0% found this document useful (0 votes)
7 views8 pages

Business Continuity Management Guide

The document outlines the principles and steps of Business Continuity Management (BCM) aimed at ensuring uninterrupted business operations during extraordinary events. It details the identification of critical business processes, risk mitigation strategies, and the management of critical situations in the IT-BPM industry, including symptoms, declarations, and recovery plans. Additionally, it introduces the 8D problem-solving approach for managing issues and changes effectively.

Uploaded by

jeraldestars
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
7 views8 pages

Business Continuity Management Guide

The document outlines the principles and steps of Business Continuity Management (BCM) aimed at ensuring uninterrupted business operations during extraordinary events. It details the identification of critical business processes, risk mitigation strategies, and the management of critical situations in the IT-BPM industry, including symptoms, declarations, and recovery plans. Additionally, it introduces the 8D problem-solving approach for managing issues and changes effectively.

Uploaded by

jeraldestars
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Module 6

Business Continuity Management


The challenge to business continuity management is to plan for seemingly “uncontrollable” circumstances to
provide for consistent excellent service. The goal of business continuity management is maintaining the
uninterrupted availability of all key business resources required to support essential business activities.

Goal of Business Continuity Management is most evident in the following:

● Uninterrupted availability - continued business operations


● Key business resources - ensuring critical business capability
● Essential business activities - key business goals

Business Continuity Management Interruptions Events


Each process has a period within which interruptions will not affect achievement of key business goal. Beyond
that period, business goal will be impacted --and interruption becomes extraordinary. Business Interruption
Event is triggered when the interruption on a key business process exceeds the maximum allowable time.

Business Continuity Management Triggering Event


Extraordinary event - Beyond normal downtimes of equipment or input process for your High Impact–
Resulting in risk of significant loss

Australian National Audit Office (ANAO uses the term “outage”) -In this course, we use Risk and Risk
Event interchangeably with “business interruption event”

Business Continuity Management Reduce Probability of Occurrence


● Develop measures to prevent risk from occurring -If within the control of the organization
● If cost effective- Shifting of factory to an underground bunker to protect from tornado damage may be
cost prohibitive
● Reduce likelihood of the risk if prevention is impossible or not cost effective
-Extensive smoke alarms to catch possible fire starts.
-Good quality circuit breakers, periodic inspection and replacement, use of standard wires/tapes reduce
risk of electrical fire.
-Multiple generator sets reduce risk of interruption from power failure.

Business Continuity Management Steps

1. Initiate Project
● Document objectives, scope, boundaries
● Establish management committee
● Establish budget and timetable

2. Identify Key Business Processes


● Identify key business objectives
● Identify key business processes
● Align with business processes with key outputs
● Understand key activities, resources, and inter-dependencies

3. Undertake Business Impact Analysis


● Identify key personnel
● Schedule and conduct interviews
● Document Concerns, priorities, and expectations
● Determine Maximum Acceptable Outage for each process

4. Design Treatments
● Review existing controls
● Identify and evaluate options
● Selects alternative activities and resources
● Implement treatments

5. Implement Continuity Treatments


● Formulate measures to migrate adverse effect, shorten interruption, if risk occurs
● Planning for redundant resources, alternative process

6. Test and Maintain the BCP


● Paper test
● Manual verification
● Supply validation
● Supply, service, and equipment availability
● Structured walkthrough
● Unannounced team assembly

Critical Situations in the IT-BPM Industry


Critical Situations - Critical Situation Management Methods
What is Critical Situation (CritSit)?

● Our capacity to deliver consistently excellent services is compromised.


● Signs of declining service quality and operational issues become apparent.

Critical Situations in the IT-BPM Industry: SYMPTOMS


“Tell Tale” signs of a CritSit:

● Prolonged period of non-achievement of key SLA’s or Contractual Obligations


● Business Controls and/or Financial posture of a contract/account is assessed as high risk.
● Lingering IT infrastructure issues causing problems in operations, e.g. delays in processing of clients’
payroll.
● Data Privacy Incidents/Fraudulent activities involving clients’ information are recurring in the workplace.
● Customer satisfaction rating is on a downward trend, Customer escalation is spiraling upwards.
● Increase in costs (e.g additional resources)

Critical Situations in the IT-BPM Industry: ENTERING INTO

1. A state of being on the verge of a crisis or emergency that if not addressed could lead to an elevated
risk level.
2. A CritSit is no ordinary exercise and it should only be declared once a defined set of criteria has been
determined by the senior management.
Critical Situations in the IT-BPM Industry: DECLARATION

Declaring a CritSit:
The CritSit should be jointly declared by the following:

● Delivery Center Leader or General Manager


● Competency Leader or Delivery Process Leader
● Delivery Center or Competency/Process Quality Leader

CRITICAL SITUATIONS IN THE IT- BPM INDUSTRY:

Situation 1:

SITUATION: Heavy Flooding Caused by the Habagat Phenomenon in August 2012.

SITUATION IN THE IT BPM: Massive absenteeism as employees are not able to leave their houses due
to the heavy flooding

IMPACT TO BUSINESS
● Non-Attainment of SLA Due to Lack of Agents to Take Calls or Do the Work
● Long Call Queues Due to Only a Handful of Agents Taking the Calls
● Other Centers/Countries Unable to Do the Next Process Due to Delays in Work from Manila

MITIGATING ACTIONS DONE BY THE IT- BPM


● Declared an Emergency Situation for Manila and Sought Assistance from Other Centers (India, China,
Singapore, and Other Centers in Asia)
● Requested Employees Already in the Center to Render Overtime Work to Cover for Absentee Agents
● Employees Who Can Work from Home (with Technical Connectivity) Were Asked to Work from Home
● Team Leaders, All Management, and Support Teams Who Can Do Actual Operations Work Were
Asked to Do Operations Work
● Shuttle Service Provided to Ferry Employees from Home to Work and Vice Versa (Where Passable)
● Reimbursement of Transportation Expenses

SUPPORT PROVIDED TO EMPLOYEES WHO WERE AT THE CENTER


● Provision of Free Food for Employees Working During the Crisis
● Provision of Pillows and Blankets for Employees Working Extended Hours
● Hotel Accommodation Provided for Employees Working Extended Days
● Provision of Clothes and Toiletries for Employees Working Extended Hours
● Provision of Shuttle Service for Employees
● Higher Premium Pays and Extra Off Days for Employees

OVERALL SUPPORT TO EMPLOYEES HEAVILY AFFECTED BY HABAGAT


● Financial Assistance and Emergency Relief
● The provision of paid absences
● Counselling for those who are emotionally affected
● Fund drives organized by the employees as well as assistance from other centers/ affiliated companies
to support affected employees
SUPPORT TO THE COMMUNITY
● Fund drives organized by the employees as well assistance from other companies to support
communities in affected areas
● Doubling the amount raised by employees
● Support in kins also provided especially evacuation centers

Situation 2:
SITUATION: METRO MANILA BLACK OUT AND TO COMPOUND THE SITUATION BUILDING
GENERATOR IS BROKEN/ NOT FUNCTIONING DUE TO MECHANICAL TROUBLE

IMPACT TO BUSINESS

● non attainment of sla as employees cannot work due to the lack of power
● Long call queues
● other centers/ countries who are the receiver of manila work output cannot do the next process as work
is delayed from manila end

MITIGATING ACTIONS DONE BY THE IT- BPM


● Declared an Emergency Situation for Manila and Sought Assistance from Other Centers (India, China,
Singapore, and Other Centers in Asia)
● Required Employees to Go Down the Building Using the Fire Exit Stairs and Wait for Instructions as to
When Work Will Resume
● Employees Who Can Work from Home (Places with Power, Technical Capability, and Connectivity)
Were Requested to Work from Home.

Recovery Plan / Business Continuity Plan (BCP) to Minimize Risk in the Future
● Meeting with Building Administration to Review Situation (What Went Wrong) and Identify Action Plan
to Increase Preparedness in the Future
● Schedule Monthly Meeting with Building Administration to Ensure Actions Are Being Done as Per
Agreed Timelines
● Monthly/Quarterly Audits/Testing to Ensure Generator and Other Power Systems/Tools Are in Good
Condition

Situation 3:
SITUATION: HIGH ABSENTEEISM DUE TO WIDESPREAD OF INFLUENZA AND COLD
IMPACT TO BUSINESS
● Delay in Response Time Due to Insufficient Agents to Take Calls
● Long Call Queues Due to Insufficient Staffing
● Turnaround Time of Work/Calls is Longer Than Required Due to Insufficient Agents/Employees
● Other Centers/Countries Receiving Manila Work Output Cannot Proceed with the Next Process Due to
Delayed Work from Manila End

MITIGATING ACTIONS DONE BY THE IT- BPM


● Required Employees to Work Overtime (Work Extension and Work on Day Off) to Cover for Colleagues
Who Are Absent
● Request for Vacation Leaves Are Revoked
● Employees Who Can Work from Home (Where There Is Power and Technical Connectivity) Were
Asked to Work from Home
Recovery Plan / Business Continuity Plan (BCP) to Minimize Risk in the Future
● Review Workforce Planning to Ensure FTE Allocation in Case of High Absenteeism
● Multi-Skilling of Agents to Allow Flexibility to Transfer Agents from One Program to Another in Case of
High Absenteeism in Certain Accounts/Programs
● Develop Health Programs to Educate Employees on How to Live Healthy and Avoid Illness

SUMMARY
● A state of being on the verge of a crisis or emergency that if not addressed could lead to an
elevated risk level.
● A Critsit is no ordinary exercise and it should only be declared once a defined set of criteria has
been determined by the senior management.
● Critsit should be declared for the following reasons:
-Non-achievement of the Service Level Agreement (SLA);
-Non-implied client dissatisfaction; and,
-Penalty paid for every month of SLA miss.

CRITICAL SITUATION MANAGEMENT METHODS


1.) PREPARE
● Identify the project manager or team leader of the CritSit team. A good option to lead this team is either
a certified project manager or 6Sigma Black Belt.
● Identify the team members of the CritSit and assemble the team.
● Identify the stakeholders/governance board of the CritSit process.
● Ensure all administrative requisites of the CritSit process. e.g meeting schedules
● Establish a dedicated “war room” that will be used by the CritSit team.

2.) ASSES
● Develop glide-paths for improvement on key metrics that will be monitored for the duration of the
CritSit.
● Define and communicate to CritSit team members the entry and exit criteria of the CritSit.
● Conduct an in-depth analysis of the problems by scrutinizing thoroughly historical data/ measures of the
problem areas.
● Use root cause analysis methods such as the Fishbone diagram, why why analysis or 8D problem
solving techniques.

3.) DEVELOP RECOVERY PLAN


● Prioritize the problems and/or root causes as a result of the assessment
● Brainstorm with the team and develop detailed action plans to address the problems and/or root causes
● Assign individuals/teams to implement solutions as defined in the overall action plan. Make sure that
each action step has defined timelines in-synch with the target exit from CritSit.
● Ensure that there will be a consistent executive status presentation and regular core team project
review schedule.

4.) GAIN COMMITMENT


● Get clients’ buy-in and/or vote of confidence on the recovery plan if they are aware of the CritSit in their
contact/account.
● Be sure that all stakeholders and team members involved in the process have signed-off on the
following:
- Over-all recovery plan
- Assignments and timeline
- Resource allocation/requirement
- Costs associated with the recovery plan

5.) EXECUTE THE PLAN


● Execute a pilot or go for a full-implementation of the recovery plan.
● Conduct frequent checkpoints and tollgates per established metric glide path.
● Document the changes in the process as it gets implemented and standardize accordingly.
● Establish regular stakeholders and customer feedback sessions during the implementation of the
recovery plan.

6.) CLOSE THE RECOVERY


● Present to the stakeholders and client the improvement of the metrics per the glide path
● Get the sign-off of the stakeholders and client to approve the exit from CritSit and return to business as
usual mode.
● After implementation of the action plans and full recovery from CritSit, conduct an evaluation of lessons
learned and collate this for future reference.
● Ensure to develop next steps that will prevent the CritSit from happening again. This could be done by
conducting another round of brainstorming sessions.
● Celebrate with the team!

THE 8D APPROACH

0- Become Aware of the Problem


This is the initial trigger. Something has gone wrong, a defect has been found, or a customer complaint
has been received. This is the moment someone realizes attention is needed.

1- Use Team Approach (Form a Team)


Recognizing that complex problems require diverse perspectives, a team is assembled. This team
brings together people with the right skills and knowledge to tackle the issue.

2- Describe the Problem (Define the Problem)


● This step is crucial for clarity. The team defines the problem in detail, using data and facts. They
answer questions like:
● What is happening?
● Where is it happening?
● When is it happening?
● How often is it happening?

3- Implement and verify the interim containment action (Develop interim containment action)
This is about "stopping the bleeding." The team takes temporary actions to prevent the problem from getting
worse or affecting more customers. This could involve things like isolating defective products or temporarily
changing a process.

4- Define and verify root causes (Determine and verify root causes)
This is where the team digs deep. They use problem-solving tools to identify the fundamental cause of the
problem, not just the symptoms. They then verify that this root cause is indeed the source of the issue.

5- Choose and verify corrective actions (develop permanent actions)


Once the root cause is known, the team develops and selects permanent solutions to eliminate it. They also
verify that these solutions will be effective and won't create new problems.

6- Implement permanent corrective actions (Implement and validate permanent corrective actions)
The chosen solutions are put into action. The team then monitors the results to ensure the problem is truly
resolved.

7- Prevalent Recurrence (Prevent Recurrence)


This step focuses on preventing the problem from ever happening again. The team makes changes to
processes, procedures, or systems to ensure long-term prevention.

8- Congratulate Team (Recognize the team)


The team's hard work and success are acknowledged. This reinforces positive behavior and encourages
teamwork.

Managing Issues and Changes


● Interaction Levels
● Issue-Management Processes
● Communication Tracking
● Issue Management Systems

MANAGING ISSUES AND CHANGES: INTERACTION LEVELS


Executive Committee– Directions. Executive-level committee of company and service provider handles
escalated issues and strategic directions.

Account/ relationship managers– Cross-Process. Service provider "account manager and company
sourcing manager (or next level operations head) resolve issues that span multiple processes

Operational Manager Escalation– Individual Process. Operational managers (Onshore manager, service
provider operations manager) can handle escalated issues.

MANAGING ISSUES AND CHANGES: MANAGEMENT PROCESSES


MANAGEMENT PROCESSES:

1. Facilitated Communication and Tracking


2. Root Cause Analysis
3. Escalation
4. Process Improvement or One-off

MANAGING ISSUES AND CHANGES: COMMUNICATION AND TRACKING

Facilitated Communication and Tracking:

● Communication of issues, particularly time-sensitive matters, can be done verbally or by email.


● BUT proper documentation by way of an issue management system is key to: structured resolution and
recurrence prevention.
● Clear documentation of issues is key to effective escalation.

MANAGING ISSUES AND CHANGES: ISSUE MANAGEMENT SYSTEM


Good Issue Management System Facilitates:
1.) Clear Documentation
-Clear statement of the following; issue (including cost of the issue if unresolved), scope affected, root cause,
proposed solution, financial impact of the proposed solution and timetable.
2.) Good Issue Management System Facilitates:
- Clear assignment of responsible persons.
3.) Approvals
-Facilitates approval by right authority in service provider and onshore/client organization.
4.) Process Improvement
-Can identify changes in people skills/training, staffing level, technology, or policy/processes.
-Analysis of trends across multiple issues can highlight areas for process changes that will prevent future
issues.

Common questions

Powered by AI

Organizations in the IT-BPM sector can prevent recurrent critical situations by developing comprehensive recovery and risk management plans, conducting regular audits, and embedding flexibility into their operational processes. Key components of managing critical situations effectively include: preparing a dedicated team with diverse skills, using analytical tools like root cause analysis to understand underlying problems, developing and executing detailed recovery plans with stakeholder commitment, and ensuring continuous feedback and communication. Post-situation reviews are vital for learning from each crisis, thereby improving future preparedness. Engaging in proactive measures like health programs and multi-skilling employees further build resilience .

During the heavy flooding caused by the Habagat phenomenon, several strategies were used to mitigate its impact on IT-BPM operations. An emergency situation was declared, assistance was sought from other centers (e.g., India, China), and employees who could work from home were asked to do so. Those present at the center were requested to work overtime, and essential resources such as food, transportation, and accommodation were provided. Lessons for future emergencies include the importance of a flexible workforce, support systems for affected employees, and the ability to leverage resources from other locations promptly. Maintaining an effective communication and support framework is crucial for minimizing business disruption .

Stakeholder buy-in on recovery plans during critical situations is crucial for ensuring organizational alignment and the availability of resources necessary for a successful recovery. Securing this commitment involves clearly communicating the recovery plan and obtaining sign-offs on its objectives, assignments, and resource requirements. Organizations should engage stakeholders early, involve them in planning discussions, and ensure transparency regarding the plan's goals and potential impacts. Regular updates and evidence of progress help maintain support, minimize resistance, and facilitate a coordinated response, ultimately enhancing the efficacy of the recovery efforts .

Proactive health programs and strategic workforce planning mitigate high absenteeism by fostering a healthier work environment and preparing the organization for workforce fluctuations. Health programs educate employees on maintaining well-being, reducing illness-related absences. Strategic workforce planning involves ensuring there are flexible, multi-skilled employees who can be reassigned as necessary, and establishing clear contingency plans for personnel shortages. These programs, along with policies like temporary remote work capabilities, support operational continuity and resilience against widespread absenteeism during critical periods .

During the blackout in Metro Manila compounded by non-functioning generators, immediate actions included declaring an emergency, instructing employees to work from home if feasible, and holding meetings with building administration to assess the failure. Future infrastructure planning is informed by ensuring robust backup systems, like regularly tested generators, and establishing comprehensive emergency protocols. Monthly or quarterly audits are crucial to ensure operational readiness of power systems. This event demonstrates the need for communication with stakeholders and thorough analysis of infrastructure reliability to preemptively resolve potential issues .

The formation of a diverse team in managing a critical situation is essential as it brings multiple perspectives and expertise needed to address complex problems comprehensively. Different skills and knowledge from team members enable effective problem-solving and decision-making. Methodologies such as root cause analysis, Fishbone diagrams, and the 8D problem-solving process help in defining, analyzing, and addressing the root causes of problems. These approaches ensure that solutions are well-researched, appropriate, and sustainable, preventing recurrence of issues .

Reducing the probability of occurrence involves implementing preventive measures to stop risks from happening, where control is possible and the cost is not prohibitive. If prevention is not feasible or cost-effective, alternative strategies focus on reducing the risk's impact. For example, extensive smoke alarms can detect potential fire starts, while good quality circuit breakers can prevent electrical fires. When such specific preventative measures aren't viable, reducing likelihood through preparedness, like having multiple generator sets for power failures, becomes necessary. Thus, while prevention aims at avoiding risks altogether, risk reduction focuses on minimizing potential impacts .

Communication and tracking play vital roles in managing issues and changes by facilitating clear and structured resolution processes. Effective communication, whether verbal or through email, ensures that all stakeholders are aware of the issue details and progress. A management system that provides clear documentation of issues is crucial to avoid misunderstandings and assists in escalation when necessary. This process enables the identification of root causes, tracks resolutions, and ensures accountability. By preventing recurrence through structured approaches, these tools and strategies contribute effectively to issue resolution and continuous improvement .

Business Continuity Management (BCM) aims to minimize the impact of extraordinary business interruption events by ensuring the uninterrupted availability of key business resources and processes, which support essential business activities. It involves planning for 'uncontrollable' circumstances to provide consistent services. Effective BCM includes steps such as initiating the project with clear objectives, identifying key business processes, undertaking a business impact analysis to determine acceptable outages, designing and implementing continuity treatments like alternative resources, and testing and maintaining the business continuity plan. These steps help manage risks related to business interruptions and maintain operations during unforeseen events .

Critical symptoms indicating a CritSit in the IT-BPM industry include prolonged periods of not achieving key Service Level Agreements (SLAs) or contractual obligations, declining service quality, operational issues, recurring data privacy incidents, and increasing customer escalations. These signs point to a compromised ability to deliver excellent services and an elevated risk level. Handling such situations involves declaring a CritSit based on defined criteria, typically by senior management, and engaging in a structured process including preparation, problem assessment, developing, and executing a recovery plan, and closing the recovery with lessons learned to prevent recurrence .

You might also like