Back to Explore
💸

IT & Cyber Audit

Disaster Recovery Testing

Currency and success of disaster recovery and failover tests for critical business systems.

📖 6 min read🎯 Intermediate✍️ Updated 2026

An untested recovery plan is an assumption, not a control

The ability to recover critical financial and service-delivery systems after a failure is a board-level resilience obligation under King IV and a core IT general control the AGSA evaluates, yet recovery capability that has never been tested cannot be relied upon. A plan on paper provides no assurance that systems will actually come back within the required time. AuditPro Core tracks the currency and outcome of disaster recovery tests so that stale plans and failed failovers are visible before an outage proves them inadequate.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Critical systems

48

DR test in date

71%

▲ 9 pts

Never tested

6

RTO met last test

82%

Systems by DR test recency

Tier-1 systems DR status

SystemLast testOutcomeRTO (hrs)
Revenue billingMar 2026Pass4
Payroll (PERSAL)Nov 2025Partial9
Financial ledgerNeverNot tested0

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Recovery objectives define adequacy

Each critical system has a recovery time and recovery point objective. A test only demonstrates the control if it actually meets those objectives, not merely if the system eventually restarts.

Currency of the last successful test

Infrastructure, configurations and dependencies drift continuously, so a recovery test ages quickly. A plan last proven a year or more ago offers limited assurance about today's environment.

Test outcome, not just occurrence

A test that ran but failed, or that succeeded only with manual workarounds, is a finding in itself. Recording the outcome and any deviations is as important as recording that a test happened.

Dependency coverage

Recovering an application is meaningless if its database, network or authentication dependencies are not recovered with it. Tests must cover the full dependency chain of each critical service.

How AuditPro Core Bridges the Gap

  • Currency tracking: the date and result of each system's last DR test are monitored against the required cadence.
  • Outcome capture: test results record whether recovery objectives were met and what deviations occurred.
  • Exception workflow: overdue tests and failed failovers are escalated to the responsible system owners.
  • Audit-ready export: test currency and outcomes export to evidence the IT general control to the AGSA.

Key Takeaways

  • An untested recovery plan provides no assurance of actual recoverability.
  • Adequacy is meeting the recovery time and point objectives, not merely restarting.
  • Record test outcomes and workarounds, not just that a test took place.
  • Cover the full dependency chain, since an app cannot recover without its dependencies.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.