The Executive Diagnostic and Governance Toolkit
Assessing and Evidencing Disaster Recovery Business Continuity
Score your own function red, amber or green, find out which part is weakest, and walk into the next budget round able to defend what you want to fix. Built for leaders reviewing they already hold the disaster recovery business continuity playbook: the implementation guide, the roadmap and the working files, so repeating any of that is worthless. What is missing is the layer after implementation. How to assess the function honestly, what evidence to retain, how to score maturity, and how to put the result in front of a manager, an auditor or a client who was not involved. The immediate question: for one month of disaster recovery business continuity work, can you show what was measured, against what target, and what changed as a result.
Each order is checked and updated against the latest insights before delivery. That is why access takes up to 24 hours rather than being instant.
| 1 |
You stop guessing where you stand. You finish with a score, not an opinion: every part of your function rated red, amber or green, with the weakest ranked first. Evidence: a Quick Scan for the shape of it, then seven domain assessments of 30 scored questions each, 210 in all, rolled into one scorecard, plus a maturity radar and a current-versus-target gap analysis. |
| 2 |
You can defend the decision. You walk into the budget round with the gap named, the owner named and done defined, instead of a case built on instinct. Evidence: project charter, scope statement, RACI, requirements traceability and work breakdown structure, pre-filled in your domain's language. |
| 3 |
The work actually moves. The month after the decision is already built, so nothing stalls waiting for someone to design a form. Evidence: more than 60 project templates across all five PMBOK process groups, plus runbooks, SOPs, a KPI framework, audit checklists and a risk matrix. 55 to 65 files in total. |
| 4 |
You use it the day it lands. No blank templates to interpret. Every workbook opens with what it is, who uses it, when, how, a 1 to 5 scoring guide, what good looks like, and a worked example you delete and type over. |
The situation this is built for
Practitioners spend months building playbooks, roadmaps, and response plans. But when auditors, executives, or clients ask for proof of effectiveness, most lack a structured way to respond. They default to showing documents — not outcomes. The real challenge isn’t implementation. It’s assessment. It’s evidence. It’s being able to say, for one month of effort, exactly what was measured, against what standard, and what changed as a result. Without a clear methodology, even the best plans look untested and unproven.
Who this is for
The practitioner who owns disaster recovery and business continuity operations and must now demonstrate the function’s maturity and impact to stakeholders who were not involved in the build.
Who this is not for
This is not for consultants selling tools, vendors pitching platforms, or teams still building their first recovery plan. It is for those who have already implemented and now must assess, score, and report.
What you walk away with
- Demonstrate measurable progress in recovery capability
- Produce auditable evidence of continuity readiness
- Score maturity using repeatable assessment logic
- Report outcomes to executives and compliance teams
- Close the loop between implementation and proof
How this maps to your situation
- You have the playbook but must prove it works
- You are being audited on recovery readiness
- You need to report maturity to leadership
- You must demonstrate value to clients
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed to be completed in parallel with ongoing operations.
How this compares to the alternatives
Most courses teach how to build recovery plans. This course is the only one focused entirely on assessing, evidencing, and proving what you’ve already built — with no overlap in content or approach.
Also included: the full course, for when you want the reasoning behind a finding (12 modules, 144 chapters)
Depth reference. The diagnostic and the templates stand on their own; this is what to read when you want the reasoning behind a finding.
- Understanding the difference between implementation and assessment
- Identifying who requires evidence and why they need it
- Defining what success looks like for recovery readiness
- Mapping assessment goals to business objectives
- Aligning with regulatory and compliance expectations
- Setting boundaries for what will be assessed
- Creating the assessment charter document
- Documenting assumptions and constraints upfront
- Establishing roles in the assessment process
- Scheduling the first assessment cycle
- Integrating assessment into ongoing operations
- Communicating intent to internal stakeholders
- Selecting dimensions of recovery capability to evaluate
- Choosing criteria for measuring plan effectiveness
- Defining scoring scales for maturity levels
- Incorporating time-to-recover and recovery-point objectives
- Building a weighted scoring model for priorities
- Including people, process, technology, and documentation
- Creating a reusable assessment questionnaire
- Validating framework design with key stakeholders
- Documenting scoring rules and interpretation logic
- Setting thresholds for pass, warning, and fail
- Versioning the assessment framework over time
- Linking framework outputs to decision rights
- Locating playbooks, runbooks, and response checklists
- Reviewing documented test results and simulation logs
- Auditing communication tree accuracy and reach
- Verifying backup schedules and retention policies
- Checking RTO and RPO alignment in design documents
- Validating vendor SLAs against recovery requirements
- Extracting training completion records for staff
- Assessing documentation update frequency and ownership
- Reviewing incident reports from past disruptions
- Mapping dependencies in system architecture diagrams
- Confirming access controls for recovery systems
- Cataloging evidence sources for audit readiness
- Assigning initial scores based on documentation completeness
- Scoring test frequency and result quality
- Evaluating team familiarity with recovery procedures
- Measuring time elapsed since last full simulation
- Assessing cross-departmental coordination effectiveness
- Scoring data integrity validation processes
- Rating alternate site activation readiness
- Evaluating communication plan execution fidelity
- Scoring decision-making speed during incidents
- Measuring stakeholder notification accuracy
- Assessing post-event review and improvement cycles
- Calculating composite maturity scores by function
- Choosing exercise types based on risk profile
- Designing tabletop scenarios for leadership teams
- Running call-tree verification drills
- Conducting data restoration time trials
- Simulating partial system failover sequences
- Testing remote access for key personnel
- Validating emergency communication channels
- Measuring response time to incident triggers
- Documenting participant actions and decisions
- Capturing deviations from expected workflows
- Generating time-stamped evidence logs
- Scheduling quarterly validation cycles
- Structuring a centralized evidence storage system
- Classifying evidence by type and sensitivity
- Setting retention periods for different artifacts
- Applying version control to all documents
- Ensuring chain of custody for test results
- Indexing evidence by recovery objective and system
- Implementing role-based access to evidence files
- Automating evidence collection from monitoring tools
- Creating evidence summary dashboards
- Preparing evidence packs for auditor requests
- Archiving outdated but required documentation
- Auditing the repository for completeness
- Summarizing recovery posture in one page
- Highlighting top risks and mitigation status
- Presenting maturity trends over time
- Comparing current state to industry benchmarks
- Explaining score changes from last quarter
- Linking recovery capability to financial exposure
- Using heat maps to show system vulnerabilities
- Reporting on test participation rates
- Describing improvement initiatives in progress
- Stating confidence level in recovery claims
- Recommending investment based on gaps
- Formatting board-ready presentation decks
- Anticipating common auditor request categories
- Preparing responses to control validation questions
- Demonstrating adherence to recovery time objectives
- Providing proof of regular testing and training
- Showing evidence of third-party dependency checks
- Documenting risk treatment decisions
- Explaining exceptions and compensating controls
- Providing audit trails for changes to plans
- Verifying evidence authenticity and dates
- Organizing responses by compliance domain
- Responding to findings with action plans
- Maintaining auditor communication logs
- Mapping assessments to ISO 22301 requirements
- Aligning with NIST SP 800-34 controls
- Comparing maturity to DRI model practices
- Evaluating against internal corporate policies
- Using peer comparison data responsibly
- Identifying gaps in coverage or rigor
- Adjusting scoring to reflect standard criteria
- Documenting deviations from best practices
- Justifying design choices based on risk
- Updating benchmarking annually
- Reporting conformance status to leadership
- Integrating standard updates into scoring
- Identifying systems with lowest maturity scores
- Analyzing root causes of repeated failures
- Evaluating cost of downtime per business unit
- Prioritizing fixes based on risk exposure
- Creating improvement backlog with owners
- Estimating effort and resources needed
- Linking initiatives to recovery objectives
- Setting measurable targets for next quarter
- Tracking progress on remediation tasks
- Balancing quick wins with long-term upgrades
- Integrating improvements into change calendar
- Reporting on initiative completion rates
- Scheduling recurring assessment intervals
- Assigning ownership for annual reviews
- Updating frameworks after major changes
- Onboarding new team members to assessment process
- Integrating assessment into project lifecycles
- Automating evidence collection where possible
- Reviewing scoring consistency across teams
- Conducting peer validation of results
- Updating documentation after incidents
- Refreshing training based on gaps
- Maintaining leadership visibility on status
- Archiving historical assessment data
- Preparing client-facing summary reports
- Redacting sensitive details while preserving proof
- Demonstrating test results without revealing weaknesses
- Using maturity scores to build trust
- Providing evidence of third-party validations
- Answering client RFP questions accurately
- Sharing anonymized exercise outcomes
- Creating client assurance packages
- Responding to due diligence requests
- Maintaining client-specific evidence sets
- Tracking client feedback on recovery claims
- Updating client materials after assessments
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.
Thousands of organisations have bought from The Art of Service since 2000.