The board's role in resilience: oversight, appetite and the right questions
Resilience oversight is the board's share of business continuity: deciding how much disruption the company may accept, naming the one executive who answers for it, and verifying — through reports, exercises and audit — that the answer still holds. The board directs and checks; management builds and runs.
A board matter, not an IT matter
When a payment service, a refinery control room or a hospital admissions system stops for a day, the damage lands on the assets a board holds in trust: the balance sheet, the customer franchise and the licence to operate. Directors' duty of care has always extended to foreseeable harm, and a prolonged outage of a critical service is today among the most foreseeable harms a company faces. Regulators have stopped implying this and started writing it. The governance clauses of NCEMA 7000, the UAE business continuity standard, assign accountability for the programme to top management by name and expect it to approve policy and review results. The Central Bank of the UAE expects boards of licensed institutions to own operational and business continuity risk, not merely to be briefed on it. In Europe, DORA makes the management body — the board and executive committee — bear final responsibility for digital operational resilience, down to a personal obligation to keep their own knowledge current. Handing resilience wholesale to the IT department is therefore not a matter of style; it is a governance gap a supervisor can cite by clause number.
What the board must own
Three decisions cannot be delegated below the boardroom.
The appetite for disruption. The board approves how much disruption the company will tolerate — expressed as impact tolerances for each key service: the hours of outage, the volume of failed transactions, the point at which harm to customers becomes unacceptable. How to construct and defend that statement is a discipline of its own, covered in our risk appetite guide.
One accountable executive. A named person — not a committee, not a shared mandate — who answers to the board for resilience across the whole organisation, with the budget and the authority to match. Where accountability is collective, exercises slip and findings age quietly.
The three lines of defence, applied to resilience. Operating management owns and runs continuity as the first line; the risk function sets the framework and challenges as the second; internal audit independently verifies as the third. The board should hear from all three — a report that has never passed through the second or third line is a self-assessment, not assurance.
The board approves the appetite; management turns it into limits and recovery targets — and breaches escalate back up.
Oversight, not management
The fastest way for a board to fail at resilience is to try to run it. The board does not write continuity plans, design scenarios, facilitate exercises or select recovery technology; those belong to the executive team and its programme. The board's two verbs are direct — approve the appetite, appoint the accountable executive, require an exercise calendar and an annual review — and verify: read the reports, probe the results, commission independent assurance, and return to the subject after every incident rather than only at the scheduled slot. The distinction is practical, not ceremonial. A board that edits plans has made itself part of the first line, and then no one is left to check its work.
The four disciplines of the continuity cycle are management's work. The board verifies that the cycle turns and that its results reach the boardroom.
Seven questions a director should ask management
Oversight is exercised through questions. These seven require no technical vocabulary, and an evasive answer to any of them is itself a finding.
"Which of our services would hurt customers within hours if they stopped?" If management cannot name them in one breath, the analysis has not been done.
"What is our tolerance for each — and when did we last test to that tolerance?" A tolerance never tested against is a wish, not a boundary.
"What did the last exercise fail, and what changed as a result?" An exercise programme that never fails anything is not exercising; it is rehearsing applause.
"What does one day of downtime cost us — in money, customers and licence?" The number anchors every later debate about the resilience budget.
"Who decides in the first hour, and does that person know it?" Disruptions are lost in the gap between the incident and the first decision.
"When did this board last see a resilience report, and what did we do with it?" If the honest answer is "over a year ago" or "we noted it", oversight exists on paper only.
"If the regulator arrived tomorrow, what would they find?" The answer should come from the second and third lines, not from the team being inspected.
What comes back to the board matters as much as what it asks. The format and metrics of a board-grade resilience report — one page, tolerances against test results, findings and their age — are covered separately in operational resilience reporting for boards. For directors and executives who want the full governance architecture — appetite, accountability, assurance — Module 1 of the ERGP programme is devoted to resilience governance and the board's role in it.
This topic is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.