Where does the Business Continuity Management team sit within your organization?  Is it acceptable for it to sit under the Chief Audit Executive's org?

514 views2 Comments
Sort By:
Oldest
Director of Finance2 months ago
Business Continuity sits with IT in our current org, but is realistically everybody's responsibility.  IT often inherits it because so many key processes depend on technology, but it is still a joint effort.  Having it roll to Chief Audit Executive makes sense from a "raising the risk profile" perspective, but may create disconnects and confusion if the people leading the effort to restore operations are not fully embedded within the relevant systems and processes (and likely far more accountable for making sure the business goes on than checking the business continuity box on an audit plan).
lock icon

Please join or sign in to view more content.

By joining the Peer Community, you'll get:

  • Peer Discussions and Polls
  • One-Minute Insights
  • Connect with like-minded individuals
Vice President - Internal Audit and Enterprise Risk Management in Healthcare and Biotech2 months ago
Business Continuity sits with IT at my company, as part of the CISO's organization.  There is direct linkage to the DR function (also in IT) and it also serves as the central coordinating function for the cross-functional crisis management team.

Regarding functional alignment with the Chief Audit Executive, I would typically avoid in cases where the CAE only has responsibility for IA.  Aligning BC under the CAE in this model would likely create potential independence concerns, at least in appearance.

In organizations where the CAE also has responsibility for broader risk-oriented functions (such as ERM), I think BC can effectively roll up under one of those functions, if structured appropriately.  The independence concerns can be addressed by resourcing and managing related audits appropriately, including through the use of co-sourced audits.

Content you might like

VP of Global IT and Cybersecurity in Manufacturing6 years ago
Have clear business requirements up front, make sure the proposal includes items such as scope, timeline, cost, resources.
Read More Comments
22.1k views3 Upvotes28 Comments

Increase47%

Stay Flat45%

Decrease6%

View Results
2.5k views4 Upvotes

0% ( No hike)3%

0-2% 30%

2-5%41%

5-7%9%

7-10%2%

10-14%11%

More than 15%1%

Switched job recently1%

Others

View Results
1.2k views1 Upvote