Business Continuity & Resilience
FM's role in keeping the organisation operational through disruption and recovering quickly afterward, grounded in ISO 22301 and ISO/TR 41019:2024.
A business continuity plan that has never been tested through a genuine exercise is a document, not a capability.
Why this service exists
The pandemic and increasing extreme-weather frequency have moved business continuity from a specialist niche to a mainstream FM capability over the past several years — a genuine shift worth stating directly rather than describing this as though it were always a standard, permanent fixture of FM practice.
What the service covers
- Business continuity plan development and testing.
- Critical-asset/critical-supplier risk mapping.
- Incident response coordination.
- Resilience planning against climate and other emerging risk categories.
Assets and objects
- Business continuity plans.
- Exercise/test records.
- Critical dependency maps.
Who takes part
- Business continuity managerRequired
Owner of plans and exercises.
- FM operations managerSituational
Execution during incidents.
- Critical-supplier liaisonsSituational
Critical dependency information.
- Demand-organisation risk/business continuity functionSituational
Strategic partner.
What the service needs
- Critical-asset and critical-supplier mapping.
- Incident history.
- ISO 22301-aligned methodology.
How delivery runs
- 01Map critical assets and suppliers whose failure would genuinely threaten continuity — not a generic risk register, a facility- and supplier-specific one.
- 02Develop continuity plans against those specific critical dependencies.
- 03Test plans through genuine exercises, not tabletop review alone.
- 04Coordinate actual incident response when disruption occurs, applying and refining the tested plan.
What is delivered
- Business continuity plans.
- Exercise/test records.
- Critical dependency maps.
- Incident response records.
From output to outcome
Tested plans and dependency maps.
Genuine organisational resilience through disruption.
Deliberately distinguished from having a continuity plan on file, since an untested plan provides false confidence rather than real capability.
Where it gets tense
- Continuity plans that exist as documents but have never been tested through a genuine exercise, discovered to be unworkable only during an actual incident.
Strategic, tactical, operational
Critical-asset and critical-supplier risk mapping should connect directly to Mechanical Systems' criticality ratings and Supplier & Contract Management's own risk monitoring, not be built as a separate, disconnected exercise.
Genuine testing (not just tabletop review) is what actually validates a plan — resourcing for this is frequently the first thing cut under budget pressure, precisely where it matters most.
Incident response coordination needs clear, tested escalation authority.
Performance indicators
- Plan testing frequency and pass rate
Baseline validation measure.
- Critical-dependency mapping coverage
Mapping completeness.
- Actual incident response time against plan
Measures real-world execution.
Risks
- The central risk this capability addresses is organisational — that continuity planning becomes documentation exercise rather than tested capability, discovered to be inadequate only when a real incident occurs.
Statutory context
No general statutory obligation; sector-specific or contractual continuity requirements may apply.
Sourcing options
- In-house
Typically an internal capability given its strategic and cross-functional nature.
- Single service
Sometimes supplemented by specialist continuity/resilience consultancy for plan development and exercise design.
Technology and data
- Business continuity management software.
- Incident-management/communication platforms.
Competencies required
- Business continuity management (ISO 22301 literacy).
- Incident command.
- Risk assessment.
Common mistakes
- Treating a documented, untested continuity plan as equivalent to genuine organisational resilience.