Business Continuity & Disaster Recovery Policy
Version 1.0
1. Purpose
Advanced Asset Management Ltd, trading as Crest Pay (“Crest Pay”, “we”, “our”, “us”) is committed to maintaining the continuity of its services and minimising disruption to customers in the event of an unexpected incident.
This Business Continuity & Disaster Recovery Policy (“BCDR Policy”) sets out the framework for responding to operational disruptions, protecting customer information and restoring critical services.
2. Objectives
The objectives of this Policy are to:
- Protect employees, customers and business operations.
- Ensure continuity of payroll processing.
- Protect customer and employee data.
- Restore systems as quickly as reasonably practicable.
- Minimise financial and operational disruption.
- Meet contractual and legal obligations.
3. Scope
This Policy applies to all:
- Employees
- Directors
- Contractors
- Temporary workers
- Consultants
- Critical third-party service providers
It covers all Crest Pay systems, premises, technology and operational processes.
4. Potential Disruptions
Examples of incidents covered by this Policy include:
- Fire or flood
- Power failure
- Internet outages
- Cyber attacks
- Ransomware
- Hardware failure
- Software failure
- Pandemic or epidemic
- Loss of premises
- Loss of key personnel
- Supplier failure
- Banking outages
- Telecommunications failures
- Severe weather
- Civil emergencies
5. Critical Services
The following services are considered business-critical:
- Payroll processing
- HMRC submissions
- Payroll funding
- Salary payments
- Customer support
- Client portal
- Data security
- Disaster recovery communications
These services receive the highest recovery priority.
6. Data Protection
Crest Pay maintains procedures designed to protect customer information through:
- encrypted storage;
- secure cloud infrastructure;
- routine backups;
- restricted user access;
- multi-factor authentication;
- audit logging;
- endpoint protection;
- disaster recovery testing.
7. Backups
Business-critical systems are backed up on a regular basis. Backups are:
- encrypted where appropriate;
- stored separately from production systems;
- tested periodically for integrity and recoverability.
Backup retention periods are determined in accordance with legal and operational requirements.
8. Incident Response
Upon becoming aware of a significant incident, Crest Pay will:
- Assess the nature and severity of the incident.
- Activate the Business Continuity Plan where appropriate.
- Protect customer data and systems.
- Notify key personnel.
- Implement contingency arrangements.
- Restore priority services.
- Communicate with affected customers where appropriate.
- Conduct a post-incident review.
9. Communication
Where a significant disruption affects customers, Crest Pay will aim to provide timely updates through appropriate communication channels, which may include email, customer portal notifications, website announcements and telephone (where appropriate).
Communications will include, where available:
- a description of the incident;
- the likely impact;
- the actions being taken;
- estimated restoration times where possible.
10. Alternative Working Arrangements
Where access to normal premises or systems is disrupted, Crest Pay may implement alternative working arrangements, including:
- secure remote working;
- temporary office facilities;
- cloud-based systems;
- alternative communication methods.
All alternative arrangements must maintain appropriate standards of security and confidentiality.
11. Third-Party Providers
Crest Pay relies on a number of third-party providers, including providers of payroll software, cloud hosting, payment processing, banking services and telecommunications.
While Crest Pay seeks to work with reputable providers that maintain appropriate resilience measures, it cannot guarantee the continuity of services supplied by third parties.
12. Testing
Business continuity and disaster recovery arrangements will be reviewed and tested periodically where reasonably practicable. Testing may include:
- backup restoration;
- remote working exercises;
- communication testing;
- tabletop incident simulations.
Lessons learned will be used to improve resilience.
13. Roles and Responsibilities
The Board of Directors is responsible for overseeing business continuity arrangements.
Management is responsible for implementing this Policy and ensuring employees understand their responsibilities.
Employees are responsible for:
- reporting incidents promptly;
- following contingency procedures;
- protecting company information;
- cooperating during recovery activities.
14. Policy Review
This Policy will be reviewed at least annually, or sooner if required due to:
- changes in legislation;
- changes in technology;
- significant operational changes;
- lessons learned from incidents or testing.
15. Contact
Business Continuity Coordinator, Advanced Asset Management Ltd, trading as Crest Pay
Email: info@crestpay.net · Website: www.crestpay.net
Schedule 1 – Recovery Priorities
| Priority | Service |
|---|---|
| Critical | Payroll processing |
| Critical | Employee salary payments |
| Critical | HMRC submissions |
| High | Customer support |
| High | Customer portal |
| Medium | Reporting and analytics |
| Medium | Administrative functions |
Schedule 2 – Business Continuity Principles
Crest Pay is committed to:
- protecting customer funds and information;
- maintaining payroll services wherever reasonably practicable;
- communicating openly during major incidents;
- restoring critical services in a structured and prioritised manner;
- continuously improving resilience through regular reviews and testing.