Skip to main content

Business Continuity and Disaster Recovery (BCDR) policy

The Trust is committed to maintaining effective Business Continuity and Disaster Recovery (BCDR) arrangements that ensure the continuity of its critical functions and the protection of its information assets in the event of a disruptive incident.

Policy details

Version number
1
Approved by
Trust Board
Responsible Director
Chair
Review by date
Within 12 months of establishment

1. Summary

  1. The Trust is committed to maintaining effective Business Continuity and Disaster Recovery (BCDR) arrangements that ensure the continuity of its critical functions and the protection of its information assets in the event of a disruptive incident.
  2. This policy establishes the framework within which the Trust will identify risks to operational continuity, maintain plans to sustain and recover priority activities, and ensure that its technology and information assets are adequately protected and recoverable. It covers both Business Continuity Management (BCM), which addresses how the organisation keeps running during disruption, and Disaster Recovery (DR), which addresses the technical recovery of systems and data following a failure or incident.
  3. The Trust recognises that, as a newly established organisation, it is at the beginning of its BCDR maturity journey. At establishment, the Trust operates within another organisation's physical office and computing environment and relies upon systems and infrastructure provided by NHS England and other suppliers. This policy therefore acknowledges that many BCDR controls will initially be inherited from or shared with those providers, and sets out a clear programme of work to develop the Trust's own BCDR capability progressively as the organisation grows.

This policy aligns with and implements the requirements of:

  • Civil Contingencies Act 2004 (CCA 2004) and the 2005 Regulations
  • NHS Act 2006 (as amended)
  • Health and Care Act 2022
  • NHS England Business Continuity Management Toolkit
  • NHS Core Standards for Emergency Preparedness, Resilience and Response
  • ISO 22301:2019 Business Continuity Management Systems
  • NHS England guidance on cyber security and information governance
  • Memorandum of Understanding – Future Services Programme: Service Desk and End User Support Provision to Online NHS Trust (FSP MOU NHSE/Online NHS Trust)
  • UK GDPR (Article 32(1)(c))

2. Equality Impact Statement

The author of this policy has undertaken an equality impact assessment (EIA) and has concluded that there is no negative impact on any of the protected equalities groups. A summary of the completed EIA can be found in theequality impact assessment section of this page.

3. Introduction

  1. Business continuity and disaster recovery are essential disciplines for any organisation that relies upon information systems, digital infrastructure, and operational processes to discharge its functions. For the Trust, the ability to maintain continuity of operations and to recover from disruptive incidents is fundamental both to the delivery of its statutory obligations and to maintaining the confidence of partners, patients, and the public.
  2. Business Continuity Management (BCM) is the process by which the Trust identifies the activities and resources that are most critical to its operation, assesses the risks that could disrupt those activities, and puts in place plans and arrangements to maintain or rapidly restore them in the event of disruption. Disaster Recovery (DR) is the technical subset of BCM concerned specifically with the recovery of information technology systems, data, and digital infrastructure following a failure or incident.

The Trust's operating environment presents a specific set of BCDR considerations. At establishment:

  • The Trust operates within office space and on computing infrastructure provided by NHS England. This means that many foundational controls – physical security, network resilience, shared IT services – are the responsibility of NHS England. The Trust must understand and document these inherited arrangements and satisfy itself that they are adequate, rather than seeking to duplicate them.
  • The Trust relies upon NHS England-provided systems, including Microsoft SharePoint, Teams, and related Microsoft 365 services, for its day-to-day operations. End user computing support, service desk, remote support, and device logistics are provided to the Trust by NHS England under a Memorandum of Understanding (MOU), with North East Commissioning Support (NECS) as the primary delivery supplier. The resilience and recovery of these systems is governed by NHS England's own BCDR arrangements, the terms of the MOU, and Microsoft's enterprise service commitments.
  • The MOU (effective 1 June 2026, initial term to 31 March 2027) establishes Silver-tier service levels for Online NHS Trust, including an IT Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 24 hours for end user computing systems, with 99.5% availability. These contractual commitments form an important component of the Trust's IT resilience baseline for the period of the MOU.
  • The Trust is in the process of procuring and implementing its own business systems, including payroll and HR platforms. These newly acquired systems will require the Trust to develop and maintain its own DR arrangements, in addition to relying on supplier-provided resilience.
  • The Trust is building bespoke digital services and products, hosted on cloud infrastructure including Amazon Web Services (AWS). The resilience of these services will depend on the Trust's own architectural decisions and on the DR capabilities of its cloud and code hosting providers (including version control and repository platforms such as GitHub).

This policy provides the governance framework for BCDR across all of these contexts. It establishes principles, responsibilities, and minimum standards, and signposts the areas of further development that are required as the Trust matures. It should be read alongside the Trust's EPRR Policy, which provides the wider framework for incident preparedness and response.

4. Objectives

The Trust Board recognises that all matters of BCDR are essential factors and must be integrated within all corporate and management decisions. The objectives of this BCDR policy are to:

  • Ensure the Trust can maintain or rapidly restore its priority activities in the event of a disruptive incident, including where that disruption originates from within a host organisation's environment.
  • Define clear governance structures and accountability for BCM and DR across the organisation.
  • Identify and document the Trust's critical business functions, the minimum service levels required, and the recovery time objectives for each.
  • Ensure that BCDR arrangements cover all categories of Trust system and data: NHS England-provided platforms, newly procured business systems, and systems built and operated by the Trust itself.
  • Ensure that all organisational artefacts – documents, policies, plans, data, and code – are stored, backed up, and version-controlled in a manner that supports recovery.
  • Ensure that BCDR plans and procedures are accessible when the primary systems they are designed to support may be unavailable.
  • Align the Trust's BCDR arrangements with ISO 22301:2019 and the NHS England Business Continuity Management Toolkit.
  • Embed BCDR into the Trust's broader risk management, governance, and business planning frameworks.
  • Ensure that all Board members, staff, and contractors understand their BCDR responsibilities.

5. Scope

This policy applies to:

  • All Board members of the Trust, including the Chair and Non-Executive Directors, the Trust Secretary, and all employed or contracted staff of the Trust.
  • All contractors, sub-contractors, agency workers, and individuals acting on behalf of the Trust.
  • Any organisation providing systems, infrastructure, or services under contract to the Trust where those services are critical to Trust operations.

This policy covers all Trust activities, systems, and information assets, including but not limited to:

  • NHS England-provided systems and infrastructure (including Microsoft 365, SharePoint, Teams, and associated services)
  • Newly procured Trust business systems, including payroll and HR platforms
  • Bespoke systems and digital products designed, built, and operated by or on behalf of the Trust, including those hosted on cloud platforms such as AWS
  • Code repositories, version control systems, and software development pipelines
  • Trust documents, policies, plans, and records – regardless of where they are stored
  • Third-party supplier systems upon which the Trust's critical functions depend

6. Definitions and abbreviations

Definitions

Business Continuity Management (BCM)
A management process that identifies potential threats to the Trust and the impacts those threats could have on operations. BCM provides a framework for building organisational resilience with the capability for an effective response that safeguards the interests of key stakeholders, reputation, and value-creating activities. The Trust's BCM arrangements shall align with ISO 22301:2019 and the NHS England Business Continuity Management Toolkit.
Business Continuity Plan (BCP)
A documented set of procedures and information developed, compiled, and maintained in readiness for use in the event of an incident to enable the Trust to continue delivery of its critical activities at an acceptable predefined level.
Disaster Recovery (DR)
The technical subset of BCM concerned specifically with restoring IT systems, data, and infrastructure following failure or disruption. DR plans address how technology services are recovered to support business continuity.
Recovery Time Objective (RTO)
The maximum acceptable period of time within which a system, application, or business process must be restored following a disruptive incident.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss measured in time; i.e. the point in time to which data must be recoverable following a disruptive incident.
Business Impact Analysis (BIA)
The process of analysing the Trust's functions and the effect that a disruption to those functions would have, to determine the criticality of each function and inform recovery priorities.
Critical Function
A business activity or service that, if disrupted, would have a significant impact on the Trust's ability to discharge its statutory obligations or meet its contractual commitments.
Organisational Artefacts
All documents, records, data files, code, configurations, and other outputs produced by or on behalf of the Trust in the course of its operations, regardless of the system or platform on which they reside.
Maximum Tolerable Period of Disruption (MTPD)
The duration after which the Trust's viability would be irreparably compromised if a given function were not restored.
Accountable Emergency Officer (AEO)
The individual designated under section 252A(9) of the NHS Act 2006 as responsible for ensuring the organisation is properly prepared for dealing with a relevant emergency. For BCDR purposes, the AEO holds overall accountability for BCM compliance.
North East Commissioning Support (NECS)
The primary supplier engaged by NHS England to deliver Service Desk and End User Support services to Online NHS Trust under the terms of the MOU. NECS provides first-line service desk, remote 1.5 and second-line support, logistics, warehousing, and asset management services.
Silver Service Tier
The service tier applicable to Online NHS Trust under the MOU. Silver tier defines the following IT DR commitments: Recovery Time Objective (RTO) of 4 hours; Recovery Point Objective (RPO) of 24 hours; service availability of 99.5%; and planned maintenance downtime window of Wednesday 18:00–20:00. Service Desk hours are Monday to Friday 07:00–19:00 (excluding Bank Holidays).
IT Service Management (ITSM) Tool
The ServiceNow platform used by NHS England and NECS to log, track, and manage IT incidents, service requests, and assets. Online NHS Trust's assets and service records are maintained within ServiceNow for the duration of the MOU.
Memorandum of Understanding (MOU)
The agreement between NHS England and Online NHS Trust (FSP MOU NHSE/Online NHS Trust v0.3, April 2026, effective 1 June 2026) that governs the provision of Service Desk and End User Support services to Online NHS Trust for an initial term to 31 March 2027.

Abbreviations

  • Business Continuity Management (BCM)
  • Business Continuity Plan (BCP)
  • Disaster Recovery (DR)
  • Recovery Time Objective (RTO)
  • Recovery Point Objective (RPO)
  • Business Impact Analysis (BIA)
  • Accountable Emergency Officer (AEO)
  • Amazon Web Services (AWS)
  • North East Commissioning Support (NECS)
  • IT Service Management (ITSM)
  • Memorandum of Understanding (MOU)
  • Future Services Programme (FSP)
  • Joiners, Movers and Leavers (JML)
  • NHS England (NHSE)
  • Integrated Care Board (ICB)

7. Duties and responsibilities

The following table sets out the BCDR responsibilities of each role within the Trust. At establishment, the Trust will comprise a Chair, Non-Executive Directors (NEDs), and supporting governance functions. Operational delivery during the initial mobilisation period will be supported through a combination of secondees, interim operational resources, and supplier-provided teams operating under contracted arrangements, pending the phased recruitment of the permanent executive leadership team and supporting organisational structure. As the organisation grows and matures, roles and responsibilities will be reviewed and updated accordingly. This section is therefore designed to be scalable and will be supplemented as executive and operational capacity develops.

BCDR roles and responsibilities
RoleBCDR responsibilities
The Board (collective)Holds overall corporate accountability for BCDR compliance. Ensures that BCDR is considered as part of all significant organisational decisions. Receives an annual BCDR assurance report and ensures sufficient resources are allocated to meet BCDR obligations. Approves this policy and any significant updates.
ChairProvides leadership and sets the tone for a culture of resilience across the organisation. Ensures the Board agenda includes regular BCDR reporting. Supports the AEO in discharging BCDR duties at establishment. Ensures the organisation's governance structure adequately supports BCDR compliance.
Non-Executive DirectorsProvide independent scrutiny and hold the AEO to account for BCDR performance. Ensure BCDR is included on appropriate committee forward plans. Assure themselves that requirements are being met through annual assurance reporting. Given the Trust's position as a newly established organisation, NEDs should take an active role in supporting the development of BCDR capability.
Trust SecretaryActs as the operational lead for BCDR administration and compliance. Supports the AEO in maintaining BCDR documentation and records. Coordinates testing and review schedules. Ensures all BCDR documentation is accessible via an out-of-band location in the event that primary systems are unavailable. Maintains and tests escalation contact lists.
Accountable Emergency Officer (AEO)Has board-level authority and responsibility for ensuring the Trust's BCM arrangements comply with ISO 22301:2019 and the NHS England Business Continuity Management Toolkit. Ensures a Business Impact Analysis is conducted and reviewed regularly. Ensures BCPs and DR plans are developed, tested, and maintained. Provides assurance to the Board through annual BCDR reporting. At establishment, given the Trust's early stage of development, the AEO role will be fulfilled by the Chair unless formally delegated to a named director.
Technology and Digital LeadsWhere the Trust engages technical staff or contractors responsible for building or operating Trust systems, those individuals are responsible for implementing DR controls aligned to this policy, including backup regimes, version control, and cloud DR configuration. At establishment this responsibility sits with the programme team leads.
All staff and contractorsUnderstand and comply with this policy and related BCDR procedures. Store documents and data in approved locations in line with this policy. Report incidents and near-misses promptly through agreed escalation processes. Support the organisation's response to BCDR incidents when required.

8. Standards and practice

Context

The Trust will maintain BCDR arrangements that comply with the NHS Core Standards for EPRR and the requirements of the NHS Standard Contract. The Trust's BCM programme will align with ISO 22301:2019 and will use the NHS England Business Continuity Management Toolkit as a primary reference for methodology, templates, and good practice.

Business Impact Analysis

Before developing BCPs, the Trust must conduct a Business Impact Analysis (BIA) to identify and prioritise its critical functions, assess the consequences of disruption, and determine appropriate recovery objectives. The BIA will:

  • Identify all significant business functions carried out by or on behalf of the Trust
  • Determine the criticality of each function and the potential impact of disruption (financial, regulatory, reputational, patient safety)
  • Define Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs) for each critical function and supporting system
  • Identify dependencies, including people, systems, suppliers, and infrastructure

Business Continuity Plans

The Trust will develop and maintain Business Continuity Plans (BCPs) that:

  • Address the Trust's priority functions as identified through the BIA
  • Set out the minimum acceptable service level for each critical function during a disruption
  • Define the steps required to maintain or restore each critical function within the agreed RTO
  • Identify the staff, systems, and resources required
  • Are aligned to ISO 22301:2019 and the NHS England Business Continuity Management Toolkit
  • Are tested, reviewed, and updated at least annually, following a disruptive incident, or following significant organisational change

9. Disaster Recovery – approach

Context

The Trust's digital estate can be divided into three categories, each with a distinct DR approach. The Trust must maintain an up-to-date inventory of all systems in each category, documenting where artefacts live, how they are backed up, and how they would be recovered.

NHS England-provided systems

At establishment, the Trust operates within the NHS England computing environment and uses NHS England-provided platforms for the majority of its day-to-day operations. End user IT support is provided under a Memorandum of Understanding (MOU) between NHS England and Online NHS Trust, with North East Commissioning Support (NECS) as the primary delivery supplier (effective 1 June 2026, initial term to 31 March 2027).

The MOU covers the following service areas, all of which are relevant to the Trust's IT resilience baseline:

  • Service Desk (first-line support) – single point of contact for all IT incidents and requests, via telephone, self-service portal (ServiceNow), and email
  • Remote Support Services – 1.5-line and second-line remote engineer support for all end users
  • Logistics, Warehousing and Asset Management – device provisioning, Joiners/Movers/Leavers (JML) processes, hardware break/fix, and asset lifecycle management
  • Licensing Provision – ad-hoc licence procurement for non-Microsoft software
  • Project Support Call-Off Resourcing – flexible technical resource for project-based IT activities

The commitments established by the MOU for Online NHS Trust (Silver service tier) are:

MOU Silver tier service level commitments for Online NHS Trust
Service levelSilver tier commitment (Online NHS Trust)
Recovery Time Objective (RTO)4 hours
Recovery Point Objective (RPO)24 hours
Service availability99.50% (maximum 58 minutes downtime per month)
Priority 1 incident resolution4 hours
Priority 2 incident resolution8 hours
Service Desk hoursMonday–Friday 07:00–19:00 (excluding Bank Holidays)
Planned maintenance windowWednesday 18:00–20:00
MOU effective date1 June 2026
Initial termTo 31 March 2027

The Trust's obligations in respect of NHS England-provided and NECS-delivered systems are to:

  • Retain a copy of the MOU and any associated service schedules and use these as the primary reference for Online NHS Trust's IT DR commitments during the initial term
  • Satisfy itself that the contractual RTO (4 hours) and RPO (24 hours) are adequate for the Trust's critical functions that depend on end user computing, and document this assessment as part of the BIA
  • Identify any gaps between the MOU's DR provision and the Trust's own recovery needs, and agree supplementary controls with NHS England where necessary
  • Ensure critical Trust documents, policies, plans, and records held within NHS England systems (SharePoint, Teams, OneDrive) are accessible via at least one out-of-band location in the event those systems are unavailable
  • Monitor the monthly Service Review meetings between Online NHS Trust's nominated Service Lead and NHS England Service Delivery and escalate any material service degradation to the AEO
  • Maintain awareness of the MOU's exit provisions: Online NHS Trust must give 90 calendar days' written notice to exit the MOU or headline service lines before 31 March 2027; the Trust must treat any planned or anticipated exit from the MOU as a BCDR event requiring advance planning
  • Appoint an Online NHS Trust representative to the NHS England Corporate Operations Steering Committee as required under the MOU governance arrangements
  • Formally appoint a BCDR exit manager for the purposes of the MOU exit provisions within four months of the effective date (1 June 2026)

Trust-procured business systems (e.g. payroll, HR)

As the Trust procures its own business systems, it must ensure that DR requirements are embedded in the procurement and contract management process. For each newly procured system, the Trust will:

  • Define RTOs and RPOs as requirements before procurement and include them in the specification
  • Assess supplier DR capability as part of due diligence
  • Ensure contracts include explicit obligations on the supplier regarding availability, backup, recovery, and DR testing
  • Obtain and retain documentation of the supplier's DR arrangements, and verify these are tested regularly
  • Ensure that data held in supplier systems can be exported and retained independently where required for regulatory, legal, or continuity purposes

Trust-built systems and digital products

Where the Trust designs, builds, or operates bespoke digital services, it bears direct responsibility for the DR capability of those services. This is the area of highest BCDR complexity for the Trust and requires deliberate architectural and operational decisions to ensure resilience. The Trust will ensure that all systems it builds or operates:

  • Are designed with resilience in mind from the outset, including the use of appropriate cloud architecture patterns (e.g. multi-availability zone deployment, automated failover, infrastructure-as-code)
  • Have documented RTOs and RPOs that are built into the system design and tested regularly
  • Utilise version control for all code, configuration, and infrastructure definitions, with repositories hosted on an appropriate platform (e.g. GitHub or equivalent) and subject to access control and backup
  • Have a documented and tested backup and restoration regime for all data held within Trust-built systems
  • Align to the DR provisions offered by the relevant cloud provider (e.g. AWS) and leverage provider-native resilience capabilities where possible
  • Are subject to a DR test at least annually, or following any significant change to the system

The Trust will maintain a clear artefact register for all systems it builds or operates, documenting:

  • What artefacts exist (code, configuration, data, documentation)
  • Where each artefact resides
  • How each artefact is backed up or version-controlled
  • How each artefact would be recovered and by whom

10. Out-of-band

A fundamental requirement of effective BCDR is that the plans and procedures needed to respond to a disruption are themselves accessible when the systems they support may be unavailable. The Trust must ensure that its BCDR policy, BCPs, DR runbooks, key contact lists, and critical operational documents are stored in a manner that remains accessible even when primary systems (such as SharePoint or Teams) are unavailable. The Trust will:

  • Identify and document an out-of-band storage location for BCDR documentation. This must be a system or mechanism distinct from the primary platforms, such that a failure of NHS England's shared IT environment does not simultaneously render the BCDR documentation inaccessible
  • Ensure that the BCDR policy, BCPs, escalation contacts, and key operational procedures are maintained in up-to-date form in the out-of-band location
  • Review and update the out-of-band copies whenever substantive changes are made to the primary versions
  • Ensure that the AEO and Trust Secretary know how to access the out-of-band location and that this knowledge is not solely held by one individual

11. Risk management

The Trust will:

  • Maintain a BCDR risk register, integrated into the Trust's broader organisational risk register
  • Undertake risk assessments appropriate to its systems, services, and operating environment
  • Link BCDR risk management to the organisation's broader risk management framework and EPRR risk register
  • Review the BCDR risk register at least annually, or following a significant incident, exercise, or change in operating context

12. Supplier and contract management

Where the Trust relies on third-party suppliers or host-organisation arrangements for critical systems or services, it must ensure that BCDR obligations are understood, documented, and monitored. The AEO must satisfy themselves that supplier and MOU arrangements are adequate and that DR commitments are tested.

NHS England / NECS (end user computing and IT support)

The primary supplier arrangement for end user IT support is governed by the MOU between NHS England and Online NHS Trust. In addition to the obligations set out above, the Trust will:

  • Ensure the AEO receives and reviews the monthly service report produced by NHS England / NECS and raises any material service degradation as a BCDR risk
  • Participate in the quarterly Service Management Governance Board meetings as required by the MOU
  • Ensure that the MOU's exit provisions are factored into the Trust's BCDR planning: the Trust must not become so dependent on NHS England-provided IT services that an exit (with 90 days' notice) would itself constitute a BCDR event without an adequate transition plan
  • Develop and maintain an IT exit readiness plan before the MOU initial term expires (31 March 2027), documenting the steps required to transition IT support to an alternative provider or standalone arrangement; this plan should be held in the out-of-band document store
  • Ensure that all Online NHS Trust asset, licence, and service data held within the NECS ITSM (ServiceNow) tooling is exportable and that the Trust can retrieve its own data in the event of MOU termination

Other third-party suppliers

For all other third-party suppliers upon which the Trust's critical functions depend, the Trust will ensure that BCDR obligations are embedded in contracts and that compliance is monitored. The AEO must satisfy themselves that supplier DR arrangements are documented, adequate, and tested. For NHS England-provided services not covered by the MOU, the Trust will satisfy itself that NHS England's own supplier management arrangements are documented and adequate.

13. Training requirements

Context

Training is a fundamental element of BCDR preparedness. The Trust will ensure that all individuals with a BCDR role receive training that is appropriate, proportionate, and regularly refreshed. Training requirements will be informed by the NHS England Business Continuity Management Toolkit and will align with the EPRR training framework. Given the Trust's establishment phase, training and exercising activities will initially focus on awareness, governance understanding, supplier dependency management, and foundational resilience practices, with more mature role-specific capability developed progressively as the organisation's operational footprint expands.

Training principles

  • Training will be aligned to a Training Needs Analysis (TNA) developed for each role
  • Training will address both the individual's specific BCDR role and the broader organisational context
  • Individuals undertaking significant BCDR responsibilities should receive appropriate briefing, onboarding, or training relevant to their role as soon as reasonably practicable following appointment. Existing equivalent NHS England, supplier, or professional training and experience may be recognised during the Trust's establishment period.
  • Training records will be maintained and reported to the Board at least annually

Mandatory BCDR training

Mandatory BCDR training by role
Training topicApplicable rolesFrequency
BCDR Awareness / InductionAll staff and Board membersIncluded within onboarding and organisational induction arrangements during the establishment phase; refreshed periodically thereafter.
BCM Practitioner Training (aligned to NHS England Toolkit)AEO, Trust SecretaryOn appointment; refreshed every 3 years
DR Technical TrainingTechnology / digital leads and programme staff responsible for Trust-built systemsProvided as systems, platforms, and operational responsibilities mature and become operationally live.
NED BCDR Governance BriefingChair, NEDsOn appointment; annual update

14. Implementation and dissemination

The Trust will conduct regular tests and exercises to validate its BCDR arrangements. Tests must be planned, conducted, and documented in accordance with the NHS England Business Continuity Management Toolkit. The exercise schedule should be coordinated with the EPRR exercise programme.

Minimum exercise requirements

Minimum BCDR exercise and test requirements
Exercise / test typeMinimum frequencyPurpose
Document accessibility check (out-of-band store)Every 6 monthsConfirms that BCDR documentation is accessible via the out-of-band location and is up to date
Table-top exercise (BCM)Every 12 monthsValidates BCPs and develops staff knowledge through scenario-based discussion
System backup restoration testEvery 12 months per system (or following significant change)Confirms that backups for Trust-procured and Trust-built systems can be successfully restored within the defined RTO and RPO
DR failover test (Trust-built systems)Every 12 months (or following significant architectural change)Tests the end-to-end failover and recovery capability for Trust-built digital services
Full BCP test (live play)Every 3 yearsLive test of the Trust's ability to maintain priority activities during a simulated disruptive incident

Exercise records

All tests and exercises must be documented. Records must include:

  • Date, type, and participants
  • Scenario or test parameters used
  • Outcomes, including any failures or degraded performance observed
  • Lessons identified and an action plan with named owners and timescales

15. Incident response procedures

Declaring a BCDR incident

A BCDR incident should be declared when a disruptive event has caused, or has the potential to cause, the Trust's activities to fall below minimum acceptable service levels. Upon declaration:

  • The AEO must be notified immediately
  • The AEO will assess the incident, determine whether BCPs should be activated, and identify any DR actions required
  • The incident must be logged from the point of declaration
  • NHS England and the relevant ICB must be notified where required under the EPRR Policy escalation procedures

Activation of BCDR plans

Where the AEO determines that BCPs should be activated, the Trust Secretary will coordinate the implementation of the relevant plan(s). BCDR plans must be accessible via the out-of-band document store in the event that primary systems are unavailable. All activation decisions and actions must be logged.

Upon activation, the Trust Secretary will immediately initiate a communication cascade to ensure that all relevant individuals are informed and can fulfil their responsibilities. As a minimum, this cascade must reach:

  • All Board members, including the Chair and Non-Executive Directors
  • All staff and contractors with identified roles in the relevant BCP
  • Technology and digital leads where DR actions are required
  • Key suppliers and partner organisations whose cooperation is required for the Trust's response or recovery

The communication cascade must use contact information held in the out-of-band contact list maintained by the Trust Secretary, to ensure it remains operable if primary systems are unavailable. The Trust Secretary will maintain a log of all notifications made, including the time, method, and recipient of each communication.

Response to third-party BCP invocation

Given the Trust's dependency on NHS England-provided infrastructure, NECS-delivered IT support, and other critical suppliers, a disruption originating within a partner or supplier organisation is a credible and potentially high-impact scenario. The Trust must be prepared to respond promptly and effectively when a third party invokes its own business continuity or disaster recovery arrangements.

The Trust will ensure, through its supplier contracts and the MOU governance arrangements, that it receives prompt notification if a key supplier or partner organisation invokes its BCP or declares a major incident that may affect services provided to the Trust. The AEO is the Trust's designated point of contact for such notifications. Where notification is received by any other member of staff or Board, it must be escalated to the AEO immediately.

Upon receiving notification that a third party has invoked its BCP, the AEO will assess the actual or anticipated impact on the Trust's critical functions. This assessment will consider:

  • Which Trust systems, services, or functions are affected or at risk
  • The severity and anticipated duration of the disruption
  • Whether the Trust's activities are likely to fall, or have already fallen, below minimum acceptable service levels
  • The adequacy of the third party's own recovery arrangements and the estimated time to restoration

Where the AEO determines that the Trust's critical functions are materially affected, the Trust's own BCPs will be activated, regardless of whether the disruption originated internally or externally. The Trust will not assume that a supplier's or partner's own response will be sufficient to protect Trust operations without independent assessment.

16. Recovery

Recovery from a BCDR incident should begin at the earliest opportunity and run in parallel with the immediate response. The AEO will lead recovery, supported by the Trust Secretary and relevant technical leads. Recovery is not complete until:

  • All affected systems and functions have been restored to normal operating levels
  • Any data loss or integrity issues have been identified, resolved, and documented
  • A post-incident debrief has been conducted in accordance with the debriefing section of this policy

17. Business continuity and organisational resilience

All BCDR activities, decisions, and actions must be recorded in a manner that supports accountability, learning, and, if necessary, legal scrutiny. Day-to-day duties of care, candour, and confidentiality continue to apply during incident response. At establishment this will be reported to the Trust Board.

18. Record retention

The Trust will maintain BCDR records in accordance with the retention schedule consistent with NHS England guidance. All records must be stored securely and in a manner that allows them to be retrieved promptly.

BCDR record retention schedule
CategoryExamplesMinimum retentionFinal action
BCDR Plans and ProceduresBCPs, DR runbooks, system DR documentation, artefact registersLife of organisation plus 6 yearsReview, archive or destroy under confidential conditions
Business Impact Analysis and Risk AssessmentsBIA reports, BCDR risk registerLife of organisation plus 6 yearsReview, archive or destroy under confidential conditions
BCDR IncidentsIncident logs, decision records, recovery actions20 yearsReview, archive or destroy under confidential conditions
Tests and ExercisesExercise records, restoration test results, debrief reports, action plans10 yearsReview, archive or destroy under confidential conditions
Supplier DR DocumentationSupplier BCDR commitments, test evidence, contract extracts10 years (or duration of contract plus 3 years)Review, archive or destroy under confidential conditions

19. Debriefing

Following any BCDR incident, test, or exercise, the Trust will conduct structured debriefs to identify and act on lessons. Appropriately trained staff must facilitate debriefs.

Debrief schedule

  • Hot debrief – immediately after the incident or test, and within 48 hours of stand-down
  • Cold/structured debrief – within 28 days post-incident
  • Post-incident report – within four weeks of the debrief

Debrief outputs

Post-incident reports must be supported by:

  • An action plan with timescales and accountable owners
  • Recommendations to update BCPs, DR documentation, or training
  • A mechanism for sharing lessons with the local ICS, NHS England, and relevant partners

20. Assurance and governance

The Trust will conduct an annual review of its BCDR arrangements, aligned with the NHS Core Standards for EPRR assurance process. As a newly established Trust, the first annual assurance will provide a baseline assessment of BCDR compliance and maturity, identifying areas for development as well as areas of existing strength. The Trust is committed to transparency in this process and will use it to drive progressive improvement year on year. This requires:

  • Completion of an annual self-assessment against this policy and ISO 22301:2019
  • Presentation of assurance evidence to the Board
  • Issuance of a Statement of BCDR Conformity by the Board
  • Provision of all information requested by NHS England for the purposes of monitoring compliance

21. Board reporting

The AEO will present an annual BCDR assurance report to the Board. This report will cover:

  • Compliance status against this policy and ISO 22301:2019
  • Status of all system categories (NHS England-provided, procured, Trust-built) against defined RTOs and RPOs
  • Test and exercise activity completed and outcomes
  • BCDR incidents and significant near-misses
  • Lessons identified and actions taken
  • Planned BCDR activity for the coming year, including maturity development priorities

22. NED oversight

BCDR must be included on the forward plan of the relevant Board committee. Non-Executive Directors must assure themselves, through annual reporting and scrutiny of the AEO, that the Trust's BCDR requirements are being met. Given the Trust's position as a newly established organisation, NEDs should take an active role in supporting the development of BCDR capability and in providing constructive challenge as the maturity programme progresses.

23. Implementation

This policy will be implemented through a sequenced programme of foundational actions, reflecting the Trust's establishment phase. Early priorities include confirming the AEO designation and communicating BCDR accountabilities to the Board, identifying and documenting an out-of-band storage location for BCDR documentation, obtaining and filing the MOU and associated service schedules, conducting the Business Impact Analysis, developing the BCDR risk register and Business Continuity Plans, and developing an IT exit readiness plan ahead of the MOU term expiry. DR arrangements and artefact registers will be established for each newly procured business system and Trust-built system as they go live.

This policy will be reviewed and updated no later than every three years, or sooner in the event of changes in legislation, NHS guidance, the organisation's structure or digital estate, or lessons identified from incidents or exercises. Given the Trust's position as a newly established organisation, an early review is anticipated within 12 months of establishment.

24. Dissemination and communication

Dissemination of this policy is the responsibility of the Trust Secretary, who will ensure:

  • The policy is published on the Trust intranet within 7 days of ratification
  • All Board members and staff are notified of the policy and their obligations under it
  • The policy is included in induction materials for new Board members and staff
  • A copy is held in the out-of-band document store at all times
  • The policy is available to contractors and sub-contractors where relevant to their role

25. Monitoring and audit

BCDR monitoring criteria and methods
Monitoring criterionMonitoring methodFrequency / lead / where reported
Currency and completeness of BIA and BCPsDocument control review; post-exercise reviewAnnually – AEO – Board
Accessibility of out-of-band BCDR documentationDocument accessibility checkSix-monthly – Trust Secretary – AEO
MOU service level performance (NECS / NHS England)Review of NHS England monthly service reports; attendance at quarterly Service Management Governance BoardMonthly service report review – Online NHS Trust Service Lead – AEO; quarterly governance – AEO – Board
MOU exit readiness plan currencyDocument review; check against MOU term expiry dateSix-monthly – Trust Secretary – AEO; escalated if MOU extension uncertain
Completion of system backup restoration testsTest records; DR test logsAnnually per system – technical leads – AEO
DR documentation for procured and Trust-built systemsArtefact register review; system DR documentation reviewAnnually – AEO – Board
Completion of BCDR trainingTraining records; TNA reviewAnnually – Trust Secretary – Board
Completion of required exercises and testsExercise log; debrief reportsAnnually – Trust Secretary – Board
BCDR incident and near-miss reportingReview of incident log; debrief reportsFollowing each incident; annually in aggregate – AEO – Board
Supplier DR complianceContract compliance monitoring; annual review of supplier DR documentation; MOU annual review (by 1 April 2027)Annually – AEO – Board

Lessons learnt from non-compliance will be documented and fed back to all relevant staff. An early review of this policy may be requested by the monitoring committee at any time.

26. Equality and health inequalities

Promoting equality and addressing health inequalities are central to NHS values. The Trust will, throughout the development and implementation of this policy and all related BCDR plans:

  • Give due regard to the need to eliminate discrimination, harassment, and victimisation, and to advance equality of opportunity, in accordance with the Equality Act 2010
  • Give regard to the need to reduce inequalities between patients in access to, and outcomes from, healthcare services
  • Ensure that BCDR arrangements do not inadvertently disadvantage any group with a protected characteristic

Equality impact assessment

The author of this policy has undertaken an equality impact assessment and concluded that there is no negative impact on any of the protected characteristics. The policy applies to all Trust activities and to all staff working for or on behalf of the Trust. Following consultation with key groups, no negative impact has been identified for any protected characteristic.

Equality impact assessment by protected characteristic
Protected characteristicNegative impact?Rationale
AgeNoNo negative impact identified. The policy applies equally to all age groups.
SexNoNo negative impact identified. The policy applies equally to all genders.
Gender reassignmentNoNo provisions in the policy differentiate on the basis of gender identity or reassignment.
RaceNoNo negative impact identified. The policy does not introduce race-based criteria.
DisabilityNoNo negative impact. The policy supports reasonable adjustments.
Religion or beliefNoThe policy is neutral regarding religion or belief.
Marriage and civil partnershipNoNo provisions relate to marital or partnership status.
Pregnancy and maternityNoNo negative impact on these staff members.
Sexual orientationNoThe policy is neutral regarding sexual orientation.