---
title: "BC Plan Automation: What Software Should and Shouldn't Do"
description: Learn which BC plan tasks software should automate, which need human review, and how to test templates, data reuse, workflows, and AI.
image: https://bcmmetrics.com/hubfs/BC%20Plan%20Automation.png
---

[Skip to content](https://bcmmetrics.com/blog/evaluate-bc-plan-automation-human-judgment#main-content)

<https://bcmmetrics.com/>

SOLUTIONS

[PRICING](https://bcmmetrics.com/pricing)

USE CASES

RESOURCES

[ABOUT US](https://bcmmetrics.com/about-bcmmetrics)

Flexible BCM software solutions

[See all solutions →](https://bcmmetrics.com/business-continuity-solutions)

[![Group 1171274363](https://bcmmetrics.com/hubfs/Group%201171274363.svg) **REGULATORY COMPLIANCE** A self-assessment tool to evaluate the level of compliance of your business continuity program](https://bcmmetrics.com/business-continuity-solutions/compliance-confidence)

[![Frame 16367](https://bcmmetrics.com/hubfs/Frame%2016367.svg) **BUSINESS CONTINUITY PLANNING** A single platform where you can build and share business continuity plans (BCPS) across your entire team](https://bcmmetrics.com/business-continuity-solutions/bcm-planner)

[![Frame 16365](https://bcmmetrics.com/hubfs/Frame%2016365.svg) **BUSINESS IMPACT ANALYSIS** An everyday business impact analysis (BIA) software to help you prepare and plan for anything](https://bcmmetrics.com/business-continuity-solutions/bia-on-demand)

[![Group 1171274403](https://bcmmetrics.com/hubfs/Group%201171274403.svg) **FACILITIES MANAGEMENT** An intuitive icon-based mapping tool to better manage your facilities around the globe](https://bcmmetrics.com/business-continuity-solutions/bcm-one)

[**INSURANCE** Identify critical systems and create streamlined response plans](https://bcmmetrics.com/industry/insurance)

[**HEALTHCARE** Simplify compliance and risk assessments in one platform](https://bcmmetrics.com/industry/healthcare)

[**FINANCE** Manage audits and meet standards with ease](https://bcmmetrics.com/industry/finance)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/case-studies.svg) CASE STUDIES** Learn how others have redefined their BC management with BCMMetrics](https://bcmmetrics.com/business-continuity-case-studies)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/resource-library.svg) RESOURCE LIBRARY** Access our collection of free downloadable resources](https://bcmmetrics.com/business-continuity-resources)

[**![case-studies](https://bcmmetrics.com/hubfs/Website%20Images/Global/blog.svg) BLOG** Read along for expert BC advice from our senior consultants](https://bcmmetrics.com/blog)

[LOG IN](https://app.bcmmetrics.com/Portal/login.aspx) [VIRTUAL TOUR](https://bcmmetrics.com/virtual-tour-form) [BOOK YOUR DEMO](https://bcmmetrics.com/demo)

![Mask group (7)](https://bcmmetrics.com/hubfs/Mask%20group%20(7).png)

![Mask group (6)](https://bcmmetrics.com/hubfs/Mask%20group%20(6).png)

Business Continuity

# BC Plan Automation: What Software Should Automate and What People Must Decide

 Michael Herrera

 Published on: September 30, 2026

### Prepare For the Worst with the Best in the Business

Experience capable, consistent, and easy-to-use business continuity management software.

[BOOK YOUR DEMO](https://bcmmetrics.com/demo)

BC plan automation should handle repeatable, traceable work while leaving context-dependent decisions with accountable people. The right evaluation question is not whether a platform can automate planning. It is whether the software automates the appropriate tasks without hiding source data, exceptions, assumptions, or responsibility.

That distinction matters across business continuity, crisis management, and site-level plans. Software can apply structure, reuse approved information, and organize plan work. It should not independently decide recovery strategy, activation thresholds, safety procedures, authority, or legal obligations.

**In short**

- **Automate** repeatable tasks that follow clear rules and use reliable source data.
- **Automate with human review** when software can prepare or route the work but context still affects the result.
- **Keep under human control** decisions involving strategy, authority, safety, compliance, or resource commitments.
- Evaluate deterministic automation separately from generative AI.
- Test software with a real plan, a known data issue, and a realistic change.

## What BC Plan Automation Should and Should Not Do

[Michael Herrera has described](https://bcmmetrics.com/blog/business-continuity-automation) conducting BIAs in Word, recording interviews on a conference-room chalkboard, and retyping the information afterward. That approach became unworkable when the work expanded across countries. The lesson was not that software should make every decision. It was that practitioners should not spend their time repeating administrative work that a controlled system can handle.

Two forms of automation now need to be evaluated separately.

**Deterministic automation** follows defined rules. A template applies an approved structure. A placeholder pulls a value from a known source. A workflow assigns or routes a task. The input, rule, and result can usually be traced.

**Generative AI** creates new content based on patterns, instructions, and available data. It may help draft text or summarize material, but it can also introduce inaccurate details, omit context, or present assumptions as facts.

The July 2024 [NIST Generative AI Profile](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) identifies risks including confabulation, information integrity, privacy, and content provenance. It recommends ground-truth comparison, fact-checking, domain-expert involvement, and realistic testing. NIST AI 600-1 is voluntary cross-sector guidance, not a BCM standard, but those controls are relevant when generated content could influence incident decisions.

Software evaluation should therefore use three categories:

1. **Automate:** The task is rules-based, repeatable, traceable, and does not require case-specific judgment.
2. **Automate with human review:** The system can populate, draft, flag, or route the work, but a qualified person must validate the result.
3. **Keep under human control:** The decision changes strategy, authority, safety, compliance obligations, or resource commitments.

[![BUSINESS CONTINUITY CHECKLIST](https://no-cache.hubspot.com/cta/default/46578083/interactive-223249861196.png)](https://bcmmetrics.com/hs/cta/wi/redirect?encryptedPayload=AVxigLIX9Xj9jh13V4SyK4BxdSjMKqCNQapRI%2FODkzgtjmAEjbeV6FpVoGG%2FiUY4SjZQHZYyutrx4XS2adIavT%2F2%2F4f2Hj1TPKlnKqLMSi8838X5G8LKtEQtSjd5%2FJJ0PZHtTep7H%2BawQwEc9ABdrHSTaGBKek5qL3EDHzy9Ta5Yx4GNAfDmBdPsmpdTKvvuHJjWdG5ZDW6TmgAq%2B0NxbGDodpWuVKrkK9I%2FYBDt0wxlHm%2BZkD3X8VpdmURVUL1hOtmKl4g2VWRUGsVovRFaIOm7eiinaz%2FJVr8CYE%2FEVaCI9CgN35IKnkVawspXAQrJ3mi2TVjQvGUzSNqJeDjrSkQcLhcN%2FS33mnCe2As%2Fz8gNnz4STFOTYhkR0A3ctA%3D%3D&webInteractiveContentId=223249861196&portalId=46578083)

## Use Four Questions to Evaluate Each Automated Task

Ask four questions about every task the software claims to automate:

1. Is the task repeatable and governed by a clear rule?
2. Does it use an approved source of truth?
3. Can a reviewer see how the result was produced?
4. Can an accountable person correct, reject, or approve it?

If all four answers are yes and the task has limited consequences, direct automation may be appropriate. If the software prepares the work but interpretation still matters, automate it with human review. If the task affects strategy, authority, safety, compliance, or major resource choices, keep the decision under human control.

| Planning task | Evaluation category | Appropriate software role | Human responsibility | Evidence to request |
| --- | --- | --- | --- | --- |
| Apply plan structure | Automate with human review | Apply approved sections and required fields | Decide which sections apply and what local detail is needed | Show how templates allow justified variation |
| Reuse plan data | Automate with human review | Insert verified owners, recovery objectives, contacts, or dependencies | Confirm currency and resolve conflicting information | Show the source, missing values, and update behavior |
| Track plan status and versions | Automate | Identify the current plan and its working state | Define who may change or accept the plan | Show the current version and available history |
| Route review work | Automate with human review | Assign or route work to named people | Decide whether the plan and evidence are sufficient | Show ownership, exceptions, and the review record |
| Draft plan language | Automate with human review | Suggest wording or summarize approved material | Verify every operational statement | Identify generated text, sources, edits, and reviewer action |
| Set recovery strategy and sequence | Keep under human control | Present approved inputs and known dependencies | Decide what is workable and how scarce resources are used | Ask where the decision and rationale are recorded |
| Define activation and authority | Keep under human control | Display roles, contacts, and decision aids | Set thresholds, escalation paths, and decision rights | Test whether responsibility remains explicit |
| Record exercise results | Automate with human review | Store results and connect findings to plans | Interpret performance and decide corrective action | Show what changed and who accepted the change |

This is a practical evaluation method, not a formal control set. Legal, regulatory, contractual, safety, privacy, and local operating requirements may require additional controls.

The same boundary applies differently across plan types:

| Plan type | Useful automation | Judgment that must remain visible |
| --- | --- | --- |
| Business continuity plan | Template structure, approved BIA fields, owners, dependency data, version status | Workaround viability, recovery sequence, minimum service levels, resource tradeoffs |
| Crisis management plan | Role fields, contact information, agenda structure, decision-log format | Activation, escalation, decision authority, communications posture |
| Site-level plan | Site identifiers, recurring fields, assigned owners, document organization | Local hazards, access constraints, utility limitations, life-safety procedures, local requirements |

A connected field is useful only when its source is reliable. Pulling an approved recovery objective into a plan can reduce repeated entry, but the value still needs an owner, a review date, and a process for resolving conflicts with operating knowledge. For deeper guidance on those inputs, see [RTO, RPO, and MTPD: Setting Time Targets Without a Fight](https://bcmmetrics.com/blog/rto-rpo-mtpd-setting-time-targets).

Likewise, a status label does not prove that a plan is usable. It shows where the document sits in a process. Detailed governance for versions and approval belongs in a separate workflow, as explained in [Review and Approval Workflows for BC Plans](https://bcmmetrics.com/blog/plan-approval-workflows-bc-plans).

[![bcmmetrics-new-logo-navy](https://no-cache.hubspot.com/cta/default/46578083/interactive-212381562191.png)](https://bcmmetrics.com/hs/cta/wi/redirect?encryptedPayload=AVxigLLfEIWb%2B1NY8ttMxIfvpvOEm1DJmfiWXr49jnrbDVWcEegtho0hwZ74Zf1q%2ByXRIcqOhGgIZoXsU4TavZeu5KLgTJ0PE%2BjOiRjqxr5Fmx8Wy1XbPE0ZU8svvieop14oKKCYBRr9ONYcrAXTmuIZ5PBCjJKQXbBPUqaR1q4RlMnkPIF4L1MAhq1sRtmZpVE1j0hIRls0SqIrGhd91U8jfg%3D%3D&webInteractiveContentId=212381562191&portalId=46578083)

## Test the Software With a Real Plan Change

Do not evaluate BC plan automation only with a vendor's sample template and perfect data. Bring one current plan, one known information problem, and one recent organizational change.

Consider this **hypothetical evaluation scenario**: a regional distribution center loses power after severe weather.

The platform can populate the facility name, process owner, approved recovery objectives, dependencies, and contact data. A template can provide sections for activation, workarounds, suppliers, communications, and recovery steps.

People must still decide whether orders can be rerouted, how long manual processing is viable, which customers receive priority, whether the alternate facility has enough capacity, who can authorize a transfer, and when normal operations can resume. The crisis plan requires human decisions about activation and communications. The site-level plan requires validated local information about access, power, safety, and facility constraints.

Use that scenario to test the software:

1. **Build from an existing template.** Confirm that required structure can coexist with plan-specific variation.
2. **Populate approved information.** Ask where each value comes from and how users recognize missing or conflicting data.
3. **Change one source value.** Observe whether the effect is visible and whether the plan owner can review the change before local context is lost.
4. **Find the current plan.** Ask an alternate user to locate the correct plan and determine its status without coaching.
5. **Test an exception.** Use a business unit, crisis team, or site that does not fit the standard template.
6. **Review the evidence.** Confirm what the software records about changes, responsibility, and human decisions.

A well-designed workflow should make exceptions visible. It should not remove them in the name of consistency.

If the product includes generative AI, test it separately. Ask what sources it can use, how generated text is identified, whether sensitive data is retained or used for model training, what provenance is available, whether prompts and overrides are recorded when needed, and what prevents generated content from bypassing review. Security, privacy, legal, compliance, and operational owners should participate when the potential consequences warrant it.

## Reduce Repetitive Plan Work Without Losing Control

[BCM Planner](https://bcmmetrics.com/business-continuity-solutions/bcm-planner) supports several of the repeatable planning tasks described above. Its current public product page documents that teams can:

- upload existing templates or create templates with a Word-style editor;
- create, edit, import, store, and share plans;
- use bracketed placeholders to populate data from BIA On-Demand;
- work with several plan labels, including business recovery, crisis management, disaster recovery, and fire and life safety plans; and
- create exercise templates, record results, and generate reports.

These capabilities make BCM Planner relevant when evaluating template management, BIA data reuse, central plan handling, and exercise records. They do not establish whether every organization's requirements for review, approval, history, exceptions, or AI governance are met. Buyers should test those requirements with their own template, data, users, and operating scenario.

The intended workflow value is to reduce repeated data entry and document administration while preserving practitioner review. Software can assemble information and support plan upkeep. It cannot own the operational answer.

Start with one current plan. Use the [Business Continuity Planning Checklist](https://bcmmetrics.com/resources/business-continuity-planning-checklist) to review your planning approach, then bring the plan, its source data, and one known exception to a [BCMMetrics demonstration](https://bcmmetrics.com/demo). Ask the team to show what the software automates, what requires review, and which decisions remain with your organization.

---

![](https://bcmmetrics.com/hubfs/Website%20design/Michael-Herrera-MHA-Consulting.jpg)

#### Michael Herrera

 Michael Herrera is the Chief Executive Officer (CEO) of MHA. In his role, Michael provides global leadership to the entire set of industry practices and horizontal capabilities within MHA. Under his leadership, MHA has become a leading provider of Business Continuity and Disaster Recovery services to organizations on a global level. He is also the founder of BCMMETRICS, a leading cloud based tool designed to assess business continuity compliance and residual risk. Michael is a well-known and sought after speaker on Business Continuity issues at local and national contingency planner chapter meetings and conferences. Prior to founding MHA, he was a Regional VP for Bank of America, where he was responsible for Business Continuity across the southwest region.

## Other resources you might enjoy

![critical recovery information](https://bcmmetrics.com/hs-fs/hubfs/Imported_Blog_Media/critical-recovery-information.jpg?height=245&name=critical-recovery-information.jpg)

#### [It Shouldn’t Be a Scavenger Hunt: Accessing Critical Recovery Information in Crisis](https://bcmmetrics.com/blog/critical-recovery-information)

 Michael Herrera

[Read More](https://bcmmetrics.com/blog/critical-recovery-information)

![business continuity standards](https://bcmmetrics.com/hs-fs/hubfs/Imported_Blog_Media/question-mark-on-wood-fotolia_80397099_subscription_monthly_m.jpg?height=245&name=question-mark-on-wood-fotolia_80397099_subscription_monthly_m.jpg)

#### [Should You Use Business Continuity Standards?](https://bcmmetrics.com/blog/should-you-use-business-continuity-standards)

 Michael Herrera

[Read More](https://bcmmetrics.com/blog/should-you-use-business-continuity-standards)

![](https://bcmmetrics.com/hs-fs/hubfs/Blog%20images/Imported_Blog_Media/how-to-launch-a-business-continuity-program.jpg?height=245&name=how-to-launch-a-business-continuity-program.jpg)

#### [Beyond DR & IT: Why Facility Mapping Should Be at the Heart of Every Business Continuity Program](https://bcmmetrics.com/blog/facility-mapping-business-continuity)

 Richard Long

[Read More](https://bcmmetrics.com/blog/facility-mapping-business-continuity)

## Ready to start focusing on higher-level challenges?

### ![Group 1171274345](https://bcmmetrics.com/hubfs/Website%20Images/Footer/bcmmetrics-logo-new-white.svg)

3820 W Happy Valley Road  
Glendale, AZ 85310  
USA

[SOLUTIONS](https://bcmmetrics.com/business-continuity-solutions)

- [Regulatory Compliance](https://bcmmetrics.com/business-continuity-solutions/compliance-confidence)
- [Business Impact Analysis](https://bcmmetrics.com/business-continuity-solutions/bia-on-demand)
- [Business Continuity Planning](https://bcmmetrics.com/business-continuity-solutions/bcm-planner)
- [Facilities Management](https://bcmmetrics.com/business-continuity-solutions/bcm-one)

PRICING

- [Our Pricing Model](https://bcmmetrics.com/pricing)

RESOURCES

- [Case Studies](https://bcmmetrics.com/business-continuity-case-studies)
- [Resource Library](https://bcmmetrics.com/business-continuity-resources)
- [Blog](https://bcmmetrics.com/blog)

COMPANY

- [About us](https://bcmmetrics.com/about-bcmmetrics-old)
- [Contact](https://bcmmetrics.com/demo)
- [MHA Consulting](https://www.mha-it.com/)

© 2026 BCMMetrics. All rights reserved. [Privacy Policy](https://bcmmetrics.com/privacy-policy)

```json
{
  "@context" : "",
  "@type" : "BreadcrumbList",
  "itemListElement" : [ {
    "@type" : "ListItem",
    "item" : "https://bcmmetrics.com",
    "name" : "Home",
    "position" : 1
  }, {
    "@type" : "ListItem",
    "item" : "https://bcmmetrics.com/blog",
    "name" : "Blog",
    "position" : 2
  }, {
    "@type" : "ListItem",
    "name" : "BC Plan Automation: What Software Should Automate and What People Must Decide",
    "position" : 3
  } ]
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Michael Herrera",
    "url" : "https://bcmmetrics.com/blog/author/michael-herrera"
  },
  "dateModified" : "2026-09-30T16:31:44.975Z",
  "datePublished" : "2026-09-30T16:14:42.000Z",
  "headline" : "BC Plan Automation: What Software Should and Shouldn't Do",
  "image" : [ "https://bcmmetrics.com/hubfs/BC%20Plan%20Automation.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://bcmmetrics.com/blog/evaluate-bc-plan-automation-human-judgment",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://bcmmetrics.com/hubfs/Group%201171274345.svg"
    }
  }
}
```