Many estates are legally well-formed and still operationally fragile. The failure mode is rarely missing documents; it is access under pressure — where instruments are, who can reach them, and what breaks first. The practical test is not whether an estate plan exists. It is whether the appointed operator can run the system when the principal cannot.
This is the purpose of a seventy-two-hour continuity drill: a structured stress test in which an executor — or equivalent operator — attempts to retrieve critical instruments, access designated places, and identify time-sensitive obligations without the principal's assistance, within the first three days. The drill is not a planning exercise. It is a measurement.
The gap between a valid estate plan and an executable one is wider than principals expect, and that gap shows up only when the principal is removed from the room.
A worked example
An illustrative composite of how a complex household fails the drill. The details are altered; the failure pattern is unaltered.
The principal: a fifty-eight-year-old company director, married, two adult children, primary residence in Surrey, second home in the Swiss Alps, three operating companies, four banking relationships across two jurisdictions, two pensions, one trust structure for the children, one solicitor of record, one accountant. Every legal instrument was current. The will had been reviewed within the previous eighteen months. Lasting Powers of Attorney were in place for both spouses. Trust deeds were properly executed. On paper, the estate was in good order.
The drill began on a Saturday morning. The appointed operator — the principal's eldest child, named executor — was given the task list: locate the original will, access the home safe, identify three obligations falling due within fourteen days, and reach the credential layer for the principal's email and the password manager.
By Sunday evening, the operator had located the will (in a solicitor's office that was closed until Monday and required identification the operator did not have on hand), could not open the home safe (the combination had been changed eighteen months earlier; the new combination was in the password manager), could not enter the password manager (the master password had been changed at the same time and the recovery method routed to a phone number that had been replaced), and had identified only one of the three obligations.
No instrument had been missing. No document had been lost. The estate had failed the drill on routing.
What this estate experienced is a typical first-run result on a well-documented household: not legal disorder, but routing failure.
What estate planning rarely measures
Estate planning, as a profession, measures legal validity. The questions it asks are well-formed and answerable: are the documents correctly executed, correctly witnessed, correctly structured, correctly appointed; do the trusts hold their assets cleanly; are the attorneys named and the substitutes provided. These are the right questions for the legal layer. They are not the only questions the household needs answered.
Operational readiness is a different category of question, and it is rarely on anyone's professional remit. It is not, strictly, a legal matter. It is not a financial planning matter. It is not a tax matter. It sits in the gap between those disciplines, which means it sits, in practice, with no one. The principal assumes it is handled. The solicitor assumes it is operational. The operator assumes it will be obvious. The drill is the moment those assumptions are tested.
Operational readiness asks a more physical set of questions. Can the operator retrieve the current instruments — not an outdated copy filed three years ago? Can they access each designated place independently? Can they identify obligations with real deadlines in the first three days? Can they reach the credential layer that has, over the past decade, become the household's actual control plane?
Legal failures are loud: a will contested, a trust struck down, a power of attorney rejected. Operational failures are quiet: a safe that cannot be opened, a renewal missed, a payment defaulted, a property left exposed because the insurance certificate could not be produced. The first kind generates litigation. The second kind generates loss without anyone identifying the cause.
What the drill tests
A standard seventy-two-hour drill measures four tasks. Each is a directed action with a binary outcome: the operator completes it independently, or the operator does not.
Task one — retrieve the current instruments. The operator must locate and produce the active will, any codicils, the active LPAs, the trust deeds, the operating-business documents, and the principal's record of advisers. Current is the load-bearing word. A will from 2019 superseded by a 2023 version is a failure, even if the operator finds the older document.
Task two — access every designated place independently. A designated place — the home safe, the deposit box, the solicitor's holdings, the cloud-based document store — is functional only if the operator can reach it without the principal's assistance. Independently means: with the documented access method, not with the principal in the room talking them through it.
Task three — identify time-sensitive obligations. Most estates carry a layer of recurring obligations that, if missed, generate real consequences within weeks: insurance renewals, tax payments, regulatory filings, mortgage commitments, business-critical contracts. The drill asks the operator to surface the three most urgent obligations falling due in the following fortnight. This task often fails not for lack of obligations, but for lack of any registry that lists them.
Task four — reach the credential layer. The household's information infrastructure now runs through email, password managers, device PINs, recovery methods, and second factors. The drill asks the operator to log into the principal's primary email, open the password manager, identify the password manager's recovery kit, and produce the recovery method for the second factor on the principal's main bank. This is the task most estates fail.
Three failure modes account for most of what breaks
The breakdowns sort into three patterns. Two of the three are essentially universal in first-run drills on undocumented estates.
Circular dependencies. The safe combination is in the password manager. The password manager's recovery kit is in the safe. The operator has the address of both, and access to neither, because each requires the other. Circular dependencies are not edge cases; they are the default state of any system that grows organically. They are absent only where someone has explicitly designed against them, which is rare.
Credential drift. The credential layer in 2025 is not the credential layer of 2015. Phones are replaced. Recovery emails are abandoned. Second factors are reset. Security questions are forgotten. Master phrases are rotated. Every one of these events, taken individually, is reasonable. Taken collectively, they are the slow erosion of an operator's ability to enter the system at all. Credential drift is the failure mode most likely to mean that an estate that would pass the drill today can fail it two years on, with no instrument having changed.
Knowledge assumptions. The principal believes the operator knows where the safe is, because the safe has been in the house for ten years. The operator has never been told. The principal believes the solicitor will produce the will, because the solicitor has always produced it — without the principal in the room, the solicitor will require identification the operator does not possess. Knowledge assumptions are the failure mode hardest for the principal to see, because they are invisible from inside the principal's own working knowledge of their own life.
Credential drift deserves its own attention
Of the three failure modes, credential drift is the one that returns most reliably after remediation. A circular dependency, once broken, stays broken. A knowledge assumption, once written down, stays written down. Credential drift is a process, not a state. It restarts itself the moment a phone is upgraded, a password rotated, a recovery email allowed to expire.
The implication, for any estate that intends to remain executable over years rather than months, is that the credential layer requires a maintenance discipline. The discipline has three components. Re-anchoring: recovery methods, second factors, and master credentials are reviewed and re-documented on a defined schedule — quarterly is sufficient for most households. Versioning: each documented credential carries the date of its last verification. Drift detection: a sample of credentials is tested, not merely listed, on the same schedule. A credential that has not been tested in twelve months should be assumed to have drifted, regardless of whether the documentation has been updated.
Re-running the drill on an annual cadence is the simplest available drift detection. It is also the cadence most households resist, because it surfaces failures that the household would prefer to assume were handled.
Why the operational lens matters
Execution failures create stress, delay, and escalation at the exact moment a household least needs them. The financial cost is real — emergency access, expedited credential resets, locksmith fees, solicitor charges for out-of-hours retrieval — but the financial cost is the smaller part. The larger cost is borne by people. During a medical emergency, families face treatment decisions, insurance coordination, dependent care, and fear, simultaneously. A document treasure hunt with real deadlines compounds those demands.
The legal layer can be perfect and still non-executable. The operational layer determines whether the appointed operator can act without retries, without training, and without the principal. Whether the operational layer functions is not knowable in the abstract. It is only knowable by drill.
What to do after a failed drill
Most first-run drills fail. The failure is not the conclusion; it is the input to remediation. A practical playbook proceeds in three phases.
Repair the routing. Every blocked designated place receives a documented, independent access method. Every circular dependency is broken — typically by routing the access method for place A through a third location, not through place B. Every undocumented location is documented. This phase produces a registry: a single artefact listing each designated place, its location, its access method, and what it contains. The registry is itself stored in a documented location reachable by the operator.
Build the credential discipline. Every credential the operator needs is documented with its recovery method, its second factor, and the date of last verification. A quarterly verification schedule is established. Where possible, recovery is routed through methods the operator can independently reach — a shared trusted contact, a sealed envelope, a printed kit held by the solicitor — rather than through methods that remain in the principal's sole possession.
Repeat the drill. A remediation is not complete until the same drill, run with no advance notice and with the principal absent, produces a clean result on the four tasks. The interval between drills, once the system passes, is annual. The interval can lengthen for systems that have remained stable through three consecutive clean drills, but it should not lengthen far. The credential layer drifts. The drill is the only honest measurement of whether the drift has crossed into failure.
A clean drill is not a permanent state. It is a recent verification. The distinction is the point of the discipline.
A lighter public version of the seventy-two-hour continuity drill is available as the Valoren Continuity Footprint Auditor. The next entry in this archive examines designated places: the topology of custody.