What a business continuity exercise proves, and what it leaves untested

Generador industrial de respaldo en marcha en la sala de máquinas de un edificio de oficinas, con su cable de carga enrollado y desconectado sobre el piso, mientras las oficinas del fondo siguen iluminadas por la línea eléctrica principal

What a business continuity exercise proves, and what it leaves untested

The BCI Emergency & Crisis Communications Report 2026 reports that 72.4% of organisations activated their emergency communications plan over the past twelve months. In the same report, nearly 90% say they have a formal plan and more than three quarters claim they can activate it in under thirty minutes.

Activation is no longer a laboratory assumption, and the document generally exists. What remains open in most of the continuity frameworks I review is something else. When the business continuity exercise ends and the report says it went well, it is rarely clear what exactly was tested and what went untested.

That distinction determines whether the board is making decisions about a measured capability or about the reassurance an exercise left behind.

What does ISO 22301 ask for regarding exercises?

What ISO 22301 requires is an exercise programme, and it does so in clause 8.5, which in the 2019 revision replaced the older exercising and testing sub-clause. The programme defines schedule, objectives, scope, scenarios, participants and evaluation criteria, and it accepts different formats depending on what you want to verify.

The difference between a programme and an event is the first thing lost when continuity is managed against an audit date. An event produces a report. A programme produces a series, and a series allows comparison.

Clause 8.6 sits on top of that, asking for periodic evaluation of both the continuity documentation and the organisation’s capabilities, and for confirmation that they remain adequate while the organisation changes. The two clauses work together: 8.5 generates the evidence and 8.6 forces you to do something with it.

For European financial entities the requirement also arrives through another route, because the DORA regulation treats digital operational resilience testing as a pillar of its own. The gateway to that obligation is which entities DORA applies to.

What does each type of exercise prove?

The four formats the standard accepts test different layers, and each one leaves the rest untouched.

Type of exercise What it proves What it leaves untested Who takes part
Documentation review That the plan is complete, current and internally consistent Any actual response capability The team that maintains the plan
Tabletop exercise The crisis team’s decision criteria and the dependencies between departments Whether systems and alternative channels respond The crisis team and process owners
Functional simulation That a specific procedure completes within the recovery time objective How the rest of the organisation reacts The technical team of the scope being tested
Live failover That the alternative capability sustains operations Detection of the event, since the failover starts by your own decision The operation of the process being switched over

Read down the columns, the table explains an asymmetry that shows up often in governance reports. An organisation can accumulate three years of flawless tabletop exercises and hold no evidence at all that its alternative capability sustains operations.

The programme is organised by covered layers. It is worth knowing which ones were tested in the last twelve months and which ones have gone the longest without verification.

Why does an announced exercise prove less than the report claims?

An announced exercise is still useful and hard to replace. What the advance notice does is neutralise three assumptions, and it is worth writing them next to the report’s conclusion.

The first is detection. The exercise starts when someone announces it, while the real event starts when someone recognises it and decides to escalate. The whole interval between the failure and the moment someone names it an incident falls outside the rehearsal.

The second is timing. Exercises run during business hours, with people at their desks and decision authority available. Activation at three in the morning on a Sunday depends on written delegations that almost never get tested.

The third is availability. The named role holders take part in the exercise. On the day of the event there are holidays, leave, vacant positions and people who started three weeks ago. A plan that works with the incumbents present says nothing about their backups.

What happens to the result of the exercise?

This is, in my experience, where most programmes fall apart. The exercise finds deviations, the report lists them, and from there the loop is lost.

Clause 8.6 pushes in the opposite direction, requiring the evaluation to lead to updated documentation and procedures. For that to happen, every deviation found needs three attributes from the day of the exercise: a named owner, a closure date and a later verification that it was resolved. Without that verification, the deviation reappears in next year’s exercise and gets logged as a new finding.

A deviation that is found and never closed does something worse than staying open. It settles in. It is the same mechanism by which an operational shortcut becomes the norm before the incident: if the exercise shows the procedure is being bypassed and nobody corrects it, the exercise has just documented the real practice and legitimised it.

That is also the reason to distrust a report concluding that the exercise was completed as planned. A result with no deviations usually points to a scenario designed to confirm the plan rather than stress it, and it works exactly like the compliance percentage that reaches 100% and stops informing.

Is one large exercise a year better than several short ones?

Scale carries a coordination cost that is rarely accounted for. A case published by the Business Continuity Institute in May 2026, drawn from a pilot at the British Council, documents that teams agree to a two-hour exercise far more readily than to a significantly longer one, and that beyond a certain duration the exercise is perceived as a disruption to operations rather than a development activity.

For a continuity programme the consequence is practical. A short, repeatable format covers more layers of the table above within the same year than a single large-scale exercise, and each repetition lets you verify whether the previous exercise’s deviation was closed.

The larger exercise keeps its place, but as an annual exception rather than the only rehearsal of the whole year. Sustaining that cadence is a planning problem before a methodological one, and it rests on having a month-by-month view of what is scheduled for each group, department or seniority level, instead of one annual date defended against everyone else’s calendar.

What evidence does an exercise programme leave?

An auditor reviewing clause 8.5 asks about the full series for the period. Four records organise what is worth having available.

  • Who took part in each exercise and in which assigned role, against the current directory.
  • Which deviations were found, written as deviations rather than as general observations.
  • Who owns the closure of each one and by what committed date.
  • Where the later verification that the deviation was resolved is recorded.

It is worth being honest about the reach of each tool. The exercise programme belongs to the business continuity management system. What does rest on an awareness platform is the people layer around the exercise, and there SMARTFENSE contributes two concrete things to a continuity framework. One is being able to upload your own policies and procedures and show, user by user, who was informed or assessed on each regulation. The other is an audit trail that logs every activity by users, administrators and the system itself, which lets you reconstruct afterwards what was communicated and since when.

Preparing the people who never take part in any exercise is a separate problem with its own answer, which I developed in the approved continuity plan nobody knows how to execute.

From the exercise report to the governance decision

A business continuity exercise produces two different things, and only one of them is useful for governance. It produces a conclusion, usually a reassuring one, and it produces a list of deviations covering what the organisation still cannot do.

The second is the one that reaches the board with decision value, because it allows priorities and budget to be discussed against specific missing capabilities. The first, read on its own, takes the place of a guarantee the exercise never gave.

Treating the exercise programme with the same discipline already applied to the business impact analysis and the recovery time objectives is what turns a series of annual reports into a measurement. At that point continuity stops answering for what the organisation documented and starts answering for what it proved.

Frequently asked questions

What does ISO 22301 require regarding business continuity exercises?
Clause 8.5 of ISO 22301 requires an exercise programme with a schedule, objectives, scope, scenarios, participants and evaluation criteria, and it accepts different formats such as documentation review, tabletop exercise, functional simulation and live failover. Clause 8.6 adds the periodic evaluation of business continuity documentation and capabilities.

What is the difference between a tabletop exercise and a functional simulation?
A tabletop exercise brings the crisis team together to make decisions on a described scenario, and it tests decision criteria and cross-department dependencies without touching a single system. A functional simulation runs an actual recovery procedure and tests whether it completes within the committed recovery time objective. The first validates decisions, the second validates the technical capability of one specific scope.

Why does an announced exercise prove less than it appears to?
Because the advance notice neutralises three assumptions that are still unresolved on the day of the incident. The exercise starts when someone announces it, while the real event starts when someone recognises it. The exercise runs during business hours with the named role holders available. And the exercise never crosses holidays, leave or turnover among the people listed in the plan.

How often should a business continuity plan be exercised?
It is better to sustain a short, repeatable cadence than a single large annual exercise. A case published by the Business Continuity Institute in May 2026 documents that teams agree to a two-hour exercise far more readily than to a long one, which starts being perceived as a disruption to operations. The larger format still has its place, but as an annual exception rather than the only rehearsal of the year.

What evidence does an exercise programme leave for an audit?
Four records organise what you need to be able to show. Who took part in each exercise and in which assigned role, which deviations were found, who owns the closure of each deviation and by what date, and where the later verification that the deviation was actually resolved is recorded. A report that only concludes that the exercise was completed answers none of the four.

Carla Caggiano

Ejecutiva en Gobierno, Riesgo y Cumplimiento (GRC), Seguridad de la Información y Continuidad del Negocio, con más de 8 años liderando equipos y proyectos en banca, salud y tecnología. Diseña e implementa marcos basados en ISO 27001, ISO 22301 e ISO 31000, y traduce regulaciones complejas (SOX, NIST, GDPR, DORA, COBIT) en soluciones aplicables y sostenibles.

Leave a Reply