Skip to content
Compliance

How to Create a Business Continuity Plan: 20 Practical Steps

Richard Long

Updated on: September 21, 2026

Relevant Contents

Need Tailored Business Continuity Insights?

Contact Us Now for Personalized Guidance!

Creating a business continuity plan is not simply a matter of filling out a template. A usable plan depends on understanding what the organization needs to recover, what could prevent recovery, which strategies are realistic, and who will take action when disruption occurs.

A business continuity plan documents the procedures, responsibilities, resources, and information needed to continue or recover priority business operations following a disruption.

The plan itself is one part of a broader business continuity management process. Activities such as management sponsorship, the business impact analysis, risk assessment, recovery strategy development, training, exercises, and maintenance provide the information and capability the plan depends on.

The 20 business continuity planning steps below take you from initial governance through plan development, validation, and ongoing maintenance.

Business continuity planning in five phases

  1. Establish governance and scope. Define who owns the work, what it covers, and what the organization expects from the program.
  2. Understand business priorities and exposure. Use the BIA, risk assessment, dependencies, and current capabilities to determine what must be protected.
  3. Select recovery strategies and build the plans. Decide how priority operations will recover before documenting procedures.
  4. Exercise and validate. Test whether the people, plans, technology, and strategies can actually work together.
  5. Maintain and improve. Keep plans aligned with changes in the organization and lessons from exercises and incidents.

What Should a Business Continuity Plan Accomplish?

A good business continuity plan should help people answer practical questions during a disruption:

  • What needs to be recovered first?
  • Who has the authority to make decisions?
  • Who performs each recovery activity?
  • What systems, facilities, vendors, information, and other resources are required?
  • What workarounds or alternate methods are available?
  • How will people communicate and coordinate?
  • How will the organization know when recovery is complete?

The plan should be useful during an actual event, not merely prove that a document exists.

That means the planning process has to begin before anyone starts writing detailed recovery procedures.

Phase 1: Establish Governance and Scope

1. Secure Management Support

Business continuity requires time from business units, technology teams, facilities, human resources, vendors, executives, and other stakeholders.

Before beginning detailed planning, make sure leadership understands why the work is being done, what resources it will require, and who has authority to obtain participation from the organization.

Executive sponsorship is particularly important when the planning process identifies recovery gaps that require funding or decisions outside the BC team's authority.

2. Assign Ownership and Build the Planning Team

Identify who owns the business continuity program and which functions need to participate in planning.

The BC team may facilitate the process, but the business units themselves need to contribute operational knowledge. Technology, facilities, security, human resources, communications, legal, risk, and third-party management may also need to participate depending on the organization's structure.

Assign clear owners rather than treating continuity planning as a responsibility shared vaguely by everyone.

3. Define the Scope, Objectives, and Planning Approach

Set the boundaries before collecting information.

Define:

  • which business units, locations, processes, products, or services are in scope
  • which types of plans need to be developed
  • who will approve them
  • which requirements or internal standards apply
  • how actions, issues, and decisions will be tracked
  • the expected schedule for completing the work

This prevents the planning effort from turning into an open-ended documentation project.

4. Assess the Current State

Before building new plans, understand what already exists.

Review current business continuity, crisis management, disaster recovery, emergency response, communication, and related documentation. Identify which plans are current, which are incomplete, and where important capabilities have never been documented or validated.

The current-state review should also identify regulatory, contractual, customer, and organizational requirements that may affect the program.

Phase 2: Understand Business Priorities and Exposure

5. Conduct a Business Impact Analysis

The business impact analysis helps determine which activities are most time-sensitive and what the organization needs in order to recover them.

A useful BIA should help identify:

  • priority business processes and services
  • impacts as disruption continues
  • recovery time requirements
  • data-loss tolerances where applicable
  • critical technology
  • people and skill dependencies
  • facilities and equipment
  • vendors and other third parties
  • important upstream and downstream dependencies

The BIA gives the planning team the recovery requirements the plan and strategy need to support.

For more on how the BIA differs from risk assessment, see BIA vs. Risk Assessment: What Each One Tells You.

6. Identify Threats, Vulnerabilities, and Dependencies

The BIA tells you what is important. Risk assessment helps identify what could disrupt it and where the organization may be exposed.

Review risks affecting people, technology, facilities, suppliers, utilities, data, communications, and other resources supporting priority operations.

Do not limit the analysis to a generic list of disasters. Look for the dependencies and vulnerabilities that could turn an event into an operational interruption.

7. Compare Recovery Requirements With Current Capability

Once the organization knows what recovery performance is required, compare those requirements with what can actually be achieved today.

For example:

  • Can critical applications be restored within the time the business requires?
  • Can an alternate supplier provide sufficient capacity?
  • Can employees work from another location?
  • Are manual workarounds realistic at the volume required?
  • Do alternates have the access and knowledge required to perform key activities?

The difference between the requirement and current capability is a recovery gap that needs to be addressed.

8. Prioritize Gaps and Assign Actions

Not every gap can be closed immediately.

Prioritize the issues that create the greatest exposure to priority operations. Assign an owner, expected action, decision authority, and target date for each significant gap.

Some gaps may require investment. Others may be addressed through procedures, cross-training, alternate suppliers, redundancy, contractual changes, or temporary workarounds.

The important point is that known gaps should not disappear simply because planning has moved on to the next stage.

Phase 3: Select Recovery Strategies and Build the Plans

9. Select Recovery Strategies

Decide how priority operations will continue or recover before writing detailed procedures.

A recovery strategy might involve:

  • remote work
  • relocation to another facility
  • manual processing
  • alternate technology
  • redundant infrastructure
  • alternate suppliers
  • cross-trained personnel
  • temporary reduction or prioritization of services

The strategy should be capable of supporting the recovery requirements identified through the BIA.

A plan cannot compensate for a recovery strategy that is unrealistic or under-resourced.

10. Develop Business Recovery Procedures

With the strategy established, document what the business needs to do when disruption occurs.

Recovery procedures should emphasize actions rather than lengthy policy language.

Document:

  • the conditions under which the procedure is used
  • the sequence of major recovery actions
  • who is responsible for each activity
  • required resources and dependencies
  • workarounds or alternate processes
  • decision and approval points
  • validation required before normal processing resumes

For more detail on business recovery plans, see How to Write a Business Recovery Plan.

11. Define Activation and Escalation Criteria

People should not have to improvise the basic governance of the response after an event begins.

Document how a potential disruption is identified, who evaluates it, who can activate the relevant plan, and when the issue must be escalated to crisis management or executive leadership.

Different events may require different levels of response. The plan should make those decision paths understandable.

12. Document Roles, Responsibilities, and Alternates

Identify the roles required to execute the plan and what each role is expected to do.

Include alternates for critical responsibilities. A recovery procedure that depends entirely on one person creates another single point of failure.

Keep contact information separate enough that it can be maintained efficiently, but make sure plan users can reach the people they need during an incident.

13. Document Critical Dependencies and Recovery Resources

Plans should identify the resources people need in order to carry out recovery procedures.

Depending on the process, this might include:

  • applications and data
  • facilities and workspace
  • equipment
  • records and documents
  • vendors and suppliers
  • utilities
  • specialized personnel
  • access credentials
  • transportation or logistics

Do not assume those resources will remain available merely because they are available during normal operations.

14. Coordinate Crisis Management and Crisis Communications

Business recovery planning does not happen in isolation.

A significant disruption may also require crisis leadership, emergency notification, internal communication, external communication, executive decisions, and coordination across multiple recovery teams.

Some organizations maintain these activities in separate crisis management and communication plans. Others integrate portions of them. Either approach can work if the plans connect clearly and people understand how responsibility moves between them.

For crisis-plan content, see What to Include in Your Crisis Management Plan.

15. Make the Plans Accessible and Controlled

A strong plan has limited value if people cannot find it during an outage.

Establish a controlled location for current plans and supporting documents. Make sure authorized users know where they are stored and how to access them if normal systems or facilities are unavailable.

Control versions so users can tell which plan is current. Retire obsolete copies rather than allowing multiple conflicting versions to circulate.

Phase 4: Exercise and Validate the Capability

16. Create a Testing and Exercise Strategy

Different capabilities require different types of validation.

Establish an exercise schedule that covers the business processes, technology, crisis-management functions, communication procedures, suppliers, and other capabilities that matter to recovery.

Exercise complexity should reflect program maturity. A discussion-based exercise may be appropriate for a new plan. More mature capabilities may require functional or operational testing.

17. Exercise Business Recovery Procedures

Business continuity exercises should determine whether people can actually carry out the recovery procedures documented in the plan.

Challenge assumptions about staffing, facilities, workarounds, vendors, systems, information, and dependencies.

The goal is not simply to complete the exercise. It is to identify where the documented plan and actual capability differ.

See How to Plan a Mock Disaster Exercise for a practical exercise-development process.

18. Validate Technology Recovery

Business recovery frequently depends on technology, so disaster recovery capabilities need to be tested against the needs of the business.

Confirm whether critical applications, infrastructure, data, and supporting services can be restored within the requirements the business has established.

Technology testing should also account for dependencies between systems and for the business validation required before restored applications are returned to normal use.

19. Track Findings and Corrective Actions

Every exercise, test, and actual disruption should produce information that can improve the plan.

Document significant findings and assign:

  • an action
  • an owner
  • a target date
  • the decision or funding required
  • evidence needed to close the issue

Do not close an issue simply because the exercise report has been completed.

Phase 5: Maintain and Improve the Plan

20. Establish Review and Update Triggers

A business continuity plan reflects the organization at a point in time. The organization will keep changing.

Establish a regular review cycle, but do not rely on the calendar alone.

Plans should also be reviewed when material changes occur, including:

  • new or retired systems
  • changes to business processes
  • new facilities or relocations
  • important vendor changes
  • organizational restructuring
  • staffing or role changes
  • new regulatory or contractual requirements
  • exercise findings
  • lessons from actual incidents

This article focuses on building the plan. For the deeper maintenance process, see Why You Need to Keep Your BCM Plans Up to Date.

20-Step Business Continuity Planning Checklist

Step Business Continuity Planning Action
1 Secure management support.
2 Assign ownership and build the planning team.
3 Define scope, objectives, and the planning approach.
4 Assess the current state.
5 Conduct a business impact analysis.
6 Identify threats, vulnerabilities, and dependencies.
7 Compare recovery requirements with current capability.
8 Prioritize gaps and assign actions.
9 Select recovery strategies.
10 Develop business recovery procedures.
11 Define activation and escalation criteria.
12 Document roles, responsibilities, and alternates.
13 Document dependencies and recovery resources.
14 Coordinate crisis management and crisis communications.
15 Make plans accessible and controlled.
16 Create a testing and exercise strategy.
17 Exercise business recovery procedures.
18 Validate technology recovery.
19 Track findings and corrective actions.
20 Establish review and update triggers.

A Business Continuity Plan Is Only Useful if You Can Execute It

The goal of business continuity planning is not to produce more documentation. It is to give the organization a realistic way to continue or recover important operations when normal methods are unavailable.

That requires more than writing procedures. The organization needs to understand its priorities, choose workable recovery strategies, assign responsibility, validate assumptions, exercise the plans, correct weaknesses, and keep the information current.

The 20 steps above provide a practical path from the beginning of the planning process to a plan that can be maintained and tested over time.

Need Help Building or Improving Your Business Continuity Program?

MHA Consulting helps organizations assess their current business continuity capabilities, conduct BIAs and risk assessments, develop recovery strategies and plans, exercise those capabilities, and maintain the program as the organization changes.

Learn more about MHA's business continuity consulting services or contact MHA Consulting to discuss your current program.


Frequently Asked Questions

What are the main steps in business continuity planning?

The process generally includes establishing governance, identifying critical operations through the BIA, assessing risks and dependencies, determining recovery requirements, selecting recovery strategies, documenting procedures and responsibilities, exercising the plans, correcting gaps, and maintaining the information as the organization changes.

What should a business continuity plan include?

A business continuity plan should contain the practical information people need to continue or recover priority operations. That commonly includes activation criteria, roles and responsibilities, recovery procedures, dependencies, required resources, contact information, workarounds, communication methods, and the actions needed to validate recovery.

What is the difference between a business continuity plan and a business continuity program?

The plan is the documented set of procedures and information used to support response and recovery. The business continuity program is broader. It includes governance, BIAs, risk assessments, recovery strategies, plans, training, exercises, corrective actions, and ongoing maintenance.

When should a business continuity plan be tested?

Plans should be exercised on a defined schedule appropriate to the organization's needs and after significant changes when practical. Testing should also reflect the type of capability being validated. Business recovery procedures, crisis-management processes, communications, and technology recovery may require different exercise methods.

How often should a business continuity plan be updated?

Review plans on a defined schedule and when material changes affect the processes, people, technology, facilities, vendors, dependencies, or assumptions the plan relies on. Exercise findings and actual incidents should also trigger updates when they reveal weaknesses or outdated information.

Further Reading


Start building a stronger future

Navigate uncertainty with an expert - schedule your free consultation with our CEO, Michael Herrera.

Other resources you might enjoy

Ready to start focusing on higher-level challenges?