Feature Business Continuity
Business Continuity Workaround Strategies: Document the Manual Process Before the System Goes Down
A BCP without documented manual workaround procedures isn't a continuity plan — it's a recovery plan. Here's the workaround template fields and critical-function structure FFIEC examiners expect to see.
Table of Contents
TL;DR
- A BCP that identifies critical functions without documented workaround procedures isn’t ready for a real outage — it just tells you what will break.
- Workaround procedures need specific operational content: manual processing steps, volume limits, staffing minimums, data capture method, reconciliation procedure, backlog recovery order, and unsafe-stop criteria.
- The FFIEC BCM framework shifted from recovery-focused to resilience-focused — institutions now need to sustain operations through extended disruptions, not just recover from brief ones.
- Workaround procedures that exist only in a document and have never been tested are unreliable. Functional exercises — not tabletops — are what validate them.
Three weeks after an extended core banking outage at a mid-size community bank, the examiner’s key finding wasn’t that the system failed. It was that the bank had a business continuity plan that identified payment processing as critical — but no documented procedure for processing payments manually while the core was down. Staff improvised. Records were captured inconsistently. Reconciliation took weeks. The finding wasn’t about the outage. It was about the absence of operational preparation for it.
This is the gap in most BCP programs: they identify what’s critical but don’t specify what to do manually when the system supporting that critical function stops working. The BCP template and the BIA methodology are the foundation. The workaround procedure is the operational layer that makes the plan executable when something actually goes wrong.
What a Workaround Strategy Is — and Isn’t
A workaround strategy is a documented, tested procedure that allows a critical business function to continue operating when the system that normally supports it is unavailable.
This is different from:
- A recovery procedure — which focuses on restoring the failed system or component
- A backup system — which is a technical alternative, not a manual procedure
- A BCP plan — which identifies critical functions and recovery priorities but typically doesn’t specify the step-by-step manual process
The recovery plan answers: how do we restore the system? The workaround procedure answers: what do we actually do in the meantime?
For most regulated financial institutions, both are required. The FFIEC BCM booklet — updated in 2021 with an explicit shift toward operational resilience — specifically expects institutions to document alternate processes and workarounds for critical functions. Examiners now check for both the recovery strategy and the workaround procedure as separate items.
The Shift to Resilience: Weeks, Not Hours
The most significant change in the FFIEC’s 2021 BCM booklet update was the shift from a recovery orientation to a resilience orientation. The older BCM framework assumed most disruptions would be hours to a day or two — long enough to require a documented BCP but short enough that manual processing was a brief bridge to system recovery.
Current examination expectations reflect real-world disruption patterns. The July 2024 CrowdStrike outage affected 8.5 million Windows devices globally; some affected institutions took days to restore full operations. Extended power outages from severe weather have forced banks to operate manually for a week or more. Ransomware events have kept core banking systems offline for two to four weeks at community institutions.
The practical implication: workaround procedures should be designed to sustain operations for the full maximum tolerable downtime (MTD) identified in the BIA for that function. For most critical banking functions, that’s 24–72 hours. For settlement and payment functions, it may be 4 hours or less.
If your manual workaround procedure can only sustain operations for 4 hours but your MTD is 48 hours, the procedure isn’t adequate. Staff will improvise beyond the 4-hour mark — inconsistently, without documented authority, and without a reconciliation plan.
The Workaround Procedure Template
A complete workaround procedure is a function-specific document — not a generic section of the BCP. One workaround procedure per critical function identified in the BIA.
Required fields:
| Field | What It Specifies |
|---|---|
| Function name | ”Wire transfer processing,” “ACH origination,” “Customer account access,” etc. |
| Triggering conditions | What specific events activate this workaround (system unavailable >X hours; total outage; partial degradation affecting Y) |
| Maximum manual processing capacity | Transaction volume or dollar limit the manual process can handle per shift |
| Minimum staffing requirement | Minimum number of trained staff needed to execute; backup staffing list |
| Approval authority | Who activates and who deactivates the workaround; escalation path |
| Step-by-step manual instructions | Numbered steps for the actual manual process |
| Data capture method | How transactions are recorded manually (paper log, specific Excel template, manual ledger) |
| Reconciliation procedure | How manual records are reconciled back to the system when it recovers |
| Backlog recovery order | Priority sequence for clearing manual backlog |
| Unsafe-stop criteria | Conditions under which manual processing must stop |
| Training record reference | Where staff training documentation is maintained |
| Last tested date | Date and type of test; outcome |
The “step-by-step manual instructions” field is the one most procedures skip. A workaround document that says “process transactions manually” isn’t a procedure — it’s a label. Staff need to know the specific steps: which systems to use or avoid, where to get authorization, what form to complete, how to sequence multi-step transactions, what approvals to obtain.
The Three Critical Fields Most Procedures Miss
1. Maximum manual processing capacity
Every manual procedure has a throughput ceiling. A loan servicing team that handles 500 payment postings per day in the system might only be able to handle 50 manually without errors accumulating. A wire desk that processes 200 wires per day might be able to safely process 30 manually with the documentation requirements of a manual wire.
Document the ceiling explicitly. When volume exceeds it, the procedure needs to specify what happens: queue and batch, prioritize by transaction type, escalate to management, or invoke the unsafe-stop criterion.
2. Data capture and reconciliation method
How you capture data manually determines whether you can reconcile when systems restore. “We’ll write it down” is not adequate. The procedure needs to specify: which template or form is used (attach it to the procedure document), what fields are required, how documents are numbered or labeled for sequencing, and where physical documents are stored.
The reconciliation procedure specifies: in what order are manual records entered when the system restores, who performs the entry, who performs independent verification, what constitutes a reconciliation exception, and how exceptions are resolved.
3. Unsafe-stop criteria
This is the field most procedures omit — and it’s the most important one.
An unsafe-stop criterion is a predefined condition under which manual processing must stop, even if the disruption is ongoing. Examples:
- Manual wire processing stops when cumulative unresolved reconciliation variances exceed $50,000
- Manual ACH origination stops when same-day ACH cut-off passes and deferred processing would miss settlement windows
- Manual SAR intake stops when the staffing ratio drops below one trained BSA officer per 30 manual intake forms per shift
- Manual loan payment posting stops when three consecutive verification failures occur
Without unsafe-stop criteria, staff continue processing past the point where errors are unrecoverable. The manual backlog becomes unreconcilable. The compliance documentation becomes incomplete. The problem you were trying to avoid by running manually — service interruption — gets replaced by a worse problem: incorrect records that take weeks to unwind.
Testing: Why Functional Exercises Are Required
A workaround procedure that has never been tested is a hypothesis, not a procedure. The FFIEC BCM examination procedures ask specifically whether management tests continuity strategies — including alternate processes.
Tabletop exercises test decisions — who activates the workaround, when, and how. They don’t test whether the workaround steps actually work.
Functional exercises test the process — staff actually execute the manual steps for a representative sample of transactions. A functional exercise for a payment processing workaround should:
- Give staff a set of test transactions and the workaround procedure document
- Have them execute the manual steps as documented
- Measure throughput (how many transactions per hour), error rate, and whether data capture was adequate
- Simulate system restoration and run the reconciliation procedure against the manually captured records
- Document what broke, what was slower than expected, and what the procedure needs to fix
Most institutions exercise BCPs with tabletop exercises. The BCP testing frequency and documentation requirements post covers the regulatory expectations for testing cadence. Workaround procedures for critical functions should be functionally tested at least annually.
What Examiners Specifically Ask For
The FFIEC BCM Section III.B risk assessment identifies continuity strategies — including workarounds — as a required BCM output. In practice, examiners reviewing workaround procedures ask:
- “Show me the workaround procedure for your three most critical functions.” — They want the actual documents, not the BCP narrative.
- “What’s the volume capacity of your manual process?” — They expect a number, not “we’d do our best.”
- “When did you last test this?” — Test date and type (functional vs. tabletop) should be documented.
- “What happens when volume exceeds your manual capacity?” — The escalation path and unsafe-stop criteria.
- “How do you reconcile manual records when systems come back?” — The reconciliation procedure, specifically.
If any of these questions produce “we haven’t documented that” or “we’d figure it out at the time,” that’s an exam finding in progress.
Common Gaps
Critical functions identified in the BIA without corresponding workaround procedures. The BIA says payment processing is critical. The BCP says the strategy is manual processing. There’s no document specifying what that looks like. This gap is common and consistently cited.
Workaround procedures that rely on systems that are also unavailable during the triggering event. A workaround for core banking outage that requires a shared network drive, a VPN, or a secondary system also affected by the same outage is not a workaround.
Staff who don’t know the workaround procedure exists. Training is a required component. A procedure that only the BCP coordinator has read isn’t executable.
Procedures that haven’t been tested in more than two years. Staff turnover, system changes, and volume growth mean procedures that worked two years ago may not work today. Annual functional testing catches this before an actual event does.
So What?
RTO and RPO targets define when you need to be back up and how much data loss is acceptable. Workaround procedures define what happens in the gap — the operational reality between “the system is down” and “the system is restored.”
If your BCP has identified critical functions and recovery time objectives but hasn’t documented the specific manual procedures that sustain those functions during recovery, the plan is incomplete by the FFIEC’s current standards. Not conceptually — operationally.
The work is function-specific documentation with real operational content: the steps, the staffing, the data capture, the reconciliation, and the unsafe-stop criteria. It’s not narrative — it’s procedure.
The Business Continuity & Disaster Recovery (BCP/DR) Kit includes a FFIEC BCM-aligned BIA template, recovery procedure documentation, and a tabletop exercise kit. The workaround procedure template is the operational layer that makes BCP documentation executable when a real disruption happens.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What is a business continuity workaround strategy?
How long do manual workaround procedures need to sustain operations?
What are the required components of a workaround procedure document?
What does an FFIEC examiner ask for during a BCM examination related to workarounds?
How do you test a manual workaround procedure?
What is an 'unsafe-stop criterion' and why does the workaround procedure need one?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
DORA's 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks
DORA's ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.
Jul 29, 2026
Business Continuity
Personnel Continuity Under FFIEC BCM: Succession Is Not a List of Phone Numbers
Build FFIEC business continuity management personnel coverage with tested backups, delegated authority, usable procedures, and recovery evidence.
Jul 26, 2026
Business Continuity
FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies
Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.
Jul 24, 2026