← Resources/Self-Assessment Tool

Plan vs. Program Gap Checklist

A 15-question self-audit to determine whether you have a tested recovery program — or a document that satisfies an audit.

Answer each question honestly. "Mostly" or "it used to" counts as No. Count your No answers and read the result at the end.

0 of 15 answered0% complete
1. Documentation Currency
1.

Your DR/BC plan has been reviewed or updated within the last 12 months.

2.

Every plan owner listed in the document still holds that role today.

3.

The plan reflects your current system architecture, not the environment you had 2+ years ago.

4.

RTOs and RPOs in the plan have been validated against actual recovery testing, not estimated at write-time.

2. Testing & Validation
5.

You have run a tabletop exercise, of any kind, in the last 12 months.

6.

Your most recent test included people outside the BC/DR team, not just the practitioners who wrote the plan.

7.

At least one recovery procedure has been executed end-to-end (not just discussed) in the last 24 months.

8.

Findings from your last exercise were tracked to closure, not just documented and filed.

3. Governance & Accountability
9.

Your BC/DR program has a named executive sponsor who reviews it at least annually.

10.

The board or audit committee has seen programmatic results, not just the existence of a plan, in the last 12 months.

11.

You can produce evidence of testing on demand for an auditor without a multi-week scramble.

12.

Recovery capability, not just plan existence, is part of your enterprise risk register.

4. Integration
13.

Your BC/DR plan is explicitly integrated with your cyber incident response plan, not maintained as a separate, parallel document.

14.

Cloud and third-party vendor dependencies are mapped and included in recovery scope.

15.

A system or vendor change triggers a defined process to update the affected recovery plan.