SlideShare ist ein Scribd-Unternehmen logo
1 von 15
Downloaden Sie, um offline zu lesen
Operational
Resilience
STRONGER,RESILIENT, BUSINESS DISRUPTION RESISTANT -
SYSTEMS
Operational
resilience
 Is the meeting point between risk management
systems and business continuity systems that serves to
identify, manage, respond and learn from as well as
implement mitigations to allow businesses to operate
comfortably at times when there is disruptive business
changes.
 Is the ability of firms and the financial sector as a
whole to prevent, adapt, respond to, recover and
learn from operational disruptions.
Operational
disruptions
Operational disruptions can have many causes including,
technology failures or changes to systems. Some
disruptions may also be caused by matters outside of a
firm's control, such as a cyber-attack or wider
telecommunications failure.
Ultimately, the aim is to increase firms’ operational
resilience and drive change where it is needed. Where
the weaknesses in operational resilience are identified,
firms will be expected to act. For example, by investing in
improving processes, better infrastructure or training,
building back-up systems, addressing vulnerabilities in
legacy systems or improving contingency plans.
So how do we make operational systems
more resilient ?
• Impact Assessments
• Important Business service mapping
• Outsourcing risk mapping and risk management
• Stress testing – modelling disaster scenario's
• A strong communications plan
• Lessons learned – from disaster modelling scenario's to mitigate operational resilience risks
Regulatory Perspective
What
outcome do
you want?
The aim of operational resilience is to increase a firms’
Business resilience and drive change where it is needed.
For example, increasing resilience can be done by
investing in improving processes, better infrastructure or
training, building back-up systems, addressing
vulnerabilities in legacy systems or improving contingency
plans.
We start from outcomes
Mapping
important
business
services
 Important business services – from an FCA regulatory
point of view are defined as critical services which
have a strong impact on customers – including
customer retention and access to key services such as
accounts.
 To stay operationally resilient, relevant
regulated businesses are expected to identify (map)
the key or important business services of this nature
that they offer from a selection of the business
activities they undertake on a day to day basis.
 This gives them a starting point on which services are
likely to be impacted and for which services the
disaster models and scenario testing and
impact tolerances are needed.
Impact
tolerance
An impact tolerance is a firm’s tolerance for disruption to
a particular business service. For many businesses,
disruption is part and parcel to business life.
It may not happen for a very long time but it is bound to
happen sometime.
HOW IS IT USED IN BUSINESS?

impact tolerance is expressed by referring to specific
outcomes and metrics. It is set at a level that prevents the
company from falling into long term or disastrous
disruptions to service.
This is done through metrics and outcomes based on
time, value and or products types and amount of
customers affected.
The idea is to set impact tolerances high rather than
lower to be able to effectively manage the risks attached
to business disruption. This is not the same as RAG rating or
risk scoring a business continuity plan.
Factors considered in setting impact tolerance include
• The number and types of consumers (vulnerability)
impacted and the nature of impact - e.g loss of
account services - lack of access to cash for four days
• Financial loss to consumers
• Financial loss of the type that poses a financial stability
risk
• The level of reputational damage sustained
• Impacts to market or consumer confidence
• The spread of risks to other business services or
products or across the sector
• Loss of function and access to consumers
• Loss of confidentiality, integrity or availability or data
Impact tolerance metrics
Impact tolerance metrics could be single or combination style.
Single or combinationstyle metrics couldbe used as a planning or
assurance tool.
Duration based metrics - on its own a single metric can be combined
with a volume or value (cost based) metric.
Duration metrics should always specify that disruption cannot exceed a
period of time. E.g. one business day without causing intolerable harm
to consumers or financial stability.
DURATION BASED VOLUME BASED
VALUE BASEED
Communications
Communication within risk management and
business continuity play a key role in maintaining
business operational resilience.
It's Important that Firms' policies include prompt and
meaningful communication arrangements for internal
and external parties, including regulators, consumers
and the media.
Firms are expected to have internal and external
communication strategies in place.

Internal communication plans
Firms internal communication plans should also include the escalation paths they
would use to manage communications during an incident, and identify the
appropriate decision makers. For example, the plan should address how to contact
key individuals,operational staff suppliers and the appropriate regulators.
As part of their external communications plans, the FCA expect firms to consider in
advance of a disruption how they would provide important warnings or advice
quickly to consumers and other stakeholders.
This includes where there is no direct line of communication. Firms are expected to
use effective communication to gather information about the cause, extent and
impact of operational incidents.
Governance
Board and senior management are expected to have oversight of and to be engaged in
setting the standards for operational resilience.
SM&CR
The SM&CR currently applies to banking firms and insurers and will apply to FCA solo-
Regulated firms from December 2019. Under the SM&CR ,individual that perform the Chief
Operations Function (SMF24)are required to have responsibility for managing the internal
operations or technology of the firm or of a part of the firm.
This includes ,but may not necessarily be limited to, responsibility for areas such as:
 business continuity
 operational continuity, resilience and strategy
 outsourcing, procurement and vendor management
Firms that have an individual performing the SMF24 function may find that responsibility for
implementing the proposals outlined within this CP falls within the Scope of the SMF24’s
responsibilities. MI sent to the board for regular review is part of the remit here.

Assurance /
Self
Assessment
it is important for firms to be able to demonstrate to the relevant
supervisory authority that they are meeting their responsibilities in
respect of operational resilience.
The FCA therefore proposes that firms should create a self-assessment
document. The self- assessment document should include:
The firm's important business services the impact tolerances set for
these important business services the firm's approach to
mapping,including how the firm has identified its resources, and how it
has used mapping to identify vulnerabilities and support scenario
testing
The firm’s strategy for testing its ability to deliver important business
services within impact tolerances through severe but plausible
scenarios, including a description of the scenarios used, the types of
testing undertaken and the scenarios under which firms could not
remain within their impact tolerances

Self
Assessment
Continued
An identification of the vulnerabilities that threaten thefirm's ability
to deliver its important business services within impact tolerances,
including the actions taken or planned, and justifications for their
completion time
The firm's lessons learned exercise
The methodologies used to undertaketheaboveactivities

The FCA also propose that boards, or the firm's equivalent
management body ,review and approvetheself-assessment
document regularly. Where changes occur that may havea clear
impact to the firm's operational resilience,
e.g structuralchangesto the firm, rapid expansion, poor trading or
entry into new markets, it remains important that more frequent
reviewsof the firm’s self-assessment document are held.
This will not form part of a regulatory report to be submitted to the
regulator's.

Outsourcing
Operationally resilient firms are expected to have a comprehensive understanding and
mapping of the resources that support their business services. This includes those outsourced
and third-party services over which the firm may not have direct control. They also expect
firms to be able to identify and document the resources that support their important business
services. This is because firms increasingly outsource important business services, due to data
driven innovation and tech developments. A lot of these outsourcers are outside the
regulatory perimeter - so there is a need for firms to be able to prevent, adapt, respond and
recover and learn from disruptive operational incidents.
For more on this topic contact
Ebere Ikerionwu
Go Spot It
Incillation ltd
E: ebere@incillation.com
T: 02080035962
W: https://www.incillation.com

Weitere ähnliche Inhalte

Was ist angesagt?

A to Z of Business Continuity Managment
A to Z of Business Continuity ManagmentA to Z of Business Continuity Managment
A to Z of Business Continuity ManagmentMark Conway
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management systemsubbusai82
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesSlideTeam
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Narudom Roongsiriwong, CISSP
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyNICSA
 
ERM Presentation
ERM PresentationERM Presentation
ERM PresentationH Contrex
 
Cyber Resilience: managing 3rd Party Risks in Financial Services
Cyber Resilience: managing 3rd Party Risks in Financial ServicesCyber Resilience: managing 3rd Party Risks in Financial Services
Cyber Resilience: managing 3rd Party Risks in Financial ServicesKevin Duffey
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity ManagementDiane Christina
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningBharath Rao
 
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxJayLloyd8
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301mascot4u
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recoverymadunix
 
We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?PECB
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity PlanningDipankar Ghosh
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan Emilie Gray
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IThhuihhui
 

Was ist angesagt? (20)

A to Z of Business Continuity Managment
A to Z of Business Continuity ManagmentA to Z of Business Continuity Managment
A to Z of Business Continuity Managment
 
Business continuity management system
Business continuity management systemBusiness continuity management system
Business continuity management system
 
Business Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation SlidesBusiness Continuity Management PowerPoint Presentation Slides
Business Continuity Management PowerPoint Presentation Slides
 
Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)Business continuity & disaster recovery planning (BCP & DRP)
Business continuity & disaster recovery planning (BCP & DRP)
 
Third-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a StrategyThird-Party Risk Management: Implementing a Strategy
Third-Party Risk Management: Implementing a Strategy
 
Business impact analysis
Business impact analysis Business impact analysis
Business impact analysis
 
ERM Presentation
ERM PresentationERM Presentation
ERM Presentation
 
Cyber Resilience: managing 3rd Party Risks in Financial Services
Cyber Resilience: managing 3rd Party Risks in Financial ServicesCyber Resilience: managing 3rd Party Risks in Financial Services
Cyber Resilience: managing 3rd Party Risks in Financial Services
 
Business Continuity Management
Business Continuity ManagementBusiness Continuity Management
Business Continuity Management
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptxBUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
BUSINESS-CONTINUITY-AND-DISASTER-RECOVERY.pptx
 
Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301Business impact.analysis based on ISO 22301
Business impact.analysis based on ISO 22301
 
BUSINESS CONTINUITY PLANNING
BUSINESS CONTINUITY PLANNINGBUSINESS CONTINUITY PLANNING
BUSINESS CONTINUITY PLANNING
 
Business continuity planning and disaster recovery
Business continuity planning and disaster recoveryBusiness continuity planning and disaster recovery
Business continuity planning and disaster recovery
 
Bcp
BcpBcp
Bcp
 
We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?We've been hacked! Now, what's the BCP?
We've been hacked! Now, what's the BCP?
 
BCP Awareness
BCP Awareness BCP Awareness
BCP Awareness
 
Business Continuity Planning
Business Continuity PlanningBusiness Continuity Planning
Business Continuity Planning
 
Disaster Recovery Plan
Disaster Recovery Plan Disaster Recovery Plan
Disaster Recovery Plan
 
Disaster Recovery Plan for IT
Disaster Recovery Plan for ITDisaster Recovery Plan for IT
Disaster Recovery Plan for IT
 

Ähnlich wie Operational resilience presentation 1 (1)

Enhancing and Sustaining Business Agility through Effective Vendor Resiliency
Enhancing and Sustaining Business Agility through Effective Vendor ResiliencyEnhancing and Sustaining Business Agility through Effective Vendor Resiliency
Enhancing and Sustaining Business Agility through Effective Vendor ResiliencyCognizant
 
Crafting a Robust Business-Continuity Strategy: Key Steps and Best Practices
Crafting a Robust Business-Continuity Strategy: Key Steps and Best PracticesCrafting a Robust Business-Continuity Strategy: Key Steps and Best Practices
Crafting a Robust Business-Continuity Strategy: Key Steps and Best PracticesBluechip Gulf IT Services
 
Business Continuity Management-The Case for Return on Investment-white paper
Business Continuity Management-The Case for Return on  Investment-white paperBusiness Continuity Management-The Case for Return on  Investment-white paper
Business Continuity Management-The Case for Return on Investment-white paperGreg Cybulski, CBCP, ARM
 
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management EcosystemDesigning Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystemaccenture
 
Healthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPHealthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPMohammed Al Ayoubi
 
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...Cognizant
 
TISA-Important-Business-Services-Guide-November-2021.pdf
TISA-Important-Business-Services-Guide-November-2021.pdfTISA-Important-Business-Services-Guide-November-2021.pdf
TISA-Important-Business-Services-Guide-November-2021.pdfAbdetaImi
 
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIES
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIESBUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIES
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIESMark Evans
 
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...CIOWomenMagazine
 
A Proactive Approach to Business Continuity
A Proactive Approach to Business ContinuityA Proactive Approach to Business Continuity
A Proactive Approach to Business ContinuityDiana DePaola
 
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...Covance
 
FINRA 2015 Regulatory and Examination priorities
FINRA 2015 Regulatory and Examination prioritiesFINRA 2015 Regulatory and Examination priorities
FINRA 2015 Regulatory and Examination prioritiesCliff Busse
 
Goldman Sachs Investor Presentation Deck Oct 2007.pdf
Goldman Sachs Investor Presentation Deck Oct 2007.pdfGoldman Sachs Investor Presentation Deck Oct 2007.pdf
Goldman Sachs Investor Presentation Deck Oct 2007.pdfBryann Alexandros
 
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015Claire Louis
 
Operational Resilience
Operational ResilienceOperational Resilience
Operational ResilienceGieomlabs
 
Bussiness continuity
Bussiness continuityBussiness continuity
Bussiness continuityatharabbas
 
T-Lessons_from_the_Trenches-_quality_digest_article
T-Lessons_from_the_Trenches-_quality_digest_articleT-Lessons_from_the_Trenches-_quality_digest_article
T-Lessons_from_the_Trenches-_quality_digest_articleDerrell James
 

Ähnlich wie Operational resilience presentation 1 (1) (20)

Enhancing and Sustaining Business Agility through Effective Vendor Resiliency
Enhancing and Sustaining Business Agility through Effective Vendor ResiliencyEnhancing and Sustaining Business Agility through Effective Vendor Resiliency
Enhancing and Sustaining Business Agility through Effective Vendor Resiliency
 
Crafting a Robust Business-Continuity Strategy: Key Steps and Best Practices
Crafting a Robust Business-Continuity Strategy: Key Steps and Best PracticesCrafting a Robust Business-Continuity Strategy: Key Steps and Best Practices
Crafting a Robust Business-Continuity Strategy: Key Steps and Best Practices
 
Business Continuity Management-The Case for Return on Investment-white paper
Business Continuity Management-The Case for Return on  Investment-white paperBusiness Continuity Management-The Case for Return on  Investment-white paper
Business Continuity Management-The Case for Return on Investment-white paper
 
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management EcosystemDesigning Enhanced Supervision for the Evolving Wealth Management Ecosystem
Designing Enhanced Supervision for the Evolving Wealth Management Ecosystem
 
Healthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCPHealthcare Business Continuity Planning - BCP
Healthcare Business Continuity Planning - BCP
 
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
Enterprise Risk Management: Minimizing Exposure, Fostering Innovation and Acc...
 
TISA-Important-Business-Services-Guide-November-2021.pdf
TISA-Important-Business-Services-Guide-November-2021.pdfTISA-Important-Business-Services-Guide-November-2021.pdf
TISA-Important-Business-Services-Guide-November-2021.pdf
 
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIES
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIESBUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIES
BUSINESS RISK IN MEDIUM & LARGE SCALE CORPORATE ENTITIES
 
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
Strategies for Business Continuity_ Navigating Challenges and Ensuring Resili...
 
A Proactive Approach to Business Continuity
A Proactive Approach to Business ContinuityA Proactive Approach to Business Continuity
A Proactive Approach to Business Continuity
 
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...
Pharmacovigilance Smart Sourcing Strategy: Vendor Selection for Safety & Risk...
 
How Audit Committees Can Help with Third-Party Risks
How Audit Committees Can Help with Third-Party RisksHow Audit Committees Can Help with Third-Party Risks
How Audit Committees Can Help with Third-Party Risks
 
FINRA 2015 Regulatory and Examination priorities
FINRA 2015 Regulatory and Examination prioritiesFINRA 2015 Regulatory and Examination priorities
FINRA 2015 Regulatory and Examination priorities
 
Chris Gould - BCM case
Chris Gould - BCM caseChris Gould - BCM case
Chris Gould - BCM case
 
Goldman Sachs Investor Presentation Deck Oct 2007.pdf
Goldman Sachs Investor Presentation Deck Oct 2007.pdfGoldman Sachs Investor Presentation Deck Oct 2007.pdf
Goldman Sachs Investor Presentation Deck Oct 2007.pdf
 
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015
Capgemini Consulting Claims Ops Model Alignment Program 3 13 2015
 
Operational Resilience
Operational ResilienceOperational Resilience
Operational Resilience
 
Turnaround strategy
Turnaround strategyTurnaround strategy
Turnaround strategy
 
Bussiness continuity
Bussiness continuityBussiness continuity
Bussiness continuity
 
T-Lessons_from_the_Trenches-_quality_digest_article
T-Lessons_from_the_Trenches-_quality_digest_articleT-Lessons_from_the_Trenches-_quality_digest_article
T-Lessons_from_the_Trenches-_quality_digest_article
 

Kürzlich hochgeladen

Continuous Improvement Posters for Learning
Continuous Improvement Posters for LearningContinuous Improvement Posters for Learning
Continuous Improvement Posters for LearningCIToolkit
 
situational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Ssituational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Smisbafathima9940
 
GENUINE Babe,Call Girls IN Baderpur Delhi | +91-8377087607
GENUINE Babe,Call Girls IN Baderpur  Delhi | +91-8377087607GENUINE Babe,Call Girls IN Baderpur  Delhi | +91-8377087607
GENUINE Babe,Call Girls IN Baderpur Delhi | +91-8377087607dollysharma2066
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxalinstan901
 
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort ServiceDelhi Call girls
 
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Hedda Bird
 
Reviewing and summarization of university ranking system to.pptx
Reviewing and summarization of university ranking system  to.pptxReviewing and summarization of university ranking system  to.pptx
Reviewing and summarization of university ranking system to.pptxAss.Prof. Dr. Mogeeb Mosleh
 
Construction Project Management | Coursera 2024
Construction Project Management | Coursera 2024Construction Project Management | Coursera 2024
Construction Project Management | Coursera 2024Alex Marques
 
Continuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningContinuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningCIToolkit
 
Day 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampDay 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampPLCLeadershipDevelop
 
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Pooja Nehwal
 

Kürzlich hochgeladen (20)

Continuous Improvement Posters for Learning
Continuous Improvement Posters for LearningContinuous Improvement Posters for Learning
Continuous Improvement Posters for Learning
 
situational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima Ssituational leadership theory by Misba Fathima S
situational leadership theory by Misba Fathima S
 
GENUINE Babe,Call Girls IN Baderpur Delhi | +91-8377087607
GENUINE Babe,Call Girls IN Baderpur  Delhi | +91-8377087607GENUINE Babe,Call Girls IN Baderpur  Delhi | +91-8377087607
GENUINE Babe,Call Girls IN Baderpur Delhi | +91-8377087607
 
Empowering Local Government Frontline Services - Mo Baines.pdf
Empowering Local Government Frontline Services - Mo Baines.pdfEmpowering Local Government Frontline Services - Mo Baines.pdf
Empowering Local Government Frontline Services - Mo Baines.pdf
 
Agile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptxAgile Coaching Change Management Framework.pptx
Agile Coaching Change Management Framework.pptx
 
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort ServiceBDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort Service
BDSM⚡Call Girls in Sector 99 Noida Escorts >༒8448380779 Escort Service
 
Intro_University_Ranking_Introduction.pptx
Intro_University_Ranking_Introduction.pptxIntro_University_Ranking_Introduction.pptx
Intro_University_Ranking_Introduction.pptx
 
Imagine - HR; are handling the 'bad banter' - Stella Chandler.pdf
Imagine - HR; are handling the 'bad banter' - Stella Chandler.pdfImagine - HR; are handling the 'bad banter' - Stella Chandler.pdf
Imagine - HR; are handling the 'bad banter' - Stella Chandler.pdf
 
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...Dealing with Poor Performance - get the full picture from 3C Performance Mana...
Dealing with Poor Performance - get the full picture from 3C Performance Mana...
 
Reviewing and summarization of university ranking system to.pptx
Reviewing and summarization of university ranking system  to.pptxReviewing and summarization of university ranking system  to.pptx
Reviewing and summarization of university ranking system to.pptx
 
Peak Performance & Resilience - Dr Dorian Dugmore
Peak Performance & Resilience - Dr Dorian DugmorePeak Performance & Resilience - Dr Dorian Dugmore
Peak Performance & Resilience - Dr Dorian Dugmore
 
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdfImagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
Imagine - Creating Healthy Workplaces - Anthony Montgomery.pdf
 
Construction Project Management | Coursera 2024
Construction Project Management | Coursera 2024Construction Project Management | Coursera 2024
Construction Project Management | Coursera 2024
 
Continuous Improvement Infographics for Learning
Continuous Improvement Infographics for LearningContinuous Improvement Infographics for Learning
Continuous Improvement Infographics for Learning
 
LoveLocalGov - Chris Twigg, Inner Circle
LoveLocalGov - Chris Twigg, Inner CircleLoveLocalGov - Chris Twigg, Inner Circle
LoveLocalGov - Chris Twigg, Inner Circle
 
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg PartnershipUnlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
Unlocking the Future - Dr Max Blumberg, Founder of Blumberg Partnership
 
Disrupt or be Disrupted - Kirk Vallis.pdf
Disrupt or be Disrupted - Kirk Vallis.pdfDisrupt or be Disrupted - Kirk Vallis.pdf
Disrupt or be Disrupted - Kirk Vallis.pdf
 
Day 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC BootcampDay 0- Bootcamp Roadmap for PLC Bootcamp
Day 0- Bootcamp Roadmap for PLC Bootcamp
 
Leadership in Crisis - Helio Vogas, Risk & Leadership Keynote Speaker
Leadership in Crisis - Helio Vogas, Risk & Leadership Keynote SpeakerLeadership in Crisis - Helio Vogas, Risk & Leadership Keynote Speaker
Leadership in Crisis - Helio Vogas, Risk & Leadership Keynote Speaker
 
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
Call now : 9892124323 Nalasopara Beautiful Call Girls Vasai virar Best Call G...
 

Operational resilience presentation 1 (1)

  • 2. Operational resilience  Is the meeting point between risk management systems and business continuity systems that serves to identify, manage, respond and learn from as well as implement mitigations to allow businesses to operate comfortably at times when there is disruptive business changes.  Is the ability of firms and the financial sector as a whole to prevent, adapt, respond to, recover and learn from operational disruptions.
  • 3. Operational disruptions Operational disruptions can have many causes including, technology failures or changes to systems. Some disruptions may also be caused by matters outside of a firm's control, such as a cyber-attack or wider telecommunications failure. Ultimately, the aim is to increase firms’ operational resilience and drive change where it is needed. Where the weaknesses in operational resilience are identified, firms will be expected to act. For example, by investing in improving processes, better infrastructure or training, building back-up systems, addressing vulnerabilities in legacy systems or improving contingency plans.
  • 4. So how do we make operational systems more resilient ? • Impact Assessments • Important Business service mapping • Outsourcing risk mapping and risk management • Stress testing – modelling disaster scenario's • A strong communications plan • Lessons learned – from disaster modelling scenario's to mitigate operational resilience risks Regulatory Perspective
  • 5. What outcome do you want? The aim of operational resilience is to increase a firms’ Business resilience and drive change where it is needed. For example, increasing resilience can be done by investing in improving processes, better infrastructure or training, building back-up systems, addressing vulnerabilities in legacy systems or improving contingency plans. We start from outcomes
  • 6. Mapping important business services  Important business services – from an FCA regulatory point of view are defined as critical services which have a strong impact on customers – including customer retention and access to key services such as accounts.  To stay operationally resilient, relevant regulated businesses are expected to identify (map) the key or important business services of this nature that they offer from a selection of the business activities they undertake on a day to day basis.  This gives them a starting point on which services are likely to be impacted and for which services the disaster models and scenario testing and impact tolerances are needed.
  • 7. Impact tolerance An impact tolerance is a firm’s tolerance for disruption to a particular business service. For many businesses, disruption is part and parcel to business life. It may not happen for a very long time but it is bound to happen sometime. HOW IS IT USED IN BUSINESS?  impact tolerance is expressed by referring to specific outcomes and metrics. It is set at a level that prevents the company from falling into long term or disastrous disruptions to service. This is done through metrics and outcomes based on time, value and or products types and amount of customers affected. The idea is to set impact tolerances high rather than lower to be able to effectively manage the risks attached to business disruption. This is not the same as RAG rating or risk scoring a business continuity plan.
  • 8. Factors considered in setting impact tolerance include • The number and types of consumers (vulnerability) impacted and the nature of impact - e.g loss of account services - lack of access to cash for four days • Financial loss to consumers • Financial loss of the type that poses a financial stability risk • The level of reputational damage sustained • Impacts to market or consumer confidence • The spread of risks to other business services or products or across the sector • Loss of function and access to consumers • Loss of confidentiality, integrity or availability or data
  • 9. Impact tolerance metrics Impact tolerance metrics could be single or combination style. Single or combinationstyle metrics couldbe used as a planning or assurance tool. Duration based metrics - on its own a single metric can be combined with a volume or value (cost based) metric. Duration metrics should always specify that disruption cannot exceed a period of time. E.g. one business day without causing intolerable harm to consumers or financial stability. DURATION BASED VOLUME BASED VALUE BASEED
  • 10. Communications Communication within risk management and business continuity play a key role in maintaining business operational resilience. It's Important that Firms' policies include prompt and meaningful communication arrangements for internal and external parties, including regulators, consumers and the media. Firms are expected to have internal and external communication strategies in place. 
  • 11. Internal communication plans Firms internal communication plans should also include the escalation paths they would use to manage communications during an incident, and identify the appropriate decision makers. For example, the plan should address how to contact key individuals,operational staff suppliers and the appropriate regulators. As part of their external communications plans, the FCA expect firms to consider in advance of a disruption how they would provide important warnings or advice quickly to consumers and other stakeholders. This includes where there is no direct line of communication. Firms are expected to use effective communication to gather information about the cause, extent and impact of operational incidents.
  • 12. Governance Board and senior management are expected to have oversight of and to be engaged in setting the standards for operational resilience. SM&CR The SM&CR currently applies to banking firms and insurers and will apply to FCA solo- Regulated firms from December 2019. Under the SM&CR ,individual that perform the Chief Operations Function (SMF24)are required to have responsibility for managing the internal operations or technology of the firm or of a part of the firm. This includes ,but may not necessarily be limited to, responsibility for areas such as:  business continuity  operational continuity, resilience and strategy  outsourcing, procurement and vendor management Firms that have an individual performing the SMF24 function may find that responsibility for implementing the proposals outlined within this CP falls within the Scope of the SMF24’s responsibilities. MI sent to the board for regular review is part of the remit here. 
  • 13. Assurance / Self Assessment it is important for firms to be able to demonstrate to the relevant supervisory authority that they are meeting their responsibilities in respect of operational resilience. The FCA therefore proposes that firms should create a self-assessment document. The self- assessment document should include: The firm's important business services the impact tolerances set for these important business services the firm's approach to mapping,including how the firm has identified its resources, and how it has used mapping to identify vulnerabilities and support scenario testing The firm’s strategy for testing its ability to deliver important business services within impact tolerances through severe but plausible scenarios, including a description of the scenarios used, the types of testing undertaken and the scenarios under which firms could not remain within their impact tolerances 
  • 14. Self Assessment Continued An identification of the vulnerabilities that threaten thefirm's ability to deliver its important business services within impact tolerances, including the actions taken or planned, and justifications for their completion time The firm's lessons learned exercise The methodologies used to undertaketheaboveactivities  The FCA also propose that boards, or the firm's equivalent management body ,review and approvetheself-assessment document regularly. Where changes occur that may havea clear impact to the firm's operational resilience, e.g structuralchangesto the firm, rapid expansion, poor trading or entry into new markets, it remains important that more frequent reviewsof the firm’s self-assessment document are held. This will not form part of a regulatory report to be submitted to the regulator's. 
  • 15. Outsourcing Operationally resilient firms are expected to have a comprehensive understanding and mapping of the resources that support their business services. This includes those outsourced and third-party services over which the firm may not have direct control. They also expect firms to be able to identify and document the resources that support their important business services. This is because firms increasingly outsource important business services, due to data driven innovation and tech developments. A lot of these outsourcers are outside the regulatory perimeter - so there is a need for firms to be able to prevent, adapt, respond and recover and learn from disruptive operational incidents. For more on this topic contact Ebere Ikerionwu Go Spot It Incillation ltd E: ebere@incillation.com T: 02080035962 W: https://www.incillation.com