Business Continuity and Disaster Recovery Policy
Business Continuity and Disaster Recovery Policy
The firm's framework for sustaining critical operations during disruption, recovering systems and data, and meeting recovery time and recovery point objectives for limited partners and portfolio companies.
1. Purpose
The Business Continuity and Disaster Recovery Policy describes the firm's framework for maintaining critical business operations during disruptions, recovering systems and data following an incident, and ensuring continuity of service to limited partners and portfolio companies. The policy supports the firm's regulatory obligations under Rule 206(4)-7 under the Investment Advisers Act of 1940.
2. Scope
This policy applies to all critical business functions of Slate Blue Capital LLC and its affiliates, including investment operations, fund accounting, treasury, investor relations, legal and compliance, technology, and portfolio company support. The policy covers personnel, physical premises, technology systems, third-party service providers, and information assets.
3. Ownership and Governance
The Chief Technology Officer owns the firm's Business Continuity and Disaster Recovery program. The Chief Risk Officer reviews the program annually and reports to the Audit Committee on adequacy, testing results, and material incidents. Material changes to the program require approval by the Audit Committee.
4. Business Impact Analysis
The firm maintains a Business Impact Analysis identifying critical business functions, dependencies (people, systems, vendors, premises), maximum tolerable downtime for each function, and recovery time and recovery point objectives. The Business Impact Analysis is reviewed annually and updated upon any material change to the firm's operations or technology footprint.
5. Recovery Objectives
Recovery Time Objectives and Recovery Point Objectives are established for each critical business function. The firm targets recovery of investor reporting, capital call and distribution processing, and core trading and treasury operations within one business day of a disruption. Recovery Point Objectives are set such that data loss does not exceed twenty-four hours for any critical system.
6. Technology Resilience
Critical systems are operated on infrastructure with documented redundancy, geographically diverse data centers or cloud regions, automated backup, and tested restoration procedures. Backup data is encrypted in transit and at rest. Backup restoration is tested at least quarterly. Access to systems from alternate locations is supported by secure remote access and multi-factor authentication.
7. Workplace Resilience
Personnel can perform critical functions from secondary office locations or remotely. The firm maintains alternate workplace arrangements at its regional offices and supports secure remote work for all personnel. In the event of a regional disruption, work transfers to unaffected offices or to remote work without material delay.
8. Vendor and Third-Party Continuity
Critical service providers, including the fund administrator, auditor, custodial banks, and technology vendors, are required to maintain business continuity programs and to certify continuity capabilities at onboarding and annually. The firm reviews vendor continuity programs as part of its third-party risk management process. Material gaps trigger remediation requirements or substitution.
9. Crisis Management
The firm maintains a Crisis Management Team chaired by the Chief Executive Officer and including the Chief Operating Officer, Chief Risk Officer, Chief Compliance Officer, Chief Technology Officer, General Counsel, and Head of Investor Relations. The team is activated upon a Severity 1 or Severity 2 incident as defined in the firm Cybersecurity Policy or upon any disruption expected to exceed the maximum tolerable downtime for a critical function.
10. Communications
The firm maintains predefined communications protocols for incidents involving limited partners, regulators, counterparties, employees, and the public. Communications are coordinated by the Head of Investor Relations and the General Counsel under the direction of the Crisis Management Team.
11. Testing and Exercises
The firm conducts at least one full Business Continuity exercise annually, including a simulated activation of critical systems from an alternate site or alternate cloud region. Tabletop exercises are conducted at least twice annually with the Crisis Management Team. Test results are reviewed by the Chief Risk Officer and reported to the Audit Committee. Material findings are tracked through closure.
12. Reporting and Continuous Improvement
The Chief Technology Officer reports annually to the Audit Committee on Business Impact Analysis updates, testing results, material incidents, recovery objective performance, and any program changes. Lessons learned from incidents and exercises are incorporated into the program. The policy is reviewed annually and updated as necessary to reflect changes in operations, technology, or regulatory expectations.
Notice
This document is a summary of the firm's internal policy as adopted by the approving body identified above. The complete policy as adopted governs in any case of conflict between this summary and the underlying policy document. Limited partners and other authorized parties may request the full policy from the policy owner. This document does not create contractual rights, employment rights, or third-party beneficiary rights, and may be amended at any time by action of the approving body.
Questions about this policy should be directed to [email protected]. Confidential or anonymous reports may also be made through the channels described in the Whistleblower Policy.
Questions about firm governance
Limited partners, regulators, and counterparties with questions about firm governance, policies, or compliance should contact [email protected].