Operational resilience, as a concept, is receiving a lot of attention. A combination of COVID, increased concern over the intensification, likelihood, and magnitude of major shocks, and the attention given to operational resilience by financial services regulators has placed it firmly on the corporate agenda.
Resilience derives from the Latin word ‘resilire’, which means to recoll or rebound. Operational resilience is considered “the ability of an organization to absorb and adapt in a changing environment,” (Alexander, 2023). It is considered an organizational trait that allows it to carry out its mission or business despite the presence of operational stress and disruption.
Operational resilience is considered to be the organization’s ability to handle and control external factors that may hinder it from functioning.
Turning to the financial services world, it is defined as “the ability of a bank to deliver critical operations through disruption,” (Bank of England Prudential Regulation Authority, 2022).
In the following the key components of operational resilience will be described, the steps for determining impact tolerances will be presented and, finally, some guidelines for monitoring impact tolerances will be discussed.
Key components of operational resilience
In figure one the key components of operational resilience are depicted. These five actions (prevention, robustness, recovery, adaption, and learning) have to be part of the company’s values and principles which are used on a continuous process within the organization: “They have to permeate through the company’s organizational culture,” (Alexander, 2023).

How to define and set impact tolerances
Once the strategic level in the organization has decided to implement an operational resilience management system, they should follow a methodological approach which will allow the organization to move forward in an effective and efficient way.
The first step is the identification of key business services. Organizations must define their most important products and services and then the impact tolerances for each.
Impact tolerances are very important metrics that define the point (in time, money, or other impacts) at which the consequences of a disruption become intolerable.
For example: “Impact tolerances could include the amount of revenue or customers the company is prepared to lose, or transactions that could go unfulfilled during a disruption. For an airline, an impact tolerance might be cancelled flights. For a healthcare entity the impact tolerance might be untreated patients,” (Aztek, 2022). It’s up to each organization to determine the impacts that they can tolerate from a disruption.
The setting of impact tolerances includes four defined steps:
Identify key business services
A prerequisite to starting work on impact tolerances is to identify, at an organizational level, at least one important business service. A methodological way to approach this would be to identify the full universe of business services that an organization delivers to its customers and then use clear criteria to shortlist those which are ‘important’. It is very important to be clear what an important business service is. An “important business service is an outcome the organization delivers, which if disrupted, could cause catastrophic consequences for the market, organization and /or the most vulnerable customers,” (Griffith, 2023). The impact tolerance for an important business service is the maximum tolerable level of disruption (MTLD), developed in consideration with the maximum duration of a disruption.
An important business service means a service provided by a firm to an external end user, where a disruption to the provision of the service could cause intolerable harm to consumers or market participants; harm market integrity; threaten policyholder protection, safety and soundness, or financial stability.
A way to approach the identification of important business services is to ask the following question: “Does the absence of this business service…
- Create market disruption with catastrophic consequences for other market participants and large groups of people?
- Create catastrophic consequences and unacceptable harm to customers?
- Potentially threaten the organization’s viability?
At this stage organizations should map all the resources and components needed to perform each service, including facilities, people, teams, equipment and infrastructure, IT applications, and internal and external service providers. The impact to the overall service needs to be considered if any one of these resources or components were removed or severely disrupted. When mapping services, time should be given to cross-referencing resources and components common to many services. This mapping will help to identify vulnerabilities in operations; and possibly help to address them. When addressing vulnerabilities, it’s essential not only to consider the importance of the services for which a vulnerability exists but also to consider whether a single vulnerability exists for many services.
By knowing what’s important, what’s vulnerable, and where disruption could cause the most harm or have the most widespread effect, investment priorities and strategic and tactical decisions can be taken.
Baseline data collection
Once an important business service has been selected and mapped out, the organization needs to establish what constitutes business as usual functioning for that business service. This involves considering possible metrics that can describe the typical functioning of the business service through measuring both outcomes and the resources to deliver the service (i.e. inputs). Agreeing a shortlist of appropriate metrics at this stage is key as they will form the basis on which impact tolerances will be set.
Set impact tolerances
Setting impact tolerances is an art! As discussed above, an impact tolerance should reflect the timeframe that the organization believes is the point in time following a disruption to an important business service that will likely result in intolerable impacts to customers, the broader market, or irrevocably threaten the organization’s viability.
The impact tolerance should specify that a particular important business service must not be disrupted beyond a certain period or point in time. Other relevant metrics, such as cost, regulatory breach, or client or service volumes, also need to be considered. Impact tolerances should also consider peak times or periods of increased activity where impact may become evident more quickly.
Both risk appetite and impact tolerance are essential in supporting the organization’s operational and financial resilience, but aligning impact tolerances to important business services will give a better indication of where investments need to be made. It will also help to determine which vulnerabilities need to be addressed to ensure the organization’s ability to continue to deliver within the impact tolerances despite – and throughout – a severe disruption.
Scenario testing
Testing is crucial to assess an organization’s impact tolerances and determine if its incident response is able to ensure that the organization can recover the business service within the impact tolerance that has been defined.
Testing also gives the organization a clear understanding of the ‘severe but plausible scenarios’ that it can use to exercise and measure its operational resilience capabilities.
The process of performing scenario testing is composed of five sequential steps:
Define scenarios: a range of realistic scenarios representing potential operational disruptions need to be identified. Several factors should be considered, such as cyber attacks, natural disasters, system failures, supply chain disruptions, and regulatory changes.
Assess impact: evaluate the potential impact of each scenario on important business services, systems, processes, and stakeholders. Consider financial, operational, reputational, and customer impacts.
Conduct testing: simulate each scenario and observe how the organization’s operational resilience measures and response plans perform as the scenario plays out. This may involve tabletop exercises, simulations, or real-time testing of specific systems or processes.
Evaluate responses: analyze the organization’s response to each scenario, including the effectiveness of incident management, communication, and recovery strategies. Identify strengths, weaknesses, and areas for improvement.
Document the lessons learned: document the lessons learned from each scenario test, including successful strategies, areas of improvement, and recommendations for enhancing operational resilience.
It’s very important to keep in mind that, however the scenario gets tested, the objective is not to assess whether crisis or business continuity plans are effective (though that might also be assessed); it’s to determine whether impact tolerances can be achieved. It could be found that for some severe but plausible scenarios, the recovery time objective of those plans cannot be achieved, but impact tolerance can.
Impact tolerances and the board
The responsibility for the implementation and control of operational resilience in the company is at the corporate level: ownership sits with the board and senior management.
Boards are specifically required to approve the important business services identified for their firm and the impact tolerances that have been set for each of these. In delivering this responsibility, boards must regularly review assessments of the organization’s important business services, impact tolerances, and the scenario analyses of its ability to remain within the impact tolerance for these important business services.
An organization’s board has the ultimate responsibility for the approval and oversight of the operational resilience framework. Leadership from the top down should ensure that resilience is intrinsically built into an organization’s strategic decisions, allowing boards to prioritize activities and target investment towards making critical or important business services more resilient. A top-down approach to operational resilience creates a uniform process flow and enhances clarity on responsibilities throughout the organization. This enables the organization to conduct business within its approved impact tolerances.
The criteria for the identification of critical or important business services should be reviewed and approved by the board annually or at the time of implementing material changes to the business – where additional critical or important business services could be introduced.
A board should review and approve impact tolerances at least annually, or when a disruption occurs, to determine whether the original approved impact tolerances are still fit for purpose.
An organization’s board should review the results of all scenario testing carried out on critical or important business services. If scenario testing identifies a situation where impact tolerances may be breached then it would be the responsibility of the board and senior management to take action to improve the resilience of the business service and focus investment where needed.
The author
Dr. Alberto G. Alexander holds a Ph.D from The University of Kansas and a M.A. from Northern Michigan University. He is a MBCI, BCMS IRCA Lead Auditor and Approved Tutor. He is the managing director of the international consulting and managerial training firm: Eficiencia Gerencial y Productividad SAC, located in Lima, Peru. He can be contacted at: alexander@egpsac.com He is currently Professor at the Graduate Business School of ESAN University, Lima, Peru.
References
- Alexander, G. Alberto. Managing Operational Resilience Resilienceforward.com, Nov 2023.
- K. Scott Griffith. The Leaders Guide to Managing Risk: a Proven Method to Build Resilience and Reliability. Harper Collins, Nov 2023.
- AZTEC Group. Building Resilience: The key to the Continuity and Long-Term Success of your Business. 2022.
- Bank of England Prudential Regulation Authority, 2022.






