Business continuity in outsourcing: how to keep mail operations running during disruption
An SLA does not help when systems fail, a site is inaccessible or a carrier stops collection. Build a continuity plan that can actually be used.

Mail operations can stop because of a system failure, power outage, inaccessible premises, staff absence, transport disruption, cyber incident or an unexpected volume peak. Outsourcing transfers part of the operational responsibility to a supplier, but the business risk remains with the organisation.
A business continuity plan is not a general statement that a supplier has procedures. It must identify which activities must continue, how quickly, with which resources and who decides to switch to fallback mode. This applies to daily business mail, printing, inserting, bulk mailing, scanning and document workflows.
Why an SLA alone does not provide continuity
An SLA measures an agreed service level under normal conditions. Continuity planning answers a different question: what happens when the normal delivery model stops working? A 24-hour turnaround target is of little value if the contract does not define an alternative worksite, data access, replacement transport and the priority order for critical items.
NIS2 lists business continuity, backup management, disaster recovery and crisis management among cybersecurity risk-management measures. Not every organisation is directly in scope, but the principle is widely useful: resilience must be designed before an incident, not during one.
Start with a business impact analysis
Not every element needs to recover at the same time. Identify which interruption causes the greatest harm. For every mail category ask:
- Which legal, contractual or business obligation could be breached?
- How long can the activity be delayed before the impact becomes unacceptable?
- Can the item wait, or does it require action on the same day?
- Is the original required, or is a secure scan sufficient?
- Who may approve a deviation from the standard process?
- What minimum number of people, devices and channels is required?
Do not put everything into one critical category. Use at least three priorities, such as regulatory and deadline-driven items, normal operational correspondence and material that can wait. Limited fallback resources can then focus on actual business impact.
Define RTO, RPO and minimum service
RTO is the maximum time allowed to restore a process. RPO is the maximum amount of data that may be lost since the last safe recovery point. In a document process, RPO may cover the received-mail register, scans, dispatch statuses and proof of posting.
Also define a minimum operating level. For example, priority registration resumes within four hours, secure scans become available within eight hours and standard mail is processed after full capacity returns. This is more useful than a promise to recover quickly.
Eight elements of a workable fallback plan
1. Activation criteria
List the events and thresholds that trigger fallback mode. Examples include a site being inaccessible for two hours, an outage exceeding a time limit, absence above a defined staffing threshold or volume above capacity.
2. Roles and contact details
Identify the client's decision owner, the supplier coordinator, deputies and an up-to-date contact list. Decide who declares the incident, approves a workaround and communicates with staff, carriers and recipients.
3. Alternative site and equipment
Check whether work can move to another zone, facility or replacement device. A second address is not enough. It needs the required capacity, secure access, current configuration, materials and trained people.
4. Data access and backups
Backups should cover files, work queues, routing rules, templates, access rights, registers and evidence. Define frequency, location, encryption, ownership and restoration time. A backup that has never been restored in a test remains an assumption.
5. Manual procedures
When systems are unavailable, limited service may use a controlled emergency register. The procedure should cover numbering, timestamps, secure storage, later reconciliation and duplicate checks. A secure workflow must not be replaced with uncontrolled sharing through private channels.
6. Alternative transport and carrier
Cover missed collection, a closed posting point, courier failure and route disruption. Define an alternative point, cut-off times, transfer of responsibility and proof of receipt. Prepare replacement labels or files in advance if another carrier requires them.
7. Materials and surge capacity
Paper, envelopes, toner, containers and consumables can stop the process just as effectively as a system failure. Define minimum stock, replenishment time and an alternative source. For bulk jobs, know how quickly the supplier can add shifts, devices or people.
8. Communication and decision records
An incident update should state the impact, action taken, next update time and decisions required from the client. The incident log should preserve chronology, decision owners, deviations and the point of return to standard operations.
Five scenarios worth exercising
- System outage. Registration, scanning and reporting continue in a limited mode without losing the audit trail.
- Inaccessible site. Mail is redirected to a fallback location or stored securely until access returns.
- Unexpected volume peak. Jobs are prioritised and additional shifts and capacity communication are activated.
- Security incident. The affected process is isolated, access is restricted and recovery considers data integrity.
- Carrier or transport outage. An alternative point, carrier or later dispatch is used with complete evidence.
An exercise should do more than discuss a document. Restore a register, call the duty contacts, prepare a sample batch at the fallback site and reconcile manually recorded items.
How to assess a supplier's plan before signing
Ask for a solution that addresses the specific service, not only a generic certificate. Review locations and dependencies on subcontractors, systems, carriers, energy and transport. NCSC guidance recommends maintaining control and oversight across the supply chain because vulnerabilities can arise at any point.
Include the following in the contract or operational schedule:
- critical processes and priorities;
- RTO, RPO and minimum throughput;
- notification channels and update frequency;
- fallback location arrangements;
- backup, data and access requirements;
- subcontractor obligations;
- test frequency and results reporting;
- corrective actions after a test or incident;
- controlled return to normal service.
Continuity planning complements supplier due diligence, SLA and exit arrangements. Use our detailed guide on how to choose an outsourcing provider.
Test the plan before it is needed
ENISA connects impact analysis, continuity planning, periodic testing, alternative means and backup management. Every exercise needs an owner, scope, pass criteria and corrective-action report.
A full annual test is a reasonable baseline, with shorter tests after important changes to systems, sites, carriers or scope. Measure actual activation time, data completeness, error count, achieved throughput and communication quality. Each failure should produce an assigned action and deadline.
Common mistakes
- The plan is only a statement in a proposal. It contains no process-specific resources or actions.
- One RTO for all mail. Urgent items compete with work that can wait.
- No restoration test. Backups exist, but nobody knows whether they can restart the process.
- Dependency on one person. Only one employee knows credentials, procedures or contacts.
- Subcontractors are excluded. Carrier, transport and external system dependencies are missing.
- No controlled return. Recovery creates duplicates, gaps and inconsistent statuses.
Move from paper resilience to operational resilience
A good plan does not promise that incidents will never occur. It limits impact, accelerates decisions and keeps the most important activities under control. The quick instructions can be short because resources, roles and tests have already been prepared.
When preparing to outsource mail, printing, inserting or document workflows, begin with the process map and priorities. Our 30-day transition plan provides the implementation framework. To discuss scope, continuity requirements and a secure delivery model, contact BackOffice Outsourcing.
Sources
- Directive (EU) 2022/2555, NIS2, Article 21
- ENISA, NIS2 Technical Implementation Guidance, 26 June 2025
- UK National Cyber Security Centre, Supply chain security guidance
- UK Government, Business Continuity Management Toolkit
Frequently asked questions
Does a supplier's continuity plan remove the client's responsibility?
No. The supplier is responsible for agreed operational actions, while the client still owns business risk, priorities, decisions and process requirements.
What is the difference between RTO and RPO?
RTO is the maximum process restoration time. RPO is the acceptable data loss since the last safe recovery point, such as a mail register or dispatch status.
How often should a continuity plan be tested?
At least annually and after a significant change to systems, sites, carriers, subcontractors or service scope. Individual components should be tested more often where appropriate.
Does a second site automatically provide continuity?
No. It needs adequate capacity, equipment, current data, materials, secure access and trained people. Its practical operation must be tested.