Where does the Business Continuity Management team sit within your organization?  Is it acceptable for it to sit under the Chief Audit Executive's org?

572 viewscircle icon2 Comments
Sort by:
Vice President - Internal Audit and Enterprise Risk Management in Healthcare and Biotecha year ago

Business Continuity sits with IT at my company, as part of the CISO's organization.  There is direct linkage to the DR function (also in IT) and it also serves as the central coordinating function for the cross-functional crisis management team.

Regarding functional alignment with the Chief Audit Executive, I would typically avoid in cases where the CAE only has responsibility for IA.  Aligning BC under the CAE in this model would likely create potential independence concerns, at least in appearance.

In organizations where the CAE also has responsibility for broader risk-oriented functions (such as ERM), I think BC can effectively roll up under one of those functions, if structured appropriately.  The independence concerns can be addressed by resourcing and managing related audits appropriately, including through the use of co-sourced audits.

Director of Financea year ago

Business Continuity sits with IT in our current org, but is realistically everybody's responsibility.  IT often inherits it because so many key processes depend on technology, but it is still a joint effort.  Having it roll to Chief Audit Executive makes sense from a "raising the risk profile" perspective, but may create disconnects and confusion if the people leading the effort to restore operations are not fully embedded within the relevant systems and processes (and likely far more accountable for making sure the business goes on than checking the business continuity box on an audit plan).

Content you might like

Investing in upskilling49%

Automating manual tasks50%

Outsourcing/offshoring25%

Expanding recruiting or staffing team13%

Lowering some job qualifications/requirements13%

Increasing hybrid or flexible work arrangements38%

Increasing benefits13%

Increasing compensation11%

Something else (comment below!)

We aren't experiencing a talent shortage/we don't plan on doing anything3%

View Results

Benefits (healthcare, paid time off, etc.)7%

Hours flexibility22%

Location flexibility17%

Salary/income25%

Work-life balance14%

Workplace culture12%

View Results