Business Continuity Planning (BCP/PCA) — Switzerland
Abilene Advisors builds practical business continuity plans that actually work when tested — not paper documents filed away. We combine business impact analysis, recovery strategies, and simulation exercises to ensure your organisation can survive and recover from any disruption.
Quick answers
What is a Business Continuity Plan (BCP/PCA) and why do Swiss organisations need one?
A Business Continuity Plan (BCP, or Plan de Continuité des Activités in French) defines how an organisation maintains critical functions during and after a disruptive event. In Switzerland, it is increasingly required by FINMA, DORA (for financial institutions), and NIS2 (for essential services).
Which Swiss organisations need a Business Continuity Plan?
BCP is essential for Swiss financial institutions (DORA, FINMA circular 2023/1), healthcare organisations (NIS2 essential services), public utilities, IT service providers, and any organisation with regulatory or contractual continuity obligations. All Swiss companies benefit from basic BCP.
What does business continuity planning involve?
BCP involves: Business Impact Analysis (BIA) to identify critical functions, recovery time objectives (RTO) and recovery point objectives (RPO), development of recovery strategies, plan documentation, staff training, and regular simulation exercises to test and improve the plan.
What are the risks of not having a BCP in Switzerland?
Organisations without a BCP risk: extended downtime after incidents, regulatory penalties (DORA: up to 1% of annual global turnover), loss of client contracts requiring BCP evidence, and reputational damage. FINMA expects Swiss banks to demonstrate operational resilience.
How long does it take to build a BCP in Switzerland?
A basic BCP for an SME can be completed in 2–3 months. A full BCP with ISO 22301 alignment, multiple business units, and simulation exercises typically takes 4–8 months. Abilene Advisors phases the work to deliver a usable plan quickly, then refine.
How does BCP relate to DORA compliance for Swiss financial institutions?
DORA (Digital Operational Resilience Act) requires EU financial entities — including Swiss firms with EU operations — to have ICT business continuity policies, tested recovery plans, and operational resilience testing. Abilene Advisors builds BCP programs that satisfy both DORA and Swiss FINMA requirements.
Is a Business Continuity Plan required by Swiss law?
BCP is not universally mandated by Swiss law, but it is required for FINMA-regulated entities (banking, insurance), for organisations subject to DORA, and for NIS2 essential-service operators with Swiss and EU operations. Many enterprise contracts also require BCP evidence.
How does Abilene Advisors approach business continuity planning?
We take a risk-based, practical approach: business impact analysis first, then proportionate recovery strategies, then simulation exercises. All deliverables are bilingual (EN/FR) and aligned with ISO 22301. We work with your team, not just produce documents for a shelf.
Our BCP development process
- 1
Business Impact Analysis (BIA)
Identify critical business functions, define RTOs and RPOs, and assess the financial and operational impact of disruptions.
- 2
Risk assessment
Identify and prioritise threats specific to your organisation and sector in Switzerland (cyber, pandemic, supply chain, natural hazard).
- 3
Recovery strategy development
Design recovery strategies for each critical function — people, premises, technology, and supply chain alternatives.
- 4
BCP documentation
Write the Business Continuity Plan, Disaster Recovery Plan, and crisis communication procedures. Bilingual EN/FR.
- 5
Staff training and awareness
Train crisis teams, communication leads, and business unit owners on their roles in the plan.
- 6
Tabletop exercise and simulation
Facilitate a tabletop exercise to test the plan, identify gaps, and refine procedures. Annual testing recommended.
Frequently asked questions
- What is the difference between a BCP and a Disaster Recovery Plan (DRP)?
- A BCP covers all business functions — people, processes, premises, and technology. A DRP focuses specifically on IT systems recovery. An effective BCP includes a DRP as one component.
- Does Abilene Advisors offer ISO 22301 certification support?
- Yes. We can align your BCP program with ISO 22301 (Business Continuity Management Systems) and support certification if that is your objective. ISO 22301 is the international standard referenced by FINMA and major enterprise clients.
- How often should a BCP be tested?
- Best practice (and ISO 22301 requirement) is annual testing at minimum — more frequently for high-risk sectors. Abilene Advisors designs progressive exercises: tabletop simulations first, then live failover testing for IT systems.
Build a BCP your organisation can rely on
Book a free consultation with Abilene Advisors to assess your business continuity maturity and define a practical implementation roadmap.
Book a free consultationRelated resources
DORA Compliance
Digital Operational Resilience Act — requires BCP for EU financial institutions.
NIS2 Compliance
EU cybersecurity directive — BCP required for essential service operators.
ISO 27001 Advisory
Information security management — complements business continuity planning.