HMRC compliant·Fully managed payroll
C
CrestPay

Business Continuity & Disaster Recovery Policy

Version 1.0

1. Purpose

Advanced Asset Management Ltd, trading as Crest Pay (“Crest Pay”, “we”, “our”, “us”) is committed to maintaining the continuity of its services and minimising disruption to customers in the event of an unexpected incident.

This Business Continuity & Disaster Recovery Policy (“BCDR Policy”) sets out the framework for responding to operational disruptions, protecting customer information and restoring critical services.

2. Objectives

The objectives of this Policy are to:

  • Protect employees, customers and business operations.
  • Ensure continuity of payroll processing.
  • Protect customer and employee data.
  • Restore systems as quickly as reasonably practicable.
  • Minimise financial and operational disruption.
  • Meet contractual and legal obligations.

3. Scope

This Policy applies to all:

  • Employees
  • Directors
  • Contractors
  • Temporary workers
  • Consultants
  • Critical third-party service providers

It covers all Crest Pay systems, premises, technology and operational processes.

4. Potential Disruptions

Examples of incidents covered by this Policy include:

  • Fire or flood
  • Power failure
  • Internet outages
  • Cyber attacks
  • Ransomware
  • Hardware failure
  • Software failure
  • Pandemic or epidemic
  • Loss of premises
  • Loss of key personnel
  • Supplier failure
  • Banking outages
  • Telecommunications failures
  • Severe weather
  • Civil emergencies

5. Critical Services

The following services are considered business-critical:

  • Payroll processing
  • HMRC submissions
  • Payroll funding
  • Salary payments
  • Customer support
  • Client portal
  • Data security
  • Disaster recovery communications

These services receive the highest recovery priority.

6. Data Protection

Crest Pay maintains procedures designed to protect customer information through:

  • encrypted storage;
  • secure cloud infrastructure;
  • routine backups;
  • restricted user access;
  • multi-factor authentication;
  • audit logging;
  • endpoint protection;
  • disaster recovery testing.

7. Backups

Business-critical systems are backed up on a regular basis. Backups are:

  • encrypted where appropriate;
  • stored separately from production systems;
  • tested periodically for integrity and recoverability.

Backup retention periods are determined in accordance with legal and operational requirements.

8. Incident Response

Upon becoming aware of a significant incident, Crest Pay will:

  • Assess the nature and severity of the incident.
  • Activate the Business Continuity Plan where appropriate.
  • Protect customer data and systems.
  • Notify key personnel.
  • Implement contingency arrangements.
  • Restore priority services.
  • Communicate with affected customers where appropriate.
  • Conduct a post-incident review.

9. Communication

Where a significant disruption affects customers, Crest Pay will aim to provide timely updates through appropriate communication channels, which may include email, customer portal notifications, website announcements and telephone (where appropriate).

Communications will include, where available:

  • a description of the incident;
  • the likely impact;
  • the actions being taken;
  • estimated restoration times where possible.

10. Alternative Working Arrangements

Where access to normal premises or systems is disrupted, Crest Pay may implement alternative working arrangements, including:

  • secure remote working;
  • temporary office facilities;
  • cloud-based systems;
  • alternative communication methods.

All alternative arrangements must maintain appropriate standards of security and confidentiality.

11. Third-Party Providers

Crest Pay relies on a number of third-party providers, including providers of payroll software, cloud hosting, payment processing, banking services and telecommunications.

While Crest Pay seeks to work with reputable providers that maintain appropriate resilience measures, it cannot guarantee the continuity of services supplied by third parties.

12. Testing

Business continuity and disaster recovery arrangements will be reviewed and tested periodically where reasonably practicable. Testing may include:

  • backup restoration;
  • remote working exercises;
  • communication testing;
  • tabletop incident simulations.

Lessons learned will be used to improve resilience.

13. Roles and Responsibilities

The Board of Directors is responsible for overseeing business continuity arrangements.

Management is responsible for implementing this Policy and ensuring employees understand their responsibilities.

Employees are responsible for:

  • reporting incidents promptly;
  • following contingency procedures;
  • protecting company information;
  • cooperating during recovery activities.

14. Policy Review

This Policy will be reviewed at least annually, or sooner if required due to:

  • changes in legislation;
  • changes in technology;
  • significant operational changes;
  • lessons learned from incidents or testing.

15. Contact

Business Continuity Coordinator, Advanced Asset Management Ltd, trading as Crest Pay

Email: info@crestpay.net · Website: www.crestpay.net

Schedule 1 – Recovery Priorities

PriorityService
CriticalPayroll processing
CriticalEmployee salary payments
CriticalHMRC submissions
HighCustomer support
HighCustomer portal
MediumReporting and analytics
MediumAdministrative functions

Schedule 2 – Business Continuity Principles

Crest Pay is committed to:

  • protecting customer funds and information;
  • maintaining payroll services wherever reasonably practicable;
  • communicating openly during major incidents;
  • restoring critical services in a structured and prioritised manner;
  • continuously improving resilience through regular reviews and testing.