---
title: "Answer an RFP business continuity question beyond IT recovery"
description: "Explain how priority work continues through disruption, with tested people and supplier arrangements, bounded reduced service and a controlled return."
canonical: "https://zephior.com/insights/answer-an-rfp-business-continuity-question"
last-updated: 2026-09-05
---

# Answer an RFP business continuity question beyond IT recovery

> Explain how priority work continues through disruption, with tested people and supplier arrangements, bounded reduced service and a controlled return.

By [Tony Kim](https://zephior.com/authors/tony-kim). Published 2026-09-05; updated 2026-09-05. 16 minute read.

## Definition

A business continuity RFP response explains which customer work will continue during disruption, at what level, for how long and under whose authority. Build it around a service continuity card linking priority activities to people, premises, information, suppliers, reduced operating methods, activation, evidence and return criteria. System recovery is one dependency in that account. A restored application does not prove that staff can deliver the service or that deferred work has been resolved.

## Problem

The fictional Fenbrook venue-booking service receives 120 requests on a normal working day. Its application remains available when its main office cannot be used, but half the trained staff cannot reach the alternate workplace. The overflow supplier uses the same building access service, and the approved decision-maker is absent. The tender draft says that cloud hosting and daily backups ensure uninterrupted service. Neither explains who can process a booking, how much work will accumulate or when another operating decision becomes necessary.

## Point of view

Follow the customer outcome through the disruption. Separate the level the business needs, the arrangement designed to provide it, the capability demonstrated in a particular exercise and the commitment offered to the buyer. Test whether alternatives survive the same event. A credible answer makes reduced capacity and remaining exposure visible, with owners for the decisions needed before those limits are reached.

## A working system is not the same as a working service

Name the customer activity and its usable result. At Fenbrook, receiving a form, deciding whether a venue can be booked and issuing an accurate confirmation are separate steps. State which steps must continue, which users are affected and what happens if work waits. Include peak periods and obligations that become more difficult with time. Do not select priorities solely by which tasks are easiest to move online.

ISO/TS 22317:2021 provides guidance for a documented business impact analysis suited to the organization rather than one uniform method. Use the approved analysis as an input to the response. Record its scope, owner, review date and applicability to this contract. An analysis of head-office finance does not establish the acceptable interruption of the offered customer service.

Keep interruption tolerance, recovery objectives and minimum operating level distinct. A temporary service may process only selected requests while other work waits. That can be useful without being normal service. UK government resilience guidance treats business continuity as a capability to sustain delivery at predefined acceptable levels and connects it with other organizational functions. Its public-sector context is a reference point, not an extra contractual rule for every bidder.

If the buyer’s requirement is stronger than the approved continuity design, identify the decision needed. Do not solve the gap by changing the label from outage to degraded operation. A risk acceptance within the supplier also cannot unilaterally change the buyer’s rights or waive an applicable requirement.

**Define the continuity outcome before selecting a method**

| Field | Fenbrook planning question | Required decision |
| --- | --- | --- |
| Priority work | Which requests need a decision during the disruption? | Service owner approves the priority rule |
| Minimum usable result | Is intake enough, or must a valid confirmation be issued? | Buyer and supplier align the outcome |
| Impact over time | Which delays become unacceptable and when? | Use the approved impact assessment |
| Deferred work | How much can wait, for how long and with what notification? | Set a visible limit and escalation owner |

## A second supplier can still share the first supplier’s failure

Trace each priority activity through the resources needed to perform it. Include trained people, delegation, a usable workplace, equipment, current information, communications and third-party input. For remote operation, verify that the relevant people can work under the expected conditions. A laptop inventory says little about access, appropriate workspace or the absence of the only person authorized to approve a transaction.

Look for shared failure causes. Two offices may share an inaccessible area; two suppliers may rely on one logistics partner; the backup contact channel may use the same account system as the primary channel. Fenbrook’s overflow arrangement fails if it depends on the same inaccessible building service. Test the dependency, not merely the fact that two names appear in a contract.

An alternate supplier also needs a usable commitment: the relevant service, capacity, activation process and constraints during widespread demand. Ordinary commercial availability is not reserved emergency capacity. Confirm onboarding, permissions, information access and any required customer approval before relying on the alternative. Supplier distress or insolvency may require a separate legal and commercial response; it does not automatically give the bidder access to the supplier’s people or assets.

In the proposal, summarize the dependency and evidence boundary. Keep actual contact trees, site locations, security details and restricted supplier terms in the approved assurance channel. The evaluator needs to understand what is covered and what remains conditional, not receive an operational map that creates a new exposure.

## Give the workaround a capacity and a stopping rule

Describe how the alternative produces an acceptable result, not just where staff relocate. State required people, skills, information, equipment and checks. If a manual register is used, define unique identifiers, permitted approvals, secure handling and later reconciliation. Do not bypass a mandatory control to preserve the appearance of throughput. Where work cannot be performed within its required safeguards, escalate or pause it through the approved decision route.

In a hypothetical Fenbrook capacity model, 120 requests arrive each working day and the reduced method correctly completes 80. With no initial backlog, no cancellations and a comparable task mix, the queue grows by 40 per day. After three days, 120 requests remain outstanding. This arithmetic is a planning illustration, not measured service performance. Real demand spikes, rework and aging priorities can make the result worse.

Agree a review point before the workaround reaches its limit. Limits may include staffing endurance, workspace availability, stock, supplier capacity, backlog age or an inability to maintain quality. A three-day plan is not evidence of a three-week capability. Explain whether the next decision is additional approved capacity, a different alternative, reprioritization or suspension of affected work. A deadline or obligation does not disappear because the system used to manage it is unavailable.

The continuity card should connect activation prerequisites to a bounded operating level. Keep a designed rate separate from an observed rate, and both separate from a contractual promise. If an exercise covers only simple requests, do not extend its throughput to exception-heavy work without evidence.

**Illustrative Fenbrook continuity card, not a live operating instruction**

| Element | Example entry | Evidence or authority required |
| --- | --- | --- |
| Activation condition | Primary workplace unavailable for priority booking work | Authorized continuity lead assesses the event and prerequisites |
| Reduced output | 80 comparable requests correctly completed per working day | Capacity exercise with trained available staff |
| Planning horizon | Review before three working days or an earlier approved limit | Service owner monitors queue age, quality and resources |
| Record control | Unique temporary record linked to the eventual booking | Approved handling and reconciliation method |
| Next decision | Add permitted capacity or change the operating arrangement | Named decision role; no automatic waiver of obligations |

## Decisions must still be possible when the usual approver is absent

Define who recognizes the disruption, who can invoke the arrangement and who can approve spending, priority changes and customer commitments. Provide authorized alternates rather than a phone list with no decision rights. Explain the relationship to incident management and any separate emergency or security response. Continuity does not authorize unsafe working or override the professionals responsible for those decisions.

Show the activation sequence in elapsed stages: assess impact, locate available people, confirm the alternate method, validate access and information, begin the defined service and notify affected users. If the usual communication channel is part of the failure, the alternate must be reachable and understood in advance. A message drafted in a system nobody can access is not a communication capability.

For Fenbrook, customer updates should distinguish requests received, requests decided and work deferred. State the next update point without inventing a restoration time. Agree the buyer’s role in changing priorities or communicating with its own users. Test what happens when the expected buyer contact cannot be reached. Silence should not be treated as permission for a new commitment or a change to contractual service levels.

## A discussion can test a decision, but it cannot prove throughput

Choose the exercise from the claim the answer needs to support. A tabletop can expose unclear authority or an overlooked dependency. A practical exercise can show whether people can operate the alternate process and maintain its controls. A component recovery test supports a different claim again. UK exercising guidance distinguishes discussion-based formats and requires evaluation against defined objectives. Do not describe every activity as an end-to-end continuity test.

Use a scenario that challenges the proposed alternative: the normal office is unavailable, the usual approver cannot participate and the overflow supplier cannot accept the assumed volume. State which conditions were exercised, simulated or excluded. Agree safe exercise boundaries and approved test data. A test must not create an uncontrolled live disruption merely to make the evidence more impressive.

A useful record names the date, service scope, objectives, participants by role, scenario, evidence captured, result and limitation. For the 80-request Fenbrook example, a discussion of staffing would not establish the rate. The evidence would need representative completed work, time measurement, quality checks and the actual resource conditions. Until that exists, retain the rate as a planning assumption.

Turn findings into owned corrections with due dates and appropriate retesting. Updating a document can close a wording issue, but it does not prove that an unavailable supplier can now deliver. Show material unresolved findings in the assurance summary. An exercise that reveals a problem is useful evidence; claiming the problem is closed before verification is not.

**Match the exercise to the public claim**

| Claim | Useful evidence | What remains unproven |
| --- | --- | --- |
| Alternates can make the required decisions | Scenario decisions with the usual approver absent | Actual processing capacity unless separately exercised |
| Reduced method completes 80 requests per day | Representative timed work with accuracy checks | Other task mixes and longer operating periods |
| Supplier can activate under disruption | Observed activation and applicable capacity commitment | Capacity during a different or wider event |
| Temporary work can return to the main process | Reconciliation exercise including duplicates and exceptions | Production completeness beyond the tested scope |

## Restoration does not clear the queue

Define the conditions for leaving reduced operation: the normal workplace or method is usable, the required people and controls are available, information is validated and the service owner accepts the transition. Coordinate with technical recovery without repeating its detailed restoration procedure. Someone must decide when to stop creating temporary records so that two parallel processes do not issue conflicting confirmations.

Continue the hypothetical Fenbrook calculation. After three reduced days, the backlog is 120. If normal processing can correctly complete 180 comparable requests per day while 120 new ones continue to arrive, net clearance is 60 per day. The backlog would take two further working days to clear under those assumptions. If capacity returns only to 120, the queue does not shrink. Returning the application to service is therefore not the same milestone as completing outstanding work.

Check backlog age and priority as well as count. Reconcile temporary identifiers, decisions, customer messages and records with the main process. Investigate duplicates, missing items and conflicting approvals rather than importing everything blindly. Preserve the evidence needed under the applicable rules, retire temporary access and materials through the approved process, and make any residual work someone’s explicit responsibility.

Close continuity through a documented service decision. State what has returned, what remains open and who owns the follow-up. Review the actual or exercised event for changes to assumptions, supplier arrangements and training. An incident ticket marked resolved cannot, by itself, establish that the customer’s service and records are back to the agreed state.

**Fenbrook queue model with constant comparable work**

| Period | Calculation | Interpretation |
| --- | --- | --- |
| Each reduced day | 120 arriving minus 80 completed = 40 added | Outstanding work grows despite continued operation |
| Three reduced days | 3 × 40 = 120 outstanding | Assumes no opening backlog, cancellations or rework |
| Each restored day | 180 completed minus 120 arriving = 60 cleared | Only spare capacity reduces the existing queue |
| Clearance period | 120 ÷ 60 = 2 working days | A conditional planning estimate, not a recovery guarantee |

## Give the buyer assurance without handing over the full plan

Open with the offered service and continuity outcome. Explain the priority basis, alternatives, minimum operating level, activation authority and evidence. Summarize the latest relevant exercise and unresolved limits, then describe reconciliation and return. Reference supporting documents through the permitted assurance route. Do not publish private contact details, site instructions, credentials or confidential dependency maps to make the response look detailed.

ISO 22301 sets requirements for a business continuity management system, while ISO 22313 gives application guidance. Referencing either does not establish certification. If a certification is relevant and actually held, verify its entity, scope and validity before using it. It does not by itself prove this customer’s reduced throughput or recovery outcome.

Schedule 22 of the England and Wales Model Services Contract version 2.2A distinguishes continuity, disaster recovery and insolvency-related arrangements and addresses testing and review. It illustrates why the answer must align with the actual contract; do not import its time periods or assume invocation grants service-level relief. Reconcile continuity wording with recovery targets, support coverage, buyer responsibilities, commercial assumptions and funded resources.

Have service, continuity, security and commercial owners approve the commitment within their authority. Mark customer-specific design work still required after award rather than calling it completed. Reopen the answer when people, sites, suppliers, volumes or processes materially change. The final artifact should let an evaluator identify the service that continues, its limits and the evidence for believing the arrangement will work.

## Useful outcomes

- Priority activities, affected users and unacceptable impacts are defined for the offered service.
- Minimum operation has measurable scope, capacity, duration and conditions rather than a blanket continuity claim.
- People, workplaces, information and supplier dependencies are checked for shared failure causes.
- Activation, priority changes, customer messages and return decisions have authorized owners and alternates.
- Exercise evidence distinguishes discussion, demonstrated work and untested assumptions.
- Return to normal includes temporary records, duplicate prevention, backlog and customer validation.

## Workflow

1. **Define the service that must continue.** Use the buyer requirement and impact analysis to identify priority work, affected users, time-sensitive harm and minimum acceptable operation.
2. **Trace the operating dependencies.** Check people, decision authority, premises, information, communications and suppliers, including failure causes shared by the fallback.
3. **Bound reduced operation.** Describe the alternative method, activation time, sustainable throughput, quality controls, duration and escalation conditions.
4. **Exercise the relevant scenario.** Test the people and dependencies needed for the promised outcome, record observations and limitations, and assign corrective actions.
5. **Plan the return and outstanding work.** Define validation, reconciliation, backlog clearance and authority to retire temporary arrangements.
6. **Release the supported commitment.** Align evidence, continuity wording, recovery assumptions, service levels, customer duties and price without disclosing sensitive plans.

## Key decisions

- Which activities must continue first, and which can be deferred within an approved limit?
- Does the alternate arrangement survive the disruption affecting the primary one?
- How long can the reduced service operate before capacity, quality or another constraint requires a new decision?
- Who can activate the plan, change priorities and approve a return when the usual decision-maker is unavailable?
- What was actually demonstrated, and what remains a target or an untested dependency?
- Which records and outstanding obligations must be reconciled before continuity is considered closed?

## Risks

- Application uptime is presented as proof that the whole service continues.
- The alternate site, supplier or communications route depends on the same failed resource.
- Lower throughput is hidden behind a claim of normal service.
- A manual workaround loses approval, privacy, accuracy or duplicate-prevention controls.
- A tabletop discussion is described as a measured capacity test.
- The incident is closed while deferred work and temporary records remain unreconciled.

## Metrics

- Priority activities with an approved minimum level and an evidenced operating alternative.
- Elapsed activation stages from disruption recognition to usable reduced service.
- Correctly completed work per period under the exercised reduced conditions.
- Backlog volume and age compared with the next decision threshold.
- Critical dependencies exercised, simulated or excluded, reported separately.
- Corrective actions closed through appropriate retesting and temporary records reconciled on return.

## Frequently asked questions

### Does cloud availability prove business continuity?

No. Staff, authority, communications, information and suppliers may still prevent the customer activity from being completed. Explain the service outcome and the dependencies required to deliver it.

### Is reduced service the same as uninterrupted normal service?

No. State which activities continue, their capacity, quality conditions and duration. Do not hide deferred work or assume a different label changes the contract.

### Can a tabletop exercise prove our processing rate?

A discussion can test decisions and assumptions. A rate needs representative timed work and quality evidence under the stated operating conditions.

### Is a second supplier sufficient evidence of resilience?

Only if the alternative can be activated, has the required capacity and survives relevant shared failure causes. A second supplier name alone establishes none of those facts.

### When should the reduced method be reconsidered?

Before an approved limit is reached, or earlier if capacity, controls, backlog age or dependencies deteriorate. Assign the decision owner and define the available next actions.

### Can the event close when the system is restored?

Technical restoration is one condition. The service owner must also address temporary records, duplicates, outstanding work, customer validation and any residual obligations.

### Should we attach the complete continuity plan to every bid?

Follow the buyer’s evidence requirement and approved disclosure process. A scoped assurance summary may be appropriate; sensitive operational material belongs only in its authorized channel.


## Primary sources

- [ISO 22301:2019 business continuity management systems](https://www.iso.org/standard/75106.html), International Organization for Standardization
- [ISO 22313:2020 guidance on applying ISO 22301](https://www.iso.org/standard/75107.html), International Organization for Standardization
- [ISO/TS 22317:2021 business impact analysis guidance](https://www.iso.org/standard/79000.html), International Organization for Standardization
- [Organisational resilience guidance for UK government bodies](https://www.gov.uk/government/publications/organisational-resilience-guidance-for-uk-government-departments-agencies-and-arms-length-bodies/organisational-resilience-guidance-for-uk-government-departments-agencies-and-arms-length-bodies-albs-html), UK Government
- [Exercising Best Practice Guidance](https://www.gov.uk/government/publications/exercising-best-practice-guidance/exercising-best-practice-guidance-html), Cabinet Office
- [Model Services Contract version 2.2A, Schedule 22 on service continuity](https://www.gov.uk/government/publications/the-model-services-contract-schedules-england-wales), Cabinet Office and Government Legal Department


## Related articles

- [How to answer a disaster recovery question in an RFP](https://zephior.com/insights/answer-an-rfp-disaster-recovery-question)
- [Answer an RFP support model question with a workable rota](https://zephior.com/insights/answer-an-rfp-support-model-question)
- [Answer an RFP key-personnel question without overcommitting](https://zephior.com/insights/answer-an-rfp-key-personnel-question)
- [Can the operating model support the buyer’s step-in rights?](https://zephior.com/insights/review-step-in-rights-in-a-tender)
