Statement of Guidance
Statement of Guidance - Business Continuity Management (All Licensees) (March 2007)
Status not confirmedView on CIMA's website Source document
Summary
This is a CIMA Statement of Guidance (from March 2007) setting out supervisory expectations for business continuity management (BCM) that apply to all CIMA licensees. It explains what CIMA regards as sound practice for developing, implementing, testing and maintaining a business continuity plan (BCP), covering business impact analysis, risk assessment, risk management and risk monitoring/review as the core planning process.
- Board and senior management responsibility: A licensee's board and senior management are collectively responsible for BCM, must foster a culture prioritising continuity, ensure adequate resourcing, and have reporting and independent review arrangements in place.
- Preparing for major disruptions: Licensees should prepare for major operational disruptions, drawing on lessons from Hurricane Ivan, including choosing sufficiently remote/resilient alternate sites, ensuring data and systems are recoverable at those sites, and ensuring adequate staffing arrangements.
- Recovery objectives: Licensees are expected to establish recovery time/level objectives proportionate to the risk they pose to the domestic financial system, citing a five-day recovery objective as an example for critical market participants.
- Communication protocols: Expectations cover communication protocols, internally, with the Authority, with associations and with the public.
- Outsourcing arrangements: Expectations address outsourcing arrangements as part of BCM.
- Staff training: Expectations cover staff training on business continuity.
- Testing and review: Expectations cover periodic testing of BCPs with independent review of test results.
CIMA incorporates BCM review into its examination/inspection process, assessing whether a licensee's BCM, including recovery objectives and testing, is appropriate to its size, scope and systemic risk. As a Statement of Guidance, it does not itself create binding legal rules with fixed compliance dates, but describes the standards CIMA will use when supervising and inspecting licensees' business continuity arrangements.
Key obligations
- Licensees should adopt a business continuity planning process comprising business impact analysis, risk assessment, risk management, and risk monitoring/review.
- A licensee's board of directors and senior management should take collective responsibility for business continuity management, endorse BCM policies, and ensure sufficient financial and human resources are allocated to BCM.
- Licensees should implement a framework for reporting to the board and senior management on BCM matters (implementation status, incidents, testing results, action plans) and subject BCM to review by an independent party (internal or external audit).
- Licensees should incorporate the risk of major operational disruption into their BCPs, including identifying priority business functions via BIA and setting recovery objectives for them.
- Licensees should ensure alternate sites are sufficiently resilient/remote from the primary site, have adequate current data, equipment and systems, and sufficient staff to recover critical operations.
- Licensees should establish recovery objectives proportionate to the risk they pose to the domestic financial system, with the highest objectives (e.g., five-day recovery) expected of the most critical market participants.
- Licensees should include in their BCPs communication procedures for internal and external parties (including the Authority and associations) during a disruption, and maintain/update contact lists (calling trees) with periodic testing.
- Where a significant business activity is outsourced, licensees should maintain a contingency plan in case the outsourcing arrangement is terminated or the vendor fails to perform, and outsourcing agreements should address business continuity expectations.
- Licensees should provide business continuity training for personnel, including enterprise-wide and unit-specific training, and cross-training to cover absence of key employees.
- Licensees should periodically test their BCPs, evaluate effectiveness, update BCM as needed, and have an independent party assess the testing programme and report findings to senior management and the board.
Applies to
All CIMA licensees, retail banks, insurance licensees conducting domestic insurance business