Blog | BCMMetrics

7 Site-Document Retrieval Tests for BCM Software

Written by Michael Herrera | Sep 18, 2026, 1:00:00 PM

When evaluating BCM software, give each vendor the same realistic incident scenario and ask an alternate user to locate the complete site response set without coaching. Start with the affected location, not a document name, and require the user to find the approved continuity plan, emergency procedures, floor plans, access instructions, utility information, site contacts, vendor details, and incident forms.

Do not score the platform only on whether it can upload files. Record whether the user found the correct documents, recognized the approved versions, had appropriate access, understood what belonged to the site, and could move from retrieval into incident work. There is no universal time threshold for this test. Compare the steps, uncertainty, assistance, and manual work each platform requires.

In short

  • Start the demonstration with an affected site, not a document name supplied by the vendor.
  • Ask an alternate, non-administrator user to retrieve the complete response set.
  • Confirm that approved, current content is distinguishable from drafts or obsolete files.
  • Test access, upkeep, incident context, and fallback arrangements.
  • Record demonstrated results instead of awarding credit for verbal assurances.

When a Generic Document Library Falls Short

A general document library can work when users know the file name, owner, or folder path. A BCM software evaluation should also test the harder case: the responder knows which branch, clinic, office, warehouse, or plant is affected but does not know where every relevant file is stored.

Under OSHA 29 CFR 1910.38, US employers required by an OSHA standard to maintain an emergency action plan must keep it in the workplace and make it available to employees for review. FEMA’s May 2025 Developing and Maintaining Emergency Operations Plans guidance recommends keeping emergency plans accessible and providing alternate formats where needed. Neither source prescribes the software tests below.

For guidance on structuring and maintaining the repository itself, see the BCMMetrics guide to site-level document storage. This article addresses the purchasing decision: can a proposed platform demonstrate effective retrieval with your users, locations, document set, and access rules?

Seven Tests for Site-Document Retrieval

Use these criteria as a starting point, not a formal standard or exhaustive control set. Add any security, regulatory, labor, facility, and incident requirements that apply to your organization.

Evaluation test Ask the vendor to demonstrate Evidence to record
1. Location-first navigation Start with a named affected site and reach its continuity records without knowing a file name or department folder. Navigation path, number of decisions, search terms, coaching required
2. Complete site response set Retrieve emergency procedures, floor plans, access instructions, utility information, site contacts, vendor details, the approved continuity plan, and incident forms. Items found, missing items, items stored elsewhere, manual reconciliation
3. Current and approved content Distinguish the approved plan and current site documents from drafts, superseded files, or material with unclear status. Visible status, owner, approval or review information, ambiguity
4. Appropriate access Have an alternate non-administrator retrieve what that role should see without receiving broader access than necessary. Successful and blocked items, role changes, administrator intervention
5. Incident context Move from the affected site and its documents into the incident record or response documentation used by the team. Links or steps between site, contacts, plans, incident record, and forms
6. Maintenance and ownership Update a site contact or replace a document, then show how the current record is identified and who owns the next review. Update steps, ownership, review information, duplicate or stale copies
7. Continuity of access Explain and demonstrate the approved alternative when the platform, identity provider, network, or user device is unavailable. Export or fallback method, responsibility, update process, test evidence

“Available in the platform” and “available under incident conditions” are not the same claim. Do not assume offline access, automatic exports, or another fallback unless the vendor demonstrates it and the contract supports it.

Run a Realistic Retrieval Scenario During the Demo

A task-based demonstration exposes differences that a feature checklist can hide.

At 7:15 p.m., a water leak makes a regional office inaccessible. The primary site lead cannot be reached. An alternate continuity coordinator must identify who can authorize local actions, give a vendor the correct access instructions, locate utility information and the floor plan, open the approved continuity plan, and start the organization’s incident documentation.

Give the user only the site name and the scenario. Do not provide document titles, folder paths, or hints about the interface.

Observe whether the user can:

  1. Find the correct location record.
  2. Identify the alternate site contact and applicable vendor.
  3. Retrieve the emergency procedure, access instructions, utility information, and floor plan.
  4. Open the approved continuity plan and recognize its status.
  5. Locate the correct incident form or begin the supported incident record.
  6. Explain what they would do if the normal access path were unavailable.

Record the path, wrong turns, inaccessible records, coaching, and work completed outside the platform. Speed matters only when the documents are correct, current, appropriately protected, and sufficient for the task.

Ask the vendor to use one representative site and show how an alternate user would find its approved plan, contacts, critical documents, and incident records without coaching. Record what the software demonstrates, what requires configuration, and what will remain your team’s responsibility.

Evaluate the Implementation Work Behind the Demonstration

Before selecting the platform, determine what your organization must configure and maintain:

  • Location model: Define whether the retrieval unit is a campus, building, office, clinic, warehouse, branch, plant, or another location.
  • Document set: Specify what belongs with each site type. A plant, clinic, and leased office will not require identical records.
  • Ownership: Identify the owner, approver where required, review trigger, current version, and treatment of obsolete material.
  • Access and fallback: Confirm who needs access, which alternates must be prepared, and who maintains the approved fallback.
  • Exercises: Repeat the scenario after configuration and material changes, then track failures as corrective actions.

The organization remains responsible for record accuracy and authority. A successful demonstration does not prove that the workflow will remain usable without maintenance and exercises.

For broader BCM software criteria covering reporting, evidence, adoption, security, implementation, and cost, use the BCMMetrics guide to evaluating BCM software before purchase. For guidance on the content and sequence of emergency response work, see MHA Consulting’s article on the six tasks an emergency plan should address.

Evaluate BCM One Against the Same Retrieval Tests

BCM One uses the facility as the organizing point. Current approved product materials support:

  • Facility records with location details
  • Connections to related recovery plans
  • Primary site contacts and location-specific uploads
  • Site-level incident records
  • Incident action plans and briefing agendas
  • An accessible archive of closed incidents

These capabilities make BCM One relevant to a buyer evaluating how BCM software organizes and retrieves plans, contacts, documents, and incident information for one affected location.

The organization still determines which documents belong to each site, which version is authoritative, who receives access, and what fallback is required. Confirm security, access, export, device, identity, and integration requirements directly during evaluation.

During a demonstration, ask BCMMetrics to start with a named facility and show the path to its recovery plans, contacts, uploaded documents, and incident records. Verify any requirements involving permissions, document status, exports, device access, identity dependencies, or fallback arrangements directly rather than assuming that a location-based repository provides them.

If you are still defining the physical and access information that belongs with each site, the BCMMetrics guide to facility mapping for business continuity provides the adjacent implementation guidance.

Choose Software Based on the Retrieval Work You Need

The right evaluation asks whether the people responsible for an affected location can reach the correct, current, authorized response set and continue the incident workflow without hidden folder knowledge or administrator rescue.

Use the same scenario for every shortlisted vendor. Record demonstrated performance, unresolved questions, customer responsibilities, and manual work. Evaluate the result alongside security, implementation effort, administration, support, and total cost.

Retrieval works only when the underlying plans contain the information people need. Use the Business Continuity Planning Checklist to identify the plans, procedures, contacts, and supporting documents the software must make easy to retrieve.