Business Continuity & Resilience · BC-Q10

Question: Are critical suppliers and partners included in business continuity and recovery planning?

Why This Matters

Continuity depends on external partners as much as internal readiness. Engaging suppliers ensures end-to-end resilience.

Maturity

0 — Unaware
No supplier continuity considerations.
1 — Ad Hoc
Vendors contacted only during incidents.
2 — Defined
Critical vendors identified with contact details.
3 — Managed
Supplier continuity requirements added to contracts.
4 — Integrated
Joint recovery testing and BCP alignment performed.
5 — Optimized
Continuous joint resilience monitoring and assurance.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |List critical suppliers for key processes. | | 1 → 2 |Add them to continuity contact list. | | 2 → 3 |Include continuity obligations in contracts. | | 3 → 4 |Run joint recovery drills. | | 4 → 5 |Establish continuous resilience scorecard. |

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Tracking | Airtable | Supplier BCP matrix | | Collaboration | Nextcloud | Document sharing | | Dashboards | Metabase | Test participation rate |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO 22301 | 8.4 / 8.5 | | ISO 27001 | A.5.19 | | NIST CSF 2.0 | ID.SC / RS.RP | | NIRMATA Mapping | BC-Q10 ensures continuity dependencies include suppliers. |