Prepare For the Worst with the Best in the Business
Experience capable, consistent, and easy-to-use business continuity management software.
An exercise after-action report is usable when someone who was not in the meeting can understand what was tested, what happened, why it matters, and what must change next. It should act as a handoff into remediation and plan maintenance, not as a transcript or a record that the exercise occurred.
That distinction matters. An AAR can be accurate and still be difficult to use. It may describe the scenario and discussion in detail but leave the program owner to reconstruct which finding relates to which objective, who owns the response, what plan needs to change, and how closure will be verified.
In short
- Tie observations to defined objectives and evidence.
- Separate what happened from why it matters and what should change.
- Give each required action an owner, target date, and closure evidence.
- Identify the plan, procedure, training, or decision affected by the finding.
- Keep the AAR as the source record while managing changing action status in a connected tracker.
- Report both findings and what changed afterward.
What Makes an Exercise After-Action Report Usable?
A useful AAR lets the reader follow a clear line:
Objective → observation → evidence → consequence → decision → action → plan change → closure
Not every observation needs to become a corrective action. Some observations confirm that a process worked. Others identify an assumption that needs validation, a decision that must be escalated, or a lower-priority issue worth monitoring. The report should make those differences visible.
The following test is a practical way to review an AAR before it is finalized. It is editorial guidance, not a formal standard.
| Usability question | What the AAR should show |
|---|---|
| Can the finding be traced? | The objective, scenario point, observation, and supporting exercise evidence |
| Can someone act on it? | A specific change, decision, or investigation rather than a vague recommendation |
| Is ownership clear? | One accountable owner, a realistic target date, and any required approver |
| Is it connected to the program? | The plan, procedure, training, dependency, or control affected |
| Can closure be verified? | The evidence required to show completion and whether retesting is needed |
If the report cannot answer one or more of those questions, the missing work usually reappears later as email follow-up, spreadsheet cleanup, or uncertainty during the next exercise.
Build the AAR From Objectives and Evidence
The AAR should begin before the exercise. Evaluation criteria need to be tied to the exercise objectives so evaluators know what to observe and what evidence to capture.
NIST Special Publication 800-84 says an after-action report should be based on evaluation criteria established before the exercise. Those criteria are tied to the objectives and help data collectors determine what information to capture. The report should document the exercise background, observations, and recommendations for improving the plan that was exercised.
FEMA’s Homeland Security Exercise and Evaluation Program uses a combined After-Action Report/Improvement Plan approach. Its current improvement-planning guidance describes improvement plans as dynamic documents whose corrective actions are continually monitored and implemented.
These sources serve different contexts, but both support the same practical point: the report should be built from defined objectives and observed evidence, then carried into improvement work.
At minimum, preserve:
- Exercise name, date, scope, type, and scenario
- Plans, processes, systems, locations, or business units tested
- Objectives and the criteria used to evaluate them
- Participants, facilitators, evaluators, and relevant decision roles
- Observations supported by facilitator notes, controller logs, participant feedback, timestamps, system results, or produced artifacts
- Objective results, with any limitation that affects the conclusion
- Decisions made during or immediately after the exercise
- Findings, recommendations, and required follow-up
- The records that will show completion or support a later retest
This does not mean the report needs to include every note. Include enough evidence to support the conclusion, and point to the detailed source when the source needs to be retained separately.
Write Findings So Another Person Can Act on Them
Vague findings create vague follow-through.
“Communications need improvement” may be true, but it does not tell the owner which communication failed, under what condition, or what would count as fixed. “Update the plan” has the same problem. It names an activity without defining the required change.
A usable finding separates five elements:
- Observation: What happened during the exercise?
- Evidence: What record supports that observation?
- Consequence: Why did it affect the objective or response?
- Required change or decision: What needs to happen next?
- Follow-through: Who owns it, when is it due, and what will prove closure?
A Hypothetical Before-and-After Example
The following example is illustrative. It does not describe a BCMMetrics customer or a documented exercise.
Weak finding
The team was unclear about notification responsibilities. Update the crisis plan.
Usable finding
| Field | Example record |
|---|---|
| Objective | Confirm the team can declare an incident and initiate the required internal and vendor notifications |
| Observation | Participants identified the incident-declaration role, but the vendor notification did not begin because the plan assigned responsibility to a department rather than a named role and alternate |
| Evidence | Facilitator log entries 6–9, participant decision log, and crisis plan section 3.2 |
| Consequence | The team could not confirm who would contact the vendor when the primary department lead was unavailable |
| Required change | Update the notification procedure with a primary role, alternate role, trigger, sequence, and contact source |
| Owner and target | Crisis plan owner, within 30 days |
| Affected record | Crisis plan section 3.2 and the notification checklist |
| Closure evidence | Approved plan revision and confirmation that both assigned roles can locate and use the updated procedure |
| Retest | Recheck the notification handoff during the next exercise or focused walkthrough |
The longer version is not better merely because it contains more words. It is better because the next person can see the issue, source, consequence, required change, and proof of closure without reopening the entire exercise discussion.
Keep the AAR and Remediation Tracker Connected
The AAR and the remediation tracker serve different purposes.
The AAR is the approved account of what the exercise tested and revealed. Once finalized, it should remain a stable source record. The remediation tracker is a working record. Owners, dates, status, dependencies, evidence, and escalation needs may change as the work progresses.
Trying to make the AAR perform both jobs creates two common problems:
- The report becomes outdated as soon as action status changes.
- Teams repeatedly edit the source document, making it harder to tell what was originally concluded.
Keep the records connected with a unique finding or action identifier. A practical tracker should include:
- Finding or action ID
- Link to the source AAR and relevant observation
- Action statement
- Owner and approver, when required
- Priority and target date
- Current status
- Dependencies or blockers
- Affected plan, procedure, training, or control
- Closure evidence
- Retest requirement and result
- Closure date and approval
For the broader corrective-action workflow, see Exercise Follow-Through: Closing Actions Instead of Letting Them Drift. That process deserves its own operating cadence. The AAR should give it a clean starting point.
Connect Exercise Results to Plan Maintenance and Reporting
An AAR is not complete just because the findings were accepted. The program owner also needs to determine where the results change the continuity program.
For each material finding, ask:
- Does a continuity, crisis, recovery, or communications plan need revision?
- Does a role, authority, or escalation threshold need clarification?
- Did the exercise expose a dependency missing from the BIA or plan?
- Does a procedure or checklist need a more usable sequence?
- Is training required before the change can work?
- Does management need to fund, approve, accept, or monitor something?
- Should the issue be retested, and under what conditions?
The AAR should identify the affected artifact or decision. The tracker should then show whether the update was completed and approved.
Leadership reporting should keep the distinction clear. Report what the exercise found, what changed, what remains open, and which decisions require attention. A count of completed exercises says little about whether readiness improved.
If the exercise itself is producing weak or inconsistent findings, first review the objectives, injects, evaluation criteria, and facilitation approach in Tabletop Exercises for Audit-Ready BCM: Objectives, Injects, Follow-Through.
For deeper strategic guidance on crisis-team roles and decision authority, MHA Consulting’s How to Set Up a Crisis Management Team provides useful context. The BCMMetrics workflow should document and maintain those decisions, not replace the strategic work required to define them.
Where BCM Sotware Fits
Document and spreadsheet processes can support an AAR when the volume is manageable and ownership is disciplined. They become harder to maintain when exercise records, plan versions, approvals, and reporting are spread across different locations.
BCM Planner supports exercise templates, selection of participating business units, applications, and plans, capture of exercise results, and ad hoc reporting. It also supports creating or uploading continuity plans and managing their review and approval status.
That makes the module relevant when the team wants exercise records and the plans affected by those exercises managed in the same platform. It does not decide whether a finding is material, write the corrective action, or determine what evidence is sufficient. The team still needs clear evaluation criteria, ownership rules, and closure standards.
Make the AAR the Start of the Next Work Cycle
The meeting is not the end of the exercise. The AAR is the point where observed performance becomes organized work.
Before approving the report, ask whether someone outside the meeting can trace each material finding, understand its significance, identify the required change, locate the owner, and verify closure later. If not, the report is preserving discussion rather than supporting improvement.
Theron Long
Theron Long is responsible for supporting BCMMetrics' development and operations. Prior to taking on this role, Theron worked as a Consultant under one of MHA’s Senior Advisory Consultants where he had hands on experience in business continuity. He now uses that experience to further innovate BCMMetrics for our internal functions and subscribers alike. Theron has a bachelor’s degree in Technical Communication with a concentration in User Experience from Arizona State University.