Promotes the ability of institutions to maintain their critical operations through disruptions, and to recover from them, based on international standards.
Objective and functions
Analyze and disseminate business continuity and operational resilience standards and best practices, so that financial institutions can keep providing their critical services through serious disruptions and recover from them.
- 01Analyze international continuity and resilience standards and frameworks.
- 02Follow regulatory initiatives on continuity and resilience and their effect on the sector.
- 03Share best practices in impact analysis, testing and exercises.
- 04Hold discussions with figures from the public and private sectors.
What business continuity and operational resilience are
Business continuity
An organization’s ability to continue delivering products and services within acceptable time frames and at a predefined level during a disruption. The ISO 22301 standard sets out the requirements of a management system to achieve this.
SourceISO 22301:2019, Business continuity management systems (opens in a new tab)
Operational resilience
A bank’s ability to deliver its critical operations even during a disruption: to withstand, adapt to and recover from events such as pandemics, cyber incidents, technology failures or natural disasters. Basel (2021) sets it out in seven principles.
SourceBasel Committee (BCBS), Principles for Operational Resilience, 2021 (opens in a new tab)
How it is measured and quantified
It starts from the business impact analysis, which sets how long an interruption can be tolerated.
Business impact analysis (BIA)
Identifies critical activities and their dependencies, and estimates the impact of their interruption over time.
Maximum tolerable period of disruption (MTPD)
The limit beyond which the organization’s viability is at risk.
Recovery time objective (RTO)
Time after an incident to resume a product, service or activity before the impact becomes unacceptable. It is set within the MTPD, with a margin.
Recovery point objective (RPO)
The point to which data must be restored for the activity to work again: the maximum tolerable loss of information.
Impact tolerance
The maximum level of disruption that a critical operation can withstand. It is tested with severe but plausible scenarios.
Results of tests and exercises
Percentage of critical processes with a tested plan, success of the tests against the RTOs and RPOs, and closed findings.
How it is managed
Coordination
Those who lead the committee. The coordination and co-coordination roles rotate once a year.
Coordination
To be appointed
This position is assigned by annual rotation.
Co-coordination
To be appointed
This position is assigned by annual rotation.
Regulations and recommended readings
Standards and documents that the committee uses as the basis of its work.
- ISO 22301:2019, Business continuity management systems (opens in a new tab)
- Basel Committee (BCBS), Principles for Operational Resilience, 2021 (opens in a new tab)
- Basel Committee (BCBS), Principles for the Sound Management of Operational Risk, 2011 (opens in a new tab)
- ISO 22313, Business continuity guidance
Sign up for this committee
Members who wish to take part notify the Club’s Executive Committee, and this form is the channel. Regular members and representatives of sponsor members may take part. Not a member yet? Find out how to become one.
Connect with our networks