1. Define continuity as the ability to make and execute critical decisions
An internationally mobile family can appear diversified because its members, homes, banks, advisers, entities and investments span several countries. That distribution also creates operating dependencies. A principal may be in one jurisdiction, the investment company in another, the bank in a third and the records needed to prove authority in a fourth. A crisis exposes the gaps between those components. Continuity exists when an authorised person can identify the required decision, obtain the right information, satisfy the relevant institution and complete the action within an agreed tolerance.
The Basel Committee defines operational resilience for banks as the ability to deliver critical operations through disruption and asks institutions to map the people, technology, processes, information, facilities and third parties supporting those operations [23]. A family office can adapt that logic without copying a bank's regulatory perimeter. The family first identifies its own critical services: personal safety, emergency cash, custody and payments, governance decisions, payroll, insurance, healthcare information, property access, entity compliance, investment controls and communication with dependants.
Each service needs an owner, a backup owner, a maximum tolerable interruption and evidence of how it can continue. The tolerance should reflect consequences. A delay in a discretionary investment may be acceptable. A delay in medical consent, accommodation, payroll, insurance notification or a margin payment may create immediate harm. The plan should therefore order recovery by impact and time sensitivity.
This paper proposes a three-part continuity test. Authority asks whether a person has a valid power to act. Access asks whether the institution, system or counterparty will accept that person and permit the action. Data asks whether the person can retrieve current, authentic and appropriately protected information. A decision fails when any one of the three is absent. The board should govern the three together and test them through actual exercises.

The model is a governance diagnostic. Legal validity and institutional acceptance require jurisdiction-specific confirmation.
2. Build the critical-services perimeter before drafting documents
A continuity programme should begin with services and consequences. Documents, software and contact lists then support defined operating needs. The perimeter should cover personal, family, entity and investment responsibilities because a disruption can move rapidly between them. A principal's incapacity may affect a holding-company signature, a property payment, a dependent's care and the ability to instruct an investment manager at the same time.
The service inventory should identify the outcome, deadline, initiating event, decision owner, executing party, systems, records, counterparties and jurisdiction. It should also identify dependencies that sit outside the family's direct control. Examples include a bank's identity-verification process, a registrar's certified-document requirements, a cloud provider's recovery method, a trustee's reserved powers, a hospital's consent rules and an insurer's notification window. These dependencies shape the practical recovery path.
Service tolerances need management approval. The numbers in Table 1 are illustrations and should be replaced after legal, operational and family review. The owner should document why each tolerance is appropriate and the resources required to meet it. A family may choose a shorter tolerance for emergency liquidity and a longer one for portfolio reporting. A vulnerable beneficiary may require a dedicated care and payment route that operates independently from the main investment structure.
The inventory should distinguish an event that stops one person from acting from an event that stops the entire operating model. Travel disruption, detention, illness or communications loss can isolate a principal. A cyber incident can disable the family office and several advisers simultaneously. A geopolitical shock can affect banks, travel, data access and sanctions screening across jurisdictions. The design should therefore include person-level, institution-level and system-level alternatives.
Table 1. Illustrative critical-services register
| Critical service | Illustrative tolerance | Primary owner | Continuity dependency | Minimum evidence |
|---|---|---|---|---|
| personal safety and medical coordination | 1 hour | family coordinator | local care provider and valid consent route | identity, emergency contacts, medical summary |
| emergency liquidity and essential payments | 4 hours | treasury lead | funded account and accepted mandate | signatory proof, payment protocol, source-of-funds record |
| payroll and household obligations | 1 business day | finance controller | payment platform and backup approver | approved payroll file, beneficiary list, audit trail |
| investment risk intervention | 1 business day | investment lead | custodian and delegated limits | mandate, limits, positions and escalation record |
| entity filings and statutory action | 3 business days | governance lead | registered agent and board quorum | registers, resolutions, filing calendar and authority matrix |
| property and insurance response | 4 hours to 3 days | asset manager | local manager, insurer and documented access | title or lease, policy, keys and incident record |
Every tolerance and escalation threshold is a hypothetical management assumption and requires family-specific approval and testing.
3. Separate legal authority from institutional acceptance
Legal authority and usable authority are different operating states. A power of attorney, board resolution, trust instrument, foundation by-laws or delegation schedule may establish a right to act. A bank, registry, hospital, insurer or digital platform may still require a specific form, certification, translation, legalisation, identity check or internal review before allowing the action. Continuity planning should record both layers.
The official guidance for lasting powers of attorney in England and Wales states that an LPA must be registered before it can be used and may not work in other countries; it directs people with foreign residence or property to obtain legal advice [3, 4]. Singapore's Office of the Public Guardian describes a separate statutory LPA under which a donor appoints donees for personal welfare and property and affairs if mental capacity is lost [5, 6]. These examples show why a single global document should not be assumed to operate everywhere.
The authority register should identify the legal instrument, governing law, trigger, scope, limitations, joint or several action, substitutes, expiry or revocation conditions, location of originals and acceptance status at each relevant institution. An acceptance status should be based on documented confirmation or a completed test. A lawyer's view on validity remains important; the operating team also needs evidence that the receiving institution can locate and apply the mandate.
The family should avoid powers that are broad in text and ambiguous in execution. Payment thresholds, investment powers, gifting restrictions, conflicts, digital-asset access, health decisions and entity votes may require different authority paths. Dual control can protect against abuse while slowing urgent action. The plan should define where dual control is essential, where a bounded emergency delegate can act alone and how every emergency action is reviewed afterward.
4. Create an authority map by asset, decision and jurisdiction
A family-level authority map turns legal instruments into a decision system. Rows represent decisions; columns represent the owning entity, asset location, governing law, primary decision maker, alternate, trigger, required approvals and accepting counterparty. The map should cover formal powers and practical dependencies. It should identify who can initiate, approve, execute, observe and challenge each action.
Authority can arise from several sources. A company acts through constitutional documents, board and shareholder decisions, delegations and bank mandates. A foundation acts through its charter, by-laws, council, guardian or other officeholders under the governing regime. ADGM describes foundations as vehicles that can support wealth management, preservation, succession, asset protection and corporate structuring [7, 8]. DIFC's family-wealth materials similarly place foundations within a governance and succession ecosystem [9]. Each structure requires its own operating map.
The map should distinguish a principal's personal authority from an office held in an entity. A personal attorney may manage an individual's property without automatically becoming a company director, foundation councillor, trustee, protector or investment-committee member. An alternate director may have entity power without access to the principal's personal account or medical records. The continuity plan assigns these routes explicitly.
Jurisdictional counsel should confirm the validity, form, certification and recognition of each instrument. The HCCH 2000 Protection of Adults Convention provides rules for jurisdiction, applicable law, recognition and enforcement among Contracting Parties in international adult-protection matters [1, 2]. Its existence does not create universal recognition. The live status table and the facts of each route require review. The authority map should record the relevant legal opinion date and the countries covered.

The overlay shows a review sequence. It does not state that any instrument is recognised in a particular jurisdiction.
5. Design succession of authority for people and offices
Continuity requires a deliberate sequence of authority. The sequence should address temporary unavailability, prolonged incapacity, death, resignation, conflict, loss of eligibility and removal for cause. It should also address the possibility that the first alternate is unavailable in the same event. A family that travels together or relies on advisers in one location can have correlated succession risk.
Each critical role should have a primary, first alternate and second route. The second route may be another person, a committee, a professional fiduciary or a legal application. Independence matters for controls. The same person should not unilaterally declare the trigger, approve a payment, execute it and certify the review when the action is material. The plan should allocate those functions while retaining a route for urgent bounded action.
Triggers must be observable and evidenced. A scheduled absence can activate a delegation on a stated date. Communications loss may activate a temporary protocol after documented attempts through approved channels. Incapacity requires the legal and medical process applicable to the instrument. Death requires official evidence and the succession route under the relevant structure. The operating team should never improvise a legal trigger from informal messages.
Role succession also needs acceptance. A replacement foundation councillor may need registry action. A substitute director may need a board or shareholder process. A bank may need to update signatories. A digital service may prohibit credential sharing and require its own account-recovery route. The continuity calendar should include pre-registration, specimen signatures, identity packs and periodic reconfirmation where permitted.
The board should review concentration. A single adviser who holds originals, knows the passwords and interprets the structure is a critical dependency. A single family member who controls every bank mandate creates a comparable weakness. The plan should distribute knowledge and access according to need, maintain confidentiality and preserve an audit trail.
Table 2. Authority succession matrix
| Role or decision | Primary route | First alternate | Trigger evidence | Acceptance test | Control after action |
|---|---|---|---|---|---|
| personal financial affairs | jurisdiction-specific authority holder | replacement authority holder | registered trigger and identity evidence | institution confirms usable mandate | independent transaction review |
| company board action | director and quorum under constitution | alternate or replacement process | board record and eligibility check | company secretary or registry confirms | minutes and conflicts review |
| foundation council action | councillors under charter and by-laws | successor councillor or guardian route | officeholder and trigger record | registrar and bank records updated | guardian or independent oversight |
| emergency treasury payment | treasury approver within delegated limit | bounded backup approver | declared incident and verified request | bank workflow test completed | next-day finance and family review |
| medical information and consent | authorised health decision route | alternate named by local instrument | provider-confirmed legal trigger | care provider confirms record | decision and disclosure log |
| digital-vault recovery | designated recovery custodians | quorum-based secondary recovery | loss event and identity proof | recovery drill completed | keys rotated and event audited |
The matrix is an illustrative design. Formal powers and triggers require legal confirmation in every relevant jurisdiction.
6. Convert bank mandates into tested access routes
Banking continuity depends on legal power, customer records, authentication, transaction controls and the bank's own operating resilience. A valid mandate can remain dormant if the institution has outdated identity documents, conflicting addresses, incomplete beneficial-ownership information or a separate requirement for the representative. The plan should therefore manage each bank as an access route with documented prerequisites.
The bank register should record account purpose, owner, jurisdiction, relationship team, authorised signatories, payment limits, authentication method, call-back protocol, source-of-funds file, beneficial-ownership record, tax-residence record, emergency contact and last completed test. It should avoid storing active credentials in the register. It should identify where a device, phone number, hardware token or physical document becomes a single point of failure.
A test should use a low-risk permitted action. Examples include verifying a signatory list, accessing a read-only statement, completing a small pre-approved payment or confirming the bank's documentary process for an authority trigger. The bank should approve the test design. The family office records the date, result, delay, additional requirements and named institutional owner. A failed test becomes a remediation item.
Financial institutions themselves apply operational-resilience controls. The Basel principles emphasise critical operations, dependency mapping, business continuity, incident management and resilient technology [23]. FINMA's operational-risk circular addresses critical data, cyber risks and business continuity for supervised Swiss institutions [25]. These standards do not transfer responsibility from the family. They show why the family's plan should include alternative accounts, validated contacts and realistic time allowances for a bank operating through disruption.
Account diversification should support defined needs. More accounts can create more KYC, security and reconciliation work. The architecture should give each account a purpose, funded minimum, owner and closure rule. An emergency reserve should be accessible through a route that has been tested and is not dependent on the same institution, person, device or network as the main operating account.
7. Build an emergency-liquidity ladder with funded alternatives
Liquidity continuity begins with obligations. The family should map essential payments by currency, jurisdiction, beneficiary, due date and consequence. These may include accommodation, care, insurance, education, payroll, taxes, debt service, property maintenance and urgent professional support. The map should distinguish payments that can wait from those that can cause harm, default or loss of access.
The liquidity ladder should provide progressively broader resources. Tier one covers immediate household and care needs through a locally accessible funded account or card with bounded limits. Tier two covers several weeks of family and operating obligations through independently accessible bank liquidity. Tier three provides portfolio-level liquidity through approved credit, money-market or asset-sale routes. Tier four addresses structural actions requiring governance, lender or investment approval.
Every tier requires authority and access. A reserve held in the correct currency has limited value if the only authorised person is unavailable. A credit facility has limited value if a covenant, borrowing-base certificate or draw notice cannot be produced. An investment sale may be inappropriate during market stress. The plan should specify eligible uses, decision rights, evidence, replenishment and post-event reporting.
Liquidity tests should avoid manufacturing emergencies. The family office can complete small controlled transfers, confirm draw documentation, validate settlement instructions and reconcile the event. It can also run tabletop exercises using hypothetical assumptions. The model should state exchange-rate, market-value and timing assumptions openly. It should avoid presenting a scenario result as a forecast.

Amounts and coverage periods are omitted because they require family-specific assumptions. The diagram presents a sequence of access routes.
8. Treat identity and authentication as continuity infrastructure
Digital access is often anchored to a person, device, email address, phone number, biometric, token or recovery secret. International movement can change phone services, device availability and identity documents. A crisis can also increase fraud attempts. The plan needs secure recovery routes that preserve the service provider's terms and avoid informal credential sharing.
NIST's current Digital Identity Guidelines address identity proofing, authentication and federation and include updated treatment of fraud, forged media, passkeys and subscriber-controlled wallets [20]. CISA recommends strong identity controls, including phishing-resistant multi-factor authentication for critical services, alongside tested offline backups [22]. A family office can use these sources to design risk-based controls for its own systems and to question providers about recovery.
The identity inventory should record the account owner, service, business purpose, administrator, authentication method, recovery method, trusted devices, registered contacts, alternate administrator, data location and last recovery test. It should not store passwords or private keys in the inventory. High-risk services should use individual named accounts, least privilege, separate administrative identities and logging.
Recovery should require more than one compromised channel. An email account that can reset the password for the vault, bank portal and phone account can become a master key. The architecture should separate recovery domains and use independent custodians or quorum controls for the most sensitive assets. Digital assets require specialist legal, technical and custody design; the plan should distinguish ownership, signing authority, key custody and recovery.
The family office should rehearse device loss, phone-number loss, principal unavailability and administrator departure. The exercise confirms who contacts the provider, what identification is required, how long recovery takes, what monitoring is triggered and how credentials are rotated afterward. Results should be documented without recording live secrets.
9. Create a controlled data vault with a clear recovery purpose
A continuity vault should contain the minimum trusted information required to restore critical decisions and services. It is a governed record system, not a miscellaneous archive. The design should define content, owner, version, sensitivity, access rule, retention, backup, recovery and deletion. Each record should have an authoritative source and review date.
The vault's core may include identity documents, family contacts, medical summaries where lawful and appropriate, authority instruments, entity records, account and custodian directories, insurance policies, property records, adviser mandates, asset maps, tax-residence records, beneficial-ownership records, recovery instructions and sealed references to credential-custody systems. It should avoid unnecessary duplication of highly sensitive data.
Cross-border access can itself be a regulated data transfer. The UAE's federal data-protection framework includes requirements for cross-border transfers and applies governance duties to personal-data processing [11]. ADGM provides specific guidance and safeguards for international transfers under its Data Protection Regulations [12, 13]. DIFC's regime uses adequacy and other safeguards for transfers out of the centre [14, 15]. The UK ICO, the European Commission and Singapore's PDPC provide their own transfer frameworks [16, 17, 18]. The vault architecture therefore needs a jurisdiction and role review.
Availability should be designed alongside confidentiality. One encrypted copy controlled by one person can fail when that person or device is unavailable. Uncontrolled replication creates privacy and cyber exposure. The paper proposes a tiered architecture: a live controlled repository, an encrypted independent backup, a sealed legal-document set and a recovery register held by authorised custodians. Each tier should have a documented purpose and test.

The architecture is conceptual. Storage, encryption, transfer and disclosure controls require technical and legal design.
10. Apply data minimisation, classification and transfer controls
The vault should classify data by harm, legal restriction and continuity value. Public entity information may have low confidentiality. Passport copies, health data, family relationships, beneficial-ownership records, account details and private keys can require strict controls. The classification should determine encryption, access, sharing, retention and recovery method.
The family office should maintain a record of processing for continuity data. It should identify the controller or responsible entity, purpose, lawful basis where applicable, data subjects, categories, recipients, locations, processors, transfers, safeguards, retention and security controls. Legal advisers should confirm the applicable regimes. The operating team can then answer who holds a record, why it is needed and how it can be disclosed during a crisis.
Remote access may count as an international transfer in some regimes. The UK ICO explains that making personal information accessible to a separate organisation outside the UK can be a restricted transfer [16]. Singapore's PDPC states that overseas transfers should meet prescribed requirements for comparable protection [17]. DIFC and ADGM provide transfer mechanisms and guidance [12, 14]. A family member's mobility can therefore change the access context even when the server does not move.
The vault should use role-based views. A medical responder may need a limited care pack. A treasury alternate may need mandates and payment protocols. A lawyer may need originals and certification records. An investment manager should not receive unrelated health or family information. Emergency access should be logged, time-bounded and reviewed.
Retention needs a controlled exit. Superseded passports, revoked powers, former advisers and closed accounts can create confusion and exposure. The system should preserve the legal record where required, mark the current instrument clearly and remove operational access when the purpose ends. A deletion and archive decision should be recorded by the data owner.
Table 3. Continuity-data classification and access matrix
| Data class | Examples | Continuity use | Normal access | Emergency control |
|---|---|---|---|---|
| critical identity | passports, residence evidence, verified contact data | identity proof and recovery | restricted compliance team | time-bounded release with event log |
| legal authority | powers, resolutions, charters, mandates | prove decision rights | governance lead and counsel | verified copy plus acceptance checklist |
| financial directory | institution, owner, purpose, relationship contacts | route payments and instructions | treasury and designated oversight | no credentials; use approved recovery channel |
| health and care | essential medical summary, consent route, provider contact | immediate care coordination | named care coordinator | minimum necessary disclosure |
| entity and ownership | registers, structure, beneficial ownership, filings | governance and KYC continuity | legal, tax and compliance roles | current certified evidence pack |
| technical recovery | system owner, recovery custodians, backup test | restore access and data | security administrators | quorum release and post-event key rotation |
Categories and controls require adjustment for applicable law, technology and family circumstances.
11. Align beneficial-ownership and tax-residence records
Continuity events often trigger institutional review. A new representative, changed address, successor officeholder, deceased principal or revised ownership chain can prompt KYC, tax-residence and beneficial-ownership questions. The continuity pack should contain current, consistent records that can be reproduced across banks, registries, trustees and advisers.
FATF's 2024 guidance on legal arrangements explains the importance of adequate, accurate and up-to-date beneficial-ownership information for express trusts and similar arrangements [26]. Its definitions include settlors, trustees, protectors, beneficiaries and other natural persons exercising ultimate effective control in the beneficial-owner analysis for legal arrangements [26]. The exact requirements depend on the applicable regime and entity, but the operating lesson is clear: roles and control cannot remain implicit.
The ownership file should map legal ownership, beneficial interest, control, officeholders and authorised representatives separately. It should record the evidence and review date for each. A foundation, trust, holding company and family-office company can have different reporting routes. The plan should avoid using one simplified diagram for every purpose.
Tax-residence information also needs continuity. The OECD's Common Reporting Standard and Crypto-Asset Reporting Framework create reporting and due-diligence concepts that can apply through financial institutions and relevant service providers [27, 28]. Mobility, entity changes and control changes can alter the information requested. Tax advisers should approve the residence and classification positions; the family office should maintain the supporting facts and deliver consistent updates.
An annual reconciliation should compare the vault, entity registers, bank records, tax files and adviser records. Differences should be assigned, resolved and evidenced. A crisis should activate the latest approved pack rather than a folder assembled from memory.
12. Govern communications without creating a second crisis
Communication can protect people and decisions during disruption. It can also expose sensitive information, create inconsistent instructions or enable fraud. The plan should define who can declare an incident, who communicates with family members, institutions, employees, advisers and public authorities, and which channels are approved.
The communication tree should contain verified contacts and alternates. It should separate urgent operational messages from family discussion and public statements. A concise incident notice can state the event category, immediate restrictions, decision authority, next update time and verification method. It should avoid distributing unnecessary personal or financial detail.
Fraud risk rises when counterparties expect unusual urgency. Payment instructions, account changes and credential-reset requests should use independent verification. A family member's voice, video or message should not be treated as sufficient proof for a material action. NIST's Digital Identity Guidelines include controls addressing forged media and identity-proofing risks [20]. The family office should agree a human verification protocol and test it.
The plan should include channel failure. A primary messaging platform, email domain or phone network can be unavailable or compromised. A secondary channel should be pre-agreed and protected. Contact lists should be available through a controlled offline route. The team should know how to reach local emergency, consular, legal and financial contacts without relying on one device.
Every external statement requires authority. A family office, portfolio company and personal representative may have different disclosure obligations. Counsel and communications advisers should determine the route. The incident log should preserve material messages, instructions, approvals and acknowledgements.
13. Build playbooks for severe but plausible family events
A continuity plan becomes operational through event playbooks. Each playbook should define the event, indicators, declaration authority, immediate objectives, prohibited actions, decision sequence, information required, internal and external contacts, recovery criteria and review. It should fit on a few usable pages with links to controlled evidence.
The event library should reflect the family's geography and assets. It may include principal incapacity, death, travel detention, communications loss, cyber compromise, bank outage, fraud attempt, sanctions or KYC escalation, political disruption, natural disaster, property loss, adviser failure and a critical employee departure. The family should select events based on exposure rather than novelty.
Playbooks should address combined events. A principal can become unavailable during a cyber incident. A geopolitical event can affect travel, a bank and a data centre simultaneously. A death can coincide with market volatility and family conflict. The plan should identify common dependencies and prevent one event owner from assuming another system remains available.
The response sequence should begin with safety and containment. The team verifies the event, protects people and assets, freezes compromised routes, confirms authority and establishes communications. It then restores critical services in the approved order. Recovery ends when services are stable, temporary powers are withdrawn or regularised, data is reconciled and open risks are assigned.
The FSB's cyber incident toolkit organises practices across governance, preparation, analysis, mitigation, recovery, communication and improvement [24]. NIST and CISA similarly emphasise governance, response, recovery, tested backups and role clarity [19, 22]. These principles support a disciplined family playbook.

Scores are hypothetical management assumptions on a five-point scale. The family should replace them through a documented risk workshop.
14. Test incapacity and death as distinct operating events
Incapacity and death activate different legal, personal and institutional processes. The plan should maintain separate playbooks even when some contacts and records overlap. Incapacity focuses on the trigger, valid decision authority, ongoing care, privacy and temporary or continuing financial management. Death focuses on official evidence, executors or administrators, entity succession, immediate family support, asset preservation and the transition to estate processes.
The incapacity playbook should identify who can assess or certify the relevant condition, who receives that information, how privacy is protected and which authority instruments become usable. It should distinguish health and welfare decisions from property and financial affairs. The England and Wales LPA framework and Singapore's LPA framework illustrate that statutory forms, scope and registration rules differ [3, 5]. Local counsel should define the applicable route in every important jurisdiction.
The death playbook should begin with people and essential obligations. It should set out the route for medical, registration, consular, funeral and family support decisions where relevant. It should then secure accounts and data, notify authorised advisers and institutions, preserve time-sensitive rights and activate entity succession. It should avoid broad notifications before counsel and the appointed personal representatives confirm the sequence.
Joint family travel creates concentration. The plan should consider an event affecting several officeholders or heirs. Entity constitutions, foundation rules, trusts, shareholder arrangements and insurance nominations should be reviewed for that possibility. The continuity architecture should preserve a functioning decision body and access to essential funds.
Exercises should use hypothetical records and avoid simulating a legal declaration. The team can test document retrieval, contact accuracy, task ownership and time to assemble a complete evidence pack. Legal and medical professionals should design any test that approaches real trigger processes.
Table 4. Incapacity and death continuity checklist
| Workstream | Incapacity questions | Death questions | Evidence owner | Exercise output |
|---|---|---|---|---|
| personal authority | which instrument, trigger and scope apply | who is personal representative and when can they act | private-client counsel | verified authority route |
| care and dependants | who can consent, coordinate and fund care | who provides immediate family and dependant support | family coordinator | current care and contact pack |
| bank and payments | which attorney or delegate is accepted | what restrictions and estate process apply | treasury lead | institution-by-institution checklist |
| entities | do offices continue and who acts temporarily | which succession provisions activate | governance lead | quorum and replacement map |
| data | who can access the minimum necessary records | who preserves, releases and archives records | data owner | access and disclosure log design |
| communication | who receives limited factual notice | who approves family, employee and external messages | incident lead and counsel | approved message tree |
The checklist identifies operating questions. Legal, medical, succession and disclosure requirements require professional advice.
15. Prepare for geopolitical, sanctions and mobility disruption
Geopolitical events can alter travel, communications, banking, logistics, sanctions screening and institutional risk appetite with little notice. The continuity plan should focus on lawful, documented operations and rapid fact validation. It should avoid assumptions that a payment, person or entity is restricted without a competent review.
The family office should maintain a jurisdiction exposure map covering people, residence and citizenship, entities, banks, custodians, assets, counterparties, data locations and critical providers. The map should show dependencies and alternates. It should also identify where two apparent alternatives rely on the same clearing bank, cloud provider, adviser network or telecommunications route.
An event protocol should require sanctions and legal review before moving assets, changing counterparties or sharing sensitive information. It should preserve source-of-funds, beneficial-ownership and transaction-purpose evidence. FATF's guidance emphasises accurate and current ownership information and international cooperation for legal arrangements [26]. Strong records can support lawful institutional review.
Mobility continuity includes passports, visas, residence evidence, local contacts, accommodation, care and communications. A family should maintain current copies and secure originals according to law and practical need. It should identify consular and local professional contacts from official sources. The plan should avoid presenting a private operating procedure as a substitute for public-authority guidance.
The exercise should test decisions under uncertainty. The team receives a hypothetical notice that travel is interrupted and a bank requests additional review. It must identify verified facts, pause unsupported action, protect immediate liquidity, locate required records and escalate to advisers. The board reviews whether the response protected people, complied with controls and avoided inconsistent messages.
16. Integrate the family office, trustees, councils and advisers
Continuity is distributed across the family, family office, trustees, foundation councils, directors, banks, custodians, lawyers, tax advisers, administrators, security providers and care coordinators. The operating model should give each party a defined role and information boundary. A large contact list without decision rights creates coordination risk.
The family should appoint a continuity owner with authority to maintain the programme and convene exercises. That owner does not replace legal officeholders. The role coordinates the service register, authority map, data vault, issue log, tests and board reporting. Each legal entity retains its own decisions and records.
Adviser mandates should address continuity. The family office should know who can act when the relationship partner is unavailable, where records are held, how instructions are authenticated, what conflicts apply, how work transfers on termination and which services depend on subcontractors. A professional provider's business-continuity plan should be reviewed at a proportionate level.
Foundation and trust governance should preserve the distinction between administration, fiduciary judgment and family preference. The council or trustee should receive the information needed for its duties and maintain its own records. A family council may express priorities without displacing formal authority. The continuity plan should state these boundaries.
The RACI model can clarify execution: responsible, accountable, consulted and informed. Critical actions also need an independent challenge or review role. The plan should identify the person who can stop an unsafe instruction, the person who resolves conflicts and the route for reporting suspected abuse.
17. Measure continuity through exercises and evidence
A plan that has not been tested remains a design hypothesis. Exercises should show whether people can retrieve records, validate authority, contact institutions and complete decisions within the approved tolerance. The programme should combine document reviews, access tests, tabletop scenarios and selected live exercises.
Document reviews confirm validity, versions, certifications, translations, expiry and storage. Access tests confirm that authorised people can reach systems and institutional contacts without sharing credentials. Tabletop exercises rehearse combined events and decisions. Live exercises use low-risk permitted actions, such as a controlled backup restoration or a small pre-approved payment.
The exercise record should capture objective, scope, scenario assumptions, participants, evidence used, elapsed times, decisions, failures, workarounds and actions. A pass requires more than completing the action. The action should follow the approved authority, security, privacy and audit controls. An unauthorised shortcut is a failed test even when it is fast.
NIST's contingency-planning guidance links recovery requirements to system impact and calls for plans, procedures and technical measures that support recovery [21]. The Basel principles call for severe but plausible scenarios, mapping and learning [23]. The family programme can adapt those disciplines to its critical services.
Testing frequency should reflect change and impact. A high-impact bank route or data recovery process may need more frequent testing than a stable archival process. A move, new entity, changed adviser, new device, altered power or major asset acquisition should trigger a targeted retest. The calendar should record evidence and next due date.

The cycle is a proposed governance process. Review frequency should reflect the family's risk, change and legal requirements.
18. Use a board dashboard that records decisions and exceptions
The board dashboard should show service readiness, authority coverage, access tests, data recovery, scenario exercises, unresolved exceptions and change events. It should support decisions rather than create a false aggregate score. A single green percentage can hide a critical failure in medical authority or emergency liquidity.
Each critical service should report its tolerance, current owner, alternate coverage, last test, actual test time, open exceptions and next action. The board should see evidence quality: documented legal opinion, institution confirmation, completed exercise or self-assessment. Evidence dates matter because mobility, personnel and provider processes change.
Exceptions should be ranked by consequence and time. A missing secondary contact may be low impact. An expired identity document on the only usable bank route can be urgent. Each exception needs an owner, remediation, due date, interim control and approval if risk is accepted. Closed items should retain the evidence of closure.
The dashboard should also track change. New residences, citizenships, marriages, births, deaths, health conditions, officeholders, entities, banks, advisers, material assets, facilities and data systems can affect the plan. A change register routes the event to legal, tax, governance, data and operating owners. The board receives material implications and required decisions.
The dashboard's value depends on challenge. The board should ask which critical service would fail if one person, bank, device or adviser became unavailable today. It should ask whether alternates were tested, which conclusions rely on outdated evidence and whether the family understands the response. The answers drive the next exercise and investment.
Table 5. Board continuity dashboard
| Dashboard line | Evidence measure | Decision signal | Board question | Required action |
|---|---|---|---|---|
| authority coverage | critical decisions with valid primary and alternate routes | red if a critical route lacks a confirmed alternate | can an authorised person act in each relevant place | commission instrument or acceptance review |
| institutional access | tests completed within approved tolerance | amber for stale or partial test | did the institution accept the named person and evidence | retest and close requirements |
| emergency liquidity | obligations covered by independently accessible routes | red for correlated access dependency | can essential payments continue through a combined disruption | fund, diversify or redesign route |
| data recovery | successful restore and minimum-data retrieval | red for untested or single-custodian recovery | can current records be recovered securely | complete restore drill and access review |
| scenario readiness | severe scenarios exercised and actions closed | amber for overdue high-impact scenario | did the team follow authority, privacy and security controls | run exercise and assign remediation |
| change control | material events assessed across workstreams | red for an unassessed legal or identity change | has the plan followed the family's current facts | convene cross-functional review |
Status labels and tolerances are illustrative. Each item requires evidence and a named owner.
19. Implement through a 100-day controlled programme
Implementation should protect current operations while correcting the highest continuity risks. The paper proposes four workstreams over one hundred days: establish the perimeter, validate authority, build access and data controls, then test and govern. The schedule is an illustrative management sequence and should change where legal or safety priorities require faster action.
Days 1 to 20 establish sponsorship, confidentiality, critical services, tolerances and the issue register. The team identifies jurisdictions, entities, institutions, advisers, systems and vulnerable dependencies. It names owners and immediately protects any evident single point of failure. The team avoids moving data or changing authority before the legal and security design is approved.
Days 21 to 50 build the authority map. Counsel reviews personal instruments, entity succession, foundation or trust roles and recognition questions. The family office confirms institution requirements and acceptance status. Treasury maps obligations and designs the liquidity ladder. The data owner classifies records and documents transfer constraints.
Days 51 to 80 implement controlled access. Institutions receive approved updates. The vault is organised, backed up and assigned to custodians. Authentication and recovery routes are tested. Playbooks are drafted for selected high-impact events. Advisers confirm their roles and alternates.
Days 81 to 100 run exercises. The team tests document retrieval, bank access, data recovery and one combined scenario. It records failures, closes urgent gaps and submits the dashboard for board approval. The board approves tolerances, residual exceptions, the annual calendar and the change-control triggers.
The programme should produce evidence, not volume. A concise verified authority register has more value than hundreds of unclassified documents. A tested payment route has more value than an unfunded account. Every deliverable should name the decision it supports and the person responsible for keeping it current.
20. Define the annual governance and assurance cycle
Continuity requires renewal. The annual cycle should combine quarterly operating checks, event-driven reviews and a formal board assessment. It should align with entity filings, insurance renewals, tax reviews, bank KYC, adviser due diligence and cybersecurity exercises where practical.
Quarterly checks can confirm people, contacts, identity documents, signatories, critical balances, data backups and outstanding exceptions. A semi-annual exercise can test a high-impact route. The annual review should reconcile every critical service, authority instrument, jurisdiction, institution, data repository and provider against current facts.
Assurance should be proportionate and independent. Legal counsel confirms instruments and jurisdictional conclusions. Cybersecurity specialists test recovery and access controls. Tax advisers confirm residence and reporting positions. Internal or external reviewers can sample evidence and action closure. The continuity owner integrates these views without presenting one adviser as responsible for every domain.
The annual board decision should approve the critical-service perimeter, tolerances, authority and access exceptions, liquidity architecture, vault controls, exercise plan and budget. It should record any accepted risk and the reason. The decision should also confirm the incident-declaration and escalation roles.
Changes during the year should enter a single controlled workflow. A new country, bank, entity, property, investment vehicle, adviser, family member or technology platform can trigger several reviews. The workflow assigns legal, tax, data, governance, treasury and security tasks and closes only when evidence is updated.
21. Govern continuity through a board-ready decision file
The final decision file should enable a new authorised person to understand the continuity system without relying on private memory. It should include the service register, authority map, institution acceptance register, liquidity ladder, data architecture, processing and transfer record, playbooks, exercise evidence, exception log, adviser matrix and board decisions. Sensitive credentials and private keys should remain in the separate approved custody system.
The board should approve the design when five conditions are met. First, critical services and tolerances reflect the family's real obligations. Second, authority routes are supported by current legal evidence. Third, institutions and systems have accepted or tested the relevant access. Fourth, minimum trusted data can be recovered securely. Fifth, severe but plausible scenarios have been exercised and failures have owners.
The decision file should state its limits. Cross-border recognition, medical authority, succession, sanctions, data transfer and tax reporting can change with jurisdiction and facts. The file records professional advice and operating evidence available at the review date. It does not convert uncertainty into a universal conclusion.
The board should also assess usability. The plan should work during stress, outside normal hours and without one central person. Clear routes, bounded authority, verified contacts and disciplined records support that objective. The strongest design preserves both action and restraint: authorised people can act when necessary, and controls stop unsupported action.
Table 6. Board approval and annual assurance file
| Approval item | Evidence required | Accountable owner | Annual assurance | Escalation trigger |
|---|---|---|---|---|
| critical-service perimeter | service register, consequences and approved tolerances | board sponsor | service owner attestation and exercise results | new dependant, obligation or material asset |
| authority architecture | instruments, legal views, succession and acceptance register | governance lead | counsel review and officeholder reconciliation | incapacity concern, role or jurisdiction change |
| access and liquidity | institution tests, funded routes, limits and reconciliation | treasury lead | controlled transaction and contact verification | bank, device, signatory or funding change |
| data and identity | classification, processing record, backups and recovery evidence | data owner | restore test and privileged-access review | provider, location, breach or identity change |
| incident playbooks | scenarios, roles, communication trees and exercise records | continuity owner | tabletop and selected live exercise | material incident or control failure |
| exceptions and change | issue register, interim controls and board risk acceptance | programme office | closure sampling and overdue-item review | missed deadline or repeated failed test |
The file records governance decisions and supporting evidence. It does not replace jurisdiction-specific professional advice.
Sources and further reading
- Hague Conference on Private International Law, Protection of Adults Section Official source
- Hague Conference on Private International Law, 2000 Protection of Adults Convention Outline Official source
- UK Office of the Public Guardian, Make and Register Your Lasting Power of Attorney Official source
- UK Government, Make, Register or End a Lasting Power of Attorney Official source
- Singapore Ministry of Social and Family Development, What Is a Lasting Power of Attorney Official source
- Singapore Ministry of Social and Family Development, Office of the Public Guardian Official source
- Abu Dhabi Global Market, Registration and Incorporation Official source
- Abu Dhabi Global Market, Setting Up Frequently Asked Questions Official source
- Dubai International Financial Centre, Family Wealth Centre Foundations Guide Official source
- Dubai International Financial Centre, Family Wealth Centre Programmes and Partnerships Official source
- UAE Government, Data Protection Laws Official source
- Abu Dhabi Global Market, Office of Data Protection Guidance Official source
- Abu Dhabi Global Market, Operating Frequently Asked Questions Official source
- Dubai International Financial Centre, Data Export and Sharing Official source
- Dubai International Financial Centre, Data Protection Law No. 5 of 2020 Official source
- UK Information Commissioner's Office, Guide to International Transfers Official source
- Singapore Personal Data Protection Commission, Data Protection Obligations Official source
- European Commission, Rules on International Data Transfers Official source
- National Institute of Standards and Technology, Cybersecurity Framework 2.0 Official source
- National Institute of Standards and Technology, Digital Identity Guidelines Revision 4 Official source
- National Institute of Standards and Technology, Contingency Planning Guide for Federal Information Systems Official source
- Cybersecurity and Infrastructure Security Agency, StopRansomware Guide Official source
- Basel Committee on Banking Supervision, Principles for Operational Resilience Official source
- Financial Stability Board, Effective Practices for Cyber Incident Response and Recovery Official source
- Swiss Financial Market Supervisory Authority, Operational Risks and Resilience for Banks Official source
- Financial Action Task Force, Beneficial Ownership and Transparency of Legal Arrangements Official source
- Organisation for Economic Co-operation and Development, Consolidated Text of the Common Reporting Standard 2025 Official source
- Organisation for Economic Co-operation and Development, Crypto-Asset Reporting Framework Introduction Official source
- UAE Government, Cyber Laws Official source
- Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals Official source

