Business Continuity Planning (BCP) in Indian Banking
A complete, exam-ready guide to BCP & Disaster Recovery for banks — key concepts (RTO, RPO, BIA), the BCP lifecycle, DR site types, testing methods, and the latest RBI framework (IT Governance Master Direction, 2023) — with tap-to-reveal MCQs.
1 What is Business Continuity Planning?
Business Continuity Planning (BCP) is the process of creating a plan to ensure that a bank’s critical business functions continue during and after a disruption — such as a natural disaster, cyber-attack, power failure or pandemic — with minimum loss to customers and the bank.
For banks, BCP is part of operational risk management. Because banks handle payments, deposits and public money, even a few hours of downtime can damage customer trust and financial stability — so BCP is a regulatory requirement, not a choice.
2 Must-Know Terms
3 BCP vs DR vs BIA
| Basis | BCP | Disaster Recovery (DR) |
|---|---|---|
| Scope | Whole business (people, processes, systems) | Mainly IT systems, applications & data |
| Goal | Keep critical functions running | Restore IT after a disaster |
| Relationship | Broader plan | A subset of BCP |
| Focus | Continuity & resilience | Technical recovery |
4 Objectives of BCP
- Ensure continuity of critical banking services (payments, ATMs, core banking, internet/mobile banking).
- Minimise financial loss and reputational damage.
- Protect customer data and assets.
- Enable quick recovery within agreed RTO/RPO targets.
- Meet regulatory (RBI) and legal obligations.
- Maintain public confidence in the banking system.
5 BCP Lifecycle (Phases)
- Risk Assessment: identify threats (natural, technical, man-made) and vulnerabilities.
- Business Impact Analysis (BIA): find critical functions, set RTO & RPO.
- Strategy Development: decide recovery strategies (DR site, backups, alternate staff/locations).
- Plan Development: document the BCP & DR plan, roles and escalation steps.
- Testing & Drills: test the plan regularly to confirm it works.
- Maintenance, Training & Review: update the plan and train staff (Board reviews at least yearly).
6 RTO vs RPO (Most Asked!)
| Basis | RTO (Recovery Time Objective) | RPO (Recovery Point Objective) |
|---|---|---|
| Measures | Maximum acceptable downtime to restore a system | Maximum acceptable data loss (in time) |
| Question it answers | “How fast must we recover?” | “How much data can we afford to lose?” |
| Decides | Speed of recovery & DR-site type | Frequency of data backup/replication |
| Direction in time | Looks forward from the disaster | Looks backward to the last good backup |
7 Types of Threats / Disasters
| Category | Examples |
|---|---|
| Natural | Floods, earthquakes, cyclones, pandemics (e.g. COVID-19) |
| Technical | Hardware/software failure, network outage, power failure, data-centre fire |
| Man-made / Cyber | Cyber-attacks, ransomware, fraud, terrorism, sabotage, human error |
8 Disaster Recovery (DR) Site Types
| DR Site | Readiness | Recovery Time | Cost |
|---|---|---|---|
| Hot Site | Fully equipped, data replicated in real time | Very fast (lowest RTO) | Highest |
| Warm Site | Partly equipped; data needs restoring | Moderate | Medium |
| Cold Site | Only space, power, cooling; set up after disaster | Slow (highest RTO) | Lowest |
Near DR vs Far DR
- Near-site DR: located close to the Data Centre; uses synchronous replication for zero/near-zero data loss.
- Far-site DR: located far away (different seismic/flood zone); uses asynchronous replication to survive regional disasters.
- Many large banks maintain DC + DR, and often a third Near-line site for RPO = 0 (zero data loss).
9 BCP/DR Testing Methods
Testing is arranged from least disruptive to most realistic:
| Test | What Happens |
|---|---|
| Checklist / Desk Check | Review the BCP documents for completeness. |
| Structured Walkthrough / Tabletop | Team discusses roles and steps in a meeting. |
| Simulation | A disaster scenario is simulated to test the response. |
| Parallel Test | Recovery systems run alongside live systems — no disruption to production. |
| Full Interruption Test | Live systems are actually shut down and switched to DR — most realistic, most risky. |
10 RBI Guidelines on BCP (India)
Current framework — IT Governance Master Direction, 2023
- Full name: RBI (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023.
- Notified on 7 November 2023; effective from 1 April 2024.
- Chapter V deals specifically with Business Continuity and Disaster Recovery Management.
- Requires a Board-approved BCP & DR Policy, reviewed at least annually.
- Mandates periodic DR drills, regular data backup, and checking the integrity of backup data.
- BCP/DR is one of the five focus areas of IT governance (along with strategic alignment, risk, resource and performance management).
- A Board-level IT Strategy Committee (ITSC) oversees IT governance and meets at least quarterly.
- Applies to banks (excl. RRBs), Small Finance Banks, Payments Banks, large NBFCs, Credit Information Companies and AIFIs (EXIM, NABARD, NaBFID, NHB, SIDBI).
11 Relevant International Standards
12 Practice MCQs (Tap to Reveal Answers)
A mix of previously-asked and high-probability questions. Attempt first, then tap to check.
Q1In BCP, RTO stands for:
- (a) Recovery Time Objective
- (b) Real Time Operation
- (c) Recovery Test Order
- (d) Restart Time Option
Tap to reveal answer
Q2RPO (Recovery Point Objective) measures the maximum acceptable:
- (a) Downtime
- (b) Data loss
- (c) Recovery cost
- (d) Staff strength
Tap to reveal answer
Q3A Business Impact Analysis (BIA) is mainly used to:
- (a) Market new products
- (b) Identify critical functions and set RTO/RPO
- (c) Recruit staff
- (d) Audit accounts
Tap to reveal answer
Q4Which DR site is fully equipped and can take over almost immediately?
- (a) Cold site
- (b) Warm site
- (c) Hot site
- (d) Mobile site
Tap to reveal answer
Q5Disaster Recovery (DR) is best described as:
- (a) Larger than BCP
- (b) Unrelated to BCP
- (c) A subset of BCP focused on IT recovery
- (d) Same as marketing
Tap to reveal answer
Q6The RBI (IT Governance, Risk, Controls and Assurance Practices) Directions, 2023 came into effect from:
- (a) 1 April 2024
- (b) 1 January 2023
- (c) 7 November 2023
- (d) 1 April 2023
Tap to reveal answer
Q7Who is responsible for approving a bank’s BCP/DR policy?
- (a) Branch Manager
- (b) Board of Directors
- (c) Auditor
- (d) RBI Governor
Tap to reveal answer
Q8The international standard for Business Continuity Management Systems is:
- (a) ISO 9001
- (b) ISO 22301
- (c) ISO 14001
- (d) ISO 27001
Tap to reveal answer
Q9An RPO of zero means:
- (a) No downtime allowed
- (b) No data loss is tolerated
- (c) No recovery needed
- (d) No backups required
Tap to reveal answer
Q10Which BCP test is the most realistic but also the most disruptive?
- (a) Checklist test
- (b) Walkthrough
- (c) Parallel test
- (d) Full interruption test
Tap to reveal answer
Q11In banking IT, “DC” and “DR” stand for:
- (a) Direct Credit / Direct Recovery
- (b) Data Centre / Disaster Recovery
- (c) Demand Cheque / Demand Recovery
- (d) Digital Currency / Digital Recovery
Tap to reveal answer
Q12BCP is primarily a part of which type of risk management in banks?
- (a) Credit risk
- (b) Market risk
- (c) Operational risk
- (d) Liquidity risk
Tap to reveal answer
Q13Which committee oversees IT governance (including BCP/DR) under the RBI 2023 Direction?
- (a) Audit Committee only
- (b) IT Strategy Committee (ITSC)
- (c) ALCO
- (d) Nomination Committee
Tap to reveal answer
Q14The earlier (2011) RBI guidance on Information Security, Technology Risk and Cyber Frauds was given by which working group?
- (a) Nachiket Mor Committee
- (b) G. Gopalakrishna Working Group
- (c) Tarapore Committee
- (d) Damodaran Committee
Tap to reveal answer
Q15A test where recovery systems run alongside live production without disrupting it is called a:
- (a) Parallel test
- (b) Cold test
- (c) Full interruption test
- (d) Checklist test
Tap to reveal answer
Q16The COVID-19 pandemic is an example of which category of BCP threat?
- (a) Technical
- (b) Cyber-attack
- (c) Natural
- (d) Financial fraud
