Operational Resilience Audit Series
Bg Bann_OR_Audit Expert_Landscape1

ORA [Sustain] Questionnaires: Introduce Cultural Change

This section is the "Sustain" phase of the Operational Resilience Planning Methodology.  These questionnaires serve as an initial audit checklists to review the first stage of the Sustain phase: Introduce Cultural Change.

Moh Heng Goh
Operational Resilience Audit-Specialist-Expert

OR Audit Questionnaires

Implement Phase

Introduce Cultural Change

OR_Roadmap_Sustain_Diagram

 

What is Organisational Culture?

Organisational Culture is not created by memo or a decision from senior management but developed over time and plays a crucial role in achieving organisational objectives, especially in this new area of operational resilience.

New call-to-actionThis section is the "Implement" phase of the Operational Resilience Planning Methodology.  It is the first stage of the Implement phase: Identify Critical Business Services.

 

Audit Checklist for Introducing Cultural Change

 

Identification of Critical Business Services

  • Has the organisation identified its critical business services?
  • Are the critical business services clearly defined and documented?
  • Has the organisation prioritised the criticality of each business service?
OR Critical Business Services BCMPedia

 

Interdependencies and Interconnections

  • Are the dependencies and interconnections of critical business services identified?
  • Has the organisation mapped the dependencies between critical business services and supporting functions, systems, and vendors?
  • Are there contingency plans in place to address disruptions independent services?
OR Mapping Interconnections and Interdependencies BCMPedia

 

Business Impact Analysis

  • Has a business impact analysis (BIA) been conducted for each critical business service?
  • Are the potential financial, operational, and reputational impacts of disruptions to critical business services assessed?
  • Are each critical business service's recovery time objectives (RTOs) and recovery point objectives (RPOs) defined?
New call-to-action

 

Risk Assessment

  • Has a comprehensive risk assessment been conducted for each critical business service?
  • Are the risks to each critical business service identified and assessed?
  • Are risk mitigation measures in place for identified risks?
  • Is there a process to regularly review and update risk assessments for critical business services?
New call-to-action

 

Business Continuity Planning

  • Are business continuity plans in place for each critical business service?
    Have the plans been tested and validated?
  • Are the business continuity plans documented and easily accessible to relevant personnel?
  • Are there clearly defined procedures for invoking and executing the business continuity plans?
 

 

Incident Management

  • Is there an incident management framework specifically tailored for critical business services?
  • Are there documented incident response procedures for critical business services?
  • Are roles and responsibilities clearly defined for managing incidents related to critical business services?
  • Is there a process to track and report incidents related to critical business services?
 

 

Communication and Stakeholder Management

  • Is there a communication plan to keep stakeholders informed during disruptions to critical business services?
  • Are there established communication channels to reach internal and external stakeholders?
  • Is there a process to prioritise and communicate with stakeholders based on the severity and impact of the disruption?
 

 

Testing and Exercises

  • Are regular testing and exercising of critical business services conducted?
  • Are the testing and exercising scenarios designed to simulate realistic disruptions?
  • Are the lessons learned from testing and exercises used to improve the operational resilience of critical business services?
New call-to-action

 

Training and Awareness

  • Is there a training program to educate employees on the operational resilience of critical business services?
  • Are employees aware of their roles and responsibilities in maintaining the operational resilience of critical business services?
  • Are there regular awareness campaigns to promote a culture of operational resilience for critical business services?
  • Are training records maintained for compliance and audit purposes?
OR Training and Awareness BCMPedia

 

Continuous Improvement

  • Is there a process to capture and analyse lessons learned from disruptions to critical business services?
  • Are there mechanisms to incorporate the lessons learned into improvements for the operational resilience of critical business services?
  • Is there a culture of continuous improvement in managing the operational resilience of critical business services?
  • Are regular reviews and updates to the business continuity plans and procedures for critical business services
OR Continuous Improvement

 

Note that some of the steps may overlap with the other stages of the "Implement" phase stages.

 

Find out more about Blended Learning BCM-8530 [BL-A-5] & BCM-8030 [BL-A-3]

New call-to-action Tell Me More About BCM- 8030 New Call-to-action
New call-to-action TMM [BL-A-5] Register [BL-A-5]
FAQ for BL-A-3

Please feel free to send us a note if you have any of these questions.

Email to Sales Team [BCM Institute]

New call-to-action

For Your Comments:

 

More Posts

New Call-to-action