1.7 Business Continuity

Business continuity ensures that critical business services remain usable and recoverable during disruptions. It protects the organisation’s ability to create value, fulfil obligations and maintain trust.

Business continuity is a shared responsibility between business and technology. Business Owners define which business outcomes must be maintained, what level of disruption is acceptable and how operations continue during disruptions. Technology and service teams design, build and operate services to be resilient and recoverable. As disruptions cannot be fully prevented, continuity is achieved by combining resilient service design with the ability to operate under degraded conditions.

Its purpose is to safeguard revenue and obligations, protect customers and partners, maintain operational stability during development and service changes, and enable effective response and recovery. By making disruption risks explicit, business continuity aligns investment decisions, service planning and service operations.

Criticality, risk and governance

Business continuity starts with identifying critical business services and the processes they support. Business Owners define the impact of service disruptions, key risk scenarios and how operations continue during outages, including manual procedures, alternative solutions and communication practices. Each critical service has a named owner, defined recovery objectives and clear escalation thresholds.

Risk assessment is an integral part of this definition. Dependencies on systems, data, suppliers, platforms and external factors are identified and evaluated to understand potential failure points and their business impact. Core platforms in global cloud infrastructure have become increasingly critical to business operations. At the same time, they often provide stronger availability, scalability and resilience capabilities than proprietary or locally hosted solutions, provided that services are designed to use these capabilities properly. This makes architecture, configuration, regional design, identity management, data protection and provider dependency essential parts of continuity planning.

Location-specific risks such as regional infrastructure reliability, data residency requirements, geopolitical conditions, regulatory constraints and exposure to regional disruptions are also considered. These factors influence both the likelihood and impact of service disruptions.

These definitions guide resilience design and development prioritisation. When planning development initiatives, their impact on critical services, dependencies and risk exposure is assessed. Architecture and portfolio governance ensure that dependencies on systems, platforms, suppliers and locations remain controlled and that single points of failure and concentration risks are avoided.

As automation, AI agents and digital workers become part of business services and operational processes, business continuity must also define what happens when these capabilities are unavailable, unreliable or operating outside expected boundaries. Critical services need fallback procedures, human escalation, monitoring, access control and clear limits for automated or AI-supported actions during disruptions.

Service delivery and continuous improvement

In service delivery, continuity is implemented through resilient service design, monitoring and tested recovery procedures. Each critical service has defined recovery plans, escalation paths and operational practices aligned with business priorities. These are regularly tested to ensure that recovery works in practice. The organisation maintains visibility into service resilience, dependencies, risks and known weaknesses, including those arising from external ecosystem partners.

The same principles apply to external services and partners. Dependencies on cloud providers, platforms, data providers and other suppliers are identified and managed. Contractual agreements define recovery expectations, escalation procedures and reporting requirements, while dependency and location-specific risks are actively monitored.

Business continuity is continuously maintained and improved. Critical services, dependencies, risks and recovery capabilities are regularly reviewed and tested. After disruptions, the organisation evaluates the impact and effectiveness of response and recovery, using these insights to improve service design, operational practices and investment decisions. Continuity is an integral part of normal governance and service management.