Regulators discovered that firms with perfect continuity documents still hurt customers when key services failed. Operational resilience answers a sharper question: which services must not fail beyond a defined point, whatever the cause? It shifts attention from protecting assets and sites to protecting the outcomes customers and markets depend on. For a board, it converts resilience from a vague virtue into named services with hard limits.
The approach is prescribed by regulators, including the Bank of England, the FCA and, in the Gulf, CBUAE for financial institutions. Management identifies important business services, sets an impact tolerance for each, for example payments restored within 4 hours, and tests them against severe but plausible scenarios. The results are documented in a board-approved self-assessment that supervisors may inspect. A bank might map 9 important business services and find that two cannot yet stay within tolerance; that gap list becomes the investment agenda.
A frequent error is treating operational resilience as a rebadged BCM programme and mapping hundreds of processes instead of a handful of services. The regime works only when the service list is short and each tolerance is a real commitment tested annually. Firms that start from customer harm, not from org charts, reach defensible results faster. In the ERGP programme, a chapter of Module 5 on regulation walks through operational resilience regimes, including CBUAE's.
Operational resilience became a supervisory term rather than an industry one. The Basel Committee published its Principles for Operational Resilience in March 2021, defining it as the ability to deliver critical operations through disruption. In the United Kingdom the Prudential Regulation Authority and the Financial Conduct Authority require firms to identify important business services, set impact tolerances for each and remain within them, with the regime phased in from March 2022. In the European Union the Digital Operational Resilience Act applies from January 2025 and extends similar obligations to information and communication technology risk, including oversight of critical third-party providers. Supervisors in the Gulf have adopted the same vocabulary in their business continuity and operational risk requirements.
The common thread is a shift of the unit of analysis. Traditional requirements asked whether systems and sites could recover. Operational resilience asks whether the service a customer depends on stays inside a tolerance, regardless of which component failed.
| Aspect | Business continuity | Operational resilience |
|---|---|---|
| Unit of analysis | Processes, sites and systems | Important business services delivered to customers |
| Central question | Can we recover | Can we stay inside a tolerance while failing |
| Assumption | Disruption is exceptional | Disruption will happen, design for it |
| Key measure | Recovery time objective | Impact tolerance for the service |
| Scope of testing | Recovery of a component | Severe but plausible scenarios across the whole service chain |
| Third parties | Contract requirements | Mapped as part of the service, tested and substitutable |
The two are not alternatives. Business continuity supplies the machinery: impact analysis, plans, exercises, recovery. Operational resilience supplies the frame that decides where that machinery is pointed and how good is good enough.
What is operational resilience in simple terms? The ability to keep delivering the services customers depend on while parts of the organisation are failing, rather than the ability to recover after they have failed.
Is operational resilience the same as business continuity? No. Business continuity is a discipline focused on recovering processes and resources. Operational resilience is a broader outcome measured at the level of the customer-facing service, with business continuity as one of its inputs.
What is an impact tolerance? The maximum level of disruption to an important business service that the organisation is willing to accept, set by the board and expressed in measurable terms.
Who owns operational resilience? The board owns the tolerances and the outcome. Accountability for each important business service sits with a named executive, supported by continuity, technology, security and third-party management.
Where do the requirements come from? Principally the Basel Committee Principles for Operational Resilience, the United Kingdom regime run by the Prudential Regulation Authority and the Financial Conduct Authority, and in the European Union the Digital Operational Resilience Act. Regional supervisors, including those in the Gulf, apply the same concepts within their own frameworks.
This term is part of the working language of ERGP — the first resilience governance certification fully available in Arabic, also in English. 94 chapters, six modules, a verifiable certificate.
Explore the ERGP programme