How to use
Run this after the exercise, not during it, with the exercise record open and the published objectives beside it. Ninety minutes is enough if the record exists; if it does not, the review has already found its most important result and the remaining items cannot be answered at all.
The review asks two questions the exercise report rarely asks itself. Did the exercise prove anything, or did it walk a path with every difficult stage assumed away? And was failback part of it, or did the estate stop with the workload running somewhere else and never come home?
Work the timeline in order rather than the item list. Every finding here is a claim about a moment: what was true at the cut, at the handover, during the write window, and at the return.
Where the numbers come from
Elapsed time comes from timestamps on observable events, not from recollection. A boundary nobody can point at in a log gets adjusted afterwards to fit the answer everyone wanted, and the result is worth less than no measurement at all, because it carries authority it has not earned.
The comparison against the published recovery time is row by row. A total that lands inside the budget while individual stages ran double is a result that will not repeat, and the review that reports only the total will not notice.
Divergence is measured in two dimensions: the interval during which the recovery site accepted writes, and the set of records created inside it. Both are recorded while the exercise runs. Reconstructing either afterwards from application logs is a research project, and in a real event it is one performed under time pressure.
The reconciliation is validated by comparison, never by the absence of an error. A rewind, a log replay or a reseed can complete cleanly and still leave the primary missing the last minutes of the write window.
Access this needs
Read access to the exercise record, the stage timings, the runbook that was followed, the published objectives, and the change and incident tracker where findings are supposed to live. Read access to both sitesβ logs for the exercise window, and to whatever recorded the write inventory and the handover times.
Nothing in this review requires write access to a repository, a replica or a production dataset. A reviewer who needs it has found a defect in how the exercise was recorded rather than a gap in their own permissions.
The last items need a person: whoever owns the published objectives and can authorise changing them.
What the review produces
One timeline for the exercise, annotated with the authoritative site at every interval and the two handovers. Beside it, a table of stages carrying the measured elapsed time, the published budget, the difference, and whether the stage was exercised or assumed.
Then the divergence record: the write window, the inventory of records created at the recovery site, the reconciliation method, and the comparison that validated it.
Last, the findings, each with an owner and a date, and an explicit statement for every published objective the exercise contradicted β corrected, funded, or accepted in writing by a named person. An exercise that changes no number and raises no work item either found nothing, which is rare, or was not looking.
Sign-off
- Reviewer: ____
- Date: ____
- Exercise lead: ____ Date: ____
- Service owner: ____ Date: ____
Every critical item must pass. A failing critical item means the exercise did not demonstrate what the estate believes it demonstrated: record the disposition of every item that did not pass, and the name of whoever accepted the residual risk until the next exercise.