Two disciplines, one confusion

Not the same thing: resilience vs continuity

Business continuity asks: if this site, system or supplier fails, how do we recover it? Operational resilience asks: whatever fails, does the service our clients rely on stay within the level of harm we said we could tolerate? One produces plans and recovery targets. The other is a supervised regulatory outcome. UK firms need both, and they are not interchangeable.

Side by side

The differences that actually matter

Most comparisons of these two terms are written by continuity practitioners for continuity practitioners. This one is grounded in the UK rules, because for a regulated firm the rules are where the distinction bites.

Dimension Business continuity Operational resilience
What it produces Plans: documented recovery procedures for sites, systems, people and suppliers, ready to invoke when something fails. Outcomes: important business services that demonstrably stay within a stated level of harm through disruption, plans or no plans.
How it measures Recovery time objectives and recovery point objectives, set per system or process: how quickly it comes back, how much data can be lost. Impact tolerances, set per important business service: the maximum tolerable disruption to clients and market, owned by the board.
Where the rules come from ISO 22301, a voluntary international management system standard a firm chooses to adopt and may certify against. PRA supervisory statement SS1/21 and the FCA's SYSC 15A rules, binding on in-scope UK financial services firms since PS21/3.
Who checks A certification body audits conformity with the standard, if the firm certifies at all. Supervisors. The FCA and PRA review self-assessments and testing evidence as part of ongoing supervision, with enforcement behind them.
The unit of analysis The site, the system, the supplier: continuity asks what happens when this asset fails. The business service as clients experience it, end to end across every resource it depends on, third parties included.
How it tests Plan exercising: walk through or simulate the plan to confirm it can be executed as written. Severe but plausible scenario testing: assume the disruption happens and establish whether the service stays within its impact tolerance.

The boundary line

Where continuity ends and resilience begins

Continuity's natural endpoint is a tested plan: for each site, system and critical supplier, a documented route back to normal inside an agreed recovery time. That is genuinely valuable work, and nothing here diminishes it.

Resilience begins with the question continuity never asks: so what? If the payments platform recovers in six hours, is six hours of failed client payments tolerable? Who decided, on what evidence, and would the answer survive a severe but plausible scenario rather than the tidy single-system failure the plan assumed? Those are questions about outcomes and harm, they belong to the board, and they are the substance of operational resilience as UK regulators define it.

The uncomfortable case

Why a certified BC plan can still fail supervision

Picture a firm with a mature, certified continuity programme: current plans, annual exercises, clean audits. Under supervision it can still come up short, for reasons the certificate never tested. Its recovery targets were set system by system, so nobody can show that the end-to-end service meets a tolerance judged on client harm. Its exercises rehearsed the plan working, not the severe case where the workaround site and the primary supplier fail together. And its third-party coverage stops at the contract, with no mapping of which services a provider's failure would actually take down.

None of that is a failure of continuity practice. It is a category difference: certification evidences that a management system conforms to a standard, while the FCA's rules and SS1/21 demand evidence that specific services stay within specific tolerances. A firm can hold the first and be unable to show the second.

Component, not synonym

How the two work together

The clean way to hold both in your head: resilience sets the requirement, continuity helps deliver it. The impact tolerance on a service tells you what its supporting recovery capabilities must achieve; the continuity plans, workarounds and alternate arrangements are among the resources that get the service back inside tolerance when disruption lands.

In practice that means continuity artefacts get re-pointed rather than rewritten. Recovery targets are re-derived from tolerances instead of system criticality scores, plan scope follows the service map instead of the site list, and exercising feeds the resilience testing calendar. Firms that treat the two as rival programmes end up funding both and evidencing neither; firms that wire continuity into the resilience framework get one coherent story for supervisors.

The cadence question

How often should business continuity plans be tested?

The honest answer: exercise each plan at least annually, and again whenever something material changes, a new system, a new site, a changed supplier, a reorganisation that moves the people the plan names. An annual walk-through of a plan nobody has touched since the last one is the minimum, not the goal; vary the format between desktop walk-throughs and fuller simulations so the plan is stressed, not recited.

For a regulated firm, though, plan exercising is only half the testing obligation. Resilience testing goes further: it assumes the disruption happens, plans included or not, and asks whether the important business service stays within its impact tolerance under a severe but plausible scenario. That is a different exercise with a different output, and it is the one supervisors read. Our scenario testing guide covers how the two fit into one calendar, and what a defensible severe but plausible scenario looks like.

Quick answers

Resilience vs continuity questions, answered

Is operational resilience replacing business continuity?

No. Operational resilience absorbs business continuity rather than replacing it: your continuity plans and recovery capabilities are among the main resources a service relies on to stay within its impact tolerance. What has been replaced is the idea that a continuity programme alone answers the regulatory question. For UK financial services firms it no longer does.

Do we still need ISO 22301?

If it is working for you, keep it. ISO 22301 gives continuity work a disciplined management system and a certificate clients recognise, and nothing in the FCA or PRA rules argues against it. Just be clear what it is not: certification evidences conformity with a voluntary standard, not compliance with SS1/21 or SYSC 15A, and supervisors will not treat one as the other.

Which comes first, business continuity or operational resilience?

For a regulated firm, start from the resilience framework: identify important business services and set impact tolerances first, because those decisions tell you what your continuity plans must actually achieve and where the current recovery targets fall short. Existing continuity work is not wasted; it becomes the delivery layer underneath tolerances chosen for the right reasons.

The framework, step by step

Rocket above the Operational Resilience UK call to action

One programme, both answered

Get continuity and resilience telling one story

A free 45 minute call maps what your continuity programme already gives you against what the resilience rules require, and shows where re-pointing existing work closes the gap faster than new work.