Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Business Continuity and Disaster Recovery: Two Different Jobs

Business continuity is keeping a service running by another route while the usual route is unavailable, and it is a business arrangement. Disaster recovery is restoring the technology the service normally runs on, and it is a technology one. Continuity asks how the customer still gets served today. Recovery asks how the machinery comes back. Both are built to two objectives: how fast, and how much recorded work may be lost.

Continuity and recovery get run together constantly, in board papers and in ordinary conversation, and the merge costs real money. The two are answers to two different questions about the same bad morning, and an institution can do one of them perfectly while failing the other. Everything below is worked on Vindhya Commercial Bank Limited, an invented bank, on its seven services, on the seven objectives set against each of them and on the whole month 12 test result.

The two objectives about to be met look technical and are not. Both of them are decisions somebody at board level took about how much the outside world should be made to put up with, and no technical training is needed to follow either one.

What is business continuity, and what is it actually for?

Business continuityKeeping a service running by another route while the usual route is unavailable. is the arrangement by which a service keeps reaching the person who uses it when the ordinary way of delivering it has stopped. Notice what that definition does not mention. The definition does not mention what broke, it does not mention fixing anything, and it does not mention how long the repair will take. Continuity is entirely about the customer being served, and not at all about mending whatever failed.

Take a school bus that will not start on a Tuesday morning. Continuity is not the mechanic. Continuity is the parent group chat that arranges four cars, a list of who is picking up whom, and one person deciding at seven fifteen that the cars are happening. The children reach school. The bus is still broken and will be broken at lunchtime, and the service was delivered anyway. Somebody else, later, deals with the bus.

A bank does the same thing at a larger scale and with more paperwork. If the branch counter cannot process a withdrawal because the branch has no power, continuity is a nearby branch, or a mobile channel, or a manual register with a per customer cash limit and two signatures. Each of those is a standby arrangementA second way of delivering a service, kept ready but not normally used. or a workaroundA manual or partial route that delivers less than the usual service and delivers something., and both are business decisions with a cost attached, made long before the morning they are needed.

The reason continuity is a business arrangement and not a technical one is that only the business can decide what a reduced service is allowed to look like. Can the manual register go up to Rs 50,000/- per customer or Rs 5,000/-? Are new account applications simply refused for the day, or taken on paper and keyed in later? None of those is a question about machinery, so nobody who runs machinery can answer them. Each one is a question about which customers get told no.

What is disaster recovery, and why is it a different job?

Disaster recoveryRestoring the technology a service normally runs on after it has failed. is the work of bringing the machinery back: the records, the processing, the connections, restored to a state the institution can carry on from. Recovery is measured by whether the machinery that stopped is running again, and it is planned, staffed and rehearsed by the people who run that machinery.

Back to the bus. Recovery is the mechanic, the spare part, and whether the bus runs tomorrow. The repair is real work, it is necessary, and while it is happening not one child is any closer to school. The distinction is that plain, and it survives translation into a bank without a single change.

The two jobs can succeed and fail in any combination. Nothing shows more clearly that they are not one job. A branch with no power has lost nothing technical at all, so there is nothing to recover and the entire answer is continuity. Nobody outside notices a processing failure that has no customer facing effect until the evening batch, so that one is almost entirely recovery. And the case that matters most is the one where recovery finishes cleanly and the service is still not being delivered.

FOUR THINGS THEY DIFFER ON, AND NOT ONE OF THEM IS HOW BAD THE FAILURE WAS BUSINESS CONTINUITY DISASTER RECOVERY What it delivers The service reaches the customer by another route The machinery the service normally runs on is back Who decides it The business, because only it can say what reduced means The people who run the technology, to a set objective How success is known A customer outside got what they came for, at some level The thing that stopped is running and can be used again What it leaves behind A broken thing, still broken, and a served customer A working thing, and a customer who may still be waiting Either column can be a clean success on a day the other column is a total failure.
Continuity and recovery differ on what they deliver, who decides them, how success is judged and what each leaves behind, and either one can succeed on a day the other fails completely.

Why are these two jobs and not two words for one job?

Because they are funded, staffed, planned, tested and reported by different people, and because the failure that triggers both of them does not care that they were merged in a document. Keeping the two apart is not a vocabulary exercise. The separation decides whether anybody is answerable for the customer while the repair is going on.

There is a practical test for any plan. Read it and ask: if this works perfectly, is a customer served? If the honest answer is no, and it is only that the machinery is running again, the document is a recovery plan that somebody has labelled continuity. A plan that restores things is not a continuity plan just because the word continuity is on the front of it.

Try it out

A branch loses power for the whole day. Every system in the bank is running normally. Is that a continuity problem or a recovery problem?

What is a recovery time objective, and who decides it?

A recovery time objectiveHow quickly the arrangement is built to bring one named service back. is a single number attached to one named service: how quickly the arrangement is built to have that service reaching customers again. The objective is a design target. The objective is what the money was spent to buy, and it is written down before anything goes wrong so that the arrangement can be built against it and then tested against it.

Two things about it surprise people. The first is that it belongs to a service and not to a system, so the same piece of machinery can sit under a service asking for one hour and a service asking for twelve, and the arrangement has to satisfy the tighter of the two. The second is that it is a business decision. The number states how long the outside world should be made to wait. Deciding how long customers wait is a judgement about customers, not a description of what the equipment can already do.

The second of the two is where it goes wrong most often. If the people who run the machinery are asked to propose the number, what usually comes back is roughly what the current arrangement already achieves, dressed up as a target. Nothing has been decided at all; the present has been written down and given a name. The board setting it, in the outside world's terms, is the only version that can ever demand a change.

Derivatives Foundation Bootcamp — Fin Maverick

What is a recovery point objective, and why is it not measured in time?

A recovery point objectiveHow much recorded work may be lost, measured as an amount of data rather than an amount of time. answers a completely different question: when the service comes back, how much of the work that was recorded before it stopped is allowed to be missing? The objective is quoted in minutes, and the minutes confuse everybody. The minutes measure an amount of work rather than a delay. Five minutes here means five minutes of instructions, entries and applications that vanished, not five minutes of waiting.

Think about a shopkeeper who writes each sale in a paper book and copies the day's total into a ledger every evening. If the book is lost at four in the afternoon, the ledger is missing everything since last night, and reopening the shop tomorrow does not bring those entries back. How often the copy is taken decides how much can be lost, and that is a decision about the copying and not about the reopening. The two numbers are set by two different considerations and there is no arithmetic that turns one into the other.

At this invented bank the two objectives on the seven services do not sit in any fixed proportion to one another. Divide the second by the first, service by service, and the answer ranges from zero to one third. Knowing how fast a service must come back says nothing about how much of its work may be lost. Both numbers have to be set, and neither can be inferred from the other.

TWO OBJECTIVES PER SERVICE, ON ONE MINUTE SCALE, AND THEY MEASURE DIFFERENT THINGS how fast it must be back how much recorded work may be lost BACK IN MAY LOSE 0 2 h 4 h 6 h 8 h 10 h 12 h S1 payments 1 h none at all S2 branch counter 3 h 15 min S3 internet and mobile 2 h 5 min S4 loan disbursal 8 h 1 h S5 account opening 12 h 4 h S6 trade finance 8 h 1 h S7 treasury settlement 1 h none at all S1 and S7 carry a red mark rather than a short bar, because no work at all may be lost, and that is a different kind of arrangement.
Each service carries two objectives on one minute scale, and the second divided by the first runs from zero at S1 and S7 to one third at S5, so neither number can be worked out from the other.
Try it out

S1 payments and remittances may lose no recorded work at all. S5 deposit account opening may lose four hours of it. What is the actual difference between those two services?

Why is the pair set service by service and never once for the whole institution?

Here is the full set at this invented bank, and read down the two number columns before reading anything else. Every figure is the board's own, and none of it is normal practice anywhere.

ServiceWhat it isBack inMay lose
S1Payments and remittances1 hournothing
S2Branch counter service and cash withdrawal3 hours15 min
S3Internet and mobile banking2 hours5 min
S4Loan disbursal8 hours1 hour
S5Deposit account opening12 hours4 hours
S6Trade finance issuance8 hours1 hour
S7Treasury settlement1 hournothing

The spread across the first column runs from one hour to twelve, a factor of twelve, and the spread across the second runs from nothing at all to four hours. Any single number set once for the whole institution is simultaneously too generous for S1 and far too demanding for S5, and it is wrong in both directions at the same time. Setting it once looks like simplification and is actually two mistakes bought together.

The everyday version is a household that decides everything must be sorted within an hour. The gas cylinder running out has to be sorted within an hour, and so does the leaking tap. One of those is dinner and the other one can wait until Sunday, and a household that treats them alike either spends its weekend on the tap or eats late. Deciding service by service is not bureaucracy; it is how the effort ends up where it changes something.

One boundary constrains every comparison that follows. Behind these seven design numbers sits a separate board promise, the impact tolerance, set out under operational resilience. For S4, S5 and S6 that promise is written in working days rather than in hours. The board never wrote down how many hours a working day is, so the two units cannot be subtracted. The promise on those three cannot be turned into hours, and cannot be compared with anything measured in hours. Every minute figure below is a recovery time objective and never a promise, and the two are not the same object.

Try it out

A bank sets one recovery time objective of four hours for everything it does, on the grounds that one number is simpler to manage. What has it just done?

What else has to fit inside a recovery time objective?

A recovery time objective catches out almost everybody who meets it for the first time. The objective is not a budget for doing the recovery. The objective is a budget for the whole gap between the service stopping and the service working again, and the doing is only the last third of that gap.

Three things happen in that gap, in this order. Somebody has to notice the service is down. Noticing is not instant, and it is sometimes very slow indeed when the first evidence is a customer telephoning. Somebody with the authority has to decide to switch to the other route. The switch carries a cost, so the decision is not taken in a second. Only then does anybody start switching. The invocationThe moment somebody decides to switch to the other route, which is a decision and not an event. is a decision made by a named person. Until that person makes it, the arrangement standing ready is doing nothing at all.

THREE THINGS FIT INSIDE ONE RECOVERY TIME OBJECTIVE, AND ONLY THE LAST IS THE SWITCH THE OBJECTIVE FOR S1: 60 MINUTES NOTICING 15 min DECIDING 10 min SWITCHING 40 min OVER BY 5 0 10 20 30 40 50 60 70 minutes 15 noticing + 10 deciding + 40 switching = 65 minutes, against an objective of 60. The arrangement that switches in 40 minutes is well inside the hour on its own, and the service still came back late. The 15, the 10 and the 40 are illustrative. The invented case records no split of any outage into these three stages.
Noticing, deciding and switching all run inside the same recovery time objective, so an arrangement that switches in forty minutes still misses a sixty minute objective once fifteen minutes of noticing and ten of deciding are spent first.

Read the drawing again and notice where the loss happened. Nothing in it was slow. Fifteen minutes to work out that something is wrong is fast when the first symptom is a customer complaint. Ten minutes to find the person who can authorise a switch is fast if that person is at their desk. Forty minutes to switch is comfortably inside the hour on its own. Three reasonable numbers, one broken objective, and no villain anywhere.

The two most valuable things that can be bought against a tight objective are usually not recovery capability at all. The first is a way of finding out sooner, and the second is a standing rule about who may say go, written down in advance so that nobody spends the third stage of the budget looking for a person. Both are cheap and neither is technical.

Try it out

Three things happen inside a recovery time objective, one after another. Which set is it?

Try it out

Seven services were tested at this invented bank in month 12. Which one missed its objective by the largest margin?

Debt Capital Markets Bootcamp — Fin Maverick

What happened when this invented bank actually tested it?

In month 12 Vindhya Commercial Bank Limited ran a continuity test across all seven important business services. The test measured one of the two objectives, the recovery time. Four services met theirs and three did not, so 57.1 per cent met and 42.9 per cent missed. The whole result repays reading row by row rather than as a headline.

ServiceObjectiveAchievedResultMargin
S1 payments and remittances60 min52 minMet8 min inside, 13.3 pc
S2 branch counter and cash180 min220 minMissed40 min over, 22.2 pc
S3 internet and mobile banking120 min190 minMissed70 min over, 58.3 pc
S4 loan disbursal480 min360 minMet120 min inside, 25.0 pc
S5 deposit account opening720 min540 minMet180 min inside, 25.0 pc
S6 trade finance issuance480 min840 minMissed360 min over, 75.0 pc
S7 treasury settlement60 min48 minMet12 min inside, 20.0 pc
Seven services4 met, 3 missed57.1 pc and 42.9 pc

Two things in that table are worth more than the headline count. The first is that the two tightest objectives, S1 and S7 at one hour each, both passed, and they passed by 8 minutes and 12 minutes. The services with the least room to spare are the ones that got the attention. The worst failure of the day was S6 trade finance issuance at 75.0 per cent over, and nobody would have called trade finance issuance urgent. That is the ordinary shape of this result, and it is worth expecting rather than being surprised by.

The second is that a count of four out of seven hides a range. The three misses were 40 minutes, 70 minutes and 360 minutes over. One of the three misses is nine times the size of another, and flattening all three into one word loses the only fact a board could act on.

THE MONTH 12 TEST, EACH SERVICE AGAINST ITS OWN OBJECTIVE, AS A PERCENTAGE Left of the line is inside the objective. Right of the line is over it. Every objective is the invented board's own figure. 25 pc inside on the objective 25 pc over 50 pc over 75 pc over S1 payments and remittances 13.3 pc 8 min inside S2 branch counter and cash 22.2 pc 40 min over S3 internet and mobile banking 58.3 pc 70 min over S4 loan disbursal 25.0 pc 120 min inside S5 deposit account opening 25.0 pc 180 min inside S6 trade finance issuance 75.0 pc 360 min over S7 treasury settlement 20.0 pc 12 min inside Four met and three missed, and the three misses run from 22.2 per cent to 75.0 per cent, which one count cannot carry.
The month 12 test met four objectives and missed three, and the three misses range from 22.2 per cent over on S2 to 75.0 per cent over on S6, so the count of three hides a spread of nine times in minutes.
Try it out

A recovery takes 3 hours in total, measured from the moment the service stopped. How many of the seven services meet their objective?

Play with it

The recovery time budget, against how many services make it

One control: the whole time from the service stopping to the service working again, in minutes, noticing and deciding included. One consequence: how many of the seven meet the objective they were built to. The result does not fall smoothly. The count sits still for hours and then drops.

HOW MANY OF THE SEVEN MEET THEIR OBJECTIVE, AS THE TOTAL TIME GROWS The upright scale counts how many of the seven meet their objective. It falls in five steps, and two of the five drop two services at once. 0 1 2 3 4 5 6 7 0 2 h 4 h 6 h 8 h 10 h 12 h 14 h total minutes 180 m, 4 meeting THE SEVEN SERVICES AT THE CURRENT SETTING the objective what the month 12 test achieved the current setting S1 payments INSIDE BY 0 m S2 branch counter INSIDE BY 0 m S3 internet and mobile INSIDE BY 0 m S4 loan disbursal INSIDE BY 0 m S5 account opening INSIDE BY 0 m S6 trade finance INSIDE BY 0 m S7 treasury settlement INSIDE BY 0 m Every objective and every achieved time here is the invented board own figure, set by that board and bynobody else. Nothing on this control is a requirement, a standard or a normal practice anywhere.
0 minutes3 h900 minutes
Total time
3 h
Meeting the objective
4 of 7
Missing it
3 of 7
Count changes next at
181 m

Educational illustration. At the default setting of 180 minutes, 4 of the 7 services meet their objective, being S2, S4, S5 and S6, and S1, S3 and S7 do not. The month 12 test also came out at 4 met and 3 missed, and from a different three. The misses there were S2, S3 and S6. The total on this control includes noticing and deciding and not only the switch. How much recorded work may be lost is a separate objective and is not drawn here. The board promise sitting behind these services is a different object again. Its figures for S4, S5 and S6 are written in working days, and none of them is converted into minutes here.

What could that test not test?

The single most important sentence about the month 12 result is not in the table. The month 12 test ran on a planned date, with the recovery team on standby, and the failure chosen in advance, so it tested the arrangement and not the surprise. Those are two different claims, and the one people quote is not the one the test supports.

Look back at the three stages that fit inside a recovery time objective and count how many of them a planned test actually exercises. Noticing takes no time when everybody already knows the failure is coming at eleven o clock. Deciding takes no time when the decision was taken at the planning meeting three weeks earlier. The switch is all that is left, it is the stage a competent arrangement is most likely to handle well, and it is the only stage the clock ran on.

THE SAME SWITCH, TWO DIFFERENT MORNINGS, ONE OBJECTIVE THE 60 MINUTE OBJECTIVE FOR S1 THE PLANNED TEST the team was waiting THE SWITCH, 52 MINUTES MET BY 8 A REAL FAILURE nobody was waiting NOTICING AND DECIDING THE SAME SWITCH OVER BY 17 0 20 40 60 80 100 120 minutes S1 passed the test with 8 minutes to spare, so 8 minutes is the whole of what noticing and deciding may cost. The 25 minutes drawn on the second row is illustrative. The invented case measured nothing outside the planned test.
A planned test removes noticing and deciding entirely, so the 8 minutes by which S1 passed is the whole budget those two stages would have to fit inside on an unplanned morning.

The four passes can now be read honestly. S1 passed by 8 minutes and S7 by 12. The 8 and 12 minute margins are not comfort, they are the entire allowance that noticing and deciding would have to fit inside on a morning nobody planned, and a fifteen minute delay in working out that something is wrong would turn both of those passes into misses without the switch getting one second slower.

None of this makes the test worthless. Testing the arrangement is worth doing, it is the only way to find out that S6 is 75.0 per cent over, and it found exactly that. The honest claim is simply smaller than the claim people usually make from the same evidence, and stating the limitation beside the result is what keeps the two the same size.

Try it out

The month 12 test met four of seven objectives. Is that a good result?

The failure: everything was restored, and the service was still down

The failure the whole distinction exists to prevent needs nobody to be careless or wrong. In the month 12 test S6 trade finance issuance came back in 14 hours against an 8 hour objective. On that same day a technology report could say, entirely correctly, that every system had been restored. A service report would have to say that trade finance issuance was unavailable for 14 hours, 75.0 per cent over and the worst result of the day.

The failure is not that either report is wrong. The failure is that only the first report gets written. The people who restore machinery know precisely when the machinery is back, because that is their work and they can see it. Nobody has been made answerable for knowing when the service is back, so nobody measures it, so it does not appear. The largest single miss of the day is invisible on the only document that was produced.

The same shape appears at a wedding. The generator is fixed by eight o clock and the caterer confirms it. Whether four hundred people ate is a question nobody at the generator was asked, and if the only person reporting is the one who fixed the generator, the evening is recorded as a success. Two honest answers to two different questions, and only one of them was ever asked.

The repair is unglamorous and cheap: name a person answerable for service availability who is not the person answerable for restoration, and make the service report a separate document with its own row per service. The repair costs one sheet of paper, and in exchange a 75.0 per cent overrun cannot leave the building disguised as a completed restoration.

TWO REPORTS ON THE SAME TEST DAY, BOTH CORRECT One of them exists. THE TECHNOLOGY RESTORATION REPORT Systems taken down as planned. Restoration run against the plan. Every system restored. No outstanding technical item. RESTORATION COMPLETE THIS REPORT WAS WRITTEN THE SERVICE AVAILABILITY REPORT S1 back in 52 minutes, met. S2 220 minutes, missed by 40. S3 190 minutes, missed by 70. S6 840 minutes, missed by 360. S6 UNAVAILABLE 14 HOURS, 75.0 PC OVER THIS REPORT WAS NOT WRITTEN Nobody has to be wrong for both sheets to be true at once. They answer two different questions and only one was asked.
A technology restoration report and a service availability report on the same test day give different answers, and the second one, which carries the 75.0 per cent overrun on S6, was never produced.
Try it out

The technology report says everything was restored by lunchtime. What question has it not answered?

Mutual Funds Bootcamp — Fin Maverick

What does a continuity plan actually contain?

A continuity planThe written arrangement naming the other route, who invokes it and what the customer is told. is a short document and most of what makes it useful is a set of names and sentences rather than any capability. Four things have to be in it. Miss any one and what remains is a description rather than a plan, and the difference shows up on the one morning it is opened.

CONTINUITY PLAN FOR ONE SERVICE, THE FOUR PARTS Every one of these is a name or a sentence. Not one of them is a capability. WHAT HAPPENS IF IT IS MISSING 1 The other route Which second way this service will be delivered by, named specifically. Nobody knows what to switch to, and the first hour goes on inventing something. 2 Who decides to switch One named role who may say go, reachable at every hour the service runs. The arrangement stands ready while somebody hunts for a person with authority. 3 What the customer is told The words, the channel and who says them, settled before the morning. Silence, and a customer who assumes their money has gone somewhere. 4 Getting back to normal The steps that close the other route and return to the usual one, in order. The workaround quietly becomes permanent and nobody reconciles what it recorded. A plan describing only part 1 is a description of an arrangement rather than a plan for using it. Illustrative structure. The invented case records no continuity plan text for any of its seven services.
A continuity plan needs the other route, the person who may switch to it, what the customer is told while it runs and how the institution returns to normal, and three of the four are sentences rather than capabilities.

Notice which of the four the money usually goes to. Part one looks like preparation, so it is the expensive one and the one every plan already has. Parts two, three and four cost almost nothing and are missing far more often. The most common reason a continuity arrangement underperforms on the day is not that the other route was absent but that nobody had settled who could say go, and no capability closes that gap.

Part three deserves a sentence of its own because it is the part the customer actually experiences. A person who cannot withdraw cash and is told, at the counter, that the counter is down for about two hours and the branch two streets away is working, has had a bad morning. The same person told nothing at all has had a different kind of morning, and it is the second one that turns up as a complaint and, eventually, as a conduct question. Telling the customer is part of continuity, not a communications afterthought.

Reading a Term Sheet Structurally — free micro-course from Fin Maverick

Who is answerable for continuity, and where is it written down?

Continuity at this invented bank is not a project that happened once. Continuity is policy PL9, one of nine policies numbered PL1 to PL9, and the placement is what makes it a standing arrangement. Each of the nine names an owner, an approver, a review cycle and the limits it cascades into. A policy carries a named person and a review date, and a completed project carries neither. The difference is between an arrangement somebody keeps current and one that was correct on the day it was built.

CONTINUITY IS ONE POLICY INSIDE A SET OF NINE, AND THAT IS WHAT MAKES IT STANDING The nine policies of one invented bank. PL9 is the one at issue here. PL1 enterprise risk PL2 credit risk PL3 market risk PL4 liquidity risk PL5 operational risk PL6 model risk PL7 information security PL8 outsourcing and third party PL9 business continuity AND EVERY ONE OF THE NINE CARRIES THESE FOUR FIELDS an owner an approver a review cycle the limits it cascades into The invented case does not record who the owner of PL9 is.
Business continuity sits as policy PL9 inside a set of nine, and each of the nine carries an owner, an approver, a review cycle and the limits it cascades into, which is what turns an arrangement into something somebody is answerable for keeping current.

There is a second reason the placement matters, and it is about who gets to argue. If continuity lives inside the technology function as an operating practice, the recovery time objective is negotiated by the people who would have to meet it. The failure set out above arrives by a different door. If it lives as a policy with a business owner and a board level approver, the objective is set outward and the arrangement has to move to meet it. Where the document sits decides which way the argument runs.

The invented case does not record who the owner of PL9 is. The case does record the shape: nine policies, each with those four fields, and business continuity as one of them rather than as a folder somebody keeps.

Try it out

Where is business continuity written down at this invented bank, and why does the answer matter?

How this gets used

What a customer, an analyst and a household each do with it

A large corporate customer does this before it concentrates its payments anywhere. Girish Talwalkar, group treasurer at the invented Nirjhar Industries Limited, will not ask his bank about its technology, and he does not need to. The two questions that get him what he needs are: which of the bank services carries an objective of an hour or less, and what does the last test say was actually achieved on each. Two questions, no technical vocabulary, and an answer that tells him whether his payroll run has a second route on the day something breaks.

An analyst reading a bank from outside uses the same two numbers differently. A published objective is a statement of intent and costs nothing to make. A published test result against that objective is evidence. The gap between an institution that discloses objectives and one that discloses results is the whole distance between an intention and a measurement, and it is visible without any access to the institution at all.

And the household version, on a smaller balance. The case is the single account a household runs every standing payment through. The other route is a second account with a month of expenses in it, and the four parts of a plan translate exactly: the second account, who in the house decides to move to it, what the landlord hears while it is happening, and how the standing instructions get moved back afterwards. Most households have part one and none of the other three, the same shape as most institutions.

Reading a Term Sheet Structurally teaches you to read the clauses that decide who gets what, and in what order.

What can these two objectives not promise?

Quite a lot, and saying so plainly is part of using them honestly. An objective is a design target and not an outcome. Writing 60 minutes against S1 does not cause a 60 minute recovery to happen; it states what the arrangement was built for and what would count as falling short. That is worth real money and it is not the same as the service coming back in an hour.

The tested figure is smaller than it looks, for the reason drawn earlier: a planned test measures the switch and not the noticing or the deciding. The untested figure is smaller still. The invented case measured recovery time in the month 12 test and did not measure how much recorded work was lost, so all seven of the second objectives stand as decisions and none of them as results. Saying so is itself the finding, and how the technology behind a service is restored, including what an objective of no data loss at all actually asks for, is taken further under disaster recovery.

A control question sits inside the failure block above, and it belongs to a different subject. The missing service availability report is not a control that failed a test. The missing report is a control nobody designed, a different kind of finding, and it is caught by a different process. How a control is designed, how it is tested for operating effectiveness, how a deficiency is recorded and how it is put right is covered separately.

One more limit, and it is about where the other route lives. A standby arrangement can sit with somebody outside the institution, and then its continuity is somebody else business to run and the institution business to be satisfied about. The invented bank has one incident in its year of exactly that shape, incident I9, a vendor-hosted payment gateway failure that ran 9 hours. Assessing a third party as a risk in its own right is covered separately, and so is the record of what each incident cost.

On that record: incident I3, the core banking outage that ran 4 hours and 20 minutes, booked a net loss of Rs 3.2 crore. Incident I9 booked the same Rs 3.2 crore, so both are always named rather than quoted as a single figure. Neither number measures anything about the two objectives, a point settled under operational resilience.

Where the rules come from

What binds an actual Indian bank here

The mechanism described here is universal. Another route to the same service, and restoring the machinery behind it, are the same two jobs in any country and at any size. Local law decides what an institution is required to maintain, how often it must be tested, what must be reported and to whom.

For a bank in India, the Reserve Bank of India at rbi.org.in is the body that sets what actually binds on business continuity, on testing, on reporting an incident, and on an arrangement that sits with a third party. The Basel Committee, publishing through the Bank for International Settlements at bis.org, is where the international standard behind the Indian requirement comes from, and naming only the international one is the confident and common mistake here. Where the entity is a market intermediary rather than a bank, the Securities and Exchange Board of India at sebi.gov.in applies instead.

None of the seven objectives above comes from any of those bodies. Each of them is a decision taken by the board of one invented bank. Confirm anything binding at the issuing source.

What operational resilience is, what an important business service is, and how a board impact tolerance is set and why it is a different object from these two objectives are settled under operational resilience and assumed here. Restoring the technology behind a service is opened here and taken further under disaster recovery, including what an objective of no recorded work lost actually asks for. Deciding under pressure with incomplete information, and running one incident from detection through to learning, are each covered separately. Third party and outsourcing risk as a risk category is covered separately; the point made here is only that another route can sit with somebody else. How an operational loss event is defined, measured and booked is covered separately, and the incident record is used here as a record. How a control is designed, tested, found deficient and remediated is covered separately.
Risk Management Program Bootcamp — Fin Maverick

Sources

SourceDocumentSite
Reserve Bank of IndiaWhat a regulated bank in India must maintain, test and report on business continuity, and on an arrangement that sits with a third partyrbi.org.in
Bank for International SettlementsThe Basel Committee international standard behind the Indian requirement, and the operational risk event categories named in this casebis.org
Securities and Exchange Board of IndiaWhat applies instead where the entity is a market intermediary rather than a banksebi.gov.in
Indian Banks AssociationMaterial on Indian banking operational conventioniba.org.in

Vindhya Commercial Bank Limited, Nirjhar Industries Limited and Girish Talwalkar are invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.