ACCA Strategic Professional · Strategic Business Leader · Managing, monitoring and mitigating risk
Orchid Bank has a business continuity plan that includes an alternative data centre. Management states that the plan has been approved by the board and filed, but it has never been simulated. A regulator asks what the most significant weakness is. Which is the most appropriate answer?
The key weakness is that the plan has never been tested. Without simulations or exercises there is no assurance that the alternative data centre, staff roles and recovery times will work in a real disruption. Approval by the board does not demonstrate effectiveness.
- AThe plan should have been prepared by external consultants rather than staff
- BThe plan has not been tested, so there is no assurance that it would work in a real disruptionCorrect
- CThe plan should have been approved by shareholders rather than the board
- DThe plan should cover only IT failures, not wider operational disruption
Explanation
A continuity plan is only reliable if rehearsed through exercises or simulations, which reveal gaps, train staff and confirm recovery times. Approval and filing give no evidence of effectiveness. Who prepares it is less important than whether it works, and limiting the scope to IT would narrow it inappropriately.
Did you get it right without looking?
One question tells you little. A timed set on Managing, monitoring and mitigating risk shows your real accuracy, how long you take and where you lose marks.
More Managing, monitoring and mitigating risk questions
- Kestrel Logistics relies on one supplier for a specialised component. Following a flood at the supplier's site, deliveries stop for weeks. A…
- Dunmore Logistics' finance director states that the company's reported profits fall whenever the euro weakens, because it earns revenue in e…
- Zentra Foods, a listed manufacturer, wants its board to adopt a risk framework that links risk management to strategy-setting and performanc…
- Halden Logistics has a risk register that the board reviews annually. During the year a major supplier failed and a new cyber threat emerged…
- Hartwell Retail Ltd's risk manager notes that the ISO 31000 standard on risk management differs from a compliance checklist. Which feature o…
- Marlow Pharma plc is adopting the COSO Enterprise Risk Management framework (Integrating with Strategy and Performance). The chief executive…