Business Continuity Planning

At 2Oaks Consulting, we provide comprehensive Business Continuity Management System (BCMS) Strategy and Adoption services that enable your organization to build resilience and maintain critical operations through any disruption. Our approach ensures that continuity planning becomes embedded in your organization's culture and aligns with your strategic objectives and regulatory requirements.

Key Components of Our Service

Partner with 2Oaks to build operational resilience capabilities that protect enterprise value, demonstrate regulatory compliance, and enable confident growth through any disruption.

FAQs

We already have a business continuity plan. Isn't that enough? 

Most disruptions seem to start with our vendors. How do we cover third-party resilience? 

Having a plan and being able to prove it works are two different things, and that gap is exactly what regulators now test. Operational resilience asks you to show that you can keep delivering critical operations through a severe disruption, with those operations mapped, tolerances set, dependencies traced, and scenarios actually exercised. A binder of documents that has not been tested rarely survives that scrutiny. The fastest way to find out where you stand is our free Business Resilience Assessment, which takes about 20 minutes and surfaces the gaps a supervisor would likely raise first. 


What is OSFI E-21, and what does it require us to do by when? 

OSFI's Guideline E-21 sets operational resilience expectations for federally regulated financial institutions, and it moves the bar from having a business continuity plan to running a tested program. Full adherence is required by September 1, 2026, and scenario testing across all critical operations is expected by September 1, 2027 (the Section 4 milestone passed in September 2025). In practice it asks four things: identify your critical operations end to end, set a tolerance for disruption for each one, map the dependencies that hold them up (including third parties), and scenario-test against those tolerances. We break down the questions institutions are asking, and the ones they tend to avoid, in OSFI E-21: The Questions Most Canadian Banks and Credit Unions Are Asking


We operate in the US. What's the equivalent, and when is it due? 

There's no deadline, and that's the problem. The expectation went live in 2019, when the FFIEC replaced its Business Continuity Planning booklet with the Business Continuity Management booklet. The rename was the point: from having a plan to running a tested program. Credit unions add NCUA Parts 748 and 749 on top. 

It asks the same four things E-21 does. Identify your critical operations and vital member services. Set recovery objectives you can defend. Map the dependencies behind them, third parties included. Then exercise and test, which FFIEC treats as two separate activities and most institutions report as one. 

What the US has instead of a deadline is clocks already running. Banks report a notification incident within 36 hours. Credit unions report a cyber incident within 72, including one a vendor reports to you. Take our free Business Resilience Assessment to see where you stand. 


We've always used the FFIEC CAT. Is that still valid? 

No. The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025 and didn't name a successor, pointing institutions to NIST CSF 2.0, the CRI Profile, the CIS Controls, and CISA's performance goals instead. If your last documented maturity baseline was a CAT self-assessment, you're reporting to your board against a framework that no longer exists 


Do we need ISO 22301 certification? 


Our plan is a few years old and our core system has changed. Do we rewrite it? 

Not necessarily. We use ISO 22301 as the framework to structure your business continuity management system, because it organizes the program well, but formal certification is a separate and optional step. What a regulator actually wants to see is evidence that the program works: critical operations identified, tolerances set, dependencies mapped, and tests run with the results acted on. We align the management system to the standard and to your regulatory obligations, then help you decide whether certification is worth pursuing for your situation. Our partners have run operations and resilience inside financial institutions, so the framework is applied to how your organization actually works, which you can see on Meet Our Team

Re-baseline it rather than rewrite it. A fresh document that does not reflect your current critical operations, dependencies, and tolerances is just a new version of the same problem. The practical sequence is to confirm what your critical operations are today, map what they actually depend on now (including the systems added since the plan was written), set tolerances against current business reality, and only then update the response procedures. This matters most right after a core go-live, when the plan is often stale at exactly the moment the risk is highest, which Derrick explains in this short video. 


How often should we test our plans, and what actually counts as a test? 

Testing is where the evidence gets created, so it is the part regulators most want to see. Start with tabletop exercises on a real critical operation, with the right people in the room and an action list that gets tracked afterward, then build up to simulations and live-systems testing as the program matures. Under E-21, scenario testing needs to reach all critical operations by September 2027, and a test that surfaces nothing to fix usually means the scenario was not hard enough. As Chris puts it, real readiness comes from plans embedded in daily operations rather than a document on a shelf, which he covers in this video


Your third-party resilience is now part of your own resilience, because most disruptions to critical operations originate at third parties and their supply chains. That means pressing your critical vendors for their own continuity plans, their test results, and their concentration risk on major cloud providers, and treating those as regulatory expectations rather than procurement niceties. It also means having a credible exit plan for critical vendors, even one that acknowledges a multi-year transition, since the absence of a plan is itself a finding. We walk through the third-party angle, and how E-21 works alongside OSFI B-10 and B-13, in our E-21 readiness piece

Explore Other Services