Back to Blog
Business Continuity

Gap assessment template: How to audit your BCM program

Gap assessment template: How to audit your BCM program

Change Healthcare went offline in February 2024 after a ransomware attack hit its parent UnitedHealth Group, disrupting prescription processing for thousands of pharmacies across the United States. Post-incident analysis consistently pointed to the same root problem: nobody had formally assessed whether the continuity controls matched the organization's actual risk profile. A gap assessment would not have prevented the breach, but it almost certainly would have surfaced the single points of failure that turned a contained incident into a cascading crisis.

This article gives you a working gap assessment template for BCM programs, explains how to score it, and shows what to do with the results.

What is a gap assessment template?

A BCM gap assessment template is a structured worksheet that compares your current program state against a chosen standard or framework , typically ISO 22301, DORA, or NIST SP 800-34 , and assigns maturity scores to each control domain. The output is a prioritized list of deficiencies with enough context to build a remediation roadmap.

Gap assessment vs gap analysis: a quick distinction

The two terms are often used interchangeably, but they carry different weights in practice. A gap *analysis* is the broader strategic exercise: where do we want to be, and where are we now? A gap *assessment* is the audit mechanism that generates the evidence , the checklists, interviews, document reviews, and scoring matrices that feed the analysis.

For BCM practitioners, the assessment is the hard work. The analysis is the slide deck.

The eight domains every BCM gap assessment should cover

Most recognized frameworks organize BCM requirements into clusters. The table below maps those clusters to ISO 22301:2019 clauses and assigns a suggested weighting for a balanced scorecard.

DomainISO 22301 clauseSuggested weight
Governance and policy4, 515%
Business impact analysis8.220%
Risk assessment6.115%
Continuity strategy8.315%
Plans and procedures8.415%
Exercises and testing8.510%
Communication and warning8.4.45%
Continual improvement105%

Weightings should shift based on regulatory context. Under DORA, ICT-related continuity testing carries significantly more weight than generic governance documentation.

How to score each domain

Use a 0-4 maturity scale. It maps cleanly to plain language that non-technical stakeholders can read without a legend.

  • 0, Not present: No evidence the control exists.
  • 1, Ad hoc: Activity happens, but informally and inconsistently.
  • 2, Defined: Documented policy or procedure exists; not always followed.
  • 3, Managed: Process is followed consistently; outcomes are measured.
  • 4, Optimized: Process is reviewed, improved, and integrated with related functions.

Score each domain by averaging its sub-control scores. Weight the domain scores as indicated in the table above. The composite score out of 4.0 is your program maturity index.

A score below 2.0 indicates a program that would likely fail during a real incident. Scores between 2.0 and 3.0 are common for mid-market organizations that have documented plans but inconsistent testing. Scores above 3.5 are rare and should be verified against actual exercise results rather than self-attestation.

The template structure, section by section

Section 1: governance and policy

Start here because everything else depends on it. Collect the following documents before the assessment begins: the business continuity policy, the BCM scope statement, evidence of executive sponsorship (board minutes, signed policy statements), and the program's last formal review date.

Key questions:

  • Is the BCM policy formally approved and version-controlled?
  • Does scope explicitly include critical third parties?
  • Is there a named BCM owner with defined authority?
  • When was the policy last reviewed? Was that review documented?

A policy that has not been reviewed since 2021 scores no higher than 2, regardless of how well-written it is.

Section 2: business impact analysis

The BIA is the analytical foundation of the entire program. Assess whether it exists in a current, validated form , not whether it was completed once three years ago.

Key questions:

  • Does the BIA cover all in-scope business functions?
  • Are RTOs and RPOs defined for each critical process?
  • Were BIA inputs validated with process owners, not just IT?
  • Has the BIA been updated to reflect organizational changes in the last 12 months?

The CrowdStrike Falcon Channel File 291 incident in July 2024 affected an estimated 8.5 million Windows devices globally. Organizations that had mapped their critical process dependencies in a current BIA recovered faster because they already knew which systems were load-bearing , and which were not.

Section 3: risk assessment

Review the business continuity risk assessment for methodology consistency, threat coverage, and linkage to continuity strategies. Flag any risk register that does not include supply chain and cyber scenarios given the threat landscape since 2023.

Section 4: continuity strategy

For each critical process, confirm that a documented recovery strategy exists and that the strategy has been validated as achievable. Common failure: strategies that assume resources (staff, systems, facilities) that are simultaneously unavailable during the disruption scenario they are meant to address.

Read more about business continuity strategies

Section 5: plans and procedures

Review the business continuity plan documents for completeness, accessibility, and version control. Check that plans exist in formats usable during an actual incident , not just as 80-page PDFs stored on a shared drive that requires VPN access.

Key sub-controls:

  • Crisis communication procedures documented and tested
  • Recovery procedures are step-by-step, not narrative
  • Plans reference current contact lists (reviewed in last 6 months)
  • IT recovery procedures align with the IT disaster recovery plan

Section 6: exercises and testing

This is where most programs score lowest. Document review and self-assessment almost always overstate readiness; exercise results almost always reveal gaps.

Key questions:

  • Has the program conducted at least one tabletop exercise in the last 12 months?
  • Are exercise results formally documented with action items?
  • Have technical recovery procedures been tested end-to-end?
  • Is there a formal exercise program with a multi-year schedule?

Section 7: communication and warning

Assess whether notification trees, escalation thresholds, and public communication protocols are documented, owned, and tested. Pay particular attention to third-party and regulatory notification obligations, which vary significantly under DORA, FCA requirements, and APRA CPS 230.

Read more about crisis communication best practice

Section 8: continual improvement

Check whether the program feeds lessons from incidents, near-misses, and exercises back into documented improvements. A program without a formal improvement loop will degrade over time even if it scores well today.

What to do with your scores

Once scoring is complete, plot domain scores on a radar chart. Domains scoring below 2.0 become immediate remediation priorities. Domains between 2.0 and 3.0 go onto a 90-day improvement plan. Domains above 3.0 move to a 12-month maintenance schedule.

Present findings to senior leadership using the weighted composite score, the radar chart, and three to five specific findings with remediation owners and target dates. Avoid presenting raw sub-control scores to executive audiences , the detail obscures the signal.

Link remediation milestones to your existing BCM program management cycle so improvements are tracked rather than aspirational.

Common gaps that assessments repeatedly surface

After running assessments across organizations of different sizes, a handful of deficiencies appear with notable consistency:

  1. BIAs that have not been updated after restructuring, acquisitions, or cloud migrations
  2. Recovery strategies that depend on a single vendor with no documented alternative
  3. Plans stored in systems that are themselves unavailable during a disruption
  4. Exercise programs that test only the scenarios that are expected to go well
  5. No formal mechanism for incorporating lessons from industry incidents (the Change Healthcare or CrowdStrike events, for example) into the organization's own risk assumptions

For the third point specifically , this is not a paperwork problem, it is an architecture problem. Fixing it requires decisions at the infrastructure level, not just the BCM team.

Linking the gap assessment to broader program governance

A standalone gap assessment is a point-in-time artifact. Its value multiplies when it feeds into a formal BCM maturity benchmark and when findings are tracked through to verified closure rather than self-reported completion.

For organizations subject to DORA or APRA CPS 230, the gap assessment also serves as evidence of due diligence during regulatory examination. Document the methodology, the assessors involved, and the evidence reviewed for each domain score.

If the assessment reveals significant IT recovery gaps, route those findings to the IT crisis management function as well as the BCM owner. Siloed remediation is one of the fastest ways to close gaps on paper while leaving actual exposure unchanged.

Discover how Fortiv's business continuity management solutions help teams move from assessment findings to verified, audit-ready program maturity →

Frequently asked questions

Learn more

See first-hand what AI-native resilience looks like

Fortiv
© Fortiv 2026Legal and Privacy