If your organization is regulated by FINRA, the federal banking agencies, HHS, the FTC, NERC, or the GDPR, business continuity plan requirements oblige you to keep a written plan that identifies your critical functions, sets recovery time and recovery point objectives, documents how you will restore operations, is tested and updated at least annually, and is approved by senior management or the board. The specifics differ by sector, but the framework and the consequences of missing pieces are consistent enough that you can build to them.
Who Has to Have a Written Plan
Not every business faces a legal obligation, but several federal regimes impose one. The rules below cover the most common triggers.
Broker-Dealers
FINRA Rule 4370 requires every member firm to create and maintain a written BCP reasonably designed to let the firm continue meeting its obligations to customers during emergencies and significant business disruptions. The plan must address, at minimum, data backup and recovery for hard-copy and electronic records; mission-critical systems for order processing, execution, clearance, settlement, and customer account access; financial and operational assessments; alternate communications with customers and employees; alternate work locations; effects on critical business constituents, banks, and counterparties; regulatory reporting; and customer access to funds and securities if the firm cannot continue operating. If a category does not apply, the plan must say so and explain why. A registered principal from senior management must approve the plan and conduct an annual review.1Financial Industry Regulatory Authority. FINRA Rule 4370 – Business Continuity Plans and Emergency Contact Information
Banks and Credit Unions
Bank examiners work from the FFIEC’s Business Continuity Management handbook, which directs management to inventory critical assets, infrastructure, and third-party service providers, then establish recovery objectives and assess the financial, operational, and reputational impact of disruptions.2FFIEC IT Examination Handbook. Business Continuity Management The board of directors must review and approve the BCP at least annually, with the review recorded in board minutes.3Federal Financial Institutions Examination Council. Business Continuity Planning Booklet
A separate rule sits alongside the planning obligation. Under 12 CFR Part 53, a banking organization must notify its primary federal regulator as soon as possible and no later than 36 hours after determining that a “notification incident” has occurred, meaning one that has materially disrupted banking operations, threatened a business line whose failure would cause material revenue loss, or posed a threat to U.S. financial stability.4eCFR. 12 CFR Part 53 – Computer-Security Incident Notification
HIPAA-Covered Entities and Business Associates
The HIPAA Security Rule requires a contingency plan for emergencies that could damage systems containing electronic protected health information. Three specifications are required: a data backup plan, a disaster recovery plan, and an emergency mode operation plan. Two more are “addressable”: testing and revision procedures, and applications and data criticality analysis. Addressable does not mean optional. You must implement each addressable specification if reasonable and appropriate, or document why an equivalent alternative measure achieves the same protection.5eCFR. 45 CFR 164.308 – Administrative Safeguards
Non-Bank Financial Institutions
The FTC Safeguards Rule covers financial institutions that fall outside another federal regulator’s oversight, such as mortgage brokers, tax preparers, auto dealers offering financing, and debt collectors. It requires a written incident response plan with clear roles and decision-making authority, internal processes for responding to security events, procedures for documenting and reporting incidents, and a post-incident review that feeds back into your security program.6Federal Trade Commission. FTC Safeguards Rule – What Your Business Needs to Know
Bulk Electric System Operators
Generator owners, transmission operators, reliability coordinators, and other operators of bulk electric system facilities must comply with NERC’s Critical Infrastructure Protection standards. CIP-008-6 requires responsible entities to maintain documented processes for identifying, classifying, and responding to cyber security incidents that could threaten reliable grid operation.7North American Electric Reliability Corporation. CIP-008-6 – Cyber Security – Incident Reporting and Response Planning
Organizations Processing EU Personal Data
Article 32 of the GDPR requires organizations processing personal data of individuals in the European Union to ensure ongoing availability and resilience of processing systems and the ability to restore access to personal data promptly after a physical or technical incident.8GDPR-Info.eu. Art. 32 GDPR – Security of Processing The regulation does not prescribe a format, but meeting the requirement in practice takes a written continuity plan.
What the Plan Must Contain
Across frameworks, a compliant plan is built out of the same core parts.
Business Impact Analysis and Recovery Targets
The starting point is a business impact analysis that identifies your critical business functions and measures the financial, operational, and reputational consequences of losing each one. The FFIEC directs management to inventory critical assets, including people, hardware, software, data, and facilities, as well as infrastructure such as network connectivity, communication lines, and utilities, including anything provided by third parties.2FFIEC IT Examination Handbook. Business Continuity Management
From that analysis you set two recovery metrics that drive the rest of the plan. The recovery time objective (RTO) defines the maximum time a system or function can remain unavailable before the impact becomes unacceptable. The recovery point objective (RPO) defines how far back in time your data recovery can reach, based on your most recent backup. A third metric, maximum tolerable downtime, marks the outer boundary beyond which the organization faces existential risk.
Risk Assessment
Where the impact analysis tells you what matters, the risk assessment tells you what could go wrong. You identify threats (natural disasters, cyberattacks, infrastructure failures, supply chain disruptions, loss of key personnel) and evaluate likelihood and severity. Documentation should explain the methodology, the assumptions, and how you prioritized among risks. Examiners look for that rationale, and a plan that identifies risks without explaining how it ranked them tends to invite more questions than it answers.
Recovery Strategies Tied to Your RTOs and RPOs
Each recovery strategy must map to a specific RTO and RPO. Technology strategies usually start with redundant data backup and offsite storage; systems with near-zero downtime requirements often need synchronized data replication to a geographically separate data center or automated failover. FINRA specifically requires plans to address backup and recovery for both hard-copy and electronic records, and to cover all mission-critical systems.1Financial Industry Regulatory Authority. FINRA Rule 4370 – Business Continuity Plans and Emergency Contact Information
Facility recovery ranges from fully equipped standby sites ready for immediate use to sites that provide only physical space. Personnel strategies must cover employee safety protocols, remote work capabilities, relocation procedures, and cross-training. A plan built around a single specialist who happens to be on vacation during a crisis is not a plan.
The Written Procedures Themselves
A compliant plan is a procedural document that people actually use when something breaks. Most frameworks require:
- Activation criteria that define what counts as a disruption serious enough to trigger the BCP, and who has the authority to declare an incident.
- A named incident management team with defined roles, responsibilities, and decision-making authority.
- Communication protocols with current contact information for employees, customers, counterparties, vendors, and regulators. FINRA requires plans to address alternate communications with both customers and employees, on the assumption that normal channels may be unavailable.1Financial Industry Regulatory Authority. FINRA Rule 4370 – Business Continuity Plans and Emergency Contact Information
- Step-by-step recovery procedures specific enough that someone unfamiliar with the process could follow them, tied to your RTOs and RPOs.
- A complete inventory of mission-critical systems and applications, including configuration details and vendor support contacts.
Third Parties and Cloud Providers Don’t Reduce Your Obligation
If your organization relies on outside providers for critical functions, your plan cannot stop at your own walls. Federal banking regulators issued interagency guidance in 2023 emphasizing that banks must assess whether their critical third parties maintain appropriate business continuity and disaster recovery plans, including specific recovery time and recovery point objectives. The guidance calls for contracts that address the third party’s responsibility for operational resilience, joint testing of business continuity plans, and provisions for transferring accounts or data to another provider in the event of the vendor’s bankruptcy or business failure.9Federal Register. Interagency Guidance on Third-Party Relationships – Risk Management FINRA Rule 4370 similarly requires that if a firm relies on another entity for any required BCP category or mission-critical system, the plan must address that relationship.1Financial Industry Regulatory Authority. FINRA Rule 4370 – Business Continuity Plans and Emergency Contact Information
Moving to the cloud does not shift your BCP obligation to the cloud provider. Under the shared responsibility model used by major providers, the vendor handles physical infrastructure security while you remain responsible for your data, including classification, protection, encryption decisions, and compliance with data governance requirements.10Microsoft Learn. Shared Responsibility in the Cloud Your plan should document which recovery tasks fall to you and which fall to the provider, tied to the provider’s service level agreements. A 99.9% uptime SLA still allows roughly nine hours of downtime per year, and your plan needs to cover those hours.
Testing, Annual Review, and Sign-Off
A plan that has never been tested is a plan that has never worked, and regulators uniformly require periodic testing. Tests can be tabletop walk-throughs, functional exercises of specific components like failover to a backup site, or full-scale simulations. Every test must be formally documented: the scenario used, what worked, what failed, and the corrective actions taken afterward. The FFIEC expects the board of directors to review both the BCP and test results at least annually, and to record that review.3Federal Financial Institutions Examination Council. Business Continuity Planning Booklet
Training is part of the compliance record. All employees should know what to do during a disruption, even if their role is simply knowing who to call and where to go. Members of the incident management team need specialized, recurring training on their specific responsibilities.
Between annual reviews, the plan must keep up with the business. FINRA Rule 4370 requires firms to update the BCP whenever a material change occurs in operations, structure, business, or location, and to conduct an annual review to determine whether modifications are needed.1Financial Industry Regulatory Authority. FINRA Rule 4370 – Business Continuity Plans and Emergency Contact Information The FFIEC similarly expects plans to be updated as business processes change.3Federal Financial Institutions Examination Council. Business Continuity Planning Booklet Common triggers for off-cycle updates include deploying new technology platforms, acquiring another company, moving offices, losing a key vendor, or changing your organizational structure.
What Non-Compliance Costs
Regulators do not treat BCP failures as paperwork technicalities.
HIPAA
Civil penalties for HIPAA violations, including failure to maintain a compliant contingency plan, follow a four-tier structure based on the organization’s level of culpability:
- Tier 1 (did not know): $100 per violation, up to $25,000 per year for identical violations.
- Tier 2 (reasonable cause): $1,000 per violation, up to $100,000 per year.
- Tier 3 (willful neglect, corrected): $10,000 per violation, up to $250,000 per year.
- Tier 4 (willful neglect, not corrected): $50,000 per violation, up to $1,500,000 per year.
These are the base statutory amounts. HHS adjusts them periodically for inflation, and a single breach involving many patients can multiply the per-violation figure rapidly.11Office of the Law Revision Counsel. 42 USC 1320d-5 – General Penalty for Failure to Comply
NERC CIP
Violations of NERC reliability standards, including the CIP incident response requirements, carry penalties that scale with the risk factor of the requirement and the severity of the violation. Daily penalties for lower-risk, lower-severity violations start around $1,000. A severe violation of a high-risk-factor requirement can reach the statutory maximum of approximately $1.3 million per violation per day.12North American Electric Reliability Corporation. Sanction Guidelines of the North American Electric Reliability Corporation
FINRA
FINRA has authority to fine member firms, suspend operations, or expel firms from membership for violations of Rule 4370. BCP failures often surface within broader compliance breakdowns rather than as standalone cases, and a public finding that a firm had no viable plan to protect customer assets can outlast any monetary fine.
FTC Safeguards Rule
The FTC can pursue enforcement actions against non-bank financial institutions that fail to maintain the required incident response plan. Remedies include consent orders requiring specific security improvements, ongoing compliance monitoring, and civil penalties for violations of those consent orders.
Across every framework, the enforcement pattern is the same. Regulators penalize not just the absence of a plan, but the absence of evidence that the plan works, and a well-documented testing and maintenance program is the strongest defense during an examination or enforcement inquiry.