> ## Content Index
> Fetch the complete content index at: https://paulobrien.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# PP6: Validation
- URL: https://paulobrien.com/pp6-validation/
- Published: 2026-08-25T17:43:29.000Z
- Updated: 2026-08-25T17:43:29.000Z
- Description: Part 6 of 6 in my CBCI study series. A practical breakdown of BCI GPG 7.0 PP6: Validation—moving from abstract plan-writing to testing actual capabilities, managing storyboard injects, and establishing robust maintenance and review frameworks.
- Author: Paul O'Brien
- Tags: CBCI Study Series, PP6: Validation

## CBCI Study Series · Professional Practice 6 of 6

BCI Good Practice Guidelines (GPG 7.0)

### Proving the Shield: A Study Guide to BCI PP6 (Validation)

Introduction: My Journey from 'Writing Plans' to 'Proving Capability'

When I wrapped up my notes on [Professional Practice 5 (PP5)](https://paulobrien.com/tag/pp5-enabling-solutions/), I felt an immense sense of accomplishment. We had mapped out the strategic, tactical, and operational response structures, designed complex warning systems, and drafted concise playbooks. Everything sat beautifully categorised in my digital folders. It looked like the ultimate, bulletproof resilience program. But as I took a step back and prepared for the BCI exam, a sudden and humbling thought struck me: how do we actually know any of this works? What if our hot backups fail? What if our operational workarounds are too slow? What if our response teams panic because they have never actually practiced their roles?

This is the exact paradigm shift that lands us at the final chapter of the GPG syllabus: PP6 (Validation). Validation is where theory meets reality. It is the process of proving—or disproving—the capability and effectiveness of the strategies, solutions, response structures, and plans we designed in the previous practices. It shifts business continuity from a passive document-writing exercise to an active, audited capability.

In my own study journey, diving into PP6 made me realise that a plan is just a list of intentions; validation is the actual insurance policy. This guide breaks down the core elements of GPG PP6—exercising, maintenance, and review—to help you master the key exam-day definitions, conquer the tricky validation categories, and clear your CBCI exam with flying colors.

#### 1\. The Three Pillars of Validation: Exercising, Maintenance, and Review

Under GPG Edition 7.0, Validation is not a single point-in-time check. Instead, it is a continuous, integrated management loop that relies on three distinct pillars to measure and prove resilience capability:

- **Exercising:** The active process to train for, assess, practice, and improve organisational performance under pressure. Exercising evaluates team cohesion, identifies resource gaps, and builds participant confidence.
- **Maintenance:** The systematic process to ensure that all business continuity arrangements, documentation, contact details, and technical resources remain fully relevant, current, and operationally ready to respond to change.
- **Review:** The formal, objective process for assessing the suitability, adequacy, and overall effectiveness of the BCMS against strategic policies, legal requirements, and international benchmarks.

By balancing these three pillars, the organization ensures that its BC capability matches its operational reality. GPG PP6 explicitly notes that validation is not about identifying failure to assign blame; rather, it is about identifying development areas as valuable opportunities for continual improvement and organisational learning.

#### 2\. The 5 Categories of Exercise: From Discussion to Pass-Fail Tests

The BCI exam heavily tests the five specific categories of exercises defined in GPG PP6\. To make sure you don't mix these up under exam-room pressure, I have compiled this comprehensive, study-friendly comparative table summarising their definitions, focus areas, and typical real-world applications:

| Category         | GPG Definition                                                                                | Primary Target                                                       | Exam-Day Example                                                     |
| ---------------- | --------------------------------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- |
| Discussion-based | Structured events where participants walk through plans in a low-pressure environment.        | Reviewing assumptions, updating roles, and validating plans.         | A formal team walkthrough or plan review performed by plan owners.   |
| Scenario         | Exercises using a pre-planned storyline with a timeline and stimuli (injects) over time.      | Evaluating response familiarity and plan flow as events unfold.      | A desktop table-top exercise using simulated timelines and jumps.    |
| Simulation       | Operations-based exercises replicating actual systems, processes, or command centers.         | Challenging decision-making, team dynamics, and system interfaces.   | A realistic IT disaster recovery run using phone/email injects.      |
| Live             | Rehearsals carried out in normal operational environments involving all active players.       | Testing physical coordination, movement, and resource capabilities.  | An unannounced fire drill or full site relocation to a DR workspace. |
| Test             | Exercises incorporating a strict expectation of a pass or fail element within the objectives. | Verifying technical equipment, data integrity, and utility switches. | Rebuilding a technical server from backups or testing a fire alarm.  |

#### 3\. Developing an Exercise: Storyboards, Injects, and the 'No Duff' Safety Halt

Developing a successful exercise is structured like a formal project, requiring a budget, scope, and clear objectives. The GPG outlines that exercises must be realistic, plausible, and carefully managed to avoid disrupting business-as-usual (BAU) operations. To drive the narrative, exercise planners design a detailed storyline called a storyboard, which releases individual pieces of information—known as injects—at pre-planned times.

These injects represent unfolding events (e.g., social media feeds, system warnings, or regulator calls) that prompt participants to make critical decisions, consult their plans, and coordinate responses. To preserve a safe and controlled learning environment, planners must put strict safety measures in place.

🚨

****EXAM TRAP ALERT: The 'No Duff' Safety Rule**  
A highly examinable GPG safety concept is the 'No Duff' rule. During a live or simulation exercise, any communication inject (such as mock phone calls or warning emails) must include a distinctive code word like 'exercise only' to ensure it is not mistaken for a real crisis. However, if a genuine, real-world emergency occurs while the exercise is running, any participant or facilitator must be able to use the military code word 'NO DUFF' (or an equivalent predetermined safety phrase). The declaration of 'No Duff' prompts an immediate and absolute halt to the exercise, allowing the response structure to shift instantly and safely back to managing the live event without confusion.

#### 4\. The 7 Types of Review: Navigating Audits, QA, and Post-Incident Learning

The third pillar of Validation—Review—aims to evaluate the suitability, adequacy, and overall performance of the BCMS. GPG Edition 7.0 defines exactly seven basic types of review. The CBCI exam will frequently challenge your ability to distinguish between these categories, particularly how they evaluate different aspects of your continuity framework:

- **1\. Audit:** A formal, impartial, and independent evaluation conducted by qualified auditors (internal or external) to measure the BCMS against an agreed national, international (ISO 22301), or regulatory standard.
- **2\. Self-Assessment:** A practical internal evaluation conducted by the personnel actively involved in the management and implementation of the BCMS to track progress against outstanding milestones or objectives.
- **3\. Quality Assurance (QA):** An ongoing, documented process that evaluates the quality of BCMS outputs against policies and expectations (e.g., checking that the BIA documents appropriate MTPDs for all prioritised activities).
- **4\. Performance Appraisal:** A formal evaluation of individuals with assigned business continuity roles and responsibilities (such as departmental representatives) to verify how well their duties are executed, typically in alignment with HR.
- **5\. Supplier Performance:** An evaluation of a prioritised supplier or outsource partner's business continuity management system and recovery capability against the service level agreements (SLAs) outlined in their contract.
- **6\. Post-Incident Review:** An essential learning session facilitated immediately after returning to BAU following a live disruption. It gathers feedback on plan activation, execution, and effectiveness to promote a 'no-blame' culture.
- **7\. Management Review:** A top-level evaluation conducted by senior leadership to assess the alignment of the BCMS with corporate risk appetite, strategic direction, previous audit findings, and shifting environmental trends.

#### 5\. Continuous Improvement: Why a BCMS is Never Truly 'Complete' (The Epilogue)

One of the most important takeaways from GPG Edition 7.0 is that a Business Continuity Management System is an iterative journey of continual improvement. This is precisely why the BCI has officially replaced the static 'BCM Lifecycle' from older editions with the dynamic, interlinked 'BCMS Professional Practices' wheel.

In our industry, there is no such thing as a 'complete' management system. Macro trends—such as technological innovations, emerging cyber threats, changing supply chain dynamics, and regulatory developments—ensure that the risk landscape is constantly shifting. A seasoned professional understands that striving for absolute completion is impossible. Instead, validation serves as our continuous feedback loop, ensuring that our capability remains flexible, relevant, and robust enough to handle the unknown challenges of tomorrow.

#### Test Your Knowledge: BCI Exam Prep PP6 Quiz

Challenge your understanding of PP6: Validation with these 5 exam-realistic practice questions. Pay close attention to the explanations—they highlight the exact definitions the BCI uses to test these concepts!

**Question 1**

**A BC Professional is planning an activity to evaluate the organisation's emergency alert system. The activity has a strict expectation of a pass or fail element within its defined objective. According to BCI GPG Edition 7.0, what type of validation activity is this?**

A) Discussion-based Walkthrough

B) Simulation Exercise

C) Scenario Exercise

D) Test

#### Answer

****Correct Answer: D**

****Explanation**: A 'test' is defined as a unique and particular type of exercise that incorporates a strict expectation of a pass or fail element within its aim or objectives. It is typically applied directly to technical equipment, warning systems, or recovery procedures (such as verifying that a backup generator starts within its required timeframe).

**Question 2**

**During a high-stakes, multi-departmental simulation exercise, a genuine, real-world emergency occurs. What action should be taken by the exercise team, and what predetermined safety protocol must be activated?**

A) The team should ignore the disruption and continue the simulation to maintain exercise realism.

B) Any participant or facilitator can declare the code word 'NO DUFF', prompting an immediate and absolute halt to the exercise to handle the real emergency.

C) The facilitator should pause the simulation for 10 minutes to verify if the emergency is part of the storyboard.

D) The exercise should be es

#### Answer

****Correct Answer: B**

****Explanation**: The GPG outlines the 'No Duff' protocol (derived from military usage) as a critical safety mechanism. Declaring the predetermined code word 'No Duff' immediately suspends or terminates the exercise, ensuring that all participants instantly understand a real crisis has occurred and can transition safely to managing the live event.

**Question 3**

**An organisation recently recovered from an unplanned cloud outage. One week after returning to BAU, the BC Professional facilitates a meeting with key participants to review how the plans performed. What is the primary purpose of conducting this post-incident review under PP6?**

A) To formally audit individual staff compliance and document performance penalties.

B) To establish a legal baseline for terminating the primary hosting provider's contract.

C) To evaluate the effectiveness of the plans, capture lessons learned, and identify improvement opportunities in a no-blame environment.

D) To satisfy a mandatory requirement for updating the high-level Business Continuity Policy statement.

#### Answer

****Correct Answer: C**

****Explanation**: The primary objective of a post-incident review is to assess the suitability, adequacy, and overall effectiveness of the response effort, capturing lessons learned to promote continual learning and enhance organizational resilience. The GPG explicitly mandates that this process must never be used to assign blame or responsibilities.

**Question 4**

**A BC Professional is reviewing the BCMS to verify that all business continuity plans contain current, validated out-of-hours contact details and correct team lists. According to GPG PP6, under which validation activity does this routine update fall?**

A) Quality Assurance (QA)

B) Maintenance

C) Management Review

D) Self-Assessment

#### Answer

****Correct Answer: B**

****Explanation**: Maintenance is the continuous, systematic process designed to keep the organisation's business continuity arrangements, documentation, contact cards, and recovery resources fully current and operationally ready. While policy reviews are typically annual, highly dynamic documents (like team lists and contact cards) require monthly or quarterly maintenance.

**Question 5**

**Which of the following types of review under BCI GPG PP6 specifically focuses on evaluating the quality of BCMS outputs (such as verifying that a BIA has documented appropriate MTPDs and RTOs) against organisational expectations and policies?**

A) Performance Appraisal

B) Supplier Performance Review

C) Quality Assurance (QA)

D) External Audit

#### Answer

****Correct Answer: C**

****Explanation**: Quality Assurance (QA) is a specific, documented review type that determines how well business continuity is incorporated into the outputs of the BCMS, verifying that those outputs meet stated expectations, policies, and specifications (such as checking that plans have defined owners and that BIAs contain logical recovery metrics).

**The Epilogue: That's all for now, folks!**

That’s all for now folks, I just have the exam to contend with now. If you are just about to take yours, then I wish you the best of luck, and hopefully these learning notes have helped a little.I'll write again post exam, to let you know how it went.

📚

New to the series?  
Start from the beginning or jump to any chapter by visiting the [CBCI Study Series Index](https://paulobrien.com/journey-to-cbci-business-continuity-gpg-7-0/) and don’t forget to grab your copy of the companion [GPG 7.0 Glossary Study Guide](https://paulobrien.com/bci-gpg-edition-7-0-complete-glossary/)!

## 📬 Never Miss a Deep Dive

I’m breaking down the entire BCI Good Practice Guidelines (GPG 7.0) step-by-step as I prepare for the CBCI exam. If you want practical resilience breakdowns and study notes delivered straight to your inbox as they publish, subscribe below—100% free, zero spam.

Subscribe 

Email sent! Check your inbox to complete your signup. 

No spam. Unsubscribe anytime.

---

*Disclaimer: These are independent study notes compiled to assist candidates preparing for the Certificate of the Business Continuity Institute (CBCI) examination. This content is not officially endorsed, sponsored, or affiliated with the Business Continuity Institute (BCI). The official body of knowledge is the BCI Good Practice Guidelines (GPG) Edition 7.0, which can be sourced directly from the BCI.*