Risk Management & Business ContinuityTemplate4 min readUpdated September 2026

Business Continuity Plan for a Small Business: A Working Template

A business continuity plan explains how your company keeps operating, or restores operations quickly, when something stops working: a key system, a location, a supplier or a person. For a small business, a useful plan is short. It ranks what matters most, sets how long you can live without each piece, and says who does what when it breaks.

Follow the steps below to build a first version in about a week, then test it before you need it.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

What are the steps to build a plan?

Work through these in order, and keep each output to a page or less:

  1. List critical functions. Write down what the business must do to bring in cash and serve customers: take orders, fulfill, invoice, pay staff, answer support.
  2. Map dependencies. For each function, note the systems, people, vendors and locations it relies on.
  3. Set recovery targets. For each function, decide how long it can be down before real damage happens, and how much recent data you can afford to lose.
  4. Identify likely disruptions. Think through the ones that could really happen to you: a cloud service outage, a power or internet failure, a key employee leaving, a supplier failing, a cyber incident, a facility closure.
  5. Write playbooks. For each high-priority risk, write the first steps, the owner and the backup owner.
  6. List contacts. Include staff, vendors, insurers, your bank, your attorney and your IT provider, with a second way to reach each.
  7. Test and schedule review. Run a short exercise and put a yearly review on the calendar.

How do you set recovery targets that mean something?

Downtime tolerance is easiest to reason about when you turn availability percentages into time. Availability targets translate to a yearly downtime allowance: 99.9% allows roughly 8.76 hours a year, while 99.99% allows about 52.6 minutes1.

Most small businesses don't need numbers that tight for every function. Ask a simpler question: how many hours can we go without this before a customer notices, and how many before we lose money we can't recover? Say your order system can be down for four hours before orders are lost, but your payroll system can be down for two days. Those are different targets, and they justify different spending.

Also decide how much recent data you can afford to lose. If your last backup ran overnight, you might lose a whole day of orders in a failure. Whether that's acceptable is a business decision, not a technical one.

What should each playbook contain?

Keep playbooks short enough to read under stress. Each one needs:

  • Trigger: how you'll know it's happening, such as "the order system shows errors for more than 15 minutes".
  • First 30 minutes: the immediate steps, in order, with the person responsible for each.
  • Workaround: how to keep serving customers manually, such as taking orders by phone with a paper form.
  • Communication: who tells customers, staff and partners, and what the message says.
  • Recovery and return to normal: how you'll confirm the system is really back, and who signs off.
  • After-action note: what you'll write down afterward so the plan improves.

Pre-write customer and staff messages with blanks for the details. Nobody writes well during an outage.

How do you cover people risk and location risk?

Systems fail loudly. People risk arrives quietly. Identify anyone whose absence would stop a critical function, and give each of them a named backup and written procedures. A short review of who alone knows or controls what is a quick way to find these gaps. Pay attention to access as well: passwords, admin rights and vendor accounts held by one person are a continuity problem.

For locations, decide where work happens if your office or shop is unavailable. For many teams the answer is remote work, which depends on having laptops, VPN or cloud access and a way to forward phones. If you have physical inventory or equipment, ask your insurance broker what's covered and how to document it. Insurance and legal requirements differ by state and industry, so confirm them with your broker or attorney.

How do you test the plan?

An untested plan is a guess. Start with a tabletop exercise, which takes about an hour. Pick one scenario, such as your main software being down for a day, and walk through the playbook with the people who would act. Note every place someone says "I'm not sure who does that."

Then, once a year, run one practical test: restore a file from backup, switch to your manual order process for an hour, or call every number on the contact list. Fix the gaps and update the plan.

Store the plan where it's reachable when your main systems are down. A copy only on your company laptop or shared drive won't help if those are what failed. Keep a printed or offline version with the contact list, and document the rest in a shared workspace such as Notion. Track the yearly review and the drills in a task tool like Asana with recurring tasks.

Where does the plan connect to the rest of operations?

Continuity work overlaps with other routines. Your operations audit checklist can include a yearly review of the plan, and your employee handbook should tell staff what to do during an incident. If you're choosing a place to keep the documentation, compare options in documentation tool comparison. For more technical planning on systems, read the guide on disaster recovery and business continuity operations.

Executive Capability Standard

What Good Looks Like

A short written plan that ranks critical functions, sets recovery targets, assigns owners and backups, and has been tested at least once in the past year.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Learn which of your functions bring in cash or serve customers, and what each depends on.
2. Do Manually:Write playbooks for your top three risks and keep an offline copy with the contact list.
3. Delegate:Give an operations lead ownership of the plan, the yearly review and the test schedule.
4. Automate:Schedule recurring drills and review reminders so the plan is tested without anyone having to remember.
5. Buy:Buy backup, failover or managed IT services for the systems where your recovery target is measured in hours.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Notion

Fits when you want the plan, contact list and playbooks in one shared workspace your team can search.

Visit Notion→
Asana

Fits when you want recurring tasks for drills, yearly reviews and contact-list checks.

Visit Asana→

Frequently Asked Questions

What is the difference between business continuity and disaster recovery?

Business continuity covers keeping the whole business running through a disruption, including people, suppliers and locations. Disaster recovery is the narrower job of restoring IT systems and data. A continuity plan usually includes recovery steps for your technology, but it also covers manual workarounds and communication.

How long should a small business continuity plan be?

Shorter than you'd expect. Ten to fifteen pages is plenty for most small businesses, and a shorter plan gets read and used. Focus on your top critical functions, the contacts, and a playbook for each likely disruption, then refine after each test.

How often should we update the plan?

Review it at least once a year, and after any major change such as a new system, a new location, a key hire or departure, or an incident. Keep the contact list current more often, because outdated phone numbers are the most common reason plans fail.

Do we need a business continuity plan for insurance or compliance?

Sometimes. Certain customers, lenders and regulated industries ask for one, and some insurance policies have related requirements. Check contracts and policies, and ask your broker or attorney what applies to you. Even when it isn't required, a plan reduces the cost of a bad day.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Allowed downtime per year by availability target. Google SRE Book, Table 1-1 Availability table, 2016.

Related Guides