Could every director explain who has authority during a major disruption?
When a major disruption hits, the board needs answers to five questions: who leads the response, what triggers board notification, which functions recover first, who speaks externally, and what record shows board oversight after the event.
NorthSeat's Business Continuity Plan gives boards, CEOs and executive teams a practical governance framework for authority, escalation, communication, recovery priorities and post-incident review.
Informed by ISO 22301, ISO 37000 and Australian governance expectations. Designed for boards that need continuity arrangements they can use, report against and review.
Real-world Triggers
Continuity gaps become visible after a specific event or external question:
- the board receives a BCP update but has no evidence of a recent scenario exercise
- the CEO is unclear which disruptions require immediate board notification
- a cloud, IT, payroll, office or supplier outage affects a critical function
- the organisation has a Cyber Incident Response Plan and a BCP, with no agreed rule for which plan governs authority, timing and communication
- minutes show the BCP was "reviewed," with little record of testing, gaps, vendor reliance or corrective action
- a new Chair, CEO, CFO, auditor, insurer, lender or buyer asks how continuity decisions are made
Many organisations can point to a BCP. The board-level test is whether directors and executives can use it when decisions are being made.
What This Solves
Continuity governance becomes unclear when the board and management apply different assumptions to the same disruption.
The practical problems are:
- no clear distinction between CEO-led response and board oversight
- unclear triggers for board notification, external communication and legal review
- weak prioritisation of critical functions, recovery time objectives and maximum acceptable outages
- directors receiving operational detail instead of decision-relevant information
- reliance on vendors, insurers and cloud platforms without visible continuity evidence
- post-incident reviews relying on management's summary, with no clear record of actions, gaps and follow-up
The Business Continuity Plan makes authority, escalation, communication, recovery priorities and board reporting explicit, so executives can act and directors can oversee at the right level.
A note on cyber
The CIRP deals with technical and incident response. The BCP deals with continuity governance, recovery priorities, authority, communication and board reporting. Each plan governs a different decision set.
Comparison
| Feature / Domain | |||
|---|---|---|---|
| Behavioural governance | |||
| Continuity governance | |||
| Board and executive roles | |||
| Cyber-continuity connection | |||
| Crisis escalation | |||
| Board record quality | |||
| Designed for | Identifying gaps | A credible board-ready baseline | Boards detailed authority, escalation, communication, recovery priorities, board reporting and post-incident review. |
What Version Does Your Board Need?
| Situation | Recommended Tier |
|---|---|
| We want to see whether our continuity governance has gaps | Board Readiness Diagnostic |
| We want to start a conversation about continuity governance | Essential Snapshot |
| Our BCP is outdated or inconsistent. We need a credible, board-ready structure we can implement efficiently. | Foundation Edition |
| We need detailed authority, escalation, communication, recovery priorities, board reporting and post-incident review. | Governance edition |
| For organisations operating under the highest levels of accountability. | Institutional Edition |
How to Engage With NorthSeat
Step 1 - Assess Your Governance
Board Readiness Diagnostic – $649 ex GST
Pressure test your BCP.
Download the Essential Snapshot
Free download. The most common tension points.
Step 2 - Choose Your Framework
Foundation Edition - $4,950 ex GST
Board-ready policy, structured for efficient adoption.
Governance Edition -$21,800 ex GST
A detailed BCP for organisations needing defined authority, escalation, communication, recovery priorities, board reporting and post-incident review.
Institutional Edition – Contact Us
Built for the most complex boards.