Toolkit
Files, not examples
Every template is generated on demand in the format you need, with its instructions and the pitfalls to avoid. An updated template is updated in all four formats at once.
45 templates
Business continuity policy
Policy template meeting ISO 22301 clause 5.2, ready to sign.
Continuity programme charter
The written mandate that gives the practitioner authority.
Business impact analysis questionnaire
Fifteen factual questions, designed to be answered in ten minutes.
Multi-criteria impact scale
Five criteria, five levels, five time horizons, with an override rule.
MTPD / RTO / RPO / MBCO register
The reference table of committed durations, with consistency checks.
Continuity strategy comparison
Three costed options per resource, with cost per hour of RTO gained.
Continuity decision case
Five pages to obtain a decision, not an approval.
Business continuity plan template
Twelve pages, three reading depths, executable actions.
Role-based action cards
Double-sided A5: ten actions, three prohibitions, no cross-references.
Crisis directory
A single source, two deputies per role, tested twice a year.
ISO 22301 conformity matrix
Clause by clause: requirement, expected evidence, status, gap, action.
Internal audit programme
A full three-year cycle, with clause-level interview grids.
Important business services register
Client-side phrasing, owner, tolerance, measured capability, gap.
Annual resilience self-assessment
The document the board approves and the supervisor requests.
End-to-end dependency map
Six layers, one row per dependency, sortable by substitutability.
Single point of failure register
Qualification, treatment or explicit acceptance, with review date.
Severe scenario library
Twenty ready-to-run scenarios covering the six disruption families.
Operational risk taxonomy
Seven Basel categories crossed with four root causes.
Risk register
Inherent risk, controls, residual risk, decision, owner.
RCSA self-assessment kit
Facilitation guide, thought-provoking questions, control effectiveness grid.
Loss data collection database
Six indispensable fields, including the occurrence-to-detection gap.
Key risk indicator dashboard
Three-level thresholds, each with a named action.
Bow-tie template
Causes, preventive barriers, top event, protective barriers, consequences.
IT disaster recovery plan template
Five restart waves, verification criteria, built-in timing.
Backup and restoration policy
3-2-1-1-0 rule, administration domain isolation, test plan.
Restoration test procedure
Five test levels, timestamped chronology, gap exploitation.
Crisis management plan
Three tiers, seven roles, binding thresholds, battle rhythm.
Crisis incident log
Three columns, six entry types, usable without authentication.
Crisis team role cards
Seven roles, each stating what it does not do.
Pre-drafted holding statements
Twelve template messages covering the major scenarios, legally cleared.
Crisis communication plan
Audience order, fallback channels, alignment with notifications.
Exercise scenario template
Measurable objectives, inject timeline, facilitation roles.
Exercise evaluation grid
Observable criteria handed to observers before the exercise.
Exercise report and action plan
Three lists, not a general conclusion.
DORA gap analysis
Article by article: requirement, evidence, status, gap, action, deadline.
DORA register of information
Relational structure: entities, arrangements, providers, functions, sub-outsourcing.
ICT risk management framework
The document the board approves under Article 6.
Incident notification procedure
Decision chain, deadlines, templates for the three reports.
Incident classification grid
One page, seven criteria, usable alone at 3 a.m.
ICT contract clause set
Common baseline and enhanced clauses for critical functions.
Resilience testing programme
Eight test types, scope, frequency, evidence of independence.
Cyber incident response plan
The five decisions prepared in advance, and the single escalation chain.
Supplier due diligence questionnaire
Fifteen questions calling for evidence, not statements.
Third-party register and concentration matrix
Three-tier segmentation and cross-referencing of shared dependencies.
Provider exit plan
Four verifiable elements, including a tested data extraction.