Control 4.10: Business Continuity and Disaster Recovery — Portal Walkthrough
Step-by-step portal configuration for establishing business continuity and disaster recovery procedures addressing Copilot service dependencies in financial services environments.
Prerequisites
- Role: Global Administrator, IT Infrastructure Manager
- License: Microsoft 365 E5 with Copilot add-on
- Access: Microsoft 365 Admin Center, Service Health Dashboard
Steps
Step 1: Document Copilot Service Dependencies
Portal: Microsoft 365 Admin Center Path: Health > Service health
- Map Copilot service dependencies across the Microsoft 365 stack:
- Azure OpenAI Service (core AI processing)
- Microsoft Graph (organizational data access)
- SharePoint Online (content grounding)
- Exchange Online (email interactions)
- Teams (meeting and chat interactions)
- Document the dependency chain and single points of failure.
- Identify which business processes have become dependent on Copilot.
Step 2: Configure Service Health Monitoring
Portal: Microsoft 365 Admin Center Path: Health > Service health > Preferences
- Configure service health notifications:
- Subscribe to Copilot-related service advisories and incidents
- Add the IT operations team and compliance team as notification recipients
- Enable notifications for all severity levels
- Create a monitoring dashboard for Copilot service dependencies.
- Set up Microsoft 365 Service Health API integration for automated monitoring.
Step 3: Develop Copilot-Specific BCP Procedures
Portal: Internal business continuity documentation Path: BCP/DR plan appendix for AI services
- Document fallback procedures for each Copilot-dependent business process:
- Document drafting without Copilot — return to manual processes
- Meeting management without Copilot — manual note-taking protocols
- Email management without Copilot — standard email practices
- Data analysis without Copilot — traditional analytics tools
- Define Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for Copilot services.
- Assign BCP coordinators for each business unit.
Step 4: Establish Communication Plan for Copilot Outages
Portal: Internal communications system Path: Incident communication templates
- Create communication templates for different outage scenarios:
- Planned maintenance — advance notice to affected users
- Unplanned partial outage — status update and workaround guidance
- Extended outage — fallback procedure activation notice
- Define the communication chain: IT Operations -> Department heads -> End users.
- Establish a status page or Teams channel for real-time outage updates.
FSI Recommendations
| Setting | Baseline | Recommended | Regulated |
|---|---|---|---|
| Service health monitoring | Email alerts | Real-time API monitoring | Automated with dashboards |
| BCP procedures for Copilot | None | Documented fallbacks | Tested fallbacks |
| DR testing frequency | Annual | Semi-annual | Quarterly |
| Communication templates | Ad hoc | Pre-defined | Pre-defined with approval chain |
Regulatory Alignment
- FFIEC BCP Booklet — Supports compliance with business continuity planning requirements for technology dependencies
- OCC Heightened Standards — Helps meet expectations for technology resilience and recovery
- FINRA Rule 4370 — Supports business continuity plan requirements for broker-dealers
Next Steps
- Proceed to PowerShell Setup for service monitoring automation
- See Verification & Testing to validate BCP/DR procedures