1. Safety team told us that they updated BC Plan regularly, including plan for 2016, but HSBC has not been informed since 2014.
• We recommend Recall to keep informing the bank with the BC Plan upon change or at least once a year.
Action: Share latest BCP to HSBC and continue sharing on Annual Basis.
2. We reviewed the plan and there is no record of contact persons for either Recall or HSBC. There is no escalation flow in case of emergency for both parties.
• We recommend to include contact points and escalation flow in BC Plan and share with HSBC.
Action: Update below attach file in yellow and share me.
3. We learned that a staff in Safety team can grant access authority assigned to staff upon HRD's request and there is no review on staff access's rights.
• We recommended Recall management to review access authority groups and access rights assigned to staff in each department to ensure that proper access rights is granted.
Action: Initiate the review and share the result. For ongoing, continue reviewing at least once a year.
4. We learned that one guard works 24 hours once a week so the other guard can take a day-off and we consider that continuous 2 working shifts will decrease guard capability.
• We recommended Recall to consider consulting with the security guard company to provide a relief guard to replace the one who is taking a day-off.
Action: Consult with security guard company and provide me an update.
5. The control room monitoring by outsourcing guard is the center of security system. Training should be conducted more often.
• We recommend Recall to consider providing the refresher training on a half yearly basis for the existing guards and immediate training when any new guard member. The attendance sheet is very recommended and for our future reference.
Action: Please consult with security guard company and provide me an update.