The Business Continuity Planner

CRA won't audit your IT. Your insurer, your funders, and your biggest clients will — and a breach still ends up in front of all three. This is the plan template they're asking to see.

Who actually audits your BCP

A common myth among Canadian small businesses and nonprofits: that CRA inspects IT and cyber resilience on audit. It doesn't — CRA looks at financial records, T3010 filings, and governance. The people who do ask about continuity are your cyber insurer, your funders (Ontario Trillium Foundation, United Way, federal grant programs), enterprise clients (via vendor-risk questionnaires), and your board (fiduciary duty now includes cyber oversight).

This planner gives you a 6-section framework those audiences recognise — short enough to actually finish, testable enough to matter when something breaks.

What's inside

  1. Critical process inventory — RTO/RPO template for every process you can't go 72 hours without
  2. Data and system inventory — where each category of important data lives, backup location, access control
  3. Dependency map — third parties that would take you down, with fallback plans
  4. Roles, contacts, and call tree — internal team + external hotlines (insurer, MSP, ISP, OPC, Canadian Anti-Fraud Centre)
  5. Incident playbooks — ransomware, Microsoft 365 outage, key-person loss, prolonged ISP/power outage
  6. Test schedule and evidence log — what to test, how often, what to keep as proof
  7. The one-page summary — the format your insurer, funder, or enterprise client wants delivered

Every section is fillable — tables with placeholder text ready for you to mark up in pencil or paste into a Word document. The one-page summary alone will get you past most vendor-risk forms.

Download the planner

Instant download. We keep your name and email so we know who we're helping — we don't spam or share your details.

Direct download — no waiting. Opting into the newsletter is optional and separate from the download.

Who should use this

This planner is for you if:

  • Your cyber insurance renewal asks "when was your BCP last tested?"
  • A funder application asks about data handling and continuity
  • An enterprise client sent you a vendor-risk questionnaire
  • Your board chair has asked for a cyber-resilience briefing
  • You've never formally written a continuity plan and don't know where to start

What makes it different

Built for organizations that don't have a dedicated IT department. Tables are short, playbooks are practical, and the one-page summary is what funders and insurers actually read — not the full binder that gathers dust. Made in Thunder Bay, calibrated for Canadian SMB and nonprofit realities.

Want help turning this into a tested, signed-off plan?

DVG Systems runs a free 45-minute BCP review for Northern Ontario businesses and nonprofits. We help you fill the template, run your first tabletop, and hand you the one-page summary and evidence pack your insurer and funders are asking for.

Ask AI

Accessibility