← Back to the journal

Operating Intelligence

Business Continuity Plan: Keep Work Moving When You Are Away

By Ben Perez, Founder, Catalyst Systems·14 September 2026· 7 min read
A graphite mechanical bridge with a terracotta backup route carrying work safely around an unavailable central support.

A business continuity plan is a practical set of priorities, roles and fallback actions for keeping essential work moving during disruption. It should cover emergencies, system outages, supplier failures and the sudden absence of a person who carries critical knowledge or authority.

Many plans list emergency contacts, backup locations and IT recovery steps. Then the owner is unavailable on a normal Tuesday and quotes wait because nobody knows the pricing exception they would approve.

That is a continuity failure too.

Here is the Catalyst authority test:

If you took two weeks off without checking messages, what would stop, stall or come back wrong?

The answers show where your real continuity plan needs work.

Business continuity includes your absence

Australian guidance already points in this direction. Business Queensland asks owners to imagine being unable to run the business or communicate for six months. It asks whether staff could operate the business and whether the plan contains everything needed in the owner's absence.

The two-week test makes that question usable now. It is long enough to cross a pay cycle, a client deadline, an approval queue and several exceptions.

The test also separates a process problem from a dependency problem. If the team knows the steps but cannot access a system, approve a payment or judge an exception, another procedure will not solve the blockage.

That is why key person risk often sits in four places:

  • knowledge: one person remembers the history or workaround
  • access: one person controls the account, file or credential
  • authority: one person can approve the decision
  • relationships: one person holds the customer or supplier trust

A workable continuity plan addresses all four.

Start with the work that must continue

Do not try to protect every activity equally. List the outcomes the business must still deliver to avoid serious harm. The NSW Small Business Commissioner provides practical templates and stresses that the plan should be built around the business's own needs.

For a small service business, those might include:

  • respond to urgent customer issues
  • deliver work already promised
  • issue invoices and collect payment
  • run payroll and make required payments
  • protect and restore essential records
  • communicate delays or changed arrangements

For each outcome, decide:

  1. the longest acceptable interruption
  2. the minimum level of service that would be acceptable
  3. the person who normally owns it
  4. the alternate person or provider
  5. the systems, data, suppliers and authority required

The Australian Government's emergency management plan guidance recommends identifying critical products and services, continuity strategies, staff skills, information backups, responsibilities and recovery contacts. It also recommends reviewing the plan after staff or location changes and rehearsing it with the team.

Build a dependency map, not only a contact list

A contact list says who to call. A dependency map shows what has to be available for a critical outcome to continue.

Three-card business continuity diagram showing people, access and authority as requirements for critical work.
A named backup still needs access, operating context and authority to keep critical work moving.

Build one row for each critical outcome:

  • Dependency: People; Record: Primary role, alternate and minimum staffing
  • Dependency: Systems; Record: Applications, devices, connectivity and administrator access
  • Dependency: Information; Record: Current work status, customer commitments, instructions and records
  • Dependency: Authority; Record: Spending limits, approval thresholds and escalation rules
  • Dependency: Third parties; Record: Supplier, adviser and support contacts plus alternatives
  • Dependency: Communication; Record: Who informs staff, customers and suppliers, through which channel

Then remove one dependency in a simulation. Can the alternate still find the plan if the identity provider is down? Can they contact clients without the CRM? Can they approve a refund within limits? These questions turn assumptions into testable controls.

Write the plan for the person using it under pressure

A business continuity plan should be easy to find and easy to act on. Use short checklists for the first hour, first day and first week.

For each disruption scenario, include:

  • the trigger for activating the plan
  • who becomes the incident lead
  • immediate safety and containment actions
  • the critical work that continues first
  • manual or alternate ways to deliver it
  • customer, staff and supplier communication
  • decisions the team can make without the owner
  • conditions that require specialist or regulatory advice
  • how normal operations will be restored
  • what evidence and decisions should be recorded

Link technical recovery instructions from the continuity plan instead of letting system detail obscure the first actions.

The plan must also be accessible during the disruption it describes. Business Queensland recommends checking whether staff can reach it from another location, including in the cloud from a mobile phone. For some risks, an offline copy of the critical contacts and first actions is sensible as well.

Transfer authority with boundaries

Many owner-led businesses document tasks but leave authority unchanged. The alternate person can prepare the payment, quote or customer remedy, then the work still waits for the owner.

Define three levels for recurring decisions:

  • decide: the alternate owns the call within the normal process
  • decide within limits: the alternate can act within agreed value, risk or service boundaries
  • escalate: unusual, regulated, high-cost or sensitive decisions require another named reviewer

Include past examples and the criteria behind them. This preserves useful judgement without handing over unlimited discretion.

The same principle applies when you reduce founder dependency. A strong handover carries decision rights, standards, context and exception memory with the task.

Run the two-week test in stages

A written plan has not proved that the business can use it. ISO 22301 treats business continuity as a system that is monitored, reviewed, maintained and continually improved. Business Queensland likewise recommends workplace simulations because they reveal whether people can find the plan, use the checklists and recover operations.

Start with controlled tests:

  • Test: Owner stays silent for one recurring decision; What it reveals: Missing authority or criteria
  • Test: Backup person runs one critical process; What it reveals: Missing instructions, access or confidence
  • Test: Team works without one core system for an hour; What it reveals: Missing data export or manual fallback
  • Test: Tabletop exercise for a supplier failure; What it reveals: Weak alternatives and stale contacts
  • Test: Full business day without owner intervention; What it reveals: Hidden approvals, context and relationships
  • Test: Two planned weeks away; What it reveals: Whether the fixes work across real operating cycles
Three-step business continuity test showing one silent decision, one day and two weeks without owner intervention.
Build confidence in stages: one silent decision, one day without intervention, then two planned weeks away.

Record every blocked action and question that would normally go to the absent person. Sort each gap into process, context, access, authority or relationship, then assign an owner and date for the fix.

Do not quietly rescue the test through private messages. The interruption is the evidence.

What often fails in a business continuity plan

  • It covers disasters but not ordinary absence: leave can remove a key person without damaging the office or systems.
  • A backup is named but not prepared: capability requires access, practice and authority.
  • It assumes the systems work: contacts and runbooks may be trapped inside the platform that failed.
  • The steps lack operating context: this is where small-business knowledge management supports continuity.
  • It is never exercised or updated: stale contacts, credentials, roles and assumptions remain hidden.

A continuity plan should be treated as part of the operating system, not a file created for emergencies and forgotten.

Make continuity part of normal work

The strongest controls improve everyday operations as well as emergency response:

  • shared work status reduces handover loss
  • role-based system access avoids credential bottlenecks
  • decision limits speed up routine approvals
  • current client context improves communication
  • cross-training creates leave coverage
  • recorded exceptions make the next response better

This is closely connected to systemising a small business. A resilient business knows what should happen, who can act and where the required context lives. An organisational brain can help preserve decisions and exceptions, but it still needs clear ownership and tested operating procedures around it.

Your continuity plan is credible when the team can use it without reconstructing the business from the absent person's memory. The two-week test gives you a direct way to find out.