ICAS ICAS logo

Quicklinks

  1. About Us

    Find out about who we are and what we do here at ICAS.

  2. Find a CA

    Search our directory of individual CAs and Member organisations by name, location and professional criteria.

  3. CA Magazine

    View the latest issues of the dedicated magazine for ICAS Chartered Accountants.

  4. Contact Us

    Get in touch with ICAS by phone, email or post, with dedicated contacts for Members, Students and firms.

Login
  • Annual renewal
  • About us
  • Contact us
  • Find a CA
  1. About us
    1. Governance
  2. Members
    1. Become a member
    2. Newly qualified
    3. Manage my membership
    4. Benefits of membership
    5. Careers support
    6. Mentoring
    7. CA Wellbeing
    8. More for Members
    9. Area networks
    10. International communities
    11. Get involved
    12. Top Young CAs
    13. Career breaks
    14. ICAS podcast
    15. Newly admitted members 2022
    16. Newly admitted members 2023
  3. CA Students
    1. Student information
    2. Student resources
    3. Learning requirements
    4. Learning updates
    5. Learning blog
    6. Totum Pro | Student discount card
    7. CA Student wellbeing
  4. Become a CA
    1. How to become a CA
    2. Routes to becoming a CA
    3. CA Stories
    4. Find a training agreement
    5. Why become a CA
    6. Qualification information
    7. University exemptions
  5. Employers
    1. Become an Authorised Training Office
    2. Resources for Authorised Training Offices
    3. Professional entry
    4. Apprenticeships
  6. Find a CA
  7. ICAS events
    1. CA Summit
  8. CA magazine
  9. Insight
    1. Finance + Trust
    2. Finance + Technology
    3. Finance + EDI
    4. Finance + Mental Fitness
    5. Finance + Leadership
    6. Finance + Sustainability
  10. Professional resources
    1. Anti-money laundering
    2. Audit and assurance
    3. Brexit
    4. Charities
    5. Coronavirus
    6. Corporate and financial reporting
    7. Business and governance
    8. Ethics
    9. Insolvency
    10. ICAS Research
    11. Pensions
    12. Practice
    13. Public sector
    14. Sustainability
    15. Tax
  11. CPD - professional development
    1. CPD courses and qualifications
    2. CPD news and updates
    3. CPD support and advice
  12. Regulation
    1. Complaints and sanctions
    2. Regulatory authorisations
    3. Guidance and help sheets
    4. Regulatory monitoring
  13. CA jobs
    1. CA jobs partner: Rutherford Cross
    2. Resources for your job search
    3. Advertise with CA jobs
    4. Hays | A Trusted ICAS CA Jobs Partner
    5. Azets | What's your ambition?
  14. Work at ICAS
    1. Business centres
    2. Meet our team
    3. Benefits
    4. Vacancies
    5. Imagine your career at ICAS
  15. Contact us
    1. Technical and regulation queries
    2. ICAS logo request

The importance of a robust business continuity plan

  • LinkedIn (opens new window)
  • Twitter (opens new window)
By Liz Smith, Business Development Director at Lugo & Marie Gardner, Head of Research at ICAS

25 June 2021

Over the last year, firms have had to quickly adapt to be able to keep delivering accountancy services to clients. This has been a smoother process for some than for others. For example, did your phone system continue as normal, or did you have to stop accepting inbound calls?

Back to the very start of the current pandemic, during which, regrettably, not every firm has been able to offer the same level of service as normal, qualitative research by ICAS found that business continuity and the ability of staff to work from home were seen as emerging issues of critical importance. Although the nature of events forced us to work from home, during these unprecedented times our expectation on the standard of service we receive has probably slipped too. As restrictions begin to ease, maybe now is a good time to reflect on where your firm can become more resilient to ensure business continuity no matter the challenges you face.

Even if it’s not something as disruptive as coronavirus, natural or human-made disasters come in all forms, from a power outage or hurricane to plain old human error. Here are some of the main areas to consider when planning for your firm’s business continuity.

People

Staff are a critical resource to your business and their welfare is paramount.  With 85% of those surveyed by Lugo seeing themselves and their colleagues working from home more going forward, you may have to rethink work practices. Look at who can work from home, who needs to be in the office and who is client facing.

To ensure continuity of client service, have more than one person able to do certain tasks, and avoid ‘key man dependency’. With the risk of contracting coronavirus still high, people suffering from long COVID or even those having side-effects from the vaccine, plans need to be in place when staff members fall ill.

In the real world, great technology and technical capabilities may still not make for a great response if the right people, with appropriate skills are not in place. Human error is one of the highest risks to business continuity. Continual training and support enables employees to be confident they are acting in line with company policies and procedures.

Policies

Your business continuity plan will refer to policies, plans of action and methods for informing staff and clients. When surveyed, 75% of firms said they have a communication plan in place if they got breached.

Build a detailed emergency process with predetermined actions for communication and coordination, designated roles for employees, and emergency action plans that involve staff, clients and suppliers.

It’s good practice to build a business continuity team who are all aware of your:

  • Disaster Recovery Plan, which we look at in more detail below
  • Incident Response Plan, including communicating with clients
  • Crisis Management Plan, how you respond to a critical situation

A well planned and executed response will help to minimise the damage caused by an incident or disaster. This could mean anything from cutting the amount of data lost, to minimising public fall out or lost clients.

You should work with your legal advisor to understand what it will mean if, for example, you can’t supply services to clients, as you may have to put an additional section in your terms of engagement. If you can’t meet your obligations, a clear understanding of your contractual terms will allow you to plan and prioritise your response.

It's worth noting that preparation and mitigation for data breaches are both explicitly required by the ICO, as part of your GDPR-related measures. They state that you should, ‘Have well-defined and tested incident management processes in place in case of personal data breaches.’

IT Strategy

The pandemic may have challenged your IT to adapt and change the way you functioned in response to circumstances beyond your control. Over half (55%) of surveyed accountants said their IT strategy has changed since the impact of COVID-19, according to Lugo’s research. We probably all wish we’d bought some shares in Zoom a few years ago!

To ensure business continuity, it’s important to choose an IT support provider who has worked with and understands your industry.
Businesses in every industry have been put under pressure to switch from more traditional business models to digital-friendly ones running in the cloud. It’s important not to rush IT strategy decisions, but to be able to have informed discussions about when and how to move to the cloud, at a time that’s right for you.

Data Backup, Cyber Threats and Disaster Recovery

Lugo’s research found 90% of firms surveyed do have a disaster recovery plan in place. Some key considerations are:

  • Who’s responsible?
  • What’s backed up?
  • How quickly can you get back up and running?

As the UK – hopefully now - emerges from the COVID-19 pandemic, organisations might also consider what more they can do to manage cyber security risks in a ‘blended’ working environment.

According to the UK Government’s Cyber Security Breaches Survey 2021, three in ten businesses (31%) have a business continuity plan that covers cyber security.Cyber security framework

The U.S. Department of Commerce's National Institute of Standards and Technology (NIST) has a Cyber security Framework. They identify the five key pillars of a successful and wholistic cyber security program, being: Identify, Protect, Detect, Respond, Recover. This is a good place to start to decide where and how to focus your efforts.

If you have a robust, well tested, system in place and you can get all your vital business data from backup quickly, you can’t be blackmailed by a ransomware attack.

Payroll Processing

One of your systems with the highest impact is payroll; when people don’t get paid, there is no place to hide! That’s why payroll processing continuity is so important.

When Lugo asked, in terms of particularly your Payroll Bureau, what continuity do you have in place, accountants’ responses were varied. They included external backups, off-site data replication, running payroll from home, BACS being cloud based and a virtual server in Microsoft Azure. Some, worryingly, didn't have any continuity in place.

When considering desktop payroll software, it’s fundamental to have a clear process in place to ensure payroll continuity. Remediate the weak links and document the steps you would take, keeping security front and centre. Ask yourself, how long can you afford to be down for, and work back from there. If your payroll data is continually replicated to the cloud or another device, in a worst-case scenario, you could re-install the payroll program on a different device and get it back up and running, for at least one person, in a matter of a few hours.

You can use cloud technology to help achieve business continuity. There are some SaaS (software as a service) payroll offerings allowing you to process from wherever you have an internet connection. Some organisations go as far as to keep copies of all SaaS data locally, in case of any access issues. Do you know how to extract a copy of your data stored in SaaS solutions? Maybe now’s the time to find out.

Build for a stronger tomorrow

Long gone are the days when businesses could shy away from clearly understanding the technology-related risks they face, and could solely rely on board members who often do not have sufficient levels of technical expertise to identify and mitigate those risks, or overly rely on external suppliers without the ability to be as challenging as may be required. The clear and competent mapping of businesses key processes and vulnerabilities, and the ensuing development of robust business continuity plans to mitigate these risks will help you sleep sound at night.

We’ve all worked hard during the pandemic to continue in business, despite the challenges we’ve faced. Now’s the time to pause, recollect and learn from what the last year has taught us.

Your teams have adapted and supported your clients through tough times. Your systems have withstood unplanned home working. By reviewing and improving your business continuity plan, you can emerge stronger and be ready for whatever is to come.

Lugo are always here to ensure your accountancy firm is running smoothly, supporting you with #LugoLove. For more information visit LugoIT.co.uk or email Liz.Smith@LugoIT.co.uk.


This blog is one of a series of articles from our commercial partners.
The views expressed are those of the author and not necessarily those of ICAS.

Taking on Technology Training

By Liz Smith, Business Development Director at Lugo & Marie Gardner, Head of Research at ICAS

7 April 2021

Where to focus your cyber security – the sequel

By Marie Gardner, ICAS Head of Research, and Liz Smith, Lugo Business Development Director

12 February 2021

2022-01-xero 2022-01-xero
ICAS logo

Footer links

  • Contact us
  • Terms and conditions
  • Modern slavery statement
  • Privacy notice
  • CA magazine

Connect with ICAS

  • Facebook (opens new window) Facebook Icon
  • Twitter (opens new window) Twitter Icon
  • LinkedIn (opens new window) LinkedIn Icon
  • Instagram (opens new window) Instagram Icon

ICAS is a member of the following bodies

  • Consultative Committee of Accountancy Bodies (opens new window) Consultative Committee of Accountancy Bodies logo
  • Chartered Accountants Worldwide (opens new window) Chartered Accountants Worldwide logo
  • Global Accounting Alliance (opens new window) Global Accounting Alliance
  • International Federation of Accountants (opens new window) IFAC
  • Access Accountancy (opens new window) Access Acountancy

Charities

  • ICAS Foundation (opens new window) ICAS Foundation
  • SCABA (opens new window) scaba

Accreditations

  • ISO 9001 - RGB (opens new window)
© ICAS 2022

The mark and designation “CA” is a registered trade mark of The Institute of Chartered Accountants of Scotland (ICAS), and is available for use in the UK and EU only to members of ICAS. If you are not a member of ICAS, you should not use the “CA” mark and designation in the UK or EU in relation to accountancy, tax or insolvency services. The mark and designation “Chartered Accountant” is a registered trade mark of ICAS, the Institute of Chartered Accountants of England and Wales and Chartered Accountants Ireland. If you are not a member of one of these organisations, you should not use the “Chartered Accountant” mark and designation in the UK or EU in relation to these services. Further restrictions on the use of these marks also apply where you are a member.

ICAS logo

Our cookie policy

ICAS.com uses cookies which are essential for our website to work. We would also like to use analytical cookies to help us improve our website and your user experience. Any data collected is anonymised. Please have a look at the further information in our cookie policy and confirm if you are happy for us to use analytical cookies: