10 minute assessment
A quick assessment for you to see how far you have got with business continuity management. The assessment has been split into sections for ease of reference; ideally you should have all of these criteria fulfilled.
| General Assessment: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Has the idea of Business Continuity Management (BCM) been approved by the owner/partners/board? | |||
| Do you have a Business Continuity Plan (BCP)? | |||
| Is the plan documented clearly and easily accessible? | |||
| Have you exercised your plan within the last 12 months? | |||
| Do you have a policy for how and when to activate your plan? | |||
| Do you regularly review and update your plan? | |||
| Are your staff trained in activating and operating your plan? | |||
| Is there someone in your organisation who will have responsibility for looking after BCM? | |||
| Have you made a list of all key contacts' telephone numbers? | |||
| Have you prepared an emergency pack? |
| Building Facilities: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Do you have emergency evacuation procedures for your building? i.e. Fire, bomb | |||
| Are the emergency exits clearly marked? | |||
| Do you regularly practice emergency drills? | |||
| Do you have a primary and secondary evacuation assembly points? | |||
| Do you have a floor plan to your building? | |||
| Do you have access to your building at all times? | |||
| Do you have fire safety procedures in place? | |||
| Do you have access to an alternative workspace to use in an emergency? | |||
| Have you familiarised yourself and your staff with the location of the mains switches and valves (i.e. for electricity, gas and water)? | |||
| Do you regularly check all plumbing is in working order? | |||
| Do you regularly check that any heating and air conditioning is working? |
| Personnel: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Do you have staff personal information on file e.g. staff contact details? (include temporary and contract workers) | |||
| Doyour staff know what to do in an emergency? | |||
| Do your staff know where to get advice/information/guidance in an emergency? | |||
| Do your staff know who is in charge in the time of an emergency? | |||
| Has your staff been given specific roles to do in the event of an emergency? | |||
| Have you thought about dealing with people issues - relocation arrangements, etc. | |||
| Do you have members of staff with first aid training? | |||
| Are all staff trained in evacuation? | |||
| Do you have arrangements to cover staff with critical and unique skills? | |||
| Do you check references fully? | |||
| Do you have an up to date job description and hierarchy chart for your company? (include temporary and contract workers) |
| Physical Security: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Do you have a security policy? | |||
| Do you have an appropriate and regularly maintained security system? | |||
| Do you give any advice or training on security to relevant staff? | |||
| Are contractors checked fully (i.e. company as well as each individual)? | |||
| If you have them, do you regularly check external fences and doors? | |||
| Do you carry out end of day inspections? E.g. to check everybody has left |
| Paper and Electronic Documents: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Do you regularly copy/backup your information? | |||
| Are your critical documents adequately protected? | |||
| Do you have copies of your critical records at a separate location? |
| Company Equipment: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Have you identified your key equipment? | |||
| Do you have contingency plans in place to cater for the loss/ failure of key equipment? | |||
| Do you regularly update an inventory of your company equipment? | |||
| Do you have controls over the movements of your company equipment? |
| IT: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Have you identified the critical IT systems for your business? | |||
| Do you have a documented and tested IT disaster recovery plan? | |||
| Are the relevant staff aware of the IT disaster recovery plan? | |||
| Do you know how long it would take to recover IT functions? | |||
| Are documented IT security policies and procedures in place? | |||
| Are all staff aware of IT security policies and procedures? | |||
| Do you have vital computer information stored off site? |
| Suppliers: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Have you identified who your key suppliers are? | |||
| Do your key suppliers have a business continuity plan? | |||
| Have you identified alternative sources for key supplies? | |||
| Do you have the up to date contact details for all your suppliers? |
| Customers: | YES | NO | DON'T KNOW |
|---|---|---|---|
| If relevant, do you have up to date contact details for your key customers? | |||
| Do you have a mechanism for communicating with your customers during an emergency? |
| Location: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Have you identified and considered the risks from your surrounding area and businesses? E.g. Flood risk, chemical plants etc. |
| Insurance: | YES | NO | DON'T KNOW |
|---|---|---|---|
| Do you have sufficient insurance to pay for disruption to business, cost of repairs, hiring temporary employees, leasing temporary accommodation and equipment? | |||
| Do you have a copy of the insurance company's details and policy held on and off site? |
