CORAA

Business Continuity & Disaster Recovery (BCP/DR) Audit Checklist

Tests RTO/RPO definition and actual achievement, backup integrity, and DR drill evidence — whether the entity's continuity plan would actually work if invoked, not just whether a document exists.

Free · CORAA original — SA-aligned
Updated 28 Jul 2026
Tests
RTO/RPO, backup integrity, drill evidence
Key distinction
"Plan exists" vs. "plan actually works if invoked"
Common gap
No test-restore of backups; drill is tabletop-only
Format
Microsoft Word (.docx)
Share this template
Your firm — letterhead
Appears at the top of the document as the audit firm letterhead.
Used as the letterhead block.
Engagement details
The client and period this document is for.
What’s inside

An excerpt from the template.

BUSINESS CONTINUITY & DISASTER RECOVERY (BCP/DR) — AUDIT CHECKLIST

Entity: ___ · Period: ___

Scope: tests whether the entity's business continuity and disaster recovery arrangements would actually work if invoked — RTO/RPO targets, backup integrity, and drill evidence — not merely whether a BCP/DR document exists.

Conclusion

↑ Excerpt only — the full template is what you download as Word
About this template

What you’re downloading, and when to use it.

This template follows the format published by the Institute of Chartered Accountants of India (ICAI) in the AASB Audit Working Paper Templates (June 2023), the authoritative reference for Indian statutory-audit documentation. Fill in your firm’s letterhead and the engagement details on the form above, click Download Word file, and you’ll get a fully formatted .docx ready to use.

Everything is generated in your browser and on a stateless API endpoint — no account, nothing stored on our servers. We’ll ask for a work email once before your first download so we can send you the file and the occasional relevant update; after that, downloads on this device are instant. Edit freely in Word, Google Docs or Pages before sending to your client.

Common questions

FAQs.

What is the difference between RTO and RPO?
Recovery Time Objective (RTO) is the maximum acceptable time a system can be down before it must be restored. Recovery Point Objective (RPO) is the maximum acceptable amount of data loss, measured in time — e.g. an RPO of 4 hours means backups must run at least every 4 hours, since anything since the last backup could be lost. Both should be set per system based on business criticality, not applied as one blanket figure across the entity.
Why test that backups are "test-restored," not just that backups run?
A backup job completing successfully only confirms that data was written somewhere — it does not confirm the backup file is actually usable to restore a working system. A surprisingly common finding is that backups have been running on schedule for months or years but were never test-restored, and turn out to be corrupted, incomplete, or incompatible with current infrastructure when a real recovery is attempted.
Is a tabletop discussion sufficient evidence of a DR drill?
A tabletop exercise (walking through the plan verbally) has value but is not equivalent to an actual technical drill — failing over a system, or restoring from backup, and measuring the real time taken against the stated RTO. This checklist specifically looks for evidence of at least one technical drill, since a plan that has only ever been discussed and never executed carries meaningfully higher risk of failing when it is actually needed.
Related templates

You might also need.

IT General Controls (ITGC) Checklist
Free IT General Controls (ITGC) checklist for internal audit. Access management, change management, SoD, backu
Treasury & Cash Management Internal Audit Checklist
Free treasury and cash management internal audit checklist. Risks and controls for borrowing approval, covenan
Internal Audit Annual Plan Template — Risk-Scored Audit Universe
Free Internal Audit Annual Plan template. Risk-scored audit universe (impact × likelihood computed) with quart