Blog | BCMMetrics

Governance Calendar for BCM Reviews and Evidence Checks

Written by Michael Herrera | Aug 19, 2026, 3:01:31 PM

A governance calendar turns business continuity obligations into scheduled, owned work. For each activity, it should identify what will be reviewed, when or why the review starts, who owns and checks it, what evidence must result, when it is due, and what happens if the work is late or incomplete.

The calendar is not just a list of meetings. It is the control that connects your review cadence to plan approvals, exercise results, attestations, management reporting, and change follow-through.

In short

  • Schedule recurring work, but add triggers for material changes and findings.
  • Give every calendar item an owner and a separate reviewer or approver when needed.
  • Define the evidence expected before work begins.
  • Track completion by the resulting record, not by whether a meeting occurred.
  • Spread activity across the year so limited teams can finish the work.
  • Keep the calendar connected to current plans, approvals, exercise outputs, and change records.

What a Governance Calendar Should Control

A useful governance calendar controls repeatable work. It should answer six questions for every scheduled item:

  1. What activity or record is in scope?
  2. Is the work started by a date, a change trigger, or both?
  3. Who owns the work, and who reviews or approves it?
  4. What evidence shows that the work was completed?
  5. What is the due date and current status?
  6. What follow-up or escalation applies if the result is incomplete?

This structure matters because a meeting invitation only proves that time was reserved. It does not prove that a plan was reviewed, an exercise finding was assigned, or management accepted an unresolved issue.

ISO 22301:2019 describes a business continuity management system as one that is planned, operated, monitored, reviewed, maintained, and continually improved. It does not prescribe the calendar in this article. The practical inference is that recurring work needs an operating mechanism if a team wants to show that those activities occurred consistently.

The calendar should remain at the governance level. Detailed plan edits, exercise injects, BIA interview notes, and corrective-action tasks belong in their working records. The calendar points to those records and shows whether the required review or evidence check is complete.

Review Activity and Evidence Checks Are Not the Same

A review asks whether a BCM record or decision is still accurate, complete, and appropriate. A plan owner might confirm contacts, dependencies, recovery steps, and approval status.

An evidence check asks whether the resulting proof exists, is current, is retrievable, and supports the status being reported. For example, the evidence for a completed plan review could include the reviewed version, reviewer identity, approval record, change history, and any assigned follow-up.

The distinction prevents a common reporting problem. A calendar item marked “complete” because a meeting occurred can hide the fact that no approval was captured or that identified changes remain open.

Combine a Fixed Review Cadence With Change Triggers

A date-based calendar alone is too slow for material change. A trigger-only process is too easy to forget. A workable governance calendar uses both.

Fixed Reviews

Fixed reviews create a predictable workload. They may include monthly contact checks, quarterly plan cohorts, scheduled exercises, management reporting, and an annual confirmation of scope and ownership.

The frequency should come from the organization’s obligations, risk, rate of change, and available resources. It should not be copied from a generic sample. NIST SP 800-34 Rev. 1, which applies to federal information systems, supports maintaining contingency plans through recurring review and the system development life cycle. NIST also publishes templates that illustrate scheduled test and maintenance activity. Those examples can inform a calendar, but they do not establish a universal corporate BCM frequency.

Trigger-Based Reviews

Trigger-based work starts when an event makes the current record questionable. Useful triggers include:

  • a change in business process, application, facility, supplier, or recovery dependency
  • a change in plan ownership, escalation paths, or critical contacts
  • an incident, exercise, or test that exposes a plan gap
  • a new legal, regulatory, contractual, or internal requirement
  • an audit finding, overdue corrective action, or accepted risk that needs review
  • a material change in business priorities, products, services, or organizational structure

The FFIEC Business Continuity Management booklet gives financial institutions a sector-specific example. Its maintenance guidance identifies changes in strategy, products, infrastructure, third parties, requirements, exercise results, threats, audits, personnel, systems, and facilities as possible triggers. It also says BCM documentation should include evidence supporting periodic updates to BIAs, risk assessments, and continuity plans.

Your trigger list should reflect your own environment. The useful design rule is simple: if a change could invalidate a recovery assumption, responsibility, dependency, or approved plan, it should start a defined review rather than wait for the next annual cycle.

A date tells the team when to look. A trigger tells the team when waiting is no longer acceptable.

What to Include in Every Governance Calendar Entry

Use one record for each governance activity. A practical governance calendar should include the following fields.

Calendar field What to record Why it matters
Activity or record The plan, BIA cohort, exercise, contact set, approval, report, or follow-up being governed Prevents vague entries such as “quarterly BCM review”
Scope Business unit, site, plan group, process, system, or reporting audience Shows what is included and excluded
Fixed frequency or date The planned start, due date, or recurring frequency Creates a predictable review cadence
Review trigger The change or finding that can start an out-of-cycle review Keeps records current between fixed dates
Owner The role accountable for completing the work Prevents shared ownership from becoming no ownership
Reviewer or approver The role that validates or approves the result Separates completion from independent confirmation where needed
Required evidence The record that must exist when the item is complete Makes the completion standard visible in advance
Source location Where the current plan, form, exercise record, or report is maintained Reduces time spent searching across repositories
Status Not started, in progress, awaiting review, approved, complete, overdue, or blocked Makes bottlenecks visible without opening every record
Escalation rule When and to whom an exception is raised Keeps overdue or blocked work from drifting
Follow-up Required change, decision, risk acceptance, or corrective action Connects the review to the next piece of work
Completion date When the required evidence and review were finished Supports accurate reporting and later sampling

Avoid treating “email sent” or “meeting held” as sufficient evidence. The expected record depends on the activity.

Governance activity Possible evidence of completion
Continuity plan review Reviewed plan version, owner attestation, identified changes, approval record
BIA review Updated inputs, reviewer confirmation, approved changes to priorities or dependencies
Exercise Approved objectives, participant record, results, findings, assigned actions
Contact validation Date checked, responder or source, corrected record, unresolved exception
Management reporting Issued report, source data, decisions, approvals, assigned follow-up
Post-incident update Lessons recorded, affected plans identified, approved changes, corrective actions

The FFIEC post-exercise guidance illustrates this principle for financial institutions. It calls for documented issues, action plans with target dates, analysis against exercise objectives, management reporting, and plan updates based on results. Organizations outside that sector should use their own governing requirements, but the workflow lesson is broadly useful.

A 12-Month BCM Governance Calendar Example

The following BCM calendar is a starting point for a mid-sized organization with a limited continuity team. It deliberately distributes work across the year. It is not a compliance schedule, and it should be changed to match the organization’s risk, contracts, regulations, policy, plan inventory, and exercise program.

Month Planned governance focus Accountable role Evidence to retain
January Confirm program scope, plan inventory, owners, reviewers, annual reporting dates, and calendar exceptions carried forward BCM program owner Approved calendar, current inventory, owner list, exception list
February Validate priority plan contacts and obtain owner attestations for the first plan cohort Plan owners Validation record, attestations, required update list
March Review first-quarter status and evidence sample with management BCM program owner Status report, sampled records, decisions, assigned follow-up
April Review one BIA cohort and changes to critical processes, dependencies, applications, facilities, and suppliers BIA owners and BCM reviewer Updated BIA records, reviewer notes, approved changes
May Review the second plan cohort and approve objectives for the next exercise Plan owners and exercise lead Reviewed plans, approval records, exercise objectives
June Conduct the scheduled exercise and complete second-quarter management reporting Exercise lead and BCM program owner Exercise record, results, findings, status report, decisions
July Close or escalate exercise actions and update affected plans Action owners and plan approvers Corrective-action status, approved plan changes, accepted exceptions
August Review the remaining plan cohort, alternate arrangements, and selected vendor or site dependencies Plan owners Reviewed plans, dependency confirmations, change records
September Perform a third-quarter evidence retrieval check and management review BCM program owner Evidence sample results, status report, decisions, follow-up
October Validate crisis-team roles, backups, contact paths, and run the second scheduled exercise or focused test Crisis-team owner and exercise lead Roster confirmation, exercise or test record, findings
November Review program coverage, overdue items, unresolved risks, and next year’s workload BCM program owner and management reviewer Coverage report, exception decisions, draft next-year schedule
December Complete year-end approvals, issue the final status report, and confirm the evidence index and carry-forward items BCM program owner and approvers Approved plan statuses, management report, evidence index, carry-forward list

Not every activity belongs in a particular month. Add trigger-based entries whenever an incident, exercise result, reorganization, technology change, supplier change, facility change, or new requirement could invalidate current BCM information.

The annual calendar should also show workload concentration. If one month requires every plan owner to review a plan, participate in an exercise, validate contacts, and prepare management evidence, the design is likely to create avoidable delays. Use cohorts, risk tiers, or business cycles to spread the work while preserving required deadlines.

For a deeper explanation of monthly, quarterly, and annual meeting rhythm, see BCM Governance Cadence: An Audit-Ready Operating Rhythm. For the review method itself, including attestations and change control, see Plan Maintenance Without Burnout.

A completed review is not the evidence. The approval, decision, change record, or exercise result is.

How to Keep the Calendar Working After January

The calendar creates value only if the team can update and use it without building another administrative burden.

Set a Completion Rule

Define “complete” for each activity before assigning it. A plan review might require owner confirmation, resolved edits, reviewer approval, and a current approved version. An exercise item might require results, findings, action owners, target dates, and a decision about which plans must change.

This lets the program owner report on completed outcomes rather than scheduled activity.

Escalate Exceptions, Not Every Late Task

Not every missed date needs executive attention. Define escalation based on consequence. A late contact validation may remain with the plan owner for a short correction window. A missing approval for a high-priority plan, an overdue major exercise action, or an unaddressed dependency change may need management review.

Record the escalation route and time threshold in the calendar. This keeps follow-up consistent and gives management a clearer view of exposure.

Review the Calendar as a Control

At a regular governance meeting, ask:

  • Which items are due before the next meeting?
  • Which required records are awaiting review or approval?
  • Which trigger-based reviews were opened since the last meeting?
  • Which evidence samples could not be retrieved?
  • Which overdue items create a material readiness concern?
  • Which decisions or resources are needed from management?

Management reporting should reflect these results. In the financial sector, the FFIEC board-reporting guidance calls for regular monitoring and reporting across BIAs, risk assessments, plans, resilience, exercise results, issues, strategy updates, audits, and metrics. That is a sector-specific expectation, not a universal reporting prescription, but it demonstrates why the calendar must connect scheduled work to defensible status information.

If crisis-team accountabilities or backup roles are unclear, resolve the role design before scheduling attestations against it. MHA Consulting’s guide to crisis-management team roles, backups, and decision rights provides the deeper strategic context.

Connect the Calendar to the Records It Governs

A spreadsheet can be enough for a small calendar. It becomes less effective when the schedule points to plans in shared drives, approvals in email, exercise results in another folder, and follow-up in personal task lists.

Evaluate the workflow by asking:

  • Can the team identify the current plan and its status without checking several systems?
  • Can reviewers see what changed and what still needs approval?
  • Can exercise results be connected to plan updates and follow-up?
  • Can a program owner retrieve the expected evidence without rebuilding it before a report or audit?
  • Can management see blocked or overdue work without receiving every underlying task?

BCM Planner supports the records behind this process by helping teams build, edit, store, and share continuity plans, manage plan status, and create exercise templates and record results. The governance calendar still defines the organization’s schedule, triggers, owners, evidence, and escalation rules. The software supports execution and record maintenance. It does not decide the organization’s governance requirements.

A useful governance calendar gives the continuity team one view of what is due, why it matters, who owns it, and what proof should exist when the work is done. Start with the work your program must actually complete, distribute it across the year, and add triggers for changes that cannot wait.

Use the Business Continuity Planning Checklist to identify the plan activities and records that belong on your calendar. Then compare those requirements with the way your team currently manages plans, reviews, approvals, exercises, and follow-up.