Corporate Performance & ESG 01 July, 2024

Ensuring resilience: Business continuity for financial services internal auditors

Business continuity issues for banks can manifest in various forms, often with significant impacts on operations and customer trust. For instance, the devastating impact of Hurricane Sandy in October 2012 forced banks like Goldman Sachs and Morgan Stanley to activate their business continuity plans, including relocating critical staff and operations to backup sites due to power outages and flooding in their New York headquarters. More recently, the COVID-19 pandemic in 2020 posed unprecedented challenges for banks globally, such as the need for banks to rapidly transition a significant portion of its workforce to remote operations while managing an abrupt surge in digital banking usage. These examples underscore the critical need for robust business continuity planning to ensure banks can withstand and recover from diverse and unexpected disruptions.

This article addresses business continuity, its significance in the financial sector, and the essential components of robust business continuity management (BCM). It also provides internal auditors guidance on how to effectively audit BCM.

What is business continuity management?

The Federal Financial Institutions Examination Council (FFIEC) is an interagency group that sets standards and principles for the federal examination of financial institutions. Per the FFIEC, “Business continuity management (BCM) is the process for management to oversee and implement resilience, continuity, and response capabilities to safeguard employees, customers, and products and services. Disruptions such as cyber events, natural disasters, or man-made events can interrupt an entity’s operations and can have a broader impact on the financial sector. Resilience incorporates proactive measures to mitigate disruptive events and evaluate an entity’s recovery capabilities.”

Business continuity is a proactive process designed to ensure that an organization can continue to operate and deliver critical services during and after a disruptive event. The goal of business continuity is to minimize the impact of these disruptions, ensuring that the organization can maintain essential functions and recover swiftly to normal operations.

The diagram linked here from the FFIEC maps out the lifecycle of robust business continuity management.

Benefits of business continuity in financial services

The financial services industry is particularly vulnerable to disruptions due to its reliance on technology and the critical nature of its services. For internal auditors, here are some important areas to include in the audit planning process:

  • Operational resilience: Business continuity planning ensures that critical operations can continue despite disruptions. Reliable access to banking services ensures financial stability for customers. It allows them to manage their finances effectively, make timely payments, and avoid potential financial difficulties caused by service disruptions. This is vital for maintaining the smooth functioning of financial markets and preventing systemic risks.
  • Customer trust: Financial institutions handle sensitive information and manage significant financial transactions. A disruption in services can erode customer trust and lead to substantial financial losses.
  • Regulatory compliance: Regulatory bodies — such as the Federal Financial Institutions Examination Council (FFIEC) and the Financial Industry Regulatory Authority (FINRA)— mandate financial institutions to have robust business continuity management, including plans and testing. Failure to comply can result in severe penalties and loss of credibility. See FINRA requirements here and FFIEC requirements here.
Review and consider future ready software used by financial services auditors around the globe to support business continuity audits and more!

Subscribe below to receive monthly Expert Insights in your inbox

Missing the form below?

To see the form, you will need to change your cookie settings. Click the button below to update your preferences to accept all cookies. For more information, please review our Privacy & Cookie Notice.

Dana Lawrence Headshot
Sr. Director of Fintech Compliance at Pacific West Bank and Board Member at Technology
Dana Lawrence is the Sr. Director of Fintech Compliance at Pacific West Bank and Board Member at Technology Association of Oregon.
Back To Top