Key Takeaways
These four points capture the core of what a workable business continuity plan looks like for a small business. Each stands on its own.
1. A practical business continuity plan must name decision-makers, define activation triggers, and set clear downtime limits in hours for each critical function.
2. Business continuity is how the business keeps serving customers during an outage, while a disaster recovery plan is how IT brings systems and data back.
3. Realistic sample plans for a professional services firm, a medical practice, and a distributed nonprofit give small businesses concrete models to copy and adapt this week.
4. A written plan only works if contact details stay current, out-of-band communication is defined, backups are tested, and the plan is reviewed at least once a year.
Introduction: Why you’re really here
Someone told you “we need a business continuity plan,” and now you need to produce a document. You searched for a business continuity plan example and found pages of empty templates with “[Insert company name]” placeholders. That is not helpful when you need to see what a finished plan actually looks like.
This article gives you three complete, filled-in sample business continuity plans plus a downloadable template you can edit. The examples are sized for small businesses of about 25–75 employees and cover realistic events like a natural disaster, a ransomware attack, or an extended internet outage. A business continuity plan is essential for organizational resilience – organizations without a BCP face delays and confusion during crises. You can adapt one of these examples into a working plan within a week, even without prior continuity experience.
What a business continuity plan actually has to do
A business continuity plan (BCP) is a document that outlines procedures for business disruptions. It explains how the company continues its critical operations during and after a disruption – not just how IT restores servers. BCP focuses on maintaining operations during disruptions: people, communication, physical space, and processes. It is broader, covering all business functions during crises.
A disaster recovery plan (DRP) is a subset of BCP focused on IT recovery. DRP is specific to restoring IT infrastructure after disasters and outlines steps for data access restoration post-disaster. Most people conflate the two. They are related but distinct.
Every business continuity plan must answer five questions:
- What triggers it? Define the specific events – internet outage, office inaccessible, system breach – that activate the plan.
- Who decides? Roles and responsibilities should clearly define decision-making authority. Establish an emergency preparedness team for planning responsibilities.
- Who does what? Identify essential services to maintain during emergencies and assign tasks.
- How do people communicate when normal channels fail? Communication protocols should establish methods for contacting stakeholders during emergencies. Documentation should include emergency contact information for critical stakeholders.
- How long can each function be offline? A business continuity plan must define recovery priorities and timelines for restoring functions. Conduct a business impact analysis to prioritize recovery efforts.
Effective business continuity plans include risk assessments and communication strategies, and should include alternative operations and workspaces. The three sample plans below show these five elements in action.
Sample Plan 1 – 40-person professional services firm (completed example)
Riverview Advisory Group is a fictional 40-person consulting and accounting firm in Richmond, VA. The firm runs on Microsoft 365 email, SharePoint for shared files, a VoIP phone system, and cloud-based accounting software. This sample business continuity plan is written as a finished document with concrete recovery times. Companies with a BCP can recover operations faster after disruptions, and this plan demonstrates proactive management to employees and customers.
Plan activation triggers and authority. The plan activates when any of these occur: loss of office access for more than 2 hours, firm-wide internet outage over 1 hour, SharePoint or cloud file service outage exceeding 2 hours, confirmed ransomware attack affecting shared drives, or VoIP phone system down for more than 1 hour. The Managing Partner has authority to declare a continuity event and activate this plan. If the Managing Partner is unavailable, the Operations Lead assumes that authority.
Continuity team. During an incident, the following roles activate:
- Managing Partner – makes strategic decisions, approves client communications, declares return to normal
- Operations Lead – coordinates response across departments, tracks task completion
- IT Contact – liaises with managed IT provider, verifies backups, leads technology recovery
- Communications Lead – sends staff updates, manages client-facing messages
- Client Service Lead – triages active client requests, prioritizes urgent deliverables
- Facilities Contact – handles building access, physical security, and workspace alternatives
Critical functions and maximum tolerable downtime. Based on a business impact analysis of how each function affects revenue, client relationships, and safety, the firm ranks its critical functions:
| Function | Maximum Tolerable Downtime | Key Dependency |
|---|---|---|
| Phone system | 2 hours | VoIP provider, office internet |
| 4 hours | Microsoft 365, internet | |
| Client file access | 8 hours | SharePoint, managed backups |
| Payroll | 24 hours | Cloud payroll vendor |
| Client billing | 48 hours | Accounting software, client data |
Communication plan. If email is down, the Communications Lead initiates a WhatsApp group for leadership and a phone tree for all staff. A printed contact sheet with personal cell numbers is stored in a binder at the front desk and backed up in a cloud folder accessible from mobile devices. The initial status message goes out within 30 minutes of plan activation. Clients with active engagements receive a brief update by phone within 2 hours.
Data and systems recovery steps. Data backup strategies follow the 3-2-1 rule for data protection – three copies, two different media, one offsite.
- IT Contact confirms the nature and scope of the incident
- IT Contact calls the managed IT provider and opens an emergency ticket
- Verify that offsite backups are intact and accessible
- Restore email access within 4 hours using webmail or a secondary mail route
- Restore priority client folders from the previous night’s backup within 8 business hours
- Restore accounting and billing system access within 48 hours
- Confirm no ongoing compromise before reconnecting shared drives
Return to normal operations criteria. Systems must be stable for 24 hours with no new errors. The backlog of open client tickets must be below 10. No further evidence of compromise or data loss exists. The Managing Partner and Operations Lead jointly decide when to declare normal operations. An incident report is completed within 3 business days.
Review and testing schedule. The team reviews this plan every October. A file restore test and phone failover test run at least once a year. Contacts are updated whenever staff changes occur. A tabletop exercise walks through a scenario annually.
Sample Plan 2 – Small medical practice (completed example)
Westover Family Clinic is a 6-provider primary care practice with about 30 staff in Henrico County, VA. The clinic depends on its EHR system, networked printers, e-prescribing tools, and phone lines. Business continuity plans vary by industry and specific needs – this sample highlights healthcare-specific pressures including patient safety, paper fallback procedures, and HIPAA obligations that do not pause during an outage.
Plan activation triggers and authority. The plan activates when: the EHR or practice management system is unavailable for more than 30 minutes, an internet outage disrupts e-prescribing, a natural disaster forces office closure, or a suspected breach of protected health information (PHI) occurs. The Medical Director or Practice Manager can declare a continuity event. If neither is available, the Lead Physician on duty has that authority.
Continuity team.
- Medical Director – clinical decisions, provider coordination
- Practice Manager – operational decisions, vendor calls, resource allocation
- IT Support Contact – coordinates with EHR vendor and managed IT provider
- Compliance & Privacy Officer – manages breach assessment, HIPAA notification timelines
- Front Desk Lead – patient communication, schedule management, signage
- Clinical Lead Nurse – oversees paper fallback, coordinates reconciliation after recovery
Critical functions and maximum tolerable downtime. The business impact analysis behind these times reflects patient safety, appointment volume, and payer rules:
| Function | Maximum Tolerable Downtime | Notes |
|---|---|---|
| Patient check-in and triage | 1 hour | Safety-critical |
| Phone system | 1 hour | Patients calling for urgent needs |
| Medication/allergy list access | 1 hour | Patient safety – no guessing |
| E-prescribing | 4 hours | Paper Rx fallback available |
| EHR documentation | 24 hours | Paper charting interim |
| Billing submissions | 72 hours | Payer deadlines allow buffer |
BCPs help maintain essential services during emergencies, and this tiered approach keeps the most safety-critical functions at the top.
Patient scheduling and paper fallback procedures. Each morning at 6 a.m., the Front Desk Lead prints or exports the day’s schedule. Blank chart packets and paper prescription pads are stored at each nurse station. When the EHR is unavailable, staff record vitals, notes, and orders on paper using standardized forms. Providers write prescriptions by hand or call pharmacies directly. After systems are restored, the Clinical Lead Nurse ensures all paper encounters are entered into the EHR within 24–48 hours. Providers review and sign off on reconciled charts.
Communication plan. Staff are notified via a group SMS list built from personal cell numbers. A pre-agreed Signal group connects the leadership team. Patients reaching the main line hear an updated voicemail greeting. The website and any patient portal display a brief notice. Pharmacies and hospital partners are contacted directly by the Practice Manager.
Data, systems recovery, and HIPAA obligations. The IT Support Contact coordinates with the EHR vendor and managed IT provider to restore access, verify data integrity, and confirm that no unauthorized access occurred. A BCP should include emergency contact information and recovery strategies for every critical vendor.
If customer data – specifically PHI – may have been exposed, the Compliance & Privacy Officer starts a parallel breach assessment. HIPAA requires notification within specific federal timelines, and Virginia state law may impose additional requirements. These two tracks – operational continuity (running the clinic on paper, rescheduling patients) and breach notification – run in parallel and are documented separately.
Return to normal operations criteria. Full EHR access is restored. All paper encounters have been entered. Pending lab orders and e-prescriptions are reconciled. Any required breach notifications are sent or formally scheduled. The Medical Director and Practice Manager sign off on return to normal.
Review and testing schedule. The clinic runs at least one annual tabletop exercise simulating a full-day EHR outage. Shorter quarterly drills practice the paper fallback process. A written summary follows each test. The plan is reviewed annually and after any system or vendor change.
Sample Plan 3 – Nonprofit with a distributed team (completed example)
Capital Rivers Outreach is a Richmond-based nonprofit with 22 staff and volunteers working mostly remote across Virginia. The organization relies on a donor CRM (Bloomerang), Google Workspace for files and collaboration, and Zoom for meetings. This example shows what a solid plan looks like when there is no budget for redundant data centers – only smart planning and clear roles. Organizations with BCPs can allocate resources effectively during crises, even on a tight budget.
Plan activation triggers and authority. The plan activates when: the donor CRM is inaccessible for more than 2 hours, Google Workspace or cloud file storage is down for more than 4 hours, the primary communication platform (Slack or Zoom) is unavailable, or a natural disaster affects staff in a key region. The Executive Director activates the plan. If unavailable, the Operations Coordinator takes over and notifies the Board Chair.
Continuity team.
- Executive Director – strategic decisions, board and major donor communication
- Operations Coordinator – logistics, vendor contacts, tracks task progress
- IT Volunteer/Consultant – system troubleshooting, backup verification, vendor coordination
- Development Director – donor communication, donation tracking during outage
- Programs Director – program delivery continuity, volunteer coordination
- Board Liaison – keeps board informed, handles governance-level questions
Critical functions and maximum tolerable downtime.
| Function | Maximum Tolerable Downtime | Key Dependency |
|---|---|---|
| Accepting online donations | 4 hours | Payment processor, website |
| Donor database access | 8 hours | CRM platform |
| Grant reporting | 24 hours | Cloud files, CRM data |
| Program delivery communications | 4 hours | Email, messaging tools |
| Staff collaboration tools | 8 hours | Google Workspace |
| Payroll | 48 hours | Payroll vendor |
Missing a grant deadline on a fixed date can negatively impact funding for an entire program cycle. A business continuity plan improves overall organizational efficiency by clarifying these dependencies before a crisis hits.
Communication plan and board notification. The Operations Coordinator maintains a phone/SMS tree and a WhatsApp group for leadership. When email or Slack is down, staff check the WhatsApp group for instructions. The Board Chair receives a call within 1 hour of any significant event. If an outage delays grant reporting or a public event, the Development Director sends a brief status note to major donors.
Low-budget recovery strategy and systems steps. The Development Director exports key donor and grant data monthly to an encrypted USB drive and a separate cloud folder. When the CRM is unavailable, the team tracks incoming gifts in a shared Google Sheet (or a locally stored CSV if Google is also down). The recovery sequence prioritizes donation processing first, then grant deadlines, then internal communications. The IT Volunteer/Consultant checks provider status pages and coordinates with CRM support. These are simple, manual workarounds – no additional sites or expensive failover infrastructure required.
Return to normal operations criteria. CRM and payment systems are stable for one full business day. The backlog of unlogged donations is under 5 entries. Any delayed grant reports have been submitted. The Operations Coordinator signs off and sends a summary to the Executive Director and Board Liaison.
Review and testing schedule. The Operations Coordinator leads a twice-yearly review. At least once a year, the team simulates a donor database outage and walks through the spreadsheet-based workaround. Contact information is updated every quarter.
What these three plans have in common
Despite serving different industries, these three sample plans share the same backbone.
Each plan clearly names a decision-maker and a small continuity team. This avoids the common failure where “everyone is responsible, so no one is.” Whether it is a Managing Partner, Medical Director, or Executive Director, one person has authority to activate the plan.
All three express downtime tolerance in hours – not vague terms like “as soon as possible.” Riverview Advisory sets email recovery at 4 hours. Westover Family Clinic sets medication list access at 1 hour. Capital Rivers Outreach sets donation processing at 4 hours. These numbers force honest conversations about what matters most.
Every plan includes at least one out-of-band communication method. SMS groups, WhatsApp, Signal, phone trees – none of them depend on the system that failed. This is what makes a plan activatable during the very event it was written for.
Each plan pairs operational continuity steps with disaster recovery steps. The medical practice keeps seeing patients on paper while IT restores the EHR. The nonprofit tracks donations in a spreadsheet while the CRM comes back. Business continuity and disaster recovery work together but are distinct processes.
All three include review and testing routines. According to the US Chamber of Commerce (2023), 91% of businesses have experienced at least one significant disruption. Testing and maintenance of a business continuity plan are essential components for preparedness. BCPs are required by standards like SOC 2 and ISO 27001, and effective plans adhere to standards like ISO 22301 and FEMA guidelines. Organizations often benchmark their plans against these established industry standards.
These shared patterns matter more than industry specifics. Any small business can adapt them by filling in its own triggers, roles, and recovery priorities.
The five mistakes that make a plan useless
These come from what actually goes wrong in real incidents at small organizations.
1. It lives in one person’s head or on one server. When the plan is stored only on the file server that just crashed, nobody can read it. Keep printed copies in a binder and a second copy in a cloud location accessible from personal devices.
2. Contact information is out of date. This is the single most common failure. Staff leave, phone numbers change, vendors switch account reps. A quarterly check of the emergency contact information list takes 15 minutes and prevents wasted hours during a crisis.
3. Backups exist but restores are untested. Many businesses confirm that backups run nightly but never test restoring from them. A hardware failure or ransomware attack then reveals missing credentials, corrupt files, or incomplete images. Test a full restore at least once a year.
4. No out-of-band communication channel. If the plan assumes email will work to coordinate the response to an email outage, the plan cannot be activated. Define a backup channel – group text, messaging app, phone tree – that works when the primary infrastructure does not.
5. The plan never gets reviewed. A document written three years ago may reference retired systems, former employees, or a vendor you dropped. Review and update the business continuity plan at least annually. A stale plan can be worse than no plan because it creates false confidence.
How to adapt these samples to your business
You do not need to start from scratch. Pick the sample closest to your organization and follow these steps to make it yours within a week.
Step 1: List your critical functions and rank them. Write down the core activities that keep your business running – taking customer calls, processing orders, seeing patients, accepting donations. A business impact analysis identifies critical business processes and tells you which must come back first.
Step 2: Assign a maximum tolerable downtime to each. Use specific numbers in hours, guided by customer expectations, safety requirements, and cash flow impact. A software company BCP might focus on data security during breaches with a 2-hour RTO for its platform. A manufacturing BCP might address supply chain disruptions with a 24-hour window before production stops. TSMC, for example, restored 70% of operations within a day after an earthquake – proof that clear recovery targets drive faster recovery.
Step 3: Map dependencies. For each function, note the systems, vendors, key suppliers, locations, and people it relies on. This exposes single points of failure and shapes your recovery strategy.
Step 4: Name the humans. Assign roles for decision-making, IT contact, communications, and department leads. Use role titles, not just names, so the plan survives turnover. The security team, facilities contacts, and department leads each need clear responsibilities.
Step 5: Write your communication tree. Outline who contacts whom, using at least one channel that does not rely on office email or the main network. Remote work and remote operations mean staff may be scattered – the tree must reach everyone.
Step 6: Schedule your first test. Even a 60-minute tabletop walk-through – where the team imagines a ransomware attack or day-long internet outage and talks through the action plans – will expose gaps. The test is the step that turns a document into a plan.
Download the business continuity plan template
The downloadable template is a simple, editable document based on the three examples above, available in Word format. It includes these sections:
- Plan activation criteria and authority
- Roles, responsibilities, and emergency contact list
- Business impact analysis and critical functions table
- Communication plan with out-of-band channels
- Disaster recovery steps summary
- Return-to-normal criteria
- Review and testing log
Unlike generic templates, this one mirrors the structure of the finished plans, so you can copy language directly and swap in your own systems, tools, and roles. It works across specific business units, departments, or additional sites. Keep one copy printed in the office and another in a cloud location accessible from home or mobile devices during a disruption.
Frequently asked questions
These FAQs reflect what small-business clients usually ask when they start building a business continuity plan.
How detailed should our business continuity plan be? Detailed enough that someone new to the role could follow it during an outage, but short enough that people actually read it. Focus on triggers, roles, communication procedures, and the first 24–72 hours. A 15–25 page document with appendices is typical for a small business.
Do we really need a separate disaster recovery plan? Many small businesses combine business continuity and disaster recovery in one document. That works fine – just treat “keeping the business running” and “restoring systems and data” as distinct sections. DRP outlines steps for data access restoration post-disaster; BCP covers the broader operational continuity picture.
How often should we review and test our BCP? Review the plan at least once a year and run some form of test or exercise annually. Add extra checks after major changes – switching core systems, moving offices, or significant staff turnover. Even a short tabletop drill counts.
Who should own the business continuity plan? Ownership usually sits with operations or the most senior manager on-site, with IT as a key partner. Avoid assigning it only to IT. Many critical functions – client communication, patient scheduling, donor relations – are non-technical. The plan needs expertise from across the organization.
What scenarios should we plan for first? Start with the most likely, highest-impact events: extended internet outage, loss of access to the main office or facilities, a key cloud service outage, and a ransomware attack affecting shared data. These scenarios cover the risks most small businesses face and develop useful information for handling less common disruptions.
How long does it take to create a usable plan? Most small businesses can produce a workable first version in one to two weeks using a sample business continuity plan and template like the ones here. The plan gets sharper after the first test. Do not wait for perfection – write it, test it, then improve it.
Closing thoughts
The hardest part is not writing the business continuity plan – it is testing it with the people who will actually use it. Most small businesses only discover their real recovery time during an actual incident, which is why even a simple, tested plan is a major improvement over having nothing written down.
Pick the closest sample plan today, adapt it with your own systems and roles, and schedule a short tabletop test within the next month.