IT & Cyber Audit
Disaster Recovery Testing
Currency and success of disaster recovery and failover tests for critical business systems.
An untested recovery plan is an assumption, not a control
The ability to recover critical financial and service-delivery systems after a failure is a board-level resilience obligation under King IV and a core IT general control the AGSA evaluates, yet recovery capability that has never been tested cannot be relied upon. A plan on paper provides no assurance that systems will actually come back within the required time. AuditPro Core tracks the currency and outcome of disaster recovery tests so that stale plans and failed failovers are visible before an outage proves them inadequate.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Critical systems
48
DR test in date
71%
▲ 9 pts
Never tested
6
RTO met last test
82%
Systems by DR test recency
Tier-1 systems DR status
| System | Last test | Outcome | RTO (hrs) |
|---|---|---|---|
| Revenue billing | Mar 2026 | Pass | 4 |
| Payroll (PERSAL) | Nov 2025 | Partial | 9 |
| Financial ledger | Never | Not tested | 0 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Recovery objectives define adequacy
Each critical system has a recovery time and recovery point objective. A test only demonstrates the control if it actually meets those objectives, not merely if the system eventually restarts.
Currency of the last successful test
Infrastructure, configurations and dependencies drift continuously, so a recovery test ages quickly. A plan last proven a year or more ago offers limited assurance about today's environment.
Test outcome, not just occurrence
A test that ran but failed, or that succeeded only with manual workarounds, is a finding in itself. Recording the outcome and any deviations is as important as recording that a test happened.
Dependency coverage
Recovering an application is meaningless if its database, network or authentication dependencies are not recovered with it. Tests must cover the full dependency chain of each critical service.
How AuditPro Core Bridges the Gap
- Currency tracking: the date and result of each system's last DR test are monitored against the required cadence.
- Outcome capture: test results record whether recovery objectives were met and what deviations occurred.
- Exception workflow: overdue tests and failed failovers are escalated to the responsible system owners.
- Audit-ready export: test currency and outcomes export to evidence the IT general control to the AGSA.
Key Takeaways
- An untested recovery plan provides no assurance of actual recoverability.
- Adequacy is meeting the recovery time and point objectives, not merely restarting.
- Record test outcomes and workarounds, not just that a test took place.
- Cover the full dependency chain, since an app cannot recover without its dependencies.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
