key runbooks. Note where break-glass access credentials are stored and who holds the authority to use them.

Business continuity plan template and checklist for fast drafting

A simple business continuity management plan template keeps drafting fast and ensures nothing is missed. Use this structure as your starting point.

  • Scope and purpose
  • Critical business functions list
  • Roles, deputies, and decision rights
  • Contact list with escalation paths
  • BIA worksheet and risk assessment register
  • RTO and RPO register by application
  • Continuity actions and manual workarounds
  • Business continuity communication plan
  • IT disaster recovery links and runbooks
  • Test schedule and results log
  • Document control block

A business continuity plan checklist for sign-off should confirm that all roles have deputies named, supplier escalation paths are documented, backup targets match RTO and RPO, and an offline copy exists. Export the final document as a business continuity plan PDF for offline access on phones and laptops.

Align IT disaster recovery plan with business priorities

Your IT disaster recovery plan should follow business priorities, not server inventory order. Start with critical business functions from the BIA, then map each function to the systems it depends on. That mapping sets your restore sequence.

Document the IT disaster recovery plan steps for each platform.

Platform Backup source RTO target RPO target Owner
Email Cloud backup 2 hours 1 hour IT lead
Practice software Daily snapshot 4 hours 24 hours Vendor
File shares Offsite backup 4 hours 24 hours IT lead
Finance system Daily snapshot 4 hours 24 hours Finance lead
Identity services Cloud redundancy 1 hour 1 hour IT lead

Ransomware, identity lockout, M365 outage, ISP failure, and hardware loss are the most common recovery triggers for NZ businesses. Confirm recovery access before an incident occurs. That includes break-glass accounts, MFA backup methods, admin credentials, and restore test records. If your team cannot authenticate during an incident, recovery stops before it starts.

Test, train, and maintain business continuity planning routines

A plan that has never been tested is a guess. Business continuity testing confirms whether your recovery steps, contacts, and workarounds actually work.

Choose test types that fit your size

Start with a walkthrough, where the plan owner reads through each section with key staff to check for gaps. Move to a tabletop exercise for business continuity, where a facilitator runs a scenario and staff talk through their responses. For high-risk functions, run a live simulation that tests real restore steps and access paths.

Build a test cadence your team can maintain.

  • Quarterly quick checks for contacts, access credentials, and backup status
  • Annual full scenario test covering one or two critical disruption types
  • Ad hoc review after any major system, staff, supplier, or site change

Each staff member should know their first actions, who to call, what to record, and where the current plan is stored. After each test or real incident, record lessons learned, actions required, owners, and due dates. ISO 22301 business continuity concepts reinforce this approach, emphasising documented evidence of reviews, test results, and improvement actions as practical proof your plan works.

Avoid common mistakes that create downtime and confusion

Most business continuity plan failures come from predictable gaps, not unusual events.

  • Plans are too long to use under pressure, with no quick-start page or priority list
  • Tasks have no named owner or deputy, so no one acts when the owner is unavailable
  • Contact details are outdated and supplier escalation paths are missing
  • RTO and RPO targets were set without checking backup frequency, restore time, or vendor response commitments
  • No business continuity testing takes place after sign-off
  • The only copy of the plan is stored on the network, which may be unavailable during the incident
  • Third-party tools such as cloud applications, payment platforms, and telephony sit outside the scope entirely

A shorter plan with clear ownership and tested workarounds protects your business far better than a comprehensive document that no one can find or follow.

Reduce downtime with a plan, plus expert support from Oxygen IT

A practical business continuity management plan starts with a clear scope, named owners, a business impact analysis, and an honest risk review. From there, you set recovery priorities, document workarounds, align your IT disaster recovery plan to business needs, and secure sign-off.

The essentials stay consistent across every NZ SMB. Define RTO and RPO, build a business continuity communication plan, keep runbooks current, and prepare supplier contingencies before you need them. Regular tabletop exercises, staff training by role, backup validation, and scheduled reviews keep the plan usable when disruption hits.

Oxygen IT works with NZ businesses to validate backup coverage, test recovery steps, and confirm plans will hold up under real pressure. With a 15 minute response guarantee on P1 critical issues and a 98 per cent client retention rate, you get practical continuity support without the enterprise overhead.

Ready to build a plan your team can actually use when it counts? Contact us today to find out how Oxygen IT can support your business continuity planning.

FAQs about a business continuity management plan

What is a business continuity management plan and what does it cover?

A business continuity management plan is a documented set of procedures that keeps critical business functions running during disruption and restores priority services within defined timeframes. It covers people, work locations, suppliers, processes, and technology, and is broader in scope than an IT disaster recovery plan alone.

How do I create a business continuity management plan step by step for my organisation?

Start by setting scope and naming owners, then map critical business functions and their dependencies. Run a business impact analysis, assess likely risk scenarios, set RTO and RPO targets, document continuity actions and workarounds, then get sign-off and publish the plan where staff can access it from any device.

What components must be included in a business continuity management plan to make it executable?

An executable plan must include named roles and deputies, a call tree, a business continuity communication plan, manual workarounds for critical workflows, system and data recovery steps, supplier escalation paths, and a test schedule. Without these components, staff will not know what to do or who to contact when an incident occurs.

Where can I get a business continuity management plan template or checklist to speed up writing it?

The template structure and business continuity plan checklist in this guide give you a ready-to-use starting point. Adapt the section headings, BIA worksheet, and RTO and RPO register to your business, then export the completed document as a PDF for offline access on any device.

How do I test and maintain a business continuity management plan so it stays effective and compliant?

Run quarterly contact and access checks, an annual scenario test, and a review after any major change to systems, staff, or suppliers. Use tabletop exercises to test staff responses, record lessons learned, and update the plan before the next review cycle. This approach aligns with ISO 22301 business continuity requirements and provides evidence for audits or client assurance requests.

Let’s transform your business with our reliable IT solutions!