Board and Senior Management Responsibilities

As with other BCP activities, pandemic planning should not be viewed as solely an Information Technology (IT) issue, but rather as a significant risk to the entire business. As such, an institution's pandemic planning activities should involve senior business management from all functional, business and product areas, including administrative, human resources, legal, IT support functions, and key product lines.

An institution's board of directors is responsible for overseeing the development of the Pandemic plan. The board or a committee thereof should also approve the institution's written plan and ensure that senior management is investing sufficient resources into planning, monitoring, and testing the final plan. Senior management is responsible for developing the pandemic plan and translating the plan into specific policies, processes, and procedures.

Senior management is also responsible for communicating the plan throughout the institutions to ensure consistent understanding of the key elements of the plan and to ensure that employees understand their role and responsibilities in responding to a pandemic event. Finally, senior management is responsible for ensuring that the plan is regularly tested and remains relevant to the scope and complexity of the institution's operations.

Employee Protection Strategies

Employee protection strategies are crucial to sustaining an adequate workforce during a pandemic. Institutions should promote employee awareness by communicating the risks of a pandemic outbreak and discussing the steps employees can take to reduce the likelihood of contracting a pandemic virus. The following risk management strategies should be considered:

  • Publicize the Centers for Disease Control and Prevention “Cover Your Cough” and “Clean Your Hands” programs or other general hygiene programs;
  • Encourage employees to avoid crowded places and public transportation systems;
  • Implement “social distancing” techniques to minimize typical face-to-face contact through the use of teleconference calls, video conferencing, flexible work hours, telecommuting, encouraging customers to use online or telephone banking services, ATMs, and drive-up windows; and
  • Review and consider the use of other non-pharmaceutical interventions developed by the Centers for Disease Control and Prevention (more information is available at  http://www.pandemicflu.gov/plan/community/commitigation.html).

Mitigating Controls

Despite the unique challenges posed by a pandemic, there are control processes that management can implement to mitigate risk and the effects of a pandemic. For example, to overcome some of the personnel challenges, management should ensure 9 of 10 that employees are cross-trained and that succession plans have been developed. The institution may be able to leverage plans already established as part of traditional business continuity planning.

Remote Access

During a pandemic, there may be a high reliance on employee telecommuting, which could put a strain on remote access capabilities such as capacity, bandwidth, and authentication mechanisms. Moreover, employees who typically work onsite may not have remote access authority or the necessary technology infrastructure to work at home. Analysis of remote access capabilities, mapping of related technology infrastructure to employee needs during a pandemic, assessing the infrastructure at the neighborhood level and considering internal and external capacity are necessary to help ensure telecommuting strategies will work during a pandemic.

Risk Monitoring and Testing

As information from medical and governmental experts about the causes and effects of a pandemic continues to evolve, an institution’s pandemic plan must be sufficiently flexible to incorporate new information and risk mitigation approaches. As a result, risk monitoring and testing of the pandemic plan is important to the overall planning process. A key challenge for management is developing a testing program that provides a high degree of assurance that critical business processes, including supporting infrastructure, systems, and applications, will function even during a severe pandemic.

A robust program should incorporate testing:

  • Roles and responsibilities of management, employees, key suppliers, and
  • customers;
  • Key pandemic planning assumptions;
  • Increased reliance on online banking, telephone banking, and call center services; and
  • Remote access and telecommuting capabilities.
  • Test results should be reported to management, with appropriate updates made to the pandemic plan and testing program.

Testing for a pandemic may require variations to the scope of traditional disaster recovery and business continuity testing, as potential test scenarios will most likely be different.

Alternatives for pandemic testing can include:

  • Well-orchestrated “work at home” days for critical and essential employees to test remote access capabilities and infrastructure;
  • Crisis management team communication exercises;
  • Tabletop exercises that test various scenarios related to escalated absenteeism rates;
  • Additional or modified call tree exercises; and
  • Community, regional or industry-wide exercises with members of the financial services sector to test the financial sector’s ability to respond to a pandemic-like crisis.5
Main Menu