Feature Business Continuity
Hurricane Season BCP Testing: What FFIEC Examiners Expect Financial Institutions to Document Before October
Atlantic hurricane season peaks in August–October. Most financial institution BCP programs won't survive an FFIEC examination if they haven't run a geographic threat scenario this year. Here's what examiners look for, what documentation you need, and the exercise vs. test distinction that keeps programs from getting credit for work they actually did.
Table of Contents
Atlantic hurricane season officially started June 1. We are now five weeks in, with peak season—statistically, August through October—ten to fourteen weeks away. If your financial institution hasn’t run a geographic threat BCP scenario this year, you have a narrow window to do it, document it, and close findings before an examiner asks when you last tested your response to a regional disruption.
Most programs won’t survive that question with a straight answer.
TL;DR
- Atlantic hurricane peak season runs August–October — institutions in coastal or flood-prone regions need geographic scenario testing completed now, not in November
- The FFIEC BCM Booklet requires testing that reflects the institution’s actual risk profile — geographic concentration is a documented expectation, not an optional module
- Examiners distinguish between exercises (tabletops) and tests (execution-based) — calling a tabletop a “test” creates a finding
- Documentation gaps — no remediation tracking, no prior-year gap closure, third-party vendors not included in scenarios — are the most common BCP examination findings
- If you’re running the scenario in August, plan the test plan now so you’re not approving it the same week you’re running it
What the FFIEC BCM Booklet Actually Requires
The FFIEC Business Continuity Management Booklet is the primary examination reference for bank and credit union BCP programs. It was updated in 2019 and remains the framework examiners use when assessing program maturity.
The Booklet structures BCP around a lifecycle: business impact analysis, risk assessment, strategy development, testing, and maintenance. Each phase creates documentation requirements. The testing section is where geographic risk scenarios specifically matter.
The FFIEC expects testing to be:
- Risk-based: scenarios should reflect the institution’s actual geographic risk profile, not a generic list of disaster scenarios that could apply to any institution in any location
- Comprehensive over time: no single test covers everything, but the multi-year testing cycle should exercise the full range of the institution’s critical functions and risk exposures
- Validated against recovery objectives: tests should verify whether recovery time objectives (RTOs) and recovery point objectives (RPOs) are actually achievable, not just assumed
- Documented with results and remediation: results should be reported to management and the board, with identified gaps tracked to closure
What this means for a community bank in Louisiana, a credit union with branches throughout coastal Georgia, or a fintech with operations concentrations in Florida: your testing cycle must include scenarios where those geographic exposures are the disruption vector. An examiner reviewing your program will check whether your BIA identifies geographic concentration risk, and whether your testing addresses it.
Generic tabletop scenarios built around “data center outage” or “ransomware attack” don’t satisfy this. They’re good tests. They’re not your hurricane scenario.
The Exercise vs. Test Distinction Most Programs Get Wrong
This is the single most common documentation error in BCP programs — and one of the easiest ways to generate an examination finding you didn’t earn.
The FFIEC BCM Booklet distinguishes between exercises (discussion-based) and tests (execution-based). They are not interchangeable, and examiners know the difference.
An exercise is a tabletop, a walkthrough, a facilitated scenario discussion. Participants sit in a room or a Zoom call and work through what they would do if a Category 3 hurricane made landfall and closed five branches, knocked out power to the operations center, and forced staff evacuation for 72 hours. The discussion surfaces gaps, tests institutional knowledge, and builds team readiness. It’s valuable and examiners expect to see it.
A test is execution-based. Systems are actually failed over to backup infrastructure. Staff actually access the alternate site. Communication trees are actually called. RTOs are actually timed. The alternate site actually processes transactions. The test generates data—did recovery meet the RTO? What broke in execution that didn’t break in the tabletop?
A program that has run two tabletops this year and calls them “tests” on the board report will have that terminology corrected in an exam. The finding is usually categorized as a documentation or program adequacy issue, not a material weakness — but it reflects on program maturity, and examiners tend to dig deeper when they find inconsistency between what a program claims to have done and what it actually did.
If you’re reporting to your board, use the right terms. “Q1 tabletop exercise — geographic threat scenario, hurricane” and “Q3 alternate site test — IT systems failover” are not the same thing. Document them as what they are.
What Examiner-Facing Documentation Must Show
Running the scenario is half the job. The documentation is where programs fall apart.
The FFIEC BCM examination procedures specify what examiners will request. When your primary regulator — OCC, FDIC, Federal Reserve, or NCUA — schedules an examination, they will typically request:
Test plans approved before the activity occurred. Not drafted after. Not reconstructed. A test plan that’s dated a week before the activity with documented objectives, scope, participants, and expected outcomes. This is evidence the testing was designed, not improvised.
Attendance records or participation documentation. For tabletop exercises, this means the participants were actually from the right business lines. A hurricane scenario for an institution with concentrated coastal operations should include branch management, facilities, IT, operations, and communications — not just compliance.
Test results against stated objectives. The results document should show what was tested, what happened, and whether the result met the objective. If the RTO for the operations center was 4 hours and actual failover took 6 hours — that’s a finding in the test results, not an embarrassment to hide.
A gap log with owners and target dates. Every gap identified during testing needs a documented owner, a target remediation date, and status. Examiners look at this log and cross-reference it with the prior year’s gaps. If the same gap appears in 2024 results and 2025 results with no evidence of action, that’s a pattern finding. The remediation tracking piece is what separates a mature program from a paper program.
Evidence of management and board reporting. The results need to have gone somewhere — typically management review and annual board reporting. An untouched after-action report in a SharePoint folder doesn’t satisfy this. A board presentation slide deck showing the testing results and approved remediation plan does.
The BIA Gap: Geographic Concentration in Your Critical Functions
Before you run the scenario, make sure your business impact analysis actually supports it.
A common BCP gap in hurricane season preparation is a BIA that references geographic risk in general terms without specifically mapping critical business functions to geographic concentration. “Our branches are in the Gulf Coast region” is not the same as a BIA that identifies which branches handle what percentage of transaction volume, which back-office functions are co-located with which operational facilities, and what the recovery strategy is if those facilities are inaccessible for 5, 10, or 30 days.
The FFIEC’s post-Katrina examination guidance — which remains informative even two decades later — emphasized that financial institutions needed to evaluate the geographic scope of disasters differently from single-site disruptions. A hurricane doesn’t take down one facility. It takes down a region. Staff can’t commute to the alternate site if roads are flooded. Third-party vendors in the same region face the same disruption. Power restoration timelines are measured in weeks, not hours.
For the power and telecom resilience analysis your BIA needs to account for, hurricane scenarios introduce a specific complication: extended grid outages that stretch well beyond typical generator fuel reserves, cellular network saturation, and loss of internet infrastructure in the affected region.
Your BIA hurricane scenario should specify:
- Which critical functions have geographic concentration in the at-risk area
- Which third-party vendors are in the same geographic zone
- Whether your alternate site or recovery infrastructure is outside the probable impact area
- What the extended timeline looks like — not just 24 or 48 hours, but what a 7-day, 14-day, and 30-day disruption does to each function
If your BIA doesn’t answer those questions, your hurricane scenario test will uncover gaps you should have caught at the BIA stage.
What Your Testing Cycle Should Look Like Before October
If you’re planning to run a geographic threat scenario before peak hurricane season, the planning needs to start now. The testing calendar for a well-run program looks like this:
July (now): Develop the test plan. Identify the scenario, the scope, and the participants. Get the test plan approved by management. If you’re doing a tabletop, schedule the facilitator and block 3–4 hours for participants. If you’re doing an execution-based test — alternate site activation, IT failover — coordinate with IT, operations, and facilities now. Execution tests have logistics that can’t be arranged in a week.
Late July / Early August: Run the scenario. A tabletop hurricane scenario for a community bank should walk through the 72-hour activation timeline: storm landfall, damage assessment, branch closure decisions, alternate site activation, staff communication, regulatory notifications, and customer communication. Push participants to the decision points that are actually hard: when do you declare a disaster? Who has that authority? What if the CEO is unreachable? What if the alternate site isn’t available because it’s in the same storm path?
August: Document results. Write the after-action report while the scenario is fresh. Capture every gap identified, every assumption that didn’t hold, every process that worked better than expected. Don’t clean it up — the gaps are the value.
August–September: Open the remediation log. Assign owners and dates. Start closing the quick fixes. For items that require longer-term remediation — new vendor contracts, alternate site upgrades, infrastructure changes — put them on the record with realistic timelines and document that they’ve been escalated to the appropriate level.
The FFIEC BCM Booklet update analysis covers the program lifecycle structure in detail — the testing cycle sits within a broader annual program maintenance requirement that also drives mid-year BIA reviews and board reporting.
So What?
Hurricane season is already running. The Atlantic peak runs August through October. Financial institutions that complete geographic threat scenario testing in July or early August have a real window to identify and remediate gaps before the risk is highest. Institutions that run the scenario in November because “we got to it” have satisfied an annual calendar requirement with no operational value.
FFIEC examiners understand this. When they ask about your testing program, they will ask when in the year you ran it, what it covered, what you found, and what you did about it. A test run in July with documented remediation shows a program designed to manage risk. A test run in December with no remediation shows a program designed to check a box.
The documentation also matters. Use the right terms — exercise vs. test. Get management sign-off on the test plan before the activity. Write the after-action report with actual gaps, not a summary that everything went fine. Track remediation with owners and dates, and close the loop before next year’s examination.
For teams building out or stress-testing their BCP documentation before peak season, the Business Continuity & Disaster Recovery Kit includes tabletop exercise facilitation guides, after-action report templates, and a remediation tracking framework aligned to FFIEC examination expectations. Everything in one place, designed for the documentation standards that actually matter when the examiner asks.
Sources:
- FFIEC Business Continuity Management Booklet — IT Examination Handbook
- Lessons Learned from Hurricane Katrina: Preparing Your Institution for a Catastrophic Event — FFIEC
- FFIEC Supervisory Insights: Business Continuity Planning for Pandemics and Natural Disasters — FDIC
- Business Continuity Testing and Exercises — AlertMedia
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does the FFIEC BCM Booklet require for hurricane season or geographic threat testing?
What is the difference between a BCP exercise and a BCP test, and why does it matter for examiners?
What documentation do FFIEC examiners want to see from BCP testing?
When should financial institutions run hurricane scenario testing to satisfy FFIEC expectations?
What geographic concentration risks does the FFIEC expect to see in a business impact analysis?
What are the most common BCP examination findings related to hurricane or geographic threat scenarios?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies
Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.
Jul 24, 2026
Business Continuity
BCP Testing That Actually Satisfies Examiners: What FFIEC Requires Beyond Your Annual Tabletop
An annual tabletop that never fails anything is not a BCP test — it's theater. Here's what the FFIEC Business Continuity Management booklet actually requires, how 2026 examiners evaluate test programs, and what documentation makes your tests defensible.
Jul 20, 2026
Business Continuity
The October 2025 AWS Outage Was a BCP Exam That Most Fintechs Didn't Know They Were Taking
A 15-hour AWS outage in October 2025 locked customers out of financial accounts and froze transactions across 1,000+ companies — and exposed how few fintechs had actually stress-tested their cloud concentration risk. Here's what the FFIEC BCM handbook requires, what the OCC's 2026 report found, and what your BCP needs to say about single-provider dependency.
Jul 17, 2026