Feature Business Continuity
Personnel Continuity Under FFIEC BCM: Succession Is Not a List of Phone Numbers
Build FFIEC business continuity management personnel coverage with tested backups, delegated authority, usable procedures, and recovery evidence.
Table of Contents
TL;DR
- FFIEC business continuity management personnel coverage is an operating capability, not a phone tree: the alternate needs authority, access, instructions, and enough practiced skill to perform the critical activity.
- Build a coverage matrix at the process and task level. “Operations has a backup” hides the exact steps where one employee, token, approval limit, or undocumented workaround can stop recovery.
- Test with the primary person unavailable. Capture a transaction, system log, timed checklist, exception, and sign-off—not an attendance sheet.
A backup employee whose name appears in the business continuity plan but who cannot release a wire, retrieve the procedure, or authenticate from the alternate location is not a backup. That is a contact record wearing a continuity label.
The FFIEC business continuity management personnel question is practical: can the institution continue critical financial products and services when the people who normally run them are unavailable? The OCC’s November 14, 2019 bulletin introducing the revised Business Continuity Management booklet says BCM should take an enterprise-wide, process-oriented approach spanning technology, business operations, testing, and communications. It also names training and awareness, exercises and tests, maintenance, and board reporting as core program components (OCC Bulletin 2019-57).
That standard is much bigger than “Jane backs up Alex.” The useful record explains what Jane can do, where she can do it, what authority she has, what she needs, and what evidence proves it worked.
Start with critical activities, not the organization chart
Personnel continuity often begins in HR with a succession-planning export. That is the wrong unit of analysis for BCM. An organization chart identifies roles; a disruption breaks activities.
Take daily payment operations. “Payments Manager” may be the designated successor for the Director of Operations, but continuity can still fail because:
- only the director holds the required bank portal token;
- the alternate’s approval limit is below the expected payment batch;
- one analyst knows how to reconcile the exception file;
- the procedure points to a retired screen;
- both primary and alternate work in the same office or depend on the same local network; or
- the team can process one day’s volume but cannot sustain the workaround through a multi-day outage.
Use the process inventory and staffing questions from the business impact analysis questionnaire as the starting data. Then decompose each critical process until an unavailable person could no longer be hidden inside a broad department label.
A workable personnel continuity matrix looks like this:
| Field | What to record | Evidence to retain |
|---|---|---|
| Critical activity | A specific output, such as “release ACH file” or “complete daily suspense reconciliation” | BIA process ID and procedure link |
| Recovery requirement | When the activity must resume and minimum sustainable daily volume | Approved BIA and service obligation |
| Primary / alternate | Role and named assignee; add a second alternate where concentration warrants it | HR validation date |
| Decision authority | Approval level, delegated authority, signing mandate, or emergency override | Delegation instrument or approval matrix |
| Access dependency | Application role, device, token, VPN, physical access, privileged credential | IAM report and access-test result |
| Knowledge dependency | Procedure, job aid, exception rules, escalation contacts | Version-controlled runbook |
| Location dependency | Work location and shared site, transit, utility, or network exposure | Geographic concentration review |
| Last execution | Date the alternate actually performed the task | Ticket, transaction ID, checklist, or system log |
| Sustained capacity | Volume and duration the coverage arrangement can support | Timed exercise results and backlog calculation |
| Open gap | Missing access, skill, authority, or capacity | Issue owner, due date, and accepted interim control |
The BCM manager owns the standard and consolidated view. Business process owners own the accuracy of the activity and staffing entries. HR validates role and availability data. IT and information security validate access. Legal, the Corporate Secretary, Treasury, or another authority owner confirms formal delegations. If one person completes every field alone, challenge is probably missing.
The six tests that turn a successor into real coverage
1. Can the alternate get in?
Test access from the place and device the alternate would actually use during the scenario. A screenshot of an assigned application role is not enough. Require the alternate to authenticate, reach the correct function, retrieve necessary records, and complete a controlled step.
This is where continuity and security collide. Product or operations may ask for broad standing access “just in case,” while information security correctly resists privilege creep. Resolve it explicitly:
- Standing access for duties the alternate performs regularly;
- Just-in-time emergency access with a tested activation path and named approver; or
- Sealed/manual fallback for a narrowly defined period, with reconciliation after restoration.
The evidence is the access log plus the tested activation time. If emergency access requires approval from the person assumed unavailable, the control has failed before the exercise starts.
2. Can the alternate make the decision?
Knowing the task is different from having authority to act. Record the exact authority needed: dollar limit, contract-signing authority, incident declaration, customer-notification approval, regulatory filing authority, or access-elevation approval.
A realistic hypothetical: the primary Treasury officer is unavailable during a liquidity event. The alternate can prepare the transfer but cannot authorize the amount under the institution’s approval matrix. Calling the CEO is not a recovery procedure unless the CEO is an approved signer, reachable through an independent channel, and able to authenticate.
The test artifact should show the authority chain used during the exercise and any simulated decision made. Do not put sensitive signatures or credentials in the BCP; link to the controlled source of authority and record its last validation date.
3. Can the alternate follow the current procedure?
Give the alternate the procedure without coaching from the primary. Watch where work stops.
Strong procedures contain:
- a named starting trigger;
- systems and reports required;
- numbered execution steps;
- decision points and tolerances;
- exception handling;
- upstream and downstream handoffs;
- escalation contacts by role;
- evidence to save; and
- a clear completion condition.
NIST Special Publication 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems says readiness includes personnel trained for their plan roles and exercises that validate plan content. Its plan-maintenance guidance calls for current team and vendor contact information, while its sample plan names primary and alternate personnel rather than assuming one contact will always be available (NIST SP 800-34 Rev. 1 PDF, pp. 26, 31 and Appendix A).
If the alternate needs private notes from the primary’s desktop, capture that as a documentation gap. “Completed with assistance” is not a pass.
4. Can coverage survive the same event?
Two names do not create redundancy when both people share the same failure domain. Review whether primary and alternate depend on the same:
- building or metropolitan area;
- transit route;
- power or telecommunications provider;
- device pool;
- privileged administrator;
- childcare or local emergency constraint; or
- manager who grants emergency authority.
Geographic separation does not mean blindly assigning someone in another state. The remote alternate still needs compatible hours, system access, data permissions, procedural familiarity, and enough overlap to practice. Document the concentration decision. For a local community bank, a different branch or remote-capable employee may be proportionate; for a process supporting multiple regions around the clock, a deeper coverage model may be necessary.
NIST’s Appendix D addresses personnel welfare and prolonged disruption directly. It says contingency planning may need personnel from associated organizations, vendors, or consultants when both primary and alternate team members are unavailable—and that planners should prepare their access in advance. It also calls for arrangements to work at an alternate site or from home when the facility cannot be used (NIST SP 800-34 Rev. 1, Appendix D, pp. D-1–D-2).
5. Can the alternate handle real volume?
Executing one sample is useful. It does not prove sustained capacity.
Use internal history instead of unsupported industry thresholds. Pull the last three to six months of daily volume, identify normal and peak days, then run a timed sample. Calculate:
- units completed per hour;
- minimum safe staffing;
- expected backlog after one shift;
- maximum duration of the manual workaround;
- error and exception rate; and
- the point at which customer, legal, or regulatory obligations are threatened.
Example starter test: ask the alternate team to process a representative sample for 60 minutes, map each sample item to a source request or ticket, and independently review errors. Extrapolation is only a planning assumption; label it that way. The anti-gaming check is request-to-ticket or transaction-to-log reconciliation, so a clean sample cannot omit difficult exceptions.
6. Can the institution prove what happened?
An attendance sheet proves people joined a meeting. It does not prove continuity.
For each tested activity, retain a compact evidence packet:
- approved scenario and objective;
- primary person explicitly marked unavailable;
- alternate and observer names;
- procedure version used;
- access and authority validation;
- timed execution record;
- sampled output or transaction reference;
- errors, assistance, and exceptions;
- pass, conditional pass, or fail decision; and
- remediation owner and due date.
Feed the result into the annual BCP testing calendar, not a separate HR spreadsheet that BCM never sees. The federal Ready.gov continuity-planning resources likewise frame continuity as a team-and-plan discipline and provide exercise-planning support; the operational point is to test the arrangement, not merely document it.
Run a personnel-loss exercise without letting the primary rescue it
A discussion-only tabletop will often produce “we would call the backup.” A better exercise forces execution.
Scenario: At 8:15 a.m., the primary process owner and one experienced analyst are unavailable for the next five business days. Their company laptops and phones are unavailable. The office is accessible, but the scenario may be expanded to remove it later.
Exercise flow:
- 0–15 minutes: Activate the call tree and confirm who has authority to invoke coverage.
- 15–30 minutes: Retrieve the current plan and procedure without asking the primary.
- 30–60 minutes: Activate required access and complete one controlled transaction or task.
- 60–90 minutes: Process exceptions, perform the downstream handoff, and estimate capacity against actual historical volume.
- Day-two inject: Remove the primary worksite or a second alternate. Ask how coverage changes.
- Close: Reconcile every action to logs, record assistance provided, and decide pass status.
A conditional pass is legitimate when the core output succeeds but the arrangement needs a fix—for example, emergency access took 42 minutes against an internally approved 30-minute recovery assumption. Record the variance and recalibrate or remediate. Do not convert every imperfection into a pass because “the team figured it out.” Improvisation is useful incident response data, not proof the planned control worked.
What to put in front of an examiner or bank partner
Keep the package navigable. Start with one coverage summary, then link to controlled evidence:
- current critical-process inventory and BIA;
- personnel continuity matrix with validation dates;
- authority and emergency-access references;
- procedure inventory with versions and owners;
- training and actual-execution records;
- exercise schedule and after-action reports;
- open issues, interim controls, and accepted residual risk; and
- management or board reporting on material gaps.
The FFIEC Business Continuity Management booklet is the supervisory anchor, while OCC Bulletin 2019-57 makes clear that resilience should be commensurate with operational complexity. That supports a proportionate design, not a flimsy one. A smaller institution may have fewer alternates and simpler systems, but it still needs to know whether the named people can perform the work.
So What?
Open the BIA this week and choose one critical process with obvious key-person risk. Do not start by editing the phone tree. Pick one activity, remove the primary, and make the alternate execute it from the intended recovery location.
The first-week deliverable is a one-row evidence packet: activity, alternate, authority, access, procedure version, timed result, exception, and owner. Repeat that row across critical activities and succession stops being a list of reassuring names. It becomes a tested control.
The Business Continuity & Disaster Recovery (BCP/DR) Kit includes BIA, dependency mapping, recovery procedures, testing, and action-tracking templates for building that evidence trail.
FAQ
Does every critical role need two alternates?
No universal number fits every institution. Base depth on process criticality, shared failure domains, operating hours, skill scarcity, and how long coverage must last. One qualified alternate may be proportionate for a lower-complexity activity; a 24/7 payment or security function may need multiple shifts or external support. Document the rationale and test the resulting arrangement.
Does annual training prove cross-training?
No. Training completion proves exposure to material. Cross-training evidence should show the alternate performed the task, handled an exception, used the right authority and access, and produced an acceptable output. Use training records as supporting evidence, not the final control test.
Should emergency system access be provisioned permanently?
Only when regular duties justify it. Otherwise, a tested just-in-time or break-glass process can preserve least privilege. Measure activation time, confirm the approver remains available under the scenario, log use, set expiry, and review activity afterward.
What should happen when both primary and alternate are unavailable?
Define the next layer before the event: another business unit, regional team, affiliate, vendor, consultant, or controlled manual service. Validate contracts, confidentiality, access, skills, and activation time. NIST SP 800-34 Appendix D specifically warns planners to prepare for both primary and alternate personnel being unavailable.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
What does personnel continuity mean under FFIEC business continuity management?
Is a succession list enough for an FFIEC BCM review?
Who should own a personnel continuity matrix?
How often should alternate personnel coverage be tested?
What evidence proves that a backup employee can perform a critical process?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Business Continuity & Disaster Recovery (BCP/DR) Kit
BCP and DR templates with BIA, recovery procedures, and a standalone tabletop exercise kit.
◆ Keep reading
Related posts.
Business Continuity
DORA's 4-Hour Incident Reporting Clock: What US Banks with EU Operations Are Missing in Their Playbooks
DORA's ICT incident reporting timeline is the strictest in the world — 4 hours to initial notification, 72 hours to the intermediate report, one month to final. US banks with EU branches are subject to it and most have a gap between their US playbook and what Brussels actually requires.
Jul 29, 2026
Business Continuity
Business Continuity Workaround Strategies: Document the Manual Process Before the System Goes Down
A BCP without documented manual workaround procedures isn't a continuity plan — it's a recovery plan. Here's the workaround template fields and critical-function structure FFIEC examiners expect to see.
Jul 25, 2026
Business Continuity
FFIEC BCM Section III.B Risk Assessment: Turn Threats Into Continuity Strategies
Build an FFIEC BCM Section III.B risk assessment that traces threats, controls, gaps, continuity strategies, tests, and remediation.
Jul 24, 2026