SD-14.6 — Operational Resilience & Business Continuity
Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH
Purpose
Keeps the firm’s important business services running through disruption — and able to recover when they fail. SD-14.6 carries two linked disciplines under one capability. Operational resilience is the umbrella — identifying the firm’s important business services, setting impact tolerances for them, mapping the people, processes, technology and third parties each depends on, and testing the firm’s ability to stay within tolerance through severe-but-plausible disruption. Business continuity is the recovery component within it — the continuity and disaster-recovery plans that restore a service after it fails. It is not operational risk — that is SD-14.1, which identifies and assesses what could go wrong; SD-14.6 makes the firm resilient to it. Detection and recovery are different disciplines: SD-14.1 identifies the operational risk, SD-14.6 keeps the business service available through it.
Service Operations
- Map important business services — identify the firm’s important business services and the resources — people, processes, technology, third parties — each depends on.
- Set and test impact tolerances — set the impact tolerance for each important business service, and test the firm’s ability to stay within it under severe-but-plausible scenarios.
- Maintain business-continuity plans — maintain the continuity and disaster-recovery plans that restore a service after disruption.
- Run resilience and continuity testing — exercise the plans and the ICT-resilience testing the regulation requires.
- Respond to and learn from disruption — coordinate the firm’s response to an operational disruption, and feed the lessons back into the resilience framework.
Inputs and outputs
- Inputs: the firm’s important business services and their resource dependencies; the operational-risk picture from SD-14.1; the third-party dependency map from SD-17.8; the data-platform resilience requirements consumed by SD-13.12.
- Outputs: the resilience framework, the impact tolerances, the continuity plans and the test results — consumed by every domain (as the resilience standard), SD-14.1, the governing bodies and the regulators.
Entities
- Consumes: the firm’s service, process and third-party records; the data-platform resilience requirements consumed by SD-13.12; the SD-14.1 operational-risk picture; the SD-17.8 third-party dependency map.
- Owns: the firm’s operational-resilience framework and continuity plans — a process artefact.
Standards
- The FCA / PRA operational-resilience rules — important business services and impact tolerances.
- DORA (the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554) — its digital-operational-resilience-testing requirements (Chapter IV) and ICT-third-party-risk-management requirements (Chapter V).
- ISO 22301 — the business-continuity-management-system baseline (the general-enterprise standard SD-14.6 adopts).
Open extensions
- The important-business-service mapping and impact-tolerance sub-model.
- The interaction with SD-14.1 (operational risk) and SD-14.5 (ICT security).
- The Service-Operation-level input/output contracts.