Operational Resilience Audit

Posts by:

Moh Heng Goh

Dr Goh Moh Heng is the President of BCM Institute and the Managing Director of GMH Continuity Architects – a specialised BCM Consulting firm. His primary areas of expertise include Business Continuity Management (BCM), Disaster Recovery Planning (DRP), ISO22301 BCM Audit and Crisis Management. Since 2011, Moh Heng has assisted more than 50 organisations, particularly those operating in the Asia-Pacific and Middle-East Region in their successful implementation of their Business Continuity Management System (BCMS) and achieving their BS 25999/ SS 540 / ISO 22301 organisation certification. Prior to establishing BCM Institute and GMH BCM Consulting, Dr. Goh held senior positions with a number of large organizations. During his career with the Government of Singapore Investment Corporation (GIC), he was responsible for all aspects of its business continuity and crisis management. At Standard Chartered Bank Plc, he saw and manage the global implementation of its BC management and planning for 52 countries. He also managed the BCM practice at PricewaterhouseCoopers.

ORA [Sustain] Questionnaires: Conduct and Provide Self-assessments

ORA [Sustain] Questionnaires: Conduct and Provide Self-assessments

New call-to-action

Provide Self-assessments

New call-to-action

What is Self-assessment?

Self-Assessment in Operational Resilience ensures that the regulated organisation captures and documents the steps taken towards operational resilience and provides a comprehensive and objective evaluation of the organisation's strategy and overall ability to respond to disruptions.

New call-to-actionOR Sustain Phase Questionnaires: Provide Self-assessmentsThis section is the "Sustain" phase of the Operational Resilience Planning Methodology.  It is the fourth stage of the Sustain phase: Provide Self-assessment.

 

Audit Checklist for Provide Self-assessments

 

1. Documentation and Policies

  • Are operational resilience policies and procedures well-documented and readily accessible?
  • Are the policies and procedures aligned with industry best practices and regulatory requirements?
  • Do the documented policies clearly define roles, responsibilities, and accountability for operational resilience?
  • Is there evidence of regular reviews and updates to the operational resilience documentation?
Checklist
  • Review the documentation of operational resilience policies and procedures.
  • Assess the alignment of policies with industry best practices and regulations.
  • Evaluate the clarity and completeness of roles, responsibilities, and accountability definitions.
  • Verify the existence of a process for regular reviews and updates to the documentation.

2. Risk Assessment and Analysis

  • Has a comprehensive risk assessment been conducted to identify and assess potential risks?
  • Are risks prioritized based on their potential impact and likelihood?
  • Are mitigation strategies and controls in place to address identified risks?
  • Is there a process for regularly monitoring and updating risk assessments?
Checklist
  • Evaluate the documentation of the risk assessment process.
  • Assess the comprehensiveness of the risk assessment, including identification and assessment of risks.
  • Verify the prioritization of risks based on impact and likelihood.
  • Review the documented mitigation strategies and controls.
  • Determine if there is a process for regularly monitoring and updating risk assessments

3. Business Impact Analysis (BIA)

  • OR Implement Phase Questionnaires: Identify Critical Business ServicesHas a thorough business impact analysis (BIA) been conducted to identify critical processes and systems?
  • Have the potential impacts of disruptions to critical processes and systems been assessed?
  • Are recovery time objectives (RTOs) and recovery point objectives (RPOs) defined for critical processes?
  • Are mitigation strategies and plans in place to ensure the timely recovery of critical processes?
Checklist
  • Review the business impact analysis (BIA) process documentation.
  • Evaluate the completeness and accuracy of the identification of critical processes and systems.
  • Assess the thoroughness of the assessment of potential impacts.
  • Verify the definition of recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical processes.
  • Review the mitigation strategies and plans to ensure timely recovery.

4. Training and Awareness

  • OR [Sustain] Questionnaires:  Implement Training and AwarenessIs there a training program in place to educate employees on operational resilience?
  • Are employees aware of their roles and responsibilities regarding operational resilience?
  • Are there mechanisms to track and monitor employee completion of operational resilience training?
  • Are there regular communication and awareness campaigns to promote a culture of operational resilience?
Checklist
  • Review the training program documentation for operational resilience.
  • Evaluate the effectiveness of the training in educating employees.
  • Assess the mechanisms in place to track and monitor employee completion of training.
  • Verify the existence of regular communication and awareness campaigns.
  • Determine the extent of the culture of operational resilience within the organization.

5. Testing and Exercise Evaluation

  • Conduct Scenario TestingHave operational resilience plans and procedures been tested through exercises and simulations?
  • Is there a documented schedule for testing and exercising operational resilience capabilities?
  • Are different scenarios and levels of disruptions considered during testing?
  • Are testing results analyzed to identify areas for improvement and corrective actions?
  • Are there mechanisms to track and follow up on implementing corrective actions identified during testing?
Checklist
  • Review the operational resilience testing and exercise plan documentation. 
  • Evaluate the adequacy of the testing schedule and the consideration of various scenarios.
  • Assess the testing results analysis to identify improvement areas.
  • Determine if lessons learned from testing and exercises are documented and incorporated into improvements.

5. Incident Response Evaluation

  • Is there an incident response plan for operational resilience incidents?
  • Has the incident response plan been tested and validated?
  • Are roles, responsibilities, and communication channels clearly defined within the incident response plan?
  • Is there a designated incident response team and a straightforward escalation process?
  • Is there a process for post-incident analysis and continuous improvement of the incident response capabilities?
Checklist
  • Review the incident response plan documentation for operational resilience incidents.
  • Evaluate the testing and validation activities conducted on the incident response plan.
  • Assess the clarity and accuracy of roles, responsibilities, and communication channels.
  • Verify the incident response team's existence and composition and escalation process.
  • Determine if there is a process for post-incident analysis and continuous improvement.

5. Continuous Improvement

  • New call-to-actionIs there a process in place to monitor and review the effectiveness of the operational resilience program?
  • Are lessons learned from incidents, tests, and exercises incorporated into improvements?
  • Is there a mechanism to capture and address feedback and suggestions for operational resilience?
  • Are there metrics and performance indicators to measure the effectiveness of the operational resilience program?
  • Is there a culture of continuous improvement and learning within the organization?
Checklist
  • Evaluate the process for monitoring and reviewing the effectiveness of the operational resilience program.
  • Assess the incorporation of lessons learned from incidents, tests, and exercises into improvements.
  • Verify the existence of a mechanism to capture and address feedback and suggestions.
  • Review the metrics and performance indicators for measuring program effectiveness.
  • Determine the extent of the organization's continuous improvement and learning culture.

Do note that some steps may overlap or appear similar in the other stages of the OR planning phases.  If this occurs, the questionnaires and checklists must be contextualised to the topic under review.

New call-to-action

Questionnaires and Checklist "Sustain" Phase

Introduce Cultural Change Develop Communication Strategy

Implement Training and Awareness

Provide Self-assessment

Conduct Independent Quality Review

New call-to-action New call-to-action OR Sustain Phase Questionnaires: Develop  Communication Strategy OR [Sustain] Questionnaires:  Implement Training and Awareness OR Sustain Phase Questionnaires: Provide Self-assessments OR Sustain Phase Questionnaires: Conduct Independent Quality Reviews

More Information About Blended Learning Operational Resilience Audit (ORA) Courses

BCM Institute offers two levels of OR auditing courses: ORA-3 Blended Learning ORA-300 Operational Resilience Audit Specialist and the ORA-5 Blended Learning ORA-5000 Operational Resilience Audit Expert.

New call-to-action New call-to-action New call-to-action
New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action Email to Sales Team [BCM Institute] Operational Resilience Audit Specialist (ORAS) Certification
New call-to-action Please feel free to send us a note if you have any questions. New call-to-action
 
 
Read More
OR [Sustain] Questionnaires: Develop Communication Strategy

OR [Sustain] Questionnaires: Develop Communication Strategy

New call-to-action

Develop the Communication Strategy

New call-to-action

 

What is a Communication Strategy?

A communication strategy is a guide or a plan that helps an organization share information and achieve its communication and business objectives.  In this case, the operational resilience initiative.

Ensuring effective and timely communication of the internal and external communication plans is essential to help the organization keep customers and other stakeholders informed.


New call-to-actionOR Sustain Phase Questionnaires: Develop  Communication StrategyThis section is the "Sustain" phase of the Operational Resilience Planning Methodology.  It is the second stage of the Sustain phase: Develop the Communication Strategy.

Audit Checklist for Developing the Communication Strategy

 

1. Stakeholder Identification

  • Have key stakeholders for operational resilience been identified?
  • Is there a clear understanding of each stakeholder group's communication needs and expectations?
  • Have internal and external stakeholders, including employees, customers, suppliers, and regulators, been considered?
  • Is there a process to regularly review and update the stakeholder list and their communication requirements?
Checklist
  • Review the documentation of stakeholder identification for operational resilience.
  • Assess the clarity and completeness of understanding each stakeholder group's communication needs and expectations.
  • Verify that both internal and external stakeholders have been considered.
  • Determine the existence of a process for regular review and update of the stakeholder list and their communication requirements.

2. Communication Objectives and Key Messages

  • Have communication objectives for operational resilience been defined?
  • Are there clear and concise key messages that must be communicated to stakeholders?
  • Do the key messages align with the operational resilience goals and priorities?
  • Is there a process to regularly review and update the communication objectives and key messages?
Checklist
  • Evaluate the documentation of communication objectives for operational resilience.

  • Assess the clarity and alignment of key messages with operational resilience goals and priorities.
  • Verify the existence of a process for regular review and update of the communication objectives and key messages.

3. Communication Channels and Tools

  • Are there appropriate communication channels to reach each stakeholder group effectively?
  • Have the advantages and limitations of different communication channels been considered?
  • Is there a mix of channels, including both traditional and digital, to ensure comprehensive communication?
  • Are there tools and platforms in place to facilitate efficient and secure communication?
Checklist
  • Assess the availability and suitability of communication channels for each stakeholder group.
  • Evaluate the advantages and limitations of different communication channels.
  • Verify the presence of a mix of traditional and digital channels for comprehensive communication.
  • Determine the availability and effectiveness of tools and platforms for efficient and secure communication.

4. Communication Plan Development

  • Is there a documented communication plan for operational resilience?
  • Does the communication plan include a timeline, responsibilities, and deliverables?
  • Are there mechanisms to ensure timely and consistent communication?
  • Are there processes in place to handle urgent and sensitive communications?
Checklist
  • Review the documentation of the communication plan for operational resilience.
  • Evaluate the inclusion of a timeline, responsibilities, and deliverables in the communication plan.
  • Verify the existence of mechanisms to ensure timely and consistent communication.
  • Determine the presence of processes to handle urgent and sensitive communications.

5. Measurement and Evaluation

  • Is there a process to measure and evaluate the effectiveness of communication activities?
  • Are there metrics and performance indicators to assess the impact of communication efforts?
  • Is feedback from stakeholders collected and analyzed to identify areas for improvement?
  • Are there mechanisms to monitor and address misconceptions or misinformation?
Checklist
  • Assess the existence of a process to measure and evaluate the effectiveness of communication activities.
  • Evaluate the availability of metrics and performance indicators to assess the impact of communication efforts.
  • Verify the collection and analysis of stakeholder feedback to identify improvement areas.
  • Determine the presence of mechanisms to monitor and address misconceptions or misinformation.

Do note that some steps may overlap or appear similar in the other stages of the OR planning phases.  If this occurs, the questionnaires and checklists must be contextualised to the topic under review.

New call-to-action

Questionnaires and Checklist "Sustain" Phase

Introduce Cultural Change Develop Communication Strategy

Implement Training and Awareness

Provide Self-assessment

Conduct Independent Quality Review

New call-to-action New call-to-action OR Sustain Phase Questionnaires: Develop  Communication Strategy OR [Sustain] Questionnaires:  Implement Training and Awareness OR Sustain Phase Questionnaires: Provide Self-assessments OR Sustain Phase Questionnaires: Conduct Independent Quality Reviews

More Information About Blended Learning Operational Resilience Audit (ORA) Courses

BCM Institute offers two levels of OR auditing courses: ORA-3 Blended Learning ORA-300 Operational Resilience Audit Specialist and the ORA-5 Blended Learning ORA-5000 Operational Resilience Audit Expert.

New call-to-action New call-to-action New call-to-action
New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action Email to Sales Team [BCM Institute] Operational Resilience Audit Specialist (ORAS) Certification
New call-to-action Please feel free to send us a note if you have any questions. New call-to-action
 
 
Read More
ORA [Implement] Questionnaires: Conduct Scenario Testing

ORA [Implement] Questionnaires: Conduct Scenario Testing

New call-to-action

Conduct Scenario Testing

OR_Implement_Diagram

 

What is Scenario Testing?

Scenario Testing aims to test the organisation's ability to remain within impact tolerances in severe but plausible disruption scenarios, focusing on recovery and response arrangements rather than preventative measures.

New call-to-actionConduct Scenario TestingThis section is the "Implement" phase of the Operational Resilience Planning Methodology.  It is the fourth stage of the Implement phase: Conduct Scenario Testing.

 

Audit Checklist for Conducting Scenario Testing

 

1. Scenario Testing Planning

  • Has a scenario testing plan been developed outlining the objectives, scope, and methodology?
  • Are the scenarios relevant to the organization's critical business services and potential threats?
  • Has the testing plan considered various disruption scenarios, including natural disasters, cyberattacks, and system failures?
New call-to-action
Checklist
  • Verify the existence of a scenario testing plan that outlines objectives, scope, and methodology.
  • Assess the relevance of the scenarios to the organization's critical business services and potential threats.
  • Ensure the testing plan considers various disruption scenarios, including natural disasters, cyberattacks, and system failures.

 

2. Scenario Development

  • Has a range of realistic scenarios been identified for testing operational resilience?
  • Do the selected scenarios cover a variety of potential disruptions and stress events?
  • Have scenarios been designed to test different aspects of operational resilience, including people, processes, technology, and facilities?
  • Are the selected scenarios aligned with the organisation's risk profile and potential impact on critical business services?
  • How were the scenarios developed? Were they based on historical incidents, industry best practices, or internal risk assessments?
  • Are the scenarios realistic and representative of the organisation's potential threats and disruptions?
  • Have relevant stakeholders, including management and subject matter experts, reviewed and approved the scenarios?
 
Checklist
  • Review the scenario development process and ensure it is based on historical incidents, industry best practices, or internal risk assessments.
  • Evaluate the realism and representativeness of the scenarios concerning potential threats and disruptions.
  • Confirm that relevant stakeholders, including management and subject matter experts, have reviewed and approved the scenarios.

 

3. Scenario Execution

  • How was the scenario testing conducted? Was it a tabletop exercise or a simulation of real-time events?
  • Were the participants provided clear instructions, roles, and responsibilities during the scenario testing?
  • Did the scenario testing involve cross-functional teams and external stakeholders, such as vendors or regulatory authorities, where applicable?
  • Are the scenarios executed in a controlled and structured manner?
  • Are the scenarios realistic and representative of potential disruptions?
    Is there a clear timeline and sequence of events for each scenario?
  • Are participants provided with the necessary information and resources to respond to the scenarios effectively?
 
Checklist
  • Assess the execution of the scenario testing, whether it was a tabletop exercise or a simulation of real-time events.
  • Evaluate the clarity of instructions, roles, and responsibilities provided to participants during the scenario testing.
  • Verify if the scenario testing involved cross-functional teams and external stakeholders, such as vendors or regulatory authorities, where applicable.

 

4. Impact Assessment

  • Did the scenario testing effectively assess the impact on critical business services and their dependencies?
  • Were the impacts and consequences of the scenarios accurately evaluated, including financial, operational, reputational, and regulatory implications?
  • Was the impact assessment aligned with the objectives and scope of the operational resilience program?
 
Checklist
  • Evaluate the effectiveness of the impact assessment on critical business services and their dependencies during the scenario testing.
  • Assess whether the impacts and consequences of the scenarios were accurately evaluated, including financial, operational, reputational, and regulatory implications.
  • Verify if the impact assessment was aligned with the objectives and scope of the operational resilience program.

 

5. Response and Recovery

  • How did the organization respond to the simulated scenarios? Were the predefined incident response plans activated and followed?
  • Were the communication and coordination among relevant teams and stakeholders effective during the response and recovery process?
  • Did the organization demonstrate the ability to recover critical business services within the predefined recovery time objectives (RTOs) and recovery point objectives (RPOs)?
 
Checklist
  • Review the organization's response to the simulated scenarios, including activating and adhering to predefined incident response plans.
  • Assess the effectiveness of communication and coordination among relevant teams and stakeholders during the response and recovery process.
  • Verify if the organization demonstrated the ability to recover critical business services within the predefined recovery time objectives (RTOs) and recovery point objectives (RPOs).

 

6. Lessons Learned and Improvement

  • Was a comprehensive evaluation conducted to identify lessons learned from the scenario testing?
  • Were the identified areas for improvement documented and communicated to relevant stakeholders?
  • Has the organization implemented corrective actions and updated its operational resilience program based on the findings and recommendations from scenario testing?
New call-to-action
Checklist
  • Assess the comprehensiveness of the evaluation conducted to identify lessons learned from the scenario testing.
  • Verify if the identified areas for improvement were documented and communicated to relevant stakeholders.
  • Assess if the organization implemented corrective actions and updated its operational resilience program based on the findings and recommendations from scenario testing.

 

7. Documentation and Reporting

  • Are the scenario testing plans, results, and related documentation adequately recorded and maintained?
  • Is there a clear and consistent reporting framework for scenario testing, including key findings, observations, and recommendations?
  • Are the scenario testing reports provided to management and relevant stakeholders regularly?
 
Checklist
  • Verify if the scenario testing plans, results, and related documentation are adequately recorded and maintained.
  • Assess the existence of a clear and consistent reporting framework for scenario testing, including key findings, observations, and recommendations.
  • Confirm if the scenario testing reports are regularly provided to management and relevant stakeholders.

 

8. Continuous Improvement

  • How does the organization incorporate the insights gained from scenario testing into its ongoing operational resilience program?
  • Are there mechanisms to continuously monitor, evaluate, and update the scenario testing approach based on emerging threats and changing business environments?
  • Does the organization encourage a culture of continuous improvement and learning from scenario testing exercises?
  • Is there a culture of continuous improvement in scenario testing and operational resilience readiness?
  • Are scenario testing methodologies and practices regularly reviewed and updated based on lessons learned?
  • Is there a feedback loop to incorporate insights from scenario testing into operational resilience planning and decision-making?
  • Are there mechanisms to encourage innovation and the exploration of new scenarios and test methodologies?
 
Checklist
  • Evaluate how the organization incorporates the insights gained from scenario testing into its ongoing operational resilience program.
  • Assess the mechanisms to continuously monitor, evaluate, and update the scenario testing approach based on emerging threats and changing business environments.
  • Verify if the organization encourages continuous improvement and learning from scenario testing exercises.

Some steps may overlap with the other "Implement" phase stages.

New call-to-action

Questionnaires and Checklist "Implement" Phase

Identify Critical Business Services Map Processes and Resources

Set Impact Tolerance

Conduct Scenario Testing

Improve Lesson Learnt

New call-to-action OR Implement Phase Questionnaires: Identify Critical Business Services New call-to-action OR Implement Phase Questionnaires: Set Impact Tolerance Conduct Scenario Testing New call-to-action

Find out more about Blended Learning ORA-5000 [BL-ORA-5] & ORA-300 [BL-ORA-3]

New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action New call-to-action New call-to-action
New call-to-action

Please feel free to send us a note if you have any of these questions.

Email to Sales Team [BCM Institute]

New call-to-action
Read More
ORA[Implement] Questionnaires: Improve Lesson Learnt

ORA [Implement] Questionnaires: Improve Lesson Learnt

New call-to-action

Improve Lesson Learnt

OR_Implement_Diagram

 

What is Lesson Learnt?

The key to improving "Lesson Learnt" when implementing Operational Resilience or OR is for an organisation to promote a continuous learning and improvement culture.   It is essential to improve and communicate remediation and vulnerabilities after scenario testing.

New call-to-actionNew call-to-actionThis section is the "Implement" phase of the Operational Resilience Planning Methodology.  It is the last stage of the Implement phase: Improve Lesson Learnt.

 

Audit Checklist for Improve Lesson Learnt

 

Leadership Commitment

  • Is there a visible leadership commitment to promoting a culture of continuous learning and improvement?
  • Do leaders actively support and participate in scenario testing and incident review processes?
  • Are leaders accountable for implementing recommendations and lessons learned from scenario testing and incidents?
  • Is there a communication strategy emphasising the importance of continuous learning and improvement for all employees?
 

Learning Framework

  • Is there a documented framework or process for capturing and analysing lessons learned from scenario testing and incidents?
  • Does the framework include mechanisms for identifying and documenting root causes and contributing factors?
  • Are there standardised templates or tools for collecting and organising lessons learned information?
  • Is there a designated team or individual responsible for managing the lessons-learned process?
 

Incident Review and Analysis

  • Is there a structured process for reviewing and analysing actual incidents?
  • Are incidents thoroughly investigated to identify root causes and contributing factors?
  • Are incident review findings documented and shared with relevant stakeholders?
  • Is there a mechanism to track and monitor the implementation of corrective actions resulting from incident reviews?
 

Scenario Testing Evaluation

  • Is there a process for evaluating the effectiveness and impact of scenario testing exercises?
  • Are scenario testing results analyzed to identify areas for improvement and enhancement?
  • Are there mechanisms to capture feedback from participants and stakeholders on the scenario testing process?
  • Is there a feedback loop to incorporate insights from scenario testing into future exercises?
 

Knowledge Sharing and Communication

  • Is there a platform or mechanism for sharing lessons learned and best practices across the organisation?
  • Are lessons learned and best practices communicated to relevant teams and departments?
  • Are there regular communication channels, such as newsletters or internal portals, to disseminate information on operational resilience and continuous learning?
  • Is there a process for capturing and sharing success stories and examples of continuous learning and improvement?
 

Training and Development

  • Is there a training program in place to enhance employees' knowledge and skills related to operational resilience?
  • Are employees trained on incident response, scenario testing, and lessons learned?
  • Are there opportunities for employees to participate in specialised training or workshops related to operational resilience?
  • Is there a process to evaluate the effectiveness of training programs and incorporate feedback for improvement?
 

Metrics and Performance Monitoring

  • Are there defined metrics and indicators to measure the effectiveness of the continuous learning and improvement initiatives?
  • Is there a process to track and monitor the organization's performance in implementing lessons learned and recommendations?
  • Are performance metrics used to identify areas of success and areas that require further attention?
  • Is there a mechanism for reporting and communicating performance metrics related to operational resilience readiness?
 

Continuous Improvement Culture

  • Is there a culture of continuous improvement embedded in the organisation's values and behaviours?
  • Are employees encouraged and empowered to share insights, ideas, and suggestions for improving operational resilience?
  • Are there mechanisms to capture and evaluate employee suggestions, such as suggestion boxes or innovation platforms?
  • Are there recognition and reward mechanisms for individuals or teams that contribute to continuous learning and improvement?
 

External Benchmarking

  • Does the organisation seek opportunities for external benchmarking and learning from other organisations?
  • Are there partnerships or networks established to share experiences and best practices in operational resilience?
  • Is there a process to review and incorporate relevant industry standards and guidelines into the organisation's practices?
  • Are there mechanisms to learn from regulatory changes, industry trends, and emerging risks?
 

 

Governance and Oversight

  • Is there a designated governance body or committee responsible for overseeing and promoting continuous learning and improvement?
  • Are there regular reporting and updates provided to senior management or the board of directors on the organisation's operational resilience readiness and continuous improvement efforts?
  • Are clear accountability and responsibilities assigned for implementing and monitoring continuous learning initiatives?
  • Is there a process to review and assess the effectiveness of the organisation's continuous learning and improvement initiatives?
 

Some steps may overlap with the other "Implement" phase stages.

New call-to-action

Questionnaires and Checklist "Implement" Phase

Identify Critical Business Services Map Processes and Resources

Set Impact Tolerance

Conduct Scenario Testing

Improve Lesson Learnt

New call-to-action OR Implement Phase Questionnaires: Identify Critical Business Services New call-to-action OR Implement Phase Questionnaires: Set Impact Tolerance Conduct Scenario Testing New call-to-action

Find out more about Blended Learning ORA-5000 [BL-ORA-5] & ORA-300 [BL-ORA-3]

New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action New call-to-action New call-to-action
New call-to-action

Please feel free to send us a note if you have any of these questions.

Email to Sales Team [BCM Institute]

New call-to-action
Read More
ORA [Plan] Questionnaires: Analyse Gap

ORA [Plan] Questionnaires: Analyse Gap

New call-to-action

Analyse the Gap 

 

OR_Plan_Update Diagram

 

What is Gap Analysis in OR?

A gap analysis is a method of assessing the performance of a business unit to determine whether operational resilience requirements or objectives are being met and, if not, what steps should be taken to meet them.

A gap analysis is called a needs analysis, needs assessment or need-gap analysis.

New call-to-actionOR Plan Phase Questionnaires: Analyse GapThis section is the "Plan" phase of the Operational Resilience Planning Methodology.  It is the second stage of the Plan phase: Analyse Gap.

Audit Checklist for Analysing the Gap

 

1. Gap Analysis Process

  • Has a structured process been defined for conducting the gap analysis?
  • Are the objectives and scope of the gap analysis clearly defined?
  • Is there a designated team responsible for conducting the gap analysis?
  • Are the necessary resources allocated for conducting a thorough analysis?
  • Has a timeline or schedule been established for completing the gap analysis?

ChecklistGap Analysis Process

  • Review the documented process for conducting the gap analysis.
  • Evaluate the clarity and comprehensiveness of the defined objectives and scope.
  • Assess the qualifications and expertise of the team responsible for the analysis.
  • Verify that sufficient resources, such as personnel and technology, are available for the analysis.
  • Confirm the existence of a timeline or schedule for completing the gap analysis.

2. Identification of Current State

  • Has the current state of the operational resilience program been accurately assessed?
  • Are the program's key components, processes, and controls identified and documented?
  • Has the maturity level of each component been evaluated?
  • Are there any gaps or deficiencies identified in the current state?
  • Have relevant stakeholders been involved in the identification process?

Checklist: Identification of Current State

  • Verify the accuracy and comprehensiveness of the assessment of the current state of the operational resilience program.
  • Evaluate the documentation of key components, processes, and controls.
  • Assess the methodology used for evaluating the maturity level of each component.
  • Identify and document any identified gaps or deficiencies in the current state.
  • Confirm the involvement of relevant stakeholders in the identification process.

3. Desired Future State

  • Has a desired future state for the operational resilience program been defined?
  • Are there specific objectives and targets for each component of the program?
  • Is the desired future state aligned with regulatory requirements and industry best practices?
  • Are the resources and capabilities required for achieving the desired future state identified?
  • Has a roadmap or action plan been developed to bridge the gap between the current and desired future state?

Checklist: Desired Future State

  • Review the documentation of the desired future state for the operational resilience program.
  • Evaluate the clarity and specificity of the defined objectives and targets.
  • Verify the alignment of the desired future state with regulatory requirements and industry best practices.
  • Assess the identification of resources and capabilities needed to achieve the desired future state.
  • Confirm the existence of a roadmap or action plan for bridging the gap between the current state and the desired future state.

4. Risk Assessment and Prioritization

  • Has a risk assessment been conducted to identify the risks of closing the gap?
  • Are the identified risks prioritized based on their potential impact and likelihood?
  • Has a mitigation strategy been developed for each identified risk?
  • Are the resources and efforts allocated appropriately based on risk prioritization?
  • Have appropriate stakeholders reviewed and approved the risk assessment and prioritization?

Checklist: Risk Assessment and Prioritisation

  • Verify the completion of a risk assessment specifically focused on the gap analysis process.

  • Evaluate the methodology used for prioritizing the identified risks.
  • Assess the effectiveness and feasibility of the mitigation strategies developed for each risk.
  • Review the allocation of resources and efforts based on =risk prioritization.
  • Confirm the review and approval of the risk assessment and prioritization by appropriate stakeholders.

5. Business Impact Analysis

  • Has a comprehensive BIA been conducted to identify critical business processes, dependencies, and their impact on the organization?
  • Are each critical process clearly defined recovery time objectives (RTOs) and recovery point objectives (RPOs)?
  • Has the BIA identified and assessed the potential financial, operational, reputational, and regulatory impacts of disruptions to critical processes?
  • Are there documented strategies and plans to mitigate the identified risks and ensure timely recovery?
     

Checklist: Business Impact Analysis

  • Review the documentation of the BIA process, including its objectives and scope.

  • Evaluate the accuracy and completeness of critical process identification and dependency mapping.
  • Assess the identification and documentation of RTOs and RPOs for each critical process.
  • Verify including financial, operational, reputational, and regulatory impact assessments in the BIA.
  • Review the mitigation strategies and recovery plans developed based on the BIA findings.

6. Risk Assessment

  • Has a risk assessment been conducted to identify and evaluate potential threats and vulnerabilities to the operational resilience program?
  • Are there documented processes to identify, assess, and prioritize risks?
  • Has the likelihood and potential impact of identified risks been analyzed?
  • Are risk mitigation strategies and controls in place to address identified risks?
  • Is there a process for regularly reviewing and updating the risk assessment?
 
 

Checklist: Risk Assessment

  • Verify the completion of a risk assessment specifically focused on the operational resilience program.
  • Evaluate the adequacy and effectiveness of the risk identification and assessment processes.
  • Assess the accuracy and comprehensiveness of the risk likelihood and impact analysis.
  • Review the documented risk mitigation strategies and controls implemented to address identified risks.
  • Determine if a process is in place to review and update the risk assessment periodically.
 

7. Business Continuity Planning

  • Has a BCP framework been established to guide the development and implementation of business continuity plans?
  • Are there documented business continuity plans for critical processes and systems?
  • Have the plans been tested and validated through exercises and simulations?
  • Are roles, responsibilities, and communication channels clearly defined within the business continuity plans?
  • Is there a process to periodically review and update the business continuity plans?

Checklist: Business Continuity Planning

  • Review the documented BCP framework and its alignment with industry standards and best practices.
  • Evaluate the existence and adequacy of business continuity plans for critical processes and systems.
  • Assess the documentation of testing and validation activities conducted on the business continuity plans.
  • Verify the clarity and accuracy of the plans' roles, responsibilities, and communication channels.
  • Determine if a process is in place to review and update the business continuity plans periodically.

 

8. Incident Response/IT Disaster Recovery

  • Is there documented incident response and IT disaster recovery plans?
  • Have the plans been tested and validated through exercises and simulations?
  • Is there a designated incident response team and a clear escalation process?
  • Are there backup and recovery mechanisms in place for critical IT systems and data?
  • Is there a process for continuously monitoring and improving incident response and IT disaster recovery capabilities?

Checklist: Incident Response/IT Disaster Recovery

  • Verify the existence and adequacy of documented incident response and IT disaster recovery plans.
  • Evaluate the documentation of testing and validation activities conducted on the plans.
  • Assess the existence and composition of the incident response team and the clarity of the escalation process.
  • Review the backup and recovery mechanisms implemented for critical IT systems and data.
  • Determine if a process is in place for continuous monitoring and improvement of incident response and IT disaster recovery capabilities.

9. Vendor and Third-Party Management

  • Is there a comprehensive process in place to assess and manage the risks associated with vendors and third-party service providers
  • Are there documented criteria for selecting vendors and conducting due diligence?
  • Is there a mechanism to monitor and ensure the ongoing compliance of vendors with operational resilience requirements?
  • Are contingency plans and alternate arrangements in case of disruptions from vendors or third-party service providers?
  • Are there processes to periodically review and assess the effectiveness of vendor and third-party management practices?

Checklist: Vendor and Third-Party Management

  • Review the documented vendor and third-party management processes and procedures.
  • Evaluate the criteria used for vendor selection and due diligence.
  • Assess the effectiveness of ongoing monitoring and compliance management mechanisms.
  • Verify the existence of contingency plans and alternate arrangements for vendor disruptions.
  • Determine if periodic reviews and assessments of vendor and third-party management practices exist.

10. Training and Awareness

  • Is there a training program in place to educate employees about operational resilience policies, procedures, and best practices?
  • Are employees aware of their roles and responsibilities regarding operational resilience?
  • Are there regular communication and awareness campaigns to promote a culture of operational resilience?
  • Are training programs periodically updated to reflect changes in operational resilience requirements?
  • Is there a mechanism to track and monitor employee completion of required operational resilience training?

Checklist: Training and Awareness

  • Review the documentation of the training program for operational resilience.
  • Evaluate the effectiveness and comprehensiveness of the training materials and resources.
  • Assess the clarity and understanding of employee roles and responsibilities.
  • Verify the existence of regular communication and awareness campaigns.
  • Determine if a mechanism exists to track and monitor employee completion of operational resilience training.

11. Governance and Oversight

  • Is there a well-defined governance framework and structure for operational resilience?
  • Are individuals or teams responsible for operational resilience assigned clear roles, responsibilities, and accountabilities?
  • Is there a mechanism to ensure oversight and monitoring of operational resilience activities?
  • Are there regular reporting and escalation processes to senior management or the board of directors?
  • Are there mechanisms to review and update the governance framework and structure as needed?

Checklist: Governance and Oversight

  • Review the documented governance framework and structure for operational resilience.
  • Evaluate the clarity and effectiveness of assigned roles, responsibilities, and accountabilities.
  • Assess the mechanisms in place for oversight and monitoring of operational resilience activities.
  • Verify the existence of regular reporting and escalation processes to senior management or the board.
  • Determine if there are mechanisms to review and update the governance framework and structure.

12. Business Continuity and Resilience Testing

  • Are there documented plans and procedures for testing the effectiveness of business continuity and resilience measures?
  • Is there a schedule for conducting regular testing and exercises?
  • Are different scenarios and levels of disruptions considered during testing?
  • Are testing results analyzed and used to identify areas for improvement and corrective actions?
  • Are there mechanisms to track and follow up on implementing corrective actions identified during testing?

 

Checklist: Business Continuity and Resilience Testing

  • Review the documented plans and procedures for business continuity and resilience testing.
  • Evaluate the adequacy of the testing schedule and the consideration of different scenarios.
  • Assess the analysis and use of testing results for improvement and corrective actions.
  • Verify the existence of mechanisms to track and follow up on the implementation of corrective actions.
  • Determine if there is a process to document lessons learned from testing and exercises.

 

13. Continuous Improvement

  • Is there a process to identify and address gaps and deficiencies in the operational resilience program?
  • Are there mechanisms to capture and document lessons learned from incidents, tests, and exercises?
  • Is there a feedback loop to ensure that identified improvements are implemented?
  • Are there metrics and performance indicators to measure the effectiveness of the operational resilience program?
  • Is there a culture of continuous improvement and learning within the organization?

 

Checklist: Continuous Improvement

  • Review the process for identifying and addressing gaps and deficiencies in the operational resilience program.
  • Evaluate the mechanisms to capture and document lessons learned from incidents, tests, and exercises.
  • Assess the feedback loop to ensure the implementation of identified improvements.
  • Verify the existence of metrics and performance indicators for measuring program effectiveness.
  • Determine if there is evidence of a culture of continuous improvement and learning within the organization.

Do note that some steps may overlap or appear similar in the other stages of the OR planning phases.  If this occurs, the questionnaires and checklists must be contextualised to the topic under review.

 

New call-to-action

Questionnaires and Checklist "Plan" Phase

Assess Capability and Maturity Analyse Gap

Develop Strategy Roadmap

Confirm Risk Appetite

Develop and Embed Governance

New call-to-action New call-to-action OR Plan Phase Questionnaires: Analyse Gap New call-to-action New call-to-action New call-to-action

Find out more about Blended Learning ORA-5000 [BL-ORA-5] & ORA-300 [BL-ORA-3]

New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action New call-to-action New call-to-action
New call-to-action

Please feel free to send us a note if you have any of these questions.

Email to Sales Team [BCM Institute]

New call-to-action
Read More