Business Continuity Emerging Managers Operational Due Diligence Fund Governance Fund Operations

The Hedge Fund Business Continuity Plan: What Allocators Test at Sub-US$100m

A hedge fund business continuity plan for a two-to-five person manager is a short, tested document, not a binder. When the SEC adopted its compliance programme rule in December 2003, it listed business continuity plans among the matters an adviser's policies should address. A decade later its examiners reported that the plans which coped worst had not anticipated key personnel being unable to work. An allocator testing a manager below US$100m is not looking for enterprise resilience. It wants to know who can trade and move cash if the principal cannot, whether systems can be recovered from a second location, whether the fund's providers have plans of their own, and whether any of it has been tested. This article sets out a proportionate plan around those questions, the fund board's part in it, and the evidence an ODD team expects.

"We read a great many continuity plans and most of the long ones are the weakest. A small manager does not need forty pages. It needs a named second person who can trade and release cash under documented limits. It needs a recovery objective it has actually met in a test, and a clear view of how its administrator and prime broker would behave in the same event. When we see those three things minuted at the fund board with a test date attached, the plan is real. When we see a template with the firm's name inserted, it is not, and an experienced allocator will know within ten minutes." David Lloyd, Chief Executive Officer at CV5 Capital

Executive Summary

Business continuity for an emerging manager is a governance and evidence question before it is a technology question. The plan should be proportionate, specific about people and authorities, and demonstrably tested.

  • The most common failure in a small manager's plan is the absence of a second person with documented trading and cash authority, not a missing backup server.
  • Recovery time and recovery point objectives should be set per function by the fund's dealing cycle and proven in a test rather than asserted.
  • The administrator, custodian and prime broker have plans of their own; the manager should have read them and the board should have asked.
  • The CIMA corporate governance rule places succession, risk oversight and outsourcing with the governing body, although it does not use the phrase business continuity.
  • US and UK expectations come mostly from guidance and examination findings; the one dedicated SEC continuity rule for advisers was proposed in 2016 and never adopted.
  • ODD teams ask for the last test date, what failed and what changed; a plan with no test log is treated as untested.

What a Proportionate Plan Covers, and What It Does Not Need

The mistake most small managers make is to start from a large firm's template. Enterprise frameworks assume multiple offices, a technology function and staff who can be rotated between sites. A three-person manager with a cloud-hosted stack has none of those things, and a plan that pretends otherwise is a red flag in diligence. The right starting point is a business impact analysis that is honest about scale: which functions must continue, which can wait, and for how long.

For a sub-US$100m manager the critical functions are few. They are managing existing positions, meeting margin and settling trades; reconciling with the prime broker and administrator so the next NAV can be struck; communicating with investors, the board and providers; and instructing cash under the fund's existing controls. The table below sets out the contents of a proportionate plan and the depth appropriate to a small team.

SectionWhat it should containDepth for a two-to-five person manager
Business impact analysisCritical functions, the maximum tolerable outage for each, and the systems, people and providers each depends onOne page. Position management, margin and settlement, reconciliation and NAV support, cash instruction, communications
Scenarios and invocationLoss of office, loss of a key person, loss of a system or cloud provider, loss of a counterparty or provider, cyber incident; who decides to invoke and howFive named scenarios with a trigger and a named decision-maker for each
Key person cover and authoritiesNamed alternates for trading, cash release, provider instruction and board reporting, with documented limits and the mandates lodged with each providerA single authority matrix cross-referenced to the prime broker and administrator mandates
Systems and dataRecovery time and recovery point objectives per system, backup method and location, second-location access to the order management system and provider portalsA table of no more than ten systems with objectives, last test date and result
Providers and counterpartiesEach material provider, its continuity arrangements as disclosed, the contractual right to information, contacts and the substitute if it failsAdministrator, custodian, prime broker, cloud and email provider, order management vendor
Communications treeWho contacts whom, in what order, by which channel, with an alternate channel if the primary failsStaff, board, administrator, prime broker, custodian, auditor, investors, regulators where applicable
Governance and testingBoard approval, review cycle, test calendar, test log and remediation recordAnnual board review minuted; test log maintained continuously

Two things are absent from that table by design. There is no physical alternate office; for a small manager, working from home with tested remote access to a cloud-hosted stack is the alternate site, and diligence teams accept that once proven. And there is no separate disaster recovery document; disaster recovery is the systems and data section of the continuity plan.

Key Person Cover and Trading Authority Succession

When the SEC's examination staff reviewed the continuity plans of approximately 40 advisers after Hurricane Sandy in 2012, the weakness they singled out was plans that did not address a portfolio manager being unable to work remotely. That finding, published in a risk alert dated 27 August 2013, remains the most relevant observation for a small manager. The scenario that breaks a three-person firm is the principal being unreachable for a fortnight during a margin call, with nobody else authorised to act.

Continuity for people therefore reduces to an authority matrix: a named primary and a named alternate for each critical function, with the alternate's authority documented in the fund's own controls rather than only in the manager's plan. The prime broker mandate should list the alternate as an authorised trader. The administrator's cash procedure should recognise the alternate as a signatory, subject to the same dual-authorisation and callback controls as the principal. Where the manager has only one investment professional, the alternate's authority may sensibly be limited to risk reduction: closing or hedging positions, meeting margin and preserving cash.

The wider question of dependence on one individual is addressed in CV5's analysis of key person risk facing emerging managers. The plan should match the key person provisions in the offering document. If investors have a redemption right on a key person event, it should say who notifies the board and administrator, within what period, and who manages the book in the interim.

Designing the Authorities Before the Plan?

The authority matrix in a continuity plan only works if it matches the mandates lodged with the fund's prime broker and administrator. Those mandates are set at structuring, which is where the second signatory, the alternate trader and the cash controls should be defined.

The CV5 Fund Terms Questionnaire is the first structuring step. It captures the proposed strategy, the investment manager and its team, launch AUM, target investors, dealing and liquidity terms, fees, custody and banking arrangements, and the operational requirements from which the fund's authority controls are built.

Start the Hedge Fund Questionnaire

Systems and Data: Recovery Objectives, Backups and the Second Location

A recovery time objective is the maximum period a function may be unavailable before the impact becomes unacceptable. A recovery point objective is the maximum period of data that may be lost, measured backwards from the disruption. Both should be set per function from the fund's own cycle, not copied from a vendor's service description. A daily-dealing fund with intraday margin exposure has a shorter tolerance for losing access to positions than a monthly-dealing fund holding unlevered longs.

For most small managers the stack is already cloud-hosted: email and documents, the order and portfolio management system, the risk tool, and the provider portals. That is a continuity advantage only if two conditions hold. The manager must be able to reach each system from a second location on a second device, with multi-factor authentication that does not depend on a single phone. And the manager must know where its data lives and how it would be recovered if the vendor, rather than the office, were the point of failure. CV5's guide to the hedge fund technology stack at launch sets out the layers; the plan should map each to an objective, a backup and a test.

Backups deserve a plain statement: what is backed up, how often, to where, who can restore it and when restoration was last tried. A backup that has never been restored is an assumption. The plan should also record the fallback if the order management system were unavailable for a day; direct execution channels and a standard position file usually exist, but only work if arranged in advance. CIMA's guidance on internal controls makes the same point: information systems should be supported by adequate contingency arrangements, and business resumption plans should be periodically tested.

Counterparties and Outsourced Providers: Their Plans, and the Right to See Them

A small manager outsources most of its operations, so most of its continuity risk sits with other firms. The administrator's NAV, the custodian's settlement and the prime broker's financing depend on plans the manager did not write. Outsourcing a function does not outsource responsibility for its continuity. CIMA's statement of guidance on business continuity management, issued to licensees in March 2007, states that principle directly, and the SEC staff's 2013 alert recorded advisers that had not evaluated their providers' plans at all.

The practical discipline has three parts. The manager should obtain and read each material provider's continuity summary and, where available, its SOC 1 or ISAE 3402 controls report, noting the recovery controls tested. The engagement terms should give the fund a right to information about continuity arrangements and to incident notification, a standard term to request at appointment. And the plan should name a workaround for each provider. How would positions be valued if the administrator were unavailable at a dealing date, how would cash move if the bank relationship were interrupted, and how would execution continue if the prime broker's portal were down?

CIMA's statement of guidance on outsourcing, revised in April 2023, lists a provider's business continuity arrangements and contingency plans among the matters due diligence should assess and among the terms an outsourcing agreement should contain. Regulated mutual funds and private funds are expressly excepted from that guidance, so for the fund it is a reference point rather than a binding instrument. The corresponding expectation for funds sits in the statement of guidance on corporate governance for mutual funds and private funds, which asks operators to assess the suitability and capability of service providers on a continuing basis. The pre-appointment questions are set out in CV5's guide to administrator due diligence before launch, and the allocation of functions in what to outsource and what to own in the middle office.

The Communications Tree and the Decision to Invoke

Plans fail in the first hour more often than in the first week, usually because nobody is sure whether the plan has been invoked or who should call whom. The plan should name a decision-maker for invocation and an alternate, and state the trigger for each scenario plainly. The calling tree should run in a fixed order: staff, board, administrator, prime broker and custodian, auditor, investors where dealing or reporting is affected, and any regulator to which the manager or the fund owes a notification.

Contact details are the part of the plan most likely to be stale. The SEC staff's November 2020 review of adviser compliance programmes recorded deficiencies where plans had not been tested, lacked contact information, or did not designate responsibility for continuity actions. CIMA's business continuity guidance recommends that calling trees be updated regularly and tested periodically, with an alternate channel where the primary system has failed. A quarterly check of the tree and a stated fallback from email to a messaging channel and mobile telephone meet both points.

Investor communications need particular care. The plan should distinguish disruptions internal to the manager from those that affect the fund: a missed dealing date, a delayed NAV, a suspension or a key person event. For the second category the board, not the manager alone, decides what is said and when, and the administrator issues it.

Guidance is not requirement. Much of what is written about continuity planning describes what regulators expect or what allocators test, and both are often conflated with what a rule says. In the material referenced here, the binding rules are narrow and concern governance and internal control generally; the detailed content of a plan comes from guidance, examination findings and market practice. Overstating the regulatory basis to an allocator is itself a diligence finding.

The Fund Board's Role and What It Should Minute

The fund is a Cayman regulated entity and its board is the governing body to which CIMA's Rule on Corporate Governance for Regulated Entities applies, proportionately. The rule, gazetted in April 2023 and effective from October 2023, does not use the phrase business continuity. What it does require of a governing body is directly relevant. It must have an appropriate succession plan for directors and senior management, and oversee sound risk management and internal control systems, reviewed annually. It must manage any outsourced operations effectively at all times, and keep detailed minutes recording the substance of matters considered. The rule is sometimes described as requiring boards to consider business continuity; the accurate statement is that it requires boards to oversee succession, risk and outsourcing, of which continuity is a component in practice.

That framing tells the board what to minute. At least annually the board should record that it has received the manager's plan and noted the last test date and result. It should record that it has considered the authority matrix, confirmed that the provider mandates match it, and reviewed the continuity arrangements of the fund's own providers. Where a test failed, the minute should record the remediation and its due date. Where the fund has a key person provision, it should record who would act in the interim and how investors would be informed. The statement of guidance on corporate governance for mutual funds and private funds adds that material risks should be discussed at board meetings.

The board's place in the wider risk framework is set out in CV5's guide to the fund board's role in hedge fund risk oversight. Continuity should be a standing item within that framework rather than a separate annual ritual. CV5 Capital provides the governance framework and service provider coordination; the manager's own plan, and the investment decisions within it, remain the manager's.

Structuring a Fund with Continuity Built into the Governance

Strategy: traditional or digital asset. Vehicle: Cayman segregated portfolio. Manager: a two-to-five person team with a named alternate for trading and cash. Governance: a fund board that minutes succession, provider continuity and testing annually.

The Fund Terms Questionnaire captures the proposed strategy, the investment manager and its key people, launch AUM, target investors, dealing and liquidity terms, fees, custody and banking, and the operational requirements from which the authority matrix, the provider architecture and the board's oversight calendar are built.

Start the Hedge Fund Questionnaire

Testing Cadence and the Evidence an ODD Team Wants

An untested plan is a hypothesis. CIMA's 2007 guidance, the SEC staff's 2013 and 2020 observations and the FCA's guidance on business continuity policy converge on the same expectation. Test periodically, in proportion to the criticality of the function, and update the plan when the business changes. For a small manager the programme need not be elaborate, but it must exist, be logged and produce findings.

TestWhat is exercisedCadenceEvidence retained
Remote access testEach critical system reached from a second location on a second device, including provider portals and multi-factor authenticationQuarterlyLog with date, person, systems reached, time taken, failures
Calling tree testEvery contact on the tree reached by primary and alternate channel; stale details correctedQuarterlyCompleted tree with timestamps and corrections
Backup restorationA file, mailbox or dataset restored from backup and verifiedSemi-annuallyRestoration record with recovery point achieved
Alternate trader exerciseThe alternate places or cancels a test order and instructs a cash movement through the standard controls; provider recognises the authoritySemi-annuallyConfirmation from prime broker and administrator; board note
Scenario walk-throughTabletop exercise of one named scenario, typically key person loss or cloud provider outage, against the recovery objectivesAnnuallyWritten outcome, objectives met or missed, remediation actions
Provider continuity reviewLatest controls report and continuity summary from each material provider read and notedAnnually, and on any provider changeReview note presented to the board
Full plan reviewPlan re-read against the business as it now is: people, systems, providers, fund termsAnnually, and after any material changeRevised plan with version date; board minute

ODD teams read the test log before the plan. The questions are predictable: when was the plan last tested, what was tested, what failed, what changed, and who at the board saw it. A manager who answers with dates and findings has demonstrated continuity; one who produces a plan with no log has demonstrated a document. Questionnaires built on the AIMA illustrative due diligence questionnaire treat business continuity as a standard operational topic. AIMA's guides to sound practices for operational risk management and for business continuity management, both published in October 2020, place its governance with the governing body and senior management. The broader preparation is covered in CV5's guide to how a new hedge fund passes operational due diligence.

Common mistakes

  • Adopting an enterprise template that describes sites, teams and functions the manager does not have.
  • Naming an alternate who is not on the prime broker or administrator mandate, so the authority exists on paper only.
  • Stating recovery objectives that have never been measured, or copying a vendor's service level as the fund's objective.
  • Treating the annual board review as the test, rather than as the point at which test results are minuted.

Rules, Guidance and Practice: What Regulators Actually Say

Managers often describe their plan as required by a regulator when the position is more nuanced, and an allocator who knows the instruments will notice. The table below separates the sources by status for the three jurisdictions emerging managers launching Cayman funds are most often asked about.

InstrumentStatusWho it applies toWhat it says about continuity
CIMA Rule on Corporate Governance for Regulated Entities (April 2023, effective October 2023)RuleGoverning bodies of all CIMA regulated entities, including regulated funds, proportionately appliedRequires a succession plan for directors and senior management, oversight and annual review of risk management and internal controls, effective management of outsourced operations, and detailed minutes. Does not use the phrase business continuity
CIMA Rule and Statement of Guidance on Internal Controls for Regulated Entities (April 2023, effective October 2023)Rule with guidanceAll CIMA regulated entities, proportionately appliedThe guidance portion states that information systems should be supported by adequate contingency arrangements and that business resumption plans should be periodically tested
CIMA Statement of Guidance on Business Continuity Management (March 2007)GuidanceAddressed to CIMA licenseesDescribes a process of business impact analysis, risk assessment, plan, testing and independent review; board and senior management collectively responsible; outsourcing does not transfer continuity responsibility
CIMA Statement of Guidance on Outsourcing for Regulated Entities (April 2023)GuidanceRegulated entities other than regulated mutual funds and private funds, which are expressly exceptedDue diligence should assess a provider's continuity arrangements and contingency plans; outsourcing agreements should address them; contingency plans should be tested
SEC Rule 206(4)-7 and Release IA-2204 (December 2003)Rule, with the Commission's stated expectations in the adopting releaseSEC-registered investment advisersThe rule requires written compliance policies; the release states the Commission expects those policies, at a minimum and where relevant, to address business continuity plans
SEC proposed Rule 206(4)-4, Release IA-4439 (June 2016)Proposed, never adoptedWould have applied to SEC-registered advisersWould have required a written continuity and transition plan with five stated components and an annual review. Useful as a checklist; not a rule
SEC staff risk alerts (27 August 2013 and 19 November 2020)Staff observationsExamined advisers; published for all advisers to considerPlans that did not anticipate key personnel being unavailable, providers' plans not evaluated, plans untested or lacking contact details and designated responsibility
FCA SYSC 4.1.6R to 4.1.8GRule for common platform firms, CRR firms and management companies; guidance for other firmsUK-authorised firmsReasonable steps to ensure continuity and regularity of regulated activities; a business continuity policy covering resources, recovery priorities, communications, invocation, data integrity and regular testing
FCA SYSC 15A operational resilience (in force 31 March 2022, transition ended 31 March 2025)RuleBanks, building societies, designated investment firms, insurers, recognised investment exchanges, enhanced scope SM&CR firms, certain payment and e-money firms and a small number of other categoriesImportant business services, impact tolerances, mapping, scenario testing and self-assessment. A UK manager is in scope only if it falls within one of those categories

The pattern is consistent. Binding rules place governance, risk and outsourcing oversight with the board or the firm; the shape of the plan, and the expectation that it be tested, come from guidance and from what examiners and allocators found when plans were invoked. That is a reason to describe the plan accurately. The failures it is meant to prevent are catalogued in CV5's analysis of operational breakdowns that kill funds before investors notice, several of which are continuity failures under another name.

Key Takeaways

  • Write the authority matrix first and lodge it with the prime broker and administrator; an alternate who cannot actually trade or release cash is not cover.
  • Set a recovery time and recovery point objective for each critical function from the fund's dealing cycle, then run a test that measures them.
  • Obtain and read each material provider's continuity summary and controls report, and request an information right and incident notification term at appointment.
  • Give the fund board a standing continuity item and have it minute the plan, test results, authority matrix and provider review at least annually.
  • Keep a test log with dates, findings and remediation; it is the document an ODD team reads first.
  • Describe the regulatory basis for the plan accurately, distinguishing rule from guidance and practice.

Preparing a Fund That Will Pass the Continuity Questions?

Complete the CV5 Fund Terms Questionnaire. It is the first structuring step and provides the information required to assess the proposed strategy, the investment manager and its team, target investors, launch AUM, dealing and liquidity terms, fee structure, custody and banking, and the operational requirements from which the fund's authorities, provider architecture and governance calendar follow.

Traditional strategies route to the hedge fund questionnaire. Digital asset strategies, where wallet and exchange access add a further layer to the continuity plan, route to the digital asset fund questionnaire.

Start the Hedge Fund QuestionnaireStart the Digital Asset Fund Questionnaire

Frequently Asked Questions

Does a hedge fund manager need a business continuity plan?

Whether a plan is a legal requirement depends on where the manager is regulated. SEC-registered advisers are required to have written compliance policies, and the SEC stated in 2003 that it expects those policies to address business continuity where relevant. UK-authorised firms are subject to FCA rules or guidance on continuity under SYSC 4.1. Independently of regulation, allocators conducting operational due diligence expect a tested plan from any manager, whatever its size.

What should a small hedge fund's business continuity plan include?

A proportionate plan covers a short business impact analysis, named scenarios with an invocation decision-maker, an authority matrix naming alternates for trading and cash with matching provider mandates, recovery objectives and backup arrangements for each critical system, the continuity arrangements of material providers, a communications tree, and a test calendar with a log. For a two-to-five person manager the whole document is typically short.

What are recovery time and recovery point objectives for a hedge fund?

A recovery time objective is the maximum period a function can be unavailable before the impact becomes unacceptable. A recovery point objective is the maximum amount of data, measured in time, that can be lost. Both should be set per function by reference to the fund's dealing frequency, margin exposure and reporting obligations, and then confirmed in a test rather than asserted in the plan.

Does the SEC require investment advisers to have a business continuity plan?

There is no standalone SEC continuity rule for advisers. The Commission proposed one in June 2016, Rule 206(4)-4, and it was never adopted. The compliance programme rule, Rule 206(4)-7, requires written policies and procedures, and the 2003 adopting release states that the Commission expects those policies to address business continuity plans to the extent relevant. SEC examination staff have published observations on continuity plans in 2013 and 2020.

What does the fund board need to do about business continuity in the Cayman Islands?

CIMA's Rule on Corporate Governance for Regulated Entities requires the governing body to have a succession plan for directors and senior management, to oversee and review risk management and internal control systems annually, to manage outsourced operations effectively, and to keep detailed minutes. The rule does not itself use the phrase business continuity. In practice a fund board discharges those duties by receiving the manager's plan and test results, reviewing service provider arrangements and minuting the review.

What evidence do allocators ask for on business continuity during ODD?

Allocators typically ask for the plan, the date of the last test, what was tested, what failed and what changed, and whether the board has reviewed it. They also ask who can trade and instruct cash if the principal is unavailable, and whether that person is recognised by the prime broker and administrator. A plan without a test log is generally treated as untested.

This article is produced by CV5 Capital for general informational purposes only and does not constitute legal, regulatory, investment, tax or financial advice. References to CIMA rules and statements of guidance, to SEC rules, releases and staff risk alerts, and to the FCA Handbook reflect CV5 Capital's general understanding of the published instruments as at the date of publication and may change; the status of each instrument as a rule, guidance or staff observation is as described in the article and should be confirmed against the current text. Business continuity obligations depend on where the manager and the fund are regulated, the strategy and the service provider arrangements. Managers and investors should obtain independent professional advice appropriate to their structure, strategy and regulatory obligations before acting. CV5 Capital is registered with the Cayman Islands Monetary Authority (CIMA Registration No. 1885380, LEI: 984500C44B2KFE900490).
CV5 Capital Fund Manager Briefing

Cayman Fund Intelligence, Direct to Your Inbox

Receive concise analysis on Cayman fund formation, digital asset funds, regulation, governance and institutional infrastructure.

You're subscribed to the CV5 Capital Fund Manager Briefing. We'll send you practical analysis on Cayman fund formation, digital asset funds, regulation, governance and institutional infrastructure.
Something went wrong while submitting. Please try again.
For fund managers, allocators, family offices and professional advisers.
Privacy Policy

Considering launching a Cayman fund?

Complete the relevant CV5 Fund Terms Questionnaire to provide the core information required to assess the proposed structure.

CV5 Fund Manager Briefing

Stay current on Cayman fund formation

Receive practical updates on Cayman hedge funds, digital asset funds, CIMA regulation, governance and institutional infrastructure.

You're subscribed to the CV5 Capital Fund Manager Briefing. We'll send you practical analysis on Cayman fund formation, digital asset funds, regulation, governance and institutional infrastructure.
Something went wrong while submitting. Please try again.
For fund managers, allocators, family offices and professional advisers.
Privacy Policy
Ready to Launch Your Fund?
Whether you are launching your first hedge fund or expanding an established investment strategy, CV5 Capital provides the infrastructure, regulatory framework, and operational support required to bring your fund to market quickly and efficiently.