The term, defined properly

What operational resilience actually means

Operational resilience is an organisation's ability to prevent, adapt and respond to, recover from and learn from operational disruption. UK regulators frame it around one outcome: your important business services keep running within impact tolerances you have set, tested and evidenced, whatever the cause of the disruption.

Start with the definition

The definition, unpacked

Operational resilience is the ability of a firm to prevent, adapt and respond to, recover from and learn from operational disruption, so that its important business services continue to be delivered within impact tolerances.

Every clause is doing work. "Prevent, adapt, respond, recover, learn" makes it a whole lifecycle rather than a recovery discipline. "Important business services" fixes the unit of analysis on what the firm delivers to the outside world, not on its internal systems. And "within impact tolerances" turns resilience from an aspiration into something measurable: a stated maximum level of disruption that must not be breached.

The other word that matters is one the definition leaves out: cause. Resilience is cause-agnostic. Whether the disruption comes from a cyber attack, a supplier failure, a botched change or a flooded office, the question supervisors ask is the same. Did the service stay within tolerance, and how do you know?

The operational resilience framework

The framework behind PS21/3 and SS1/21

The UK rules are not a control catalogue. They are a single six-step loop, and every firm in scope runs the same one. Search for an operational resilience framework and this is the thing itself: each step produces an artefact, and the last step feeds the first.

1

Identify your important business services

Not systems, not departments: the services your firm delivers to the outside world whose disruption would harm clients or the market. Payments processing is an important business service; the payments platform behind it is a resource. Everything else in the framework hangs off this list.

2

Set an impact tolerance for each one

A stated maximum level of disruption for each service, typically a duration, beyond which the harm becomes intolerable. Tolerances are decisions the board owns, not measurements, and they are the framework's sharpest break with older practice.

3

Map the resources each service depends on

The people, processes, technology, facilities, information and third parties a service needs, end to end. The map is what lets you say which failure would break which service, including a dependency on a cloud provider three contracts deep.

4

Test against severe but plausible scenarios

Scenario testing asks whether each service would stay within its impact tolerance through disruptions that are severe but plausible: a ransomware event, the loss of a key supplier, a prolonged outage at a major provider. Not whether a plan exists, but whether the outcome holds.

5

Write and maintain the self-assessment

A single document recording the services, the tolerances, the mapping, the testing and what you concluded, refreshed regularly and ready for supervisors on request. It is the artefact through which the whole programme is judged.

6

Find vulnerabilities and fix them

Testing exists to surface the places a service would breach its tolerance. Each vulnerability gets an owner and a remediation route, and the cycle then repeats: services change, dependencies change, and last year's conclusions decay.

Steps one and two are where most programmes are won or lost; our impact tolerances guide covers both in depth, with worked examples of tolerance statements that survive supervision.

Neighbouring disciplines

Not risk management, not business continuity

Operational risk management works on likelihood: identify what might go wrong, score it, reduce the probability. Operational resilience starts where that ends, by assuming the disruption happens and asking whether the service survives it. The two share data but answer different questions, which is why a clean risk register is no defence when a service breaches its tolerance.

Business continuity is the nearer neighbour and the more common confusion. Continuity produces recovery plans for sites, systems and suppliers; resilience is a supervised outcome measured at the level of the business service. Continuity is a component of resilience, not a synonym for it, and the distinction has real consequences for how firms are assessed. We take that comparison apart properly in operational resilience vs business continuity.

The sector where it started

What operational resilience means in banking

In UK banking the term is not a concept but a rulebook. Banks, building societies and insurers answer to the PRA's supervisory statement SS1/21 as well as the FCA's rules, so a bank runs the six-step framework under two supervisors at once: identifying important business services such as payments, lending drawdown and access to accounts, setting impact tolerances for each, and evidencing through testing that those tolerances hold.

The transition period ended on 31 March 2025, so supervision has moved from "show us your plan" to "show us it works". The FCA published its observations one year on in March 2026, and the PRA's 2026 priorities press for deeper scenario testing, including scenarios involving critical third parties. Our SS1/21 guide covers the PRA layer, and the FCA operational resilience hub covers the conduct side that applies well beyond banks.

The second regime

Where DORA fits for dual-scoped firms

The EU regulates the same territory through DORA, the Digital Operational Resilience Act, in force since 17 January 2025. DORA is narrower in one sense, it concentrates on ICT risk, and broader in another, prescribing detailed requirements for incident reporting, resilience testing and ICT third-party contracts. A UK firm with EU entities, EU clients or an EU-touching ICT supply chain can be inside both regimes at once.

For those firms the sensible move is one programme serving two rulebooks: a single service inventory, one dependency map, one testing calendar, with each regime's specific artefacts generated from it. Whether DORA catches your firm at all is a question with a structured answer, and our DORA for UK firms guide works through it.

Quick answers

Operational resilience questions, answered

What is operational resilience, in one sentence?

Operational resilience is an organisation's ability to prevent, adapt and respond to, recover from and learn from operational disruption, demonstrated by keeping its important business services within set impact tolerances whatever the cause of the disruption.

Is operational resilience the same as business continuity?

No. Business continuity produces recovery plans for sites, systems and suppliers, usually measured in recovery time objectives. Operational resilience is a regulatory outcome: important business services staying within impact tolerances through severe but plausible disruption. A firm can hold a certified business continuity capability and still fall short of what supervisors expect.

The full comparison

Who regulates operational resilience in the UK?

The FCA and the PRA, jointly with the Bank of England. The FCA's rules were set in policy statement PS21/3 and sit in SYSC 15A; the PRA's expectations are in supervisory statement SS1/21. The rules have been fully in force since the transition period ended on 31 March 2025.

Rocket above the Operational Resilience UK call to action

From definition to evidence

See how your programme reads against the framework

A free 45 minute call walks the six steps against what your firm has today: services, tolerances, mapping, testing and the self-assessment, and tells you which gap is worth closing first.