OpenLot Book audit
Systems

When Your DMS Goes Down: A Dealership Continuity Plan

OpenLot 9 min read

A dealership business continuity plan is the written answer to a specific question: what does the store do when the systems it runs on are unavailable? Most dealers discovered they did not have one in June 2024. The plan is not an IT document. It is a department-by-department list of what stops, what continues on paper, and which data you need a copy of before you need it.

Diagram of dealership departments showing which operations stop immediately, degrade, or continue when the DMS is unavailable

This guide covers what actually stops during a DMS outage, how long a store can run manually, what a usable continuity plan contains, and which data to keep a copy of.

Why does this deserve a plan?

Because the dependency is total and almost entirely invisible until it fails.

In June 2024, a cyberattack on CDK Global — a major provider of dealer management software in North America — took its systems offline and left thousands of dealerships across the U.S. and Canada unable to use the software their operations run on. The disruption was widely reported to have lasted weeks, not hours, spanning the end of a sales month.

The specific vendor matters less than the shape of the lesson. Stores that had a plan sold cars on paper. Stores that did not spent the first several days deciding what to do, and some of that decision time was during the month-end push.

An outage is not the only way to lose access, either. A billing dispute, a failed migration, an acquisition that changes your contract terms, or your own credential problem produces the same operational morning.

What actually stops when the DMS goes down?

Not everything, and not at the same rate. The useful exercise is to sort your operations into three buckets, because they need three different responses.

Department What stops immediately What degrades What continues
Sales Deal jackets, desking, DMV/title submission, funding packets Inventory lookup, pricing accuracy Test drives, negotiation, taking deposits
F&I Credit pulls, lender submission, e-contracting, product rating Compliance documentation Nothing meaningful
Service RO creation, warranty claims, history lookup, cashiering Scheduling, technician dispatch Physical repair work already in progress
Parts Catalog lookup, stock levels, ordering, invoicing Counter sales Handing over parts already on the shelf
Accounting Posting, payroll, schedules, reconciliation Everything Nothing

Two things fall out of this table that surprise people the first time they build it.

F&I is the hard stop. You can negotiate a car on a legal pad. You cannot pull credit, submit to a lender, or e-contract without systems. A store in an outage can sell cars and cannot fund them, which means the deal sits — and the customer's enthusiasm has a shelf life.

Service is the bigger revenue leak. Sales can hold a deal for a few days and still capture it. A service customer who cannot be checked in goes somewhere else that morning and the repair order is simply gone. Fixed operations absorb the damage faster and recover it less.

How long can a store run on paper?

Realistically, a few days for sales, and the constraint is not paperwork — it is the backlog. Every manual deal has to be re-entered when systems return, and re-entry competes with the normal work of the day you return.

A store writing 100 units a month that runs manual for a week creates roughly 25 deals of re-entry, landing on a team that is also catching up on a week of service ROs and accounting posting. The outage costs you twice: once while it happens, and once while you unwind it.

That second cost is the argument for keeping manual processes structured. Loose paper produces a longer, more error-prone re-entry than a defined form does.

What does a usable continuity plan contain?

Six parts. It should be short enough that people read it during a bad morning.

1. A vendor dependency map. Every system, what it does, who the vendor is, the support number, your account number, and which department stops without it. Most stores have never written this down, and assemble it under pressure.

2. A department-by-department manual procedure. The paper forms, pre-printed and physically stocked. A manual deal jacket checklist. A paper RO. Where they live. Who is authorized to approve what without the usual system check.

3. A named incident owner. One person who decides to invoke the plan and coordinates. Not a committee, and not "the GM" by default if the GM is the person selling.

4. A communications script. What the team tells a customer, what goes on the phone greeting, what goes on the website. Silence during an outage reads to a customer as incompetence, and the correction costs more than the outage.

5. A data fallback. The copies you can read without the vendor — covered in the next section.

6. A re-entry procedure. How manual work gets back into the system, in what order, by whom. Deals before service ROs, because funding is time-sensitive.

Store it where it is reachable when the network is not. A continuity plan that lives only inside the system that is down is not a plan.

Which data do you need a copy of?

The test for each item is simple: could you operate tomorrow morning without the vendor's software? If not, you need a readable copy under your own control.

The practical minimum, refreshed daily:

  • Active inventory — stock number, VIN, price, location, status
  • Open deals and pending funding — enough to reconstruct what is in flight
  • Customer contact data — names, phones, emails for active and recent customers
  • Open repair orders and appointments — the next several days of service schedule
  • Parts on order and stock levels
  • Vendor and lender contacts — with account numbers

Two properties matter more than the contents:

It has to be readable without the vendor's software. An export in a proprietary format you can only open inside the system that is down is not a fallback. CSV, or a database in an account in your name.

It has to be current. A monthly export is nearly useless for deals in flight. Daily is the floor, and daily is what makes the copy an operational tool rather than an archive.

This is the same infrastructure question as getting data out of a DMS at all — the difference is that continuity gives you a reason to solve it that is not about reporting convenience.

A word of caution: a copy of customer data is customer data. It carries the same obligations under the FTC Safeguards Rule as the original — encrypted at rest, access controlled and logged, included in your risk assessment. A continuity copy sitting unencrypted on a manager's laptop has traded one risk for a worse one.

How do you test the plan?

A plan that has never been exercised is a document, not a capability.

A tabletop, twice a year, ninety minutes. Walk each department head through a scenario: it is the 28th, the DMS is unreachable, the vendor has no ETA. Where is the paper? Who calls the lenders? What does the receptionist say?

Check the fallback data quarterly. Open the copy. Confirm it is current, that someone besides one person can access it, and that it opens without the vendor's tools.

Confirm the paper exists physically. The most common gap found in a tabletop is that the manual forms are a PDF on a shared drive, and the shared drive is part of what is down.

Record what broke. The value of the exercise is the list of gaps, and that list is only useful if someone owns closing each one before the next tabletop.

Frequently asked questions

What is a dealership business continuity plan?

It is a written, department-by-department plan for operating when the systems the store depends on are unavailable — covering what stops, what runs on paper, who coordinates, what customers are told, which data you keep an independent copy of, and how manual work gets re-entered afterward.

What happens to a dealership when the DMS goes down?

F&I stops hardest, because credit pulls, lender submission and e-contracting all require systems. Service loses the most revenue, because a customer who cannot be checked in goes elsewhere that day and does not come back. Sales can continue manually — cars can be negotiated and deposits taken — but deals cannot be funded.

How long can a dealership operate without its DMS?

A few days for sales, and the real constraint is the re-entry backlog rather than the paperwork itself. Every manual deal has to be keyed in when systems return, competing with the normal work of that day. Structured manual forms shorten the unwind considerably compared with loose paper.

What data should a dealership keep a copy of for continuity?

At minimum, refreshed daily: active inventory, open deals and pending funding, customer contact data, open repair orders and the coming days of service schedule, parts on order, and lender and vendor contacts with account numbers. It must be readable without the vendor's software.

Was the 2024 CDK outage avoidable for dealers?

Dealers could not have prevented the attack on the provider, but the operational damage varied widely by preparation. Stores with paper procedures, a vendor dependency map and an independent copy of their own data continued transacting; stores without spent the early days deciding what to do, during a month-end.

Does a continuity copy of dealership data create a compliance risk?

Yes, if handled carelessly. A copy of customer data carries the same FTC Safeguards obligations as the original: encryption at rest, controlled and logged access, and inclusion in your written risk assessment. The copy belongs in a managed account, not on an individual laptop.

How often should a dealership test its continuity plan?

Run a tabletop exercise twice a year with each department head, and verify the fallback data quarterly by actually opening it. The most frequent gap found is that the manual forms live only on a shared drive that is part of the outage.

Conclusion

  • The dependency is invisible until it fails. Most stores have never written down which system stops which department.
  • F&I is the hard stop; service is the bigger leak. A held deal can be recovered. A lost service customer usually is not.
  • The outage costs twice — once while it runs, once during re-entry.
  • Daily, readable, independent. A copy you can only open inside the system that is down is not a fallback.
  • A continuity copy is still customer data, with the same obligations attached.
  • Untested plans fail on the details — usually that the paper forms are on the drive that is also offline.

Build the vendor dependency map first. It takes an afternoon, it is the input to everything else in the plan, and most stores find at least one system nobody realized was a single point of failure.

Last updated: