Capital in Motion · Family Wealth

The Crisis-Continuity Plan for Mobile Families: Authority, Access and Data across Borders

A tested operating framework for preserving decision authority, institutional access, emergency liquidity and trusted data across borders.

The Crisis-Continuity Plan for Mobile Families: Authority, Access and Data across Borders
Quick answer

The framework aligns valid authority, institution-accepted access and recoverable evidence across every critical decision route, then tests the combined system through severe but plausible events.

Abstract

International mobility can distribute a family's people, assets, advisers, entities and information across several legal and operating systems. A document that grants authority in one place may require a different instrument, proof or process elsewhere. A bank mandate can remain legally valid while digital credentials, identity checks or internal controls delay its use. A secure data vault can protect confidentiality while leaving the wrong people unable to recover critical records during a crisis.

Continuity therefore depends on the alignment of legal authority, institutional access, trusted data and executable decision rights. This paper develops a crisis-continuity framework for internationally mobile families and family offices. It defines a critical-services perimeter, separates legal power from practical access, maps authority by asset and jurisdiction, creates an emergency-liquidity architecture, governs identity and authentication, establishes a controlled data vault, and converts severe but plausible events into tested response playbooks.

Six original figures and six tables provide an authority-access model, jurisdiction overlay, liquidity ladder, data-vault architecture, scenario heat map and board dashboard. The framework adapts recognised operational-resilience, cybersecurity, data-protection and beneficial-ownership principles to the distinctive governance needs of family wealth.

All amounts, scores, time estimates, service tolerances, case facts and implementation sequences in this paper are hypothetical management assumptions for decision design. They are not client facts, forecasts, legal conclusions, tax opinions or promised outcomes. The paper reflects official and authoritative sources available in August 2026. It is strategic and governance research and does not replace legal, tax, medical, cybersecurity, data-protection, fiduciary or jurisdiction-specific advice.

JEL Classification: G23, G32, G53, K15, K33, M10

Keywords: family office, crisis continuity, cross-border authority, power of attorney, data governance, access control, operational resilience, emergency liquidity, mobile families

This Matchpoint Insight presents the web edition of Matchpoint Partners' research. The supporting paper contains the full framework, structures, worked examples and source material.

Read the full research paper   Explore our Alternatives practice

1. Define continuity as the ability to make and execute critical decisions

An internationally mobile family can appear diversified because its members, homes, banks, advisers, entities and investments span several countries. That distribution also creates operating dependencies. A principal may be in one jurisdiction, the investment company in another, the bank in a third and the records needed to prove authority in a fourth. A crisis exposes the gaps between those components. Continuity exists when an authorised person can identify the required decision, obtain the right information, satisfy the relevant institution and complete the action within an agreed tolerance.

The Basel Committee defines operational resilience for banks as the ability to deliver critical operations through disruption and asks institutions to map the people, technology, processes, information, facilities and third parties supporting those operations [23]. A family office can adapt that logic without copying a bank's regulatory perimeter. The family first identifies its own critical services: personal safety, emergency cash, custody and payments, governance decisions, payroll, insurance, healthcare information, property access, entity compliance, investment controls and communication with dependants.

Each service needs an owner, a backup owner, a maximum tolerable interruption and evidence of how it can continue. The tolerance should reflect consequences. A delay in a discretionary investment may be acceptable. A delay in medical consent, accommodation, payroll, insurance notification or a margin payment may create immediate harm. The plan should therefore order recovery by impact and time sensitivity.

This paper proposes a three-part continuity test. Authority asks whether a person has a valid power to act. Access asks whether the institution, system or counterparty will accept that person and permit the action. Data asks whether the person can retrieve current, authentic and appropriately protected information. A decision fails when any one of the three is absent. The board should govern the three together and test them through actual exercises.

Figure 1. Authority, access and data continuity model
Figure 1. Authority, access and data continuity model

The model is a governance diagnostic. Legal validity and institutional acceptance require jurisdiction-specific confirmation.

2. Build the critical-services perimeter before drafting documents

A continuity programme should begin with services and consequences. Documents, software and contact lists then support defined operating needs. The perimeter should cover personal, family, entity and investment responsibilities because a disruption can move rapidly between them. A principal's incapacity may affect a holding-company signature, a property payment, a dependent's care and the ability to instruct an investment manager at the same time.

The service inventory should identify the outcome, deadline, initiating event, decision owner, executing party, systems, records, counterparties and jurisdiction. It should also identify dependencies that sit outside the family's direct control. Examples include a bank's identity-verification process, a registrar's certified-document requirements, a cloud provider's recovery method, a trustee's reserved powers, a hospital's consent rules and an insurer's notification window. These dependencies shape the practical recovery path.

Service tolerances need management approval. The numbers in Table 1 are illustrations and should be replaced after legal, operational and family review. The owner should document why each tolerance is appropriate and the resources required to meet it. A family may choose a shorter tolerance for emergency liquidity and a longer one for portfolio reporting. A vulnerable beneficiary may require a dedicated care and payment route that operates independently from the main investment structure.

The inventory should distinguish an event that stops one person from acting from an event that stops the entire operating model. Travel disruption, detention, illness or communications loss can isolate a principal. A cyber incident can disable the family office and several advisers simultaneously. A geopolitical shock can affect banks, travel, data access and sanctions screening across jurisdictions. The design should therefore include person-level, institution-level and system-level alternatives.

Table 1. Illustrative critical-services register

Critical serviceIllustrative tolerancePrimary ownerContinuity dependencyMinimum evidence
personal safety and medical coordination1 hourfamily coordinatorlocal care provider and valid consent routeidentity, emergency contacts, medical summary
emergency liquidity and essential payments4 hourstreasury leadfunded account and accepted mandatesignatory proof, payment protocol, source-of-funds record
payroll and household obligations1 business dayfinance controllerpayment platform and backup approverapproved payroll file, beneficiary list, audit trail
investment risk intervention1 business dayinvestment leadcustodian and delegated limitsmandate, limits, positions and escalation record
entity filings and statutory action3 business daysgovernance leadregistered agent and board quorumregisters, resolutions, filing calendar and authority matrix
property and insurance response4 hours to 3 daysasset managerlocal manager, insurer and documented accesstitle or lease, policy, keys and incident record

Every tolerance and escalation threshold is a hypothetical management assumption and requires family-specific approval and testing.

3. Separate legal authority from institutional acceptance

Legal authority and usable authority are different operating states. A power of attorney, board resolution, trust instrument, foundation by-laws or delegation schedule may establish a right to act. A bank, registry, hospital, insurer or digital platform may still require a specific form, certification, translation, legalisation, identity check or internal review before allowing the action. Continuity planning should record both layers.

The official guidance for lasting powers of attorney in England and Wales states that an LPA must be registered before it can be used and may not work in other countries; it directs people with foreign residence or property to obtain legal advice [3, 4]. Singapore's Office of the Public Guardian describes a separate statutory LPA under which a donor appoints donees for personal welfare and property and affairs if mental capacity is lost [5, 6]. These examples show why a single global document should not be assumed to operate everywhere.

The authority register should identify the legal instrument, governing law, trigger, scope, limitations, joint or several action, substitutes, expiry or revocation conditions, location of originals and acceptance status at each relevant institution. An acceptance status should be based on documented confirmation or a completed test. A lawyer's view on validity remains important; the operating team also needs evidence that the receiving institution can locate and apply the mandate.

The family should avoid powers that are broad in text and ambiguous in execution. Payment thresholds, investment powers, gifting restrictions, conflicts, digital-asset access, health decisions and entity votes may require different authority paths. Dual control can protect against abuse while slowing urgent action. The plan should define where dual control is essential, where a bounded emergency delegate can act alone and how every emergency action is reviewed afterward.

4. Create an authority map by asset, decision and jurisdiction

A family-level authority map turns legal instruments into a decision system. Rows represent decisions; columns represent the owning entity, asset location, governing law, primary decision maker, alternate, trigger, required approvals and accepting counterparty. The map should cover formal powers and practical dependencies. It should identify who can initiate, approve, execute, observe and challenge each action.

Authority can arise from several sources. A company acts through constitutional documents, board and shareholder decisions, delegations and bank mandates. A foundation acts through its charter, by-laws, council, guardian or other officeholders under the governing regime. ADGM describes foundations as vehicles that can support wealth management, preservation, succession, asset protection and corporate structuring [7, 8]. DIFC's family-wealth materials similarly place foundations within a governance and succession ecosystem [9]. Each structure requires its own operating map.

The map should distinguish a principal's personal authority from an office held in an entity. A personal attorney may manage an individual's property without automatically becoming a company director, foundation councillor, trustee, protector or investment-committee member. An alternate director may have entity power without access to the principal's personal account or medical records. The continuity plan assigns these routes explicitly.

Jurisdictional counsel should confirm the validity, form, certification and recognition of each instrument. The HCCH 2000 Protection of Adults Convention provides rules for jurisdiction, applicable law, recognition and enforcement among Contracting Parties in international adult-protection matters [1, 2]. Its existence does not create universal recognition. The live status table and the facts of each route require review. The authority map should record the relevant legal opinion date and the countries covered.

Figure 2. Jurisdiction overlay for a cross-border decision
Figure 2. Jurisdiction overlay for a cross-border decision

The overlay shows a review sequence. It does not state that any instrument is recognised in a particular jurisdiction.

5. Design succession of authority for people and offices

Continuity requires a deliberate sequence of authority. The sequence should address temporary unavailability, prolonged incapacity, death, resignation, conflict, loss of eligibility and removal for cause. It should also address the possibility that the first alternate is unavailable in the same event. A family that travels together or relies on advisers in one location can have correlated succession risk.

Each critical role should have a primary, first alternate and second route. The second route may be another person, a committee, a professional fiduciary or a legal application. Independence matters for controls. The same person should not unilaterally declare the trigger, approve a payment, execute it and certify the review when the action is material. The plan should allocate those functions while retaining a route for urgent bounded action.

Triggers must be observable and evidenced. A scheduled absence can activate a delegation on a stated date. Communications loss may activate a temporary protocol after documented attempts through approved channels. Incapacity requires the legal and medical process applicable to the instrument. Death requires official evidence and the succession route under the relevant structure. The operating team should never improvise a legal trigger from informal messages.

Role succession also needs acceptance. A replacement foundation councillor may need registry action. A substitute director may need a board or shareholder process. A bank may need to update signatories. A digital service may prohibit credential sharing and require its own account-recovery route. The continuity calendar should include pre-registration, specimen signatures, identity packs and periodic reconfirmation where permitted.

The board should review concentration. A single adviser who holds originals, knows the passwords and interprets the structure is a critical dependency. A single family member who controls every bank mandate creates a comparable weakness. The plan should distribute knowledge and access according to need, maintain confidentiality and preserve an audit trail.

Table 2. Authority succession matrix

Role or decisionPrimary routeFirst alternateTrigger evidenceAcceptance testControl after action
personal financial affairsjurisdiction-specific authority holderreplacement authority holderregistered trigger and identity evidenceinstitution confirms usable mandateindependent transaction review
company board actiondirector and quorum under constitutionalternate or replacement processboard record and eligibility checkcompany secretary or registry confirmsminutes and conflicts review
foundation council actioncouncillors under charter and by-lawssuccessor councillor or guardian routeofficeholder and trigger recordregistrar and bank records updatedguardian or independent oversight
emergency treasury paymenttreasury approver within delegated limitbounded backup approverdeclared incident and verified requestbank workflow test completednext-day finance and family review
medical information and consentauthorised health decision routealternate named by local instrumentprovider-confirmed legal triggercare provider confirms recorddecision and disclosure log
digital-vault recoverydesignated recovery custodiansquorum-based secondary recoveryloss event and identity proofrecovery drill completedkeys rotated and event audited

The matrix is an illustrative design. Formal powers and triggers require legal confirmation in every relevant jurisdiction.

6. Convert bank mandates into tested access routes

Banking continuity depends on legal power, customer records, authentication, transaction controls and the bank's own operating resilience. A valid mandate can remain dormant if the institution has outdated identity documents, conflicting addresses, incomplete beneficial-ownership information or a separate requirement for the representative. The plan should therefore manage each bank as an access route with documented prerequisites.

The bank register should record account purpose, owner, jurisdiction, relationship team, authorised signatories, payment limits, authentication method, call-back protocol, source-of-funds file, beneficial-ownership record, tax-residence record, emergency contact and last completed test. It should avoid storing active credentials in the register. It should identify where a device, phone number, hardware token or physical document becomes a single point of failure.

A test should use a low-risk permitted action. Examples include verifying a signatory list, accessing a read-only statement, completing a small pre-approved payment or confirming the bank's documentary process for an authority trigger. The bank should approve the test design. The family office records the date, result, delay, additional requirements and named institutional owner. A failed test becomes a remediation item.

Financial institutions themselves apply operational-resilience controls. The Basel principles emphasise critical operations, dependency mapping, business continuity, incident management and resilient technology [23]. FINMA's operational-risk circular addresses critical data, cyber risks and business continuity for supervised Swiss institutions [25]. These standards do not transfer responsibility from the family. They show why the family's plan should include alternative accounts, validated contacts and realistic time allowances for a bank operating through disruption.

Account diversification should support defined needs. More accounts can create more KYC, security and reconciliation work. The architecture should give each account a purpose, funded minimum, owner and closure rule. An emergency reserve should be accessible through a route that has been tested and is not dependent on the same institution, person, device or network as the main operating account.

7. Build an emergency-liquidity ladder with funded alternatives

Liquidity continuity begins with obligations. The family should map essential payments by currency, jurisdiction, beneficiary, due date and consequence. These may include accommodation, care, insurance, education, payroll, taxes, debt service, property maintenance and urgent professional support. The map should distinguish payments that can wait from those that can cause harm, default or loss of access.

The liquidity ladder should provide progressively broader resources. Tier one covers immediate household and care needs through a locally accessible funded account or card with bounded limits. Tier two covers several weeks of family and operating obligations through independently accessible bank liquidity. Tier three provides portfolio-level liquidity through approved credit, money-market or asset-sale routes. Tier four addresses structural actions requiring governance, lender or investment approval.

Every tier requires authority and access. A reserve held in the correct currency has limited value if the only authorised person is unavailable. A credit facility has limited value if a covenant, borrowing-base certificate or draw notice cannot be produced. An investment sale may be inappropriate during market stress. The plan should specify eligible uses, decision rights, evidence, replenishment and post-event reporting.

Liquidity tests should avoid manufacturing emergencies. The family office can complete small controlled transfers, confirm draw documentation, validate settlement instructions and reconcile the event. It can also run tabletop exercises using hypothetical assumptions. The model should state exchange-rate, market-value and timing assumptions openly. It should avoid presenting a scenario result as a forecast.

Figure 3. Illustrative emergency-liquidity ladder
Figure 3. Illustrative emergency-liquidity ladder

Amounts and coverage periods are omitted because they require family-specific assumptions. The diagram presents a sequence of access routes.

8. Treat identity and authentication as continuity infrastructure

Digital access is often anchored to a person, device, email address, phone number, biometric, token or recovery secret. International movement can change phone services, device availability and identity documents. A crisis can also increase fraud attempts. The plan needs secure recovery routes that preserve the service provider's terms and avoid informal credential sharing.

NIST's current Digital Identity Guidelines address identity proofing, authentication and federation and include updated treatment of fraud, forged media, passkeys and subscriber-controlled wallets [20]. CISA recommends strong identity controls, including phishing-resistant multi-factor authentication for critical services, alongside tested offline backups [22]. A family office can use these sources to design risk-based controls for its own systems and to question providers about recovery.

The identity inventory should record the account owner, service, business purpose, administrator, authentication method, recovery method, trusted devices, registered contacts, alternate administrator, data location and last recovery test. It should not store passwords or private keys in the inventory. High-risk services should use individual named accounts, least privilege, separate administrative identities and logging.

Recovery should require more than one compromised channel. An email account that can reset the password for the vault, bank portal and phone account can become a master key. The architecture should separate recovery domains and use independent custodians or quorum controls for the most sensitive assets. Digital assets require specialist legal, technical and custody design; the plan should distinguish ownership, signing authority, key custody and recovery.

The family office should rehearse device loss, phone-number loss, principal unavailability and administrator departure. The exercise confirms who contacts the provider, what identification is required, how long recovery takes, what monitoring is triggered and how credentials are rotated afterward. Results should be documented without recording live secrets.

9. Create a controlled data vault with a clear recovery purpose

A continuity vault should contain the minimum trusted information required to restore critical decisions and services. It is a governed record system, not a miscellaneous archive. The design should define content, owner, version, sensitivity, access rule, retention, backup, recovery and deletion. Each record should have an authoritative source and review date.

The vault's core may include identity documents, family contacts, medical summaries where lawful and appropriate, authority instruments, entity records, account and custodian directories, insurance policies, property records, adviser mandates, asset maps, tax-residence records, beneficial-ownership records, recovery instructions and sealed references to credential-custody systems. It should avoid unnecessary duplication of highly sensitive data.

Cross-border access can itself be a regulated data transfer. The UAE's federal data-protection framework includes requirements for cross-border transfers and applies governance duties to personal-data processing [11]. ADGM provides specific guidance and safeguards for international transfers under its Data Protection Regulations [12, 13]. DIFC's regime uses adequacy and other safeguards for transfers out of the centre [14, 15]. The UK ICO, the European Commission and Singapore's PDPC provide their own transfer frameworks [16, 17, 18]. The vault architecture therefore needs a jurisdiction and role review.

Availability should be designed alongside confidentiality. One encrypted copy controlled by one person can fail when that person or device is unavailable. Uncontrolled replication creates privacy and cyber exposure. The paper proposes a tiered architecture: a live controlled repository, an encrypted independent backup, a sealed legal-document set and a recovery register held by authorised custodians. Each tier should have a documented purpose and test.

Figure 4. Controlled continuity-vault architecture
Figure 4. Controlled continuity-vault architecture

The architecture is conceptual. Storage, encryption, transfer and disclosure controls require technical and legal design.

10. Apply data minimisation, classification and transfer controls

The vault should classify data by harm, legal restriction and continuity value. Public entity information may have low confidentiality. Passport copies, health data, family relationships, beneficial-ownership records, account details and private keys can require strict controls. The classification should determine encryption, access, sharing, retention and recovery method.

The family office should maintain a record of processing for continuity data. It should identify the controller or responsible entity, purpose, lawful basis where applicable, data subjects, categories, recipients, locations, processors, transfers, safeguards, retention and security controls. Legal advisers should confirm the applicable regimes. The operating team can then answer who holds a record, why it is needed and how it can be disclosed during a crisis.

Remote access may count as an international transfer in some regimes. The UK ICO explains that making personal information accessible to a separate organisation outside the UK can be a restricted transfer [16]. Singapore's PDPC states that overseas transfers should meet prescribed requirements for comparable protection [17]. DIFC and ADGM provide transfer mechanisms and guidance [12, 14]. A family member's mobility can therefore change the access context even when the server does not move.

The vault should use role-based views. A medical responder may need a limited care pack. A treasury alternate may need mandates and payment protocols. A lawyer may need originals and certification records. An investment manager should not receive unrelated health or family information. Emergency access should be logged, time-bounded and reviewed.

Retention needs a controlled exit. Superseded passports, revoked powers, former advisers and closed accounts can create confusion and exposure. The system should preserve the legal record where required, mark the current instrument clearly and remove operational access when the purpose ends. A deletion and archive decision should be recorded by the data owner.

Table 3. Continuity-data classification and access matrix

Data classExamplesContinuity useNormal accessEmergency control
critical identitypassports, residence evidence, verified contact dataidentity proof and recoveryrestricted compliance teamtime-bounded release with event log
legal authoritypowers, resolutions, charters, mandatesprove decision rightsgovernance lead and counselverified copy plus acceptance checklist
financial directoryinstitution, owner, purpose, relationship contactsroute payments and instructionstreasury and designated oversightno credentials; use approved recovery channel
health and careessential medical summary, consent route, provider contactimmediate care coordinationnamed care coordinatorminimum necessary disclosure
entity and ownershipregisters, structure, beneficial ownership, filingsgovernance and KYC continuitylegal, tax and compliance rolescurrent certified evidence pack
technical recoverysystem owner, recovery custodians, backup testrestore access and datasecurity administratorsquorum release and post-event key rotation

Categories and controls require adjustment for applicable law, technology and family circumstances.

11. Align beneficial-ownership and tax-residence records

Continuity events often trigger institutional review. A new representative, changed address, successor officeholder, deceased principal or revised ownership chain can prompt KYC, tax-residence and beneficial-ownership questions. The continuity pack should contain current, consistent records that can be reproduced across banks, registries, trustees and advisers.

FATF's 2024 guidance on legal arrangements explains the importance of adequate, accurate and up-to-date beneficial-ownership information for express trusts and similar arrangements [26]. Its definitions include settlors, trustees, protectors, beneficiaries and other natural persons exercising ultimate effective control in the beneficial-owner analysis for legal arrangements [26]. The exact requirements depend on the applicable regime and entity, but the operating lesson is clear: roles and control cannot remain implicit.

The ownership file should map legal ownership, beneficial interest, control, officeholders and authorised representatives separately. It should record the evidence and review date for each. A foundation, trust, holding company and family-office company can have different reporting routes. The plan should avoid using one simplified diagram for every purpose.

Tax-residence information also needs continuity. The OECD's Common Reporting Standard and Crypto-Asset Reporting Framework create reporting and due-diligence concepts that can apply through financial institutions and relevant service providers [27, 28]. Mobility, entity changes and control changes can alter the information requested. Tax advisers should approve the residence and classification positions; the family office should maintain the supporting facts and deliver consistent updates.

An annual reconciliation should compare the vault, entity registers, bank records, tax files and adviser records. Differences should be assigned, resolved and evidenced. A crisis should activate the latest approved pack rather than a folder assembled from memory.

12. Govern communications without creating a second crisis

Communication can protect people and decisions during disruption. It can also expose sensitive information, create inconsistent instructions or enable fraud. The plan should define who can declare an incident, who communicates with family members, institutions, employees, advisers and public authorities, and which channels are approved.

The communication tree should contain verified contacts and alternates. It should separate urgent operational messages from family discussion and public statements. A concise incident notice can state the event category, immediate restrictions, decision authority, next update time and verification method. It should avoid distributing unnecessary personal or financial detail.

Fraud risk rises when counterparties expect unusual urgency. Payment instructions, account changes and credential-reset requests should use independent verification. A family member's voice, video or message should not be treated as sufficient proof for a material action. NIST's Digital Identity Guidelines include controls addressing forged media and identity-proofing risks [20]. The family office should agree a human verification protocol and test it.

The plan should include channel failure. A primary messaging platform, email domain or phone network can be unavailable or compromised. A secondary channel should be pre-agreed and protected. Contact lists should be available through a controlled offline route. The team should know how to reach local emergency, consular, legal and financial contacts without relying on one device.

Every external statement requires authority. A family office, portfolio company and personal representative may have different disclosure obligations. Counsel and communications advisers should determine the route. The incident log should preserve material messages, instructions, approvals and acknowledgements.

13. Build playbooks for severe but plausible family events

A continuity plan becomes operational through event playbooks. Each playbook should define the event, indicators, declaration authority, immediate objectives, prohibited actions, decision sequence, information required, internal and external contacts, recovery criteria and review. It should fit on a few usable pages with links to controlled evidence.

The event library should reflect the family's geography and assets. It may include principal incapacity, death, travel detention, communications loss, cyber compromise, bank outage, fraud attempt, sanctions or KYC escalation, political disruption, natural disaster, property loss, adviser failure and a critical employee departure. The family should select events based on exposure rather than novelty.

Playbooks should address combined events. A principal can become unavailable during a cyber incident. A geopolitical event can affect travel, a bank and a data centre simultaneously. A death can coincide with market volatility and family conflict. The plan should identify common dependencies and prevent one event owner from assuming another system remains available.

The response sequence should begin with safety and containment. The team verifies the event, protects people and assets, freezes compromised routes, confirms authority and establishes communications. It then restores critical services in the approved order. Recovery ends when services are stable, temporary powers are withdrawn or regularised, data is reconciled and open risks are assigned.

The FSB's cyber incident toolkit organises practices across governance, preparation, analysis, mitigation, recovery, communication and improvement [24]. NIST and CISA similarly emphasise governance, response, recovery, tested backups and role clarity [19, 22]. These principles support a disciplined family playbook.

Figure 5. Illustrative crisis scenario priority map
Figure 5. Illustrative crisis scenario priority map

Scores are hypothetical management assumptions on a five-point scale. The family should replace them through a documented risk workshop.

14. Test incapacity and death as distinct operating events

Incapacity and death activate different legal, personal and institutional processes. The plan should maintain separate playbooks even when some contacts and records overlap. Incapacity focuses on the trigger, valid decision authority, ongoing care, privacy and temporary or continuing financial management. Death focuses on official evidence, executors or administrators, entity succession, immediate family support, asset preservation and the transition to estate processes.

The incapacity playbook should identify who can assess or certify the relevant condition, who receives that information, how privacy is protected and which authority instruments become usable. It should distinguish health and welfare decisions from property and financial affairs. The England and Wales LPA framework and Singapore's LPA framework illustrate that statutory forms, scope and registration rules differ [3, 5]. Local counsel should define the applicable route in every important jurisdiction.

The death playbook should begin with people and essential obligations. It should set out the route for medical, registration, consular, funeral and family support decisions where relevant. It should then secure accounts and data, notify authorised advisers and institutions, preserve time-sensitive rights and activate entity succession. It should avoid broad notifications before counsel and the appointed personal representatives confirm the sequence.

Joint family travel creates concentration. The plan should consider an event affecting several officeholders or heirs. Entity constitutions, foundation rules, trusts, shareholder arrangements and insurance nominations should be reviewed for that possibility. The continuity architecture should preserve a functioning decision body and access to essential funds.

Exercises should use hypothetical records and avoid simulating a legal declaration. The team can test document retrieval, contact accuracy, task ownership and time to assemble a complete evidence pack. Legal and medical professionals should design any test that approaches real trigger processes.

Table 4. Incapacity and death continuity checklist

WorkstreamIncapacity questionsDeath questionsEvidence ownerExercise output
personal authoritywhich instrument, trigger and scope applywho is personal representative and when can they actprivate-client counselverified authority route
care and dependantswho can consent, coordinate and fund carewho provides immediate family and dependant supportfamily coordinatorcurrent care and contact pack
bank and paymentswhich attorney or delegate is acceptedwhat restrictions and estate process applytreasury leadinstitution-by-institution checklist
entitiesdo offices continue and who acts temporarilywhich succession provisions activategovernance leadquorum and replacement map
datawho can access the minimum necessary recordswho preserves, releases and archives recordsdata owneraccess and disclosure log design
communicationwho receives limited factual noticewho approves family, employee and external messagesincident lead and counselapproved message tree

The checklist identifies operating questions. Legal, medical, succession and disclosure requirements require professional advice.

15. Prepare for geopolitical, sanctions and mobility disruption

Geopolitical events can alter travel, communications, banking, logistics, sanctions screening and institutional risk appetite with little notice. The continuity plan should focus on lawful, documented operations and rapid fact validation. It should avoid assumptions that a payment, person or entity is restricted without a competent review.

The family office should maintain a jurisdiction exposure map covering people, residence and citizenship, entities, banks, custodians, assets, counterparties, data locations and critical providers. The map should show dependencies and alternates. It should also identify where two apparent alternatives rely on the same clearing bank, cloud provider, adviser network or telecommunications route.

An event protocol should require sanctions and legal review before moving assets, changing counterparties or sharing sensitive information. It should preserve source-of-funds, beneficial-ownership and transaction-purpose evidence. FATF's guidance emphasises accurate and current ownership information and international cooperation for legal arrangements [26]. Strong records can support lawful institutional review.

Mobility continuity includes passports, visas, residence evidence, local contacts, accommodation, care and communications. A family should maintain current copies and secure originals according to law and practical need. It should identify consular and local professional contacts from official sources. The plan should avoid presenting a private operating procedure as a substitute for public-authority guidance.

The exercise should test decisions under uncertainty. The team receives a hypothetical notice that travel is interrupted and a bank requests additional review. It must identify verified facts, pause unsupported action, protect immediate liquidity, locate required records and escalate to advisers. The board reviews whether the response protected people, complied with controls and avoided inconsistent messages.

16. Integrate the family office, trustees, councils and advisers

Continuity is distributed across the family, family office, trustees, foundation councils, directors, banks, custodians, lawyers, tax advisers, administrators, security providers and care coordinators. The operating model should give each party a defined role and information boundary. A large contact list without decision rights creates coordination risk.

The family should appoint a continuity owner with authority to maintain the programme and convene exercises. That owner does not replace legal officeholders. The role coordinates the service register, authority map, data vault, issue log, tests and board reporting. Each legal entity retains its own decisions and records.

Adviser mandates should address continuity. The family office should know who can act when the relationship partner is unavailable, where records are held, how instructions are authenticated, what conflicts apply, how work transfers on termination and which services depend on subcontractors. A professional provider's business-continuity plan should be reviewed at a proportionate level.

Foundation and trust governance should preserve the distinction between administration, fiduciary judgment and family preference. The council or trustee should receive the information needed for its duties and maintain its own records. A family council may express priorities without displacing formal authority. The continuity plan should state these boundaries.

The RACI model can clarify execution: responsible, accountable, consulted and informed. Critical actions also need an independent challenge or review role. The plan should identify the person who can stop an unsafe instruction, the person who resolves conflicts and the route for reporting suspected abuse.

17. Measure continuity through exercises and evidence

A plan that has not been tested remains a design hypothesis. Exercises should show whether people can retrieve records, validate authority, contact institutions and complete decisions within the approved tolerance. The programme should combine document reviews, access tests, tabletop scenarios and selected live exercises.

Document reviews confirm validity, versions, certifications, translations, expiry and storage. Access tests confirm that authorised people can reach systems and institutional contacts without sharing credentials. Tabletop exercises rehearse combined events and decisions. Live exercises use low-risk permitted actions, such as a controlled backup restoration or a small pre-approved payment.

The exercise record should capture objective, scope, scenario assumptions, participants, evidence used, elapsed times, decisions, failures, workarounds and actions. A pass requires more than completing the action. The action should follow the approved authority, security, privacy and audit controls. An unauthorised shortcut is a failed test even when it is fast.

NIST's contingency-planning guidance links recovery requirements to system impact and calls for plans, procedures and technical measures that support recovery [21]. The Basel principles call for severe but plausible scenarios, mapping and learning [23]. The family programme can adapt those disciplines to its critical services.

Testing frequency should reflect change and impact. A high-impact bank route or data recovery process may need more frequent testing than a stable archival process. A move, new entity, changed adviser, new device, altered power or major asset acquisition should trigger a targeted retest. The calendar should record evidence and next due date.

Figure 6. Continuity control cycle and board evidence
Figure 6. Continuity control cycle and board evidence

The cycle is a proposed governance process. Review frequency should reflect the family's risk, change and legal requirements.

18. Use a board dashboard that records decisions and exceptions

The board dashboard should show service readiness, authority coverage, access tests, data recovery, scenario exercises, unresolved exceptions and change events. It should support decisions rather than create a false aggregate score. A single green percentage can hide a critical failure in medical authority or emergency liquidity.

Each critical service should report its tolerance, current owner, alternate coverage, last test, actual test time, open exceptions and next action. The board should see evidence quality: documented legal opinion, institution confirmation, completed exercise or self-assessment. Evidence dates matter because mobility, personnel and provider processes change.

Exceptions should be ranked by consequence and time. A missing secondary contact may be low impact. An expired identity document on the only usable bank route can be urgent. Each exception needs an owner, remediation, due date, interim control and approval if risk is accepted. Closed items should retain the evidence of closure.

The dashboard should also track change. New residences, citizenships, marriages, births, deaths, health conditions, officeholders, entities, banks, advisers, material assets, facilities and data systems can affect the plan. A change register routes the event to legal, tax, governance, data and operating owners. The board receives material implications and required decisions.

The dashboard's value depends on challenge. The board should ask which critical service would fail if one person, bank, device or adviser became unavailable today. It should ask whether alternates were tested, which conclusions rely on outdated evidence and whether the family understands the response. The answers drive the next exercise and investment.

Table 5. Board continuity dashboard

Dashboard lineEvidence measureDecision signalBoard questionRequired action
authority coveragecritical decisions with valid primary and alternate routesred if a critical route lacks a confirmed alternatecan an authorised person act in each relevant placecommission instrument or acceptance review
institutional accesstests completed within approved toleranceamber for stale or partial testdid the institution accept the named person and evidenceretest and close requirements
emergency liquidityobligations covered by independently accessible routesred for correlated access dependencycan essential payments continue through a combined disruptionfund, diversify or redesign route
data recoverysuccessful restore and minimum-data retrievalred for untested or single-custodian recoverycan current records be recovered securelycomplete restore drill and access review
scenario readinesssevere scenarios exercised and actions closedamber for overdue high-impact scenariodid the team follow authority, privacy and security controlsrun exercise and assign remediation
change controlmaterial events assessed across workstreamsred for an unassessed legal or identity changehas the plan followed the family's current factsconvene cross-functional review

Status labels and tolerances are illustrative. Each item requires evidence and a named owner.

19. Implement through a 100-day controlled programme

Implementation should protect current operations while correcting the highest continuity risks. The paper proposes four workstreams over one hundred days: establish the perimeter, validate authority, build access and data controls, then test and govern. The schedule is an illustrative management sequence and should change where legal or safety priorities require faster action.

Days 1 to 20 establish sponsorship, confidentiality, critical services, tolerances and the issue register. The team identifies jurisdictions, entities, institutions, advisers, systems and vulnerable dependencies. It names owners and immediately protects any evident single point of failure. The team avoids moving data or changing authority before the legal and security design is approved.

Days 21 to 50 build the authority map. Counsel reviews personal instruments, entity succession, foundation or trust roles and recognition questions. The family office confirms institution requirements and acceptance status. Treasury maps obligations and designs the liquidity ladder. The data owner classifies records and documents transfer constraints.

Days 51 to 80 implement controlled access. Institutions receive approved updates. The vault is organised, backed up and assigned to custodians. Authentication and recovery routes are tested. Playbooks are drafted for selected high-impact events. Advisers confirm their roles and alternates.

Days 81 to 100 run exercises. The team tests document retrieval, bank access, data recovery and one combined scenario. It records failures, closes urgent gaps and submits the dashboard for board approval. The board approves tolerances, residual exceptions, the annual calendar and the change-control triggers.

The programme should produce evidence, not volume. A concise verified authority register has more value than hundreds of unclassified documents. A tested payment route has more value than an unfunded account. Every deliverable should name the decision it supports and the person responsible for keeping it current.

20. Define the annual governance and assurance cycle

Continuity requires renewal. The annual cycle should combine quarterly operating checks, event-driven reviews and a formal board assessment. It should align with entity filings, insurance renewals, tax reviews, bank KYC, adviser due diligence and cybersecurity exercises where practical.

Quarterly checks can confirm people, contacts, identity documents, signatories, critical balances, data backups and outstanding exceptions. A semi-annual exercise can test a high-impact route. The annual review should reconcile every critical service, authority instrument, jurisdiction, institution, data repository and provider against current facts.

Assurance should be proportionate and independent. Legal counsel confirms instruments and jurisdictional conclusions. Cybersecurity specialists test recovery and access controls. Tax advisers confirm residence and reporting positions. Internal or external reviewers can sample evidence and action closure. The continuity owner integrates these views without presenting one adviser as responsible for every domain.

The annual board decision should approve the critical-service perimeter, tolerances, authority and access exceptions, liquidity architecture, vault controls, exercise plan and budget. It should record any accepted risk and the reason. The decision should also confirm the incident-declaration and escalation roles.

Changes during the year should enter a single controlled workflow. A new country, bank, entity, property, investment vehicle, adviser, family member or technology platform can trigger several reviews. The workflow assigns legal, tax, data, governance, treasury and security tasks and closes only when evidence is updated.

21. Govern continuity through a board-ready decision file

The final decision file should enable a new authorised person to understand the continuity system without relying on private memory. It should include the service register, authority map, institution acceptance register, liquidity ladder, data architecture, processing and transfer record, playbooks, exercise evidence, exception log, adviser matrix and board decisions. Sensitive credentials and private keys should remain in the separate approved custody system.

The board should approve the design when five conditions are met. First, critical services and tolerances reflect the family's real obligations. Second, authority routes are supported by current legal evidence. Third, institutions and systems have accepted or tested the relevant access. Fourth, minimum trusted data can be recovered securely. Fifth, severe but plausible scenarios have been exercised and failures have owners.

The decision file should state its limits. Cross-border recognition, medical authority, succession, sanctions, data transfer and tax reporting can change with jurisdiction and facts. The file records professional advice and operating evidence available at the review date. It does not convert uncertainty into a universal conclusion.

The board should also assess usability. The plan should work during stress, outside normal hours and without one central person. Clear routes, bounded authority, verified contacts and disciplined records support that objective. The strongest design preserves both action and restraint: authorised people can act when necessary, and controls stop unsupported action.

Table 6. Board approval and annual assurance file

Approval itemEvidence requiredAccountable ownerAnnual assuranceEscalation trigger
critical-service perimeterservice register, consequences and approved tolerancesboard sponsorservice owner attestation and exercise resultsnew dependant, obligation or material asset
authority architectureinstruments, legal views, succession and acceptance registergovernance leadcounsel review and officeholder reconciliationincapacity concern, role or jurisdiction change
access and liquidityinstitution tests, funded routes, limits and reconciliationtreasury leadcontrolled transaction and contact verificationbank, device, signatory or funding change
data and identityclassification, processing record, backups and recovery evidencedata ownerrestore test and privileged-access reviewprovider, location, breach or identity change
incident playbooksscenarios, roles, communication trees and exercise recordscontinuity ownertabletop and selected live exercisematerial incident or control failure
exceptions and changeissue register, interim controls and board risk acceptanceprogramme officeclosure sampling and overdue-item reviewmissed deadline or repeated failed test

The file records governance decisions and supporting evidence. It does not replace jurisdiction-specific professional advice.

Sources and further reading

  1. Hague Conference on Private International Law, Protection of Adults Section Official source
  2. Hague Conference on Private International Law, 2000 Protection of Adults Convention Outline Official source
  3. UK Office of the Public Guardian, Make and Register Your Lasting Power of Attorney Official source
  4. UK Government, Make, Register or End a Lasting Power of Attorney Official source
  5. Singapore Ministry of Social and Family Development, What Is a Lasting Power of Attorney Official source
  6. Singapore Ministry of Social and Family Development, Office of the Public Guardian Official source
  7. Abu Dhabi Global Market, Registration and Incorporation Official source
  8. Abu Dhabi Global Market, Setting Up Frequently Asked Questions Official source
  9. Dubai International Financial Centre, Family Wealth Centre Foundations Guide Official source
  10. Dubai International Financial Centre, Family Wealth Centre Programmes and Partnerships Official source
  11. UAE Government, Data Protection Laws Official source
  12. Abu Dhabi Global Market, Office of Data Protection Guidance Official source
  13. Abu Dhabi Global Market, Operating Frequently Asked Questions Official source
  14. Dubai International Financial Centre, Data Export and Sharing Official source
  15. Dubai International Financial Centre, Data Protection Law No. 5 of 2020 Official source
  16. UK Information Commissioner's Office, Guide to International Transfers Official source
  17. Singapore Personal Data Protection Commission, Data Protection Obligations Official source
  18. European Commission, Rules on International Data Transfers Official source
  19. National Institute of Standards and Technology, Cybersecurity Framework 2.0 Official source
  20. National Institute of Standards and Technology, Digital Identity Guidelines Revision 4 Official source
  21. National Institute of Standards and Technology, Contingency Planning Guide for Federal Information Systems Official source
  22. Cybersecurity and Infrastructure Security Agency, StopRansomware Guide Official source
  23. Basel Committee on Banking Supervision, Principles for Operational Resilience Official source
  24. Financial Stability Board, Effective Practices for Cyber Incident Response and Recovery Official source
  25. Swiss Financial Market Supervisory Authority, Operational Risks and Resilience for Banks Official source
  26. Financial Action Task Force, Beneficial Ownership and Transparency of Legal Arrangements Official source
  27. Organisation for Economic Co-operation and Development, Consolidated Text of the Common Reporting Standard 2025 Official source
  28. Organisation for Economic Co-operation and Development, Crypto-Asset Reporting Framework Introduction Official source
  29. UAE Government, Cyber Laws Official source
  30. Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals Official source
Questions, answered

The Crisis-Continuity Plan for Mobile Families: frequently asked questions

The framework does not assume universal coverage. Official guidance in England and Wales states that an LPA may not work in other countries, and international recognition depends on the jurisdictions, instrument and facts. The family should obtain legal advice and maintain an authority and acceptance map for each material decision route.

An institution may require registration, certification, translation, identity proof, an updated mandate or its own review before permitting action. The continuity plan tests legal authority, institutional access and supporting data as separate conditions.

The vault should contain the minimum current records needed to restore critical decisions and services, with owners, classifications, versions and recovery controls. Live passwords, private keys and unrestricted copies of sensitive data should remain within separately approved custody and security systems.

The framework does not prescribe an amount. The family should model essential obligations, currencies, jurisdictions, access dependencies and stress periods, then approve funded tiers and test the routes. Every amount and coverage period is a family-specific management assumption.

Credential sharing can violate provider terms and weaken security and accountability. The plan should use named accounts, approved delegations, recovery methods, alternate administrators and controlled custody designed with the relevant institutions and cybersecurity advisers.

Frequency should reflect impact, change and evidence age. High-impact access and recovery routes may need quarterly or semi-annual checks, while the full framework should receive an annual board review. A material change should trigger a targeted review and retest.

A named continuity owner should coordinate the service register, authority map, vault, exercises and reporting. Legal officeholders and advisers retain their own responsibilities. The board should approve the perimeter, tolerances, exceptions and assurance cycle.

This publication is general information for professional audiences. It is not investment, legal or tax advice, and it is not an offer or solicitation. Readers should verify current legal, regulatory and tax requirements with qualified advisers.

Apply this insight to a live decision

Discuss the financing, capital allocation or transaction implications with a Matchpoint partner.

WhatsApp