Finance systems are the case where "we have backups" is not an answer. A ledger, a payments switch or a settlement system has a recovery point objective expressed in minutes or seconds, and somebody outside the organisation is entitled to ask you to demonstrate that the configuration can actually deliver it.
That is a different standard from most database work. It is not enough for the backups to run; the restore has to have been performed, the failover has to have been rehearsed, and the gap between the recovery objective written in the policy and the one the configuration can meet has to be either zero or documented.
In our experience that gap is the single most common finding in this sector — not because teams are careless, but because testing it properly has always required an outage nobody could justify scheduling.

