Prove your bank can reach every branch when systems go down
Business continuity plans assume you can contact branch staff and confirm what is open, what is down and what is secured. Robofy turns that into a tested, timestamped process on WhatsApp with the controls a compliance team expects, instead of an improvised chain of phone calls and personal chat groups.
A continuity plan is only as good as the communication behind it
Turkish banks work under some of the most detailed continuity expectations of any sector. BDDK’s regulation on banks’ internal systems and internal capital adequacy assessment process (ISEDES) expects board-approved business continuity and contingency planning. The 2020 regulation on banks’ information systems and electronic banking services adds concrete requirements: primary and secondary systems located in Turkey, the ability to resume operations within 24 hours even if primary systems are completely lost, and alternative communication arrangements for network and communication outages.
Much of that planning focuses on systems. The part that is often improvised is people: how the crisis team reaches branch managers, ATM operations and security staff when email and internal tools are unavailable, and how it confirms, branch by branch, what is actually happening.
In practice the gap is usually filled with personal phones and WhatsApp groups. That works until an auditor asks for evidence, or until a KVKK question arises about operational information shared on accounts the bank does not manage.
Where improvised communication creates risk
No evidence for the auditor
If reachability is tested with ad-hoc calls, there is no reliable record of who was contacted, when they confirmed and which branches were never reached.
KVKK exposure in personal chats
Operational details shared in personal chat groups sit outside the bank’s control, cannot be retained or deleted by policy, and stay on the phones of staff who leave.
SLAs nobody can measure
A continuity plan may promise status confirmation within 30 minutes, but without timestamps nobody can show whether the bank met it, or where the time went.
Illustrative scenario: an audit question at a regional bank
Ardıç Bank is a fictional bank. This scenario illustrates how the platform works; it is not a customer case study.
Ardıç Bank is a regional bank with 140 branches and around 600 ATMs. During a business continuity review, its compliance officer is asked to demonstrate that, if the core network goes down, branch staff can be reached and branch, ATM and vault status confirmed within the 30-minute window in the bank’s continuity plan, without relying on personal chat groups or unmanaged channels.
Before: the improvised answer
- The continuity plan lists a phone tree that was last updated eleven months ago.
- In the last drill, regional managers relayed status through personal WhatsApp groups.
- Confirmations were pieced together afterwards from an email thread and a spreadsheet.
- The bank cannot show when each branch confirmed, or that the 30-minute target was met.
After: a controlled, recorded process
- Pre-approved templates exist for core-system outage, power loss, cyber incident and natural disaster.
- Only authorised roles, signed in with two-factor authentication, can launch a continuity broadcast, from the dashboard or the mobile governance panel.
- Branch managers confirm with structured buttons: branch open or closed, ATMs operational, vault secured.
- Branches that have not confirmed within ten minutes are escalated automatically to their regional manager.
- The compliance officer exports a timestamped report showing every message, confirmation and escalation.
Drill timeline
- 00:00The crisis lead launches the continuity drill from the mobile governance panel.
- 00:05Messages delivered to 140 branch managers and the ATM operations team.
- 08:00112 of 140 branches have confirmed status; the dashboard lists the remaining 28.
- 10:00Unconfirmed branches are escalated automatically to regional managers.
- 22:00All branches confirmed; two ATM faults routed to operations.
- 30:00Drill closed inside the SLA and the audit report exported.
How Robofy supports your continuity plan
Robofy is the staff-communication layer of your business continuity plan. It does not replace your core banking or disaster-recovery systems; it makes sure the people who run them can be reached, can confirm status, and leave a record.
Prepare
Map each continuity scenario to a message template, recipient groups such as branch managers, ATM operations, security and IT, and the confirmations you need from each.
Launch
Authorised roles with two-factor authentication start a broadcast from the dashboard or the mobile governance panel, even if they are away from the office when the incident begins.
Confirm
Staff answer on WhatsApp with structured buttons, so every branch, ATM and vault status arrives as data rather than as free text.
Escalate
Branches that have not confirmed within the time you set are escalated automatically to the next level of management.
Evidence
Every broadcast, delivery, reply, escalation and access event is logged with timestamps. Export the report for your continuity test file, internal audit or supervisory review.
Personal groups and phone trees vs. Robofy
| Compared | Phone trees and personal groups | Robofy |
|---|---|---|
| Who can start a broadcast | Anyone in the group | Authorised roles with 2FA |
| Status confirmation | Free text scattered across chats | Structured branch, ATM and vault status |
| Unconfirmed branches | Found manually, if at all | Escalated automatically |
| Data control | Personal accounts outside bank policy | Encrypted, access-controlled, retained by policy |
| Audit evidence | Screenshots and email threads | Timestamped, exportable audit logs |
| Drills | Hard to run and harder to prove | Run and reported exactly like a real event |
The controls your compliance team will ask about
These are the platform capabilities behind the scenario. Our KVKK & GDPR notice describes data processing, sub-processors and retention in full.
ISO 27001, KVKK, GDPR
Compliance
Operated in line with ISO 27001, KVKK and GDPR, with a data processing agreement signed with every enterprise client.
AES-256
Encryption
AES-256 encryption for stored data and TLS 1.2+ for data in transit.
2FA + RBAC
Access control
Two-factor authentication and role-based permissions control who can prepare, launch and view each broadcast.
Audit logs
Full audit trail
Broadcasts, deliveries, replies and data access are logged with timestamps, and reports can be exported for auditors.
99.99%
Uptime on AWS Multi-AZ
Redundant across multiple AWS Availability Zones, so losing a single data centre does not stop your messages.
<5s
Message delivery
From the moment a broadcast is triggered to the message arriving on the recipient’s WhatsApp.
Mobile panel
Mobile governance panel
Launch, approve and monitor broadcasts from a phone, even when nobody can get to a laptop.
Meta Verified
Meta Verified Tech Provider
Official access to the WhatsApp Business Platform through Meta’s Tech Provider program.
Frequently asked questions
Does using Robofy make our bank compliant with BDDK requirements?
No single tool makes an institution compliant. Robofy gives you a controlled way to reach staff and confirm status during a disruption, plus timestamped evidence of every step, which your compliance and IT risk teams can map to your business continuity plan and regulatory obligations.
How does Robofy fit BDDK rules on primary systems, data location and outsourcing?
Robofy is a communication layer rather than a core banking system, but how any external service is classified, including under the rules on outsourcing and data location, is an assessment each bank makes. During onboarding we share hosting, data-flow and security documentation so your teams can complete it. Hosting details are also published in our KVKK & GDPR notice.
Why not use personal WhatsApp groups or SMS?
Personal groups sit outside the bank’s control: there is no access management, no retention policy and no audit trail. SMS offers no structured replies and little visibility of whether a message was read. Robofy keeps the familiarity of WhatsApp and adds role-based control, structured confirmations and logs.
Can we show auditors that we met our continuity SLA?
Yes. Each broadcast records when messages were sent and delivered, when they were read by recipients who have read receipts enabled, and when each recipient confirmed. Reports can be exported for your continuity test file or internal audit.
Can we run continuity drills with the same flows?
Yes. Drills use the same templates, recipient groups and escalation rules as a real event and produce the same report, so a tested plan and a real response look identical on paper.
Who at the bank can launch a broadcast?
Only the roles you authorise. Every user signs in with two-factor authentication, and role-based permissions separate who can prepare templates, launch broadcasts and view responses.
This page is general information about business continuity communication, not legal advice. Regulatory references are summarised; consult the official BDDK texts and your legal and compliance advisers on your institution’s obligations.
Put your continuity communication to the test
Walk through a branch-outage drill with your own scenarios and SLA in a 15-minute demo.
Related use cases
- Robofy ResilienceEarthquake employee safety check-inAutomatic WhatsApp check-ins after an earthquake, with a live dashboard of who is safe and who needs help.
- Robofy ResilienceEmergency drills and preparedness checksScheduled WhatsApp flows for evacuation drills and earthquake-kit checks, with automatic follow-up and audit-ready reports.