Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Business Continuity

Hurricane Season BCP Testing: What FFIEC Examiners Expect Financial Institutions to Document Before October

Atlantic hurricane season peaks in August–October. Most financial institution BCP programs won't survive an FFIEC examination if they haven't run a geographic threat scenario this year. Here's what examiners look for, what documentation you need, and the exercise vs. test distinction that keeps programs from getting credit for work they actually did.

By Rebecca Leung · July 9, 2026 ·
Table of Contents

Atlantic hurricane season officially started June 1. We are now five weeks in, with peak season—statistically, August through October—ten to fourteen weeks away. If your financial institution hasn’t run a geographic threat BCP scenario this year, you have a narrow window to do it, document it, and close findings before an examiner asks when you last tested your response to a regional disruption.

Most programs won’t survive that question with a straight answer.

TL;DR

  • Atlantic hurricane peak season runs August–October — institutions in coastal or flood-prone regions need geographic scenario testing completed now, not in November
  • The FFIEC BCM Booklet requires testing that reflects the institution’s actual risk profile — geographic concentration is a documented expectation, not an optional module
  • Examiners distinguish between exercises (tabletops) and tests (execution-based) — calling a tabletop a “test” creates a finding
  • Documentation gaps — no remediation tracking, no prior-year gap closure, third-party vendors not included in scenarios — are the most common BCP examination findings
  • If you’re running the scenario in August, plan the test plan now so you’re not approving it the same week you’re running it

What the FFIEC BCM Booklet Actually Requires

The FFIEC Business Continuity Management Booklet is the primary examination reference for bank and credit union BCP programs. It was updated in 2019 and remains the framework examiners use when assessing program maturity.

The Booklet structures BCP around a lifecycle: business impact analysis, risk assessment, strategy development, testing, and maintenance. Each phase creates documentation requirements. The testing section is where geographic risk scenarios specifically matter.

The FFIEC expects testing to be:

  • Risk-based: scenarios should reflect the institution’s actual geographic risk profile, not a generic list of disaster scenarios that could apply to any institution in any location
  • Comprehensive over time: no single test covers everything, but the multi-year testing cycle should exercise the full range of the institution’s critical functions and risk exposures
  • Validated against recovery objectives: tests should verify whether recovery time objectives (RTOs) and recovery point objectives (RPOs) are actually achievable, not just assumed
  • Documented with results and remediation: results should be reported to management and the board, with identified gaps tracked to closure

What this means for a community bank in Louisiana, a credit union with branches throughout coastal Georgia, or a fintech with operations concentrations in Florida: your testing cycle must include scenarios where those geographic exposures are the disruption vector. An examiner reviewing your program will check whether your BIA identifies geographic concentration risk, and whether your testing addresses it.

Generic tabletop scenarios built around “data center outage” or “ransomware attack” don’t satisfy this. They’re good tests. They’re not your hurricane scenario.

The Exercise vs. Test Distinction Most Programs Get Wrong

This is the single most common documentation error in BCP programs — and one of the easiest ways to generate an examination finding you didn’t earn.

The FFIEC BCM Booklet distinguishes between exercises (discussion-based) and tests (execution-based). They are not interchangeable, and examiners know the difference.

An exercise is a tabletop, a walkthrough, a facilitated scenario discussion. Participants sit in a room or a Zoom call and work through what they would do if a Category 3 hurricane made landfall and closed five branches, knocked out power to the operations center, and forced staff evacuation for 72 hours. The discussion surfaces gaps, tests institutional knowledge, and builds team readiness. It’s valuable and examiners expect to see it.

A test is execution-based. Systems are actually failed over to backup infrastructure. Staff actually access the alternate site. Communication trees are actually called. RTOs are actually timed. The alternate site actually processes transactions. The test generates data—did recovery meet the RTO? What broke in execution that didn’t break in the tabletop?

A program that has run two tabletops this year and calls them “tests” on the board report will have that terminology corrected in an exam. The finding is usually categorized as a documentation or program adequacy issue, not a material weakness — but it reflects on program maturity, and examiners tend to dig deeper when they find inconsistency between what a program claims to have done and what it actually did.

If you’re reporting to your board, use the right terms. “Q1 tabletop exercise — geographic threat scenario, hurricane” and “Q3 alternate site test — IT systems failover” are not the same thing. Document them as what they are.

What Examiner-Facing Documentation Must Show

Running the scenario is half the job. The documentation is where programs fall apart.

The FFIEC BCM examination procedures specify what examiners will request. When your primary regulator — OCC, FDIC, Federal Reserve, or NCUA — schedules an examination, they will typically request:

Test plans approved before the activity occurred. Not drafted after. Not reconstructed. A test plan that’s dated a week before the activity with documented objectives, scope, participants, and expected outcomes. This is evidence the testing was designed, not improvised.

Attendance records or participation documentation. For tabletop exercises, this means the participants were actually from the right business lines. A hurricane scenario for an institution with concentrated coastal operations should include branch management, facilities, IT, operations, and communications — not just compliance.

Test results against stated objectives. The results document should show what was tested, what happened, and whether the result met the objective. If the RTO for the operations center was 4 hours and actual failover took 6 hours — that’s a finding in the test results, not an embarrassment to hide.

A gap log with owners and target dates. Every gap identified during testing needs a documented owner, a target remediation date, and status. Examiners look at this log and cross-reference it with the prior year’s gaps. If the same gap appears in 2024 results and 2025 results with no evidence of action, that’s a pattern finding. The remediation tracking piece is what separates a mature program from a paper program.

Evidence of management and board reporting. The results need to have gone somewhere — typically management review and annual board reporting. An untouched after-action report in a SharePoint folder doesn’t satisfy this. A board presentation slide deck showing the testing results and approved remediation plan does.

The BIA Gap: Geographic Concentration in Your Critical Functions

Before you run the scenario, make sure your business impact analysis actually supports it.

A common BCP gap in hurricane season preparation is a BIA that references geographic risk in general terms without specifically mapping critical business functions to geographic concentration. “Our branches are in the Gulf Coast region” is not the same as a BIA that identifies which branches handle what percentage of transaction volume, which back-office functions are co-located with which operational facilities, and what the recovery strategy is if those facilities are inaccessible for 5, 10, or 30 days.

The FFIEC’s post-Katrina examination guidance — which remains informative even two decades later — emphasized that financial institutions needed to evaluate the geographic scope of disasters differently from single-site disruptions. A hurricane doesn’t take down one facility. It takes down a region. Staff can’t commute to the alternate site if roads are flooded. Third-party vendors in the same region face the same disruption. Power restoration timelines are measured in weeks, not hours.

For the power and telecom resilience analysis your BIA needs to account for, hurricane scenarios introduce a specific complication: extended grid outages that stretch well beyond typical generator fuel reserves, cellular network saturation, and loss of internet infrastructure in the affected region.

Your BIA hurricane scenario should specify:

  • Which critical functions have geographic concentration in the at-risk area
  • Which third-party vendors are in the same geographic zone
  • Whether your alternate site or recovery infrastructure is outside the probable impact area
  • What the extended timeline looks like — not just 24 or 48 hours, but what a 7-day, 14-day, and 30-day disruption does to each function

If your BIA doesn’t answer those questions, your hurricane scenario test will uncover gaps you should have caught at the BIA stage.

What Your Testing Cycle Should Look Like Before October

If you’re planning to run a geographic threat scenario before peak hurricane season, the planning needs to start now. The testing calendar for a well-run program looks like this:

July (now): Develop the test plan. Identify the scenario, the scope, and the participants. Get the test plan approved by management. If you’re doing a tabletop, schedule the facilitator and block 3–4 hours for participants. If you’re doing an execution-based test — alternate site activation, IT failover — coordinate with IT, operations, and facilities now. Execution tests have logistics that can’t be arranged in a week.

Late July / Early August: Run the scenario. A tabletop hurricane scenario for a community bank should walk through the 72-hour activation timeline: storm landfall, damage assessment, branch closure decisions, alternate site activation, staff communication, regulatory notifications, and customer communication. Push participants to the decision points that are actually hard: when do you declare a disaster? Who has that authority? What if the CEO is unreachable? What if the alternate site isn’t available because it’s in the same storm path?

August: Document results. Write the after-action report while the scenario is fresh. Capture every gap identified, every assumption that didn’t hold, every process that worked better than expected. Don’t clean it up — the gaps are the value.

August–September: Open the remediation log. Assign owners and dates. Start closing the quick fixes. For items that require longer-term remediation — new vendor contracts, alternate site upgrades, infrastructure changes — put them on the record with realistic timelines and document that they’ve been escalated to the appropriate level.

The FFIEC BCM Booklet update analysis covers the program lifecycle structure in detail — the testing cycle sits within a broader annual program maintenance requirement that also drives mid-year BIA reviews and board reporting.

So What?

Hurricane season is already running. The Atlantic peak runs August through October. Financial institutions that complete geographic threat scenario testing in July or early August have a real window to identify and remediate gaps before the risk is highest. Institutions that run the scenario in November because “we got to it” have satisfied an annual calendar requirement with no operational value.

FFIEC examiners understand this. When they ask about your testing program, they will ask when in the year you ran it, what it covered, what you found, and what you did about it. A test run in July with documented remediation shows a program designed to manage risk. A test run in December with no remediation shows a program designed to check a box.

The documentation also matters. Use the right terms — exercise vs. test. Get management sign-off on the test plan before the activity. Write the after-action report with actual gaps, not a summary that everything went fine. Track remediation with owners and dates, and close the loop before next year’s examination.

For teams building out or stress-testing their BCP documentation before peak season, the Business Continuity & Disaster Recovery Kit includes tabletop exercise facilitation guides, after-action report templates, and a remediation tracking framework aligned to FFIEC examination expectations. Everything in one place, designed for the documentation standards that actually matter when the examiner asks.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What does the FFIEC BCM Booklet require for hurricane season or geographic threat testing?
The FFIEC Business Continuity Management (BCM) Booklet requires financial institutions to conduct testing that covers a range of disruptive scenarios, including those that reflect the institution's geographic risk profile. For institutions in hurricane-prone regions—or those with operational concentrations in coastal areas—this means geographic threat scenarios must be included in the annual testing cycle. Examiners look for a business impact analysis that identifies geographic concentrations, testing that exercises those specific vulnerabilities, documented results with identified gaps, and a remediation tracking process showing gaps are actually being closed.
What is the difference between a BCP exercise and a BCP test, and why does it matter for examiners?
The FFIEC BCM Booklet distinguishes between exercises and tests. An exercise is a discussion-based activity—tabletop scenarios, facilitated walkthroughs—where participants talk through how they would respond. A test is an execution-based activity where procedures are actually activated: alternate sites are physically accessed, systems are recovered to backup infrastructure, communication trees are called. Both serve different purposes, and examiners expect to see both in a mature program. A program that has only done tabletops gets credit for exercises, not tests. Calling a tabletop a 'test' creates an examination finding when examiners review the documentation.
What documentation do FFIEC examiners want to see from BCP testing?
Examiners typically want: a test plan approved before the exercise or test occurred, attendance records or participant lists, test results showing what was tested against what objective, a list of gaps or deficiencies identified, a remediation log tracking those gaps to closure with responsible owners and target dates, and evidence that findings were reported to management or the board. After-action reports that list gaps but have no follow-through are a common finding. The remediation tracking piece—showing that prior year findings were actually addressed—is what separates a mature program from a paper program.
When should financial institutions run hurricane scenario testing to satisfy FFIEC expectations?
Testing should be completed while there is still time to remediate findings before peak season. The Atlantic hurricane peak runs August through October. Institutions that complete geographic scenario testing in July or early August can identify gaps, prioritize fixes, and document remediation before the highest-risk period. Testing done in November after peak season has passed provides less value from an operational resilience standpoint. Examiners don't set a specific calendar mandate, but they will ask when in the year testing occurred and whether it was positioned to be useful—not just to satisfy the annual requirement.
What geographic concentration risks does the FFIEC expect to see in a business impact analysis?
The FFIEC BCM Booklet requires institutions to assess the impact of scenarios that disrupt physical locations, utilities, and communications across specific geographic areas—not just individual systems. This means the BIA should identify which critical business functions have geographic concentration risk: branches, data centers, operations centers, and third-party vendor facilities concentrated in a single region. The BIA should also address the institution's exposure to extended power outages, road closures, staff evacuation, and vendor disruption in the affected region—all documented failure modes from prior hurricane events.
What are the most common BCP examination findings related to hurricane or geographic threat scenarios?
Common findings include: business impact analyses that identify geographic risk conceptually but don't map specific functions or facilities to specific threat scenarios; test documentation that reflects tabletop exercises but calls them 'tests'; after-action reports with no remediation tracking or ownership; critical third-party vendors not included in recovery scenario assumptions; and recovery time objectives that were never actually validated against alternate site or infrastructure capability. The pattern across these findings is that documentation exists but doesn't demonstrate operational rigor—the program looks complete on paper but hasn't been stress-tested against realistic scenarios.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Business Continuity & Disaster Recovery (BCP/DR) Kit

BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.