Skip to main content

Basel Consolidated Guidelines

This page sets out the guidelines and sound practices issued by the Basel Committee on Banking Supervision (BCBS). The application page outlines the implementation expectations for guidelines and sound practices, and their scope of application.

The consolidated guidelines and sound practices comprise the 13 modules listed below. Each module is divided into chapters. Each chapter includes links to the original source publications from which the contents of the chapter are based, related standards, related guidelines or sound practices, and other publications that are relevant to a particular topic.

Please provide first name.
Looks good!
ORR20

Operational resilience

This chapter sets out principles for improving banks’ operational resilience.
  • Published: 01 Jan 2026

Guidelines

This chapter sets out principles for improving banks’ operational resilience. It covers the following areas: (i) governance; (ii) operational risk management; (iii) business continuity planning and testing; (iv) mapping of interconnections and interdependencies of critical operations; (v) third-party dependency management; and (vi) incident management; and resilient information and communication technology (ICT), including cyber security.

The contents of this chapter are based on:

Related standards

Related guidelines

  • CGO10 Corporate governance
  • RMA50 Risk management principles for electronic banking

Other related publications

Foreword

20.1

Operational risk-related events, such as pandemics, cyber incidents, technology failures and natural disasters, can cause significant operational failures or wide-scale disruptions in financial markets.

20.2

The Covid-19 pandemic underscored the importance of operational resilience, as banks rapidly adapted their operational posture in response to new hazards or changes in existing hazards that occurred in different parts of their organisation. Pandemic-related disruptions affected information systems, personnel, facilities and relationships with third-party service providers and customers. In parallel, there was a notable spike in cyber threats (ransomware attacks, phishing, etc.), alongside an increased potential for operational risk events caused by people, failed processes and systems as a result of greater reliance on virtual working arrangements.

20.3

While the application of technology to financial services has benefited banks and their customers, it has also introduced new risks. These risks resulted from vulnerabilities related to the rapid adoption of and increased dependency on technology infrastructure for the provision of financial services and intermediation, as well as the sector's growing reliance on technology-based services provided by third parties.

20.4

Operational resilience is an outcome that benefits from the effective management of operational risk. Activities such as risk identification and assessment, risk mitigation (including the implementation of controls) and the monitoring of risks and control effectiveness work together to minimise operational disruptions and their effects. In addition, management's focus on the bank's ability to respond to and recover from disruptions, assuming failures will occur, will support operational resilience. An operationally resilient bank is less prone to incur untimely lapses in its operations and losses from disruptions, thus lessening incident impact on critical operations and related services, functions and systems. While it may not be possible to avoid certain operational risks, such as a pandemic, it is possible to improve the resilience of a bank's operations to such events.

Key terms

20.5

The following terms are used throughout this chapter and have the meaning given below:

  1. Operational resilience: is the ability of a bank to deliver critical operations through disruption. This ability enables a bank to identify and protect itself from threats and potential failures, respond and adapt to, as well as recover and learn from disruptive events to minimise their impact on the delivery of critical operations through disruption. In considering its operational resilience, a bank should assume that disruptions will occur, and consider its overall risk appetite and tolerance for disruption.
  2. Tolerance for disruption: in the context of operational resilience, refers to the level of disruption from any type of operational risk a bank is willing to accept given a range of severe but plausible scenarios.
  3. Critical functions: are activities performed for third parties where failure would lead to the disruption of services that are vital for the functioning of the real economy and for financial stability due to the banking group’s size or market share, external and internal interconnectedness, complexity and cross-border activities. Examples include payments, custody, certain lending and deposit-taking activities in the commercial or retail sector, clearing and settling, limited segments of wholesale markets, market making in certain securities and highly concentrated specialist lending sectors.1
  4. Critical operations: encompasses critical functions and is expanded to include activities, processes, services and their relevant supporting assets the disruption of which would be material to the continued operation of the bank or its role in the financial system. Whether a particular operation is "critical" depends on the nature of the bank and its role in the financial system. Banks' tolerance for disruption should be applied at the critical operations level.
  5. Supporting assets: are people, technology, information and facilities necessary for the delivery of critical operations.
  6. Respective functions: refers to the appropriate function(s) within the bank's three lines of defence.
  7. Incidents: are current or past disruptive events the occurrence of which would have an adverse effect on critical operations of the bank.

Principles for operational resilience

20.6

The Committee seeks to promote a principles-based approach to improving operational resilience. These principles are to be applied on a consolidated basis to banks consistent with the scope of the Basel Framework. When implementing the Principles, banks should take account of the nature, size, complexity and risk profile of their activities.

20.7

Recognising that a range of potential hazards cannot be prevented, the Committee believes that a pragmatic, flexible approach to operational resilience can enhance the ability of banks to withstand, adapt to and recover from potential hazards and thereby mitigate potentially severe adverse impacts.

20.8

In addition, business continuity, third-party dependency management and resilient ICT including cyber security are important factors for banks to consider when strengthening their operational resilience. It is essential for banks to ensure that existing risk management frameworks, business continuity plans and third-party dependency management are implemented consistently within the organisation. Banks should consider whether their operational resilience approach is appropriately harmonised with the stated actions, organisational mappings, and definitions of critical functions and critical shared services contained in their recovery and resolution plans as specified in the Financial Stability Board's (FSB's) Recovery and Resolution Planning framework, as appropriate.2

20.9

The practices described below should not be viewed in isolation, but rather as integral parts of a bank's forward-looking operational resilience approach in line with its operational risk appetite and tolerance for disruption.

Principle 1: Governance

20.10

Banks should utilise their existing governance structure to establish, oversee and implement an effective operational resilience approach that enables them to respond and adapt to, as well as recover and learn from, disruptive events in order to minimise their impact on delivering critical operations through disruption.

20.11

The board of directors should review and approve the bank's operational resilience approach considering the bank's risk appetite and tolerance for disruption to its critical operations. In formulating the bank's tolerance for disruption, the board of directors should consider the bank's operational capabilities given a broad range of severe but plausible scenarios that would affect its critical operations. The board of directors should ensure that the bank's policies effectively address instances where the bank's capabilities are insufficient to meet its stated tolerance for disruption.

20.12

Under the oversight of the board of directors, senior management should implement the bank's operational resilience approach and ensure that financial, technical and other resources are appropriately allocated to support the bank's overall operational resilience approach.

20.13

Senior management should provide timely reports on the ongoing operational resilience of the bank's business units in support of the board's oversight, particularly when significant deficiencies could affect the delivery of the bank's critical operations.

20.14

The board of directors should take an active role in establishing a broad understanding of the bank's operational resilience approach, through clear communication of its objectives to all relevant parties, including bank personnel, third parties and intragroup entities.

Principle 2: Operational risk management
20.15

Banks should leverage their respective functions for the management of operational risk to identify external and internal threats and potential failures in people, processes and systems on an ongoing basis, promptly assess the vulnerabilities of critical operations and manage the resulting risks in accordance with their operational resilience approach.

20.16

The bank’s operational risk management function should work alongside other relevant functions to manage and address any risks that threaten the delivery of critical operations. Banks should coordinate their business continuity planning, third-party dependency management, recovery and resolution planning and other relevant risk management frameworks to strengthen operational resilience across the bank.

20.17

Banks should have sufficient controls and procedures, consistent with and conducted alongside the risk identification process, to identify and assess threats and vulnerabilities, and more generally their operational risk, in a timely manner and, to the extent possible, prevent them from affecting critical operations delivery. The respective functions should regularly assess the effectiveness of the implemented controls and procedures. These assessments should also be conducted in the event of changes to any underlying components of the critical operations, as well as after incidents to consider lessons learned and new threats and vulnerabilities that caused the incident.

20.18

Banks should leverage change management capabilities in accordance with the change management processes under the overall management of operational risk as a way to assess potential effects on the delivery of critical operations and on their interconnections and interdependencies.

Principle 3: Business continuity planning and testing
20.19

Banks should have business continuity plans in place and conduct business continuity exercises under a range of severe but plausible scenarios in order to test their ability to deliver critical operations through disruption.

20.20

An effective business continuity plan should be forward-looking when assessing the impact of potential disruptions. Business continuity exercises should be conducted and validated for a range of severe but plausible scenarios that incorporate disruptive events and incidents.

20.21

An effective business continuity plan should identify critical operations, and key internal and external dependencies to assess the risks and potential impact of various disruption scenarios on critical operations. These plans should incorporate business impact analyses and recovery strategies as well as testing programmes, training and awareness programmes, and communication and crisis management programmes.

20.22

Business continuity plans should develop, implement and maintain a regular business continuity exercise encompassing critical operations and their interconnections and interdependencies, including those through relationships with, but not limited to, third parties and intragroup entities. Among other business continuity goals, business continuity exercises should support staff's operational resilience awareness including training of staff, so that they can effectively adapt and respond to incidents.

20.23

Business continuity plans should provide detailed guidance for implementing the bank's disaster recovery framework. These plans should establish the roles and responsibilities for managing operational disruptions and provide clear guidance regarding the succession of authority in the event of a disruption that impacts key personnel. Additionally, these plans should clearly set out the internal decision-making process and define the triggers for invoking the bank's business continuity plan.

20.24

Banks’ business continuity plans for the delivery of critical operations and critical third-party services contained in their recovery and resolution plans should be consistent with their operational resilience approaches.

Principle 4: Mapping Interconnections and Interdependencies
20.25

Once a bank has identified its critical operations, the bank should map the internal and external interconnections and interdependencies that are necessary for the delivery of critical operations consistent with its approach to operational resilience.

20.26

The respective functions should map (ie identify and document) the people, technology, processes, information, facilities, and the interconnections and interdependencies among them as needed to deliver the bank's critical operations, including those dependent upon, but not limited to, third parties or intragroup arrangements.

20.27

Banks may leverage their recovery and resolution plans, as appropriate, for definitions of critical operations and should consider whether their operational resilience approaches are appropriately harmonised with the organisational mappings of critical operations and critical third-party services contained in their recovery and resolution plans.

20.28

The approach and level of granularity of mapping should be sufficient for banks to identify vulnerabilities and to support testing of their ability to deliver critical operations through disruption, as described in Principle 3, considering the bank's risk appetite and tolerance for disruption.

Principle 5: Third-party dependency management
20.29

Banks should manage their dependencies on relationships, including those of, but not limited to, third parties or intragroup entities, for the delivery of critical operations.

20.30

Banks should perform a risk assessment and due diligence before entering into arrangements including those of, but not limited to, third parties or intragroup entities, consistent with the bank's operational risk management framework, outsourcing/third-party risk management policy and operational resilience approach. Prior to the bank entering into such an arrangement, the bank should verify whether the third party, including, if relevant, the intragroup entity to these arrangements, has at least equivalent level of operational resilience to safeguard the bank's critical operations in both normal circumstances and in the event of disruption.

20.31

Banks should develop appropriate business continuity and contingency planning procedures and exit strategies to maintain their operational resilience in the event of a failure or disruption at a third party impacting the provision of critical operations. Scenarios under the bank's business continuity plans should assess the substitutability of third parties that provide services to the bank's critical operations, and other viable alternatives that may facilitate operational resilience in the event of an outage at a third party, such as bringing the service back in-house.

Principle 6: Incident management
20.32

Banks should develop and implement response and recovery plans to manage incidents that could disrupt the delivery of critical operations in line with the bank's risk appetite and tolerance for disruption. Banks should continuously improve their incident response and recovery plans by incorporating the lessons learned from previous incidents.

20.33

Banks should maintain an inventory of incident response and recovery, internal and third-party resources to support the bank's response and recovery capabilities.

20.34

Incident management is the process of identifying, analysing, rectifying and learning from an incident and preventing recurrences or mitigating the severity thereof. The goal of incident management is to limit the disruption and restore critical operations in line with the bank’s risk appetite and tolerance for disruption.3

3

For examples of detailed response and recovery practices, see FSB, Effective Practices for Cyber Incident Response and Recovery, October 2020.

20.35

The scope of incident management should capture the life cycle of an incident,4 typically including, but not limited to:

  1. the classification of an incident's severity based on predefined criteria (eg expected time to return to business as usual), enabling proper prioritisation of and assignment of resources to respond to an incident;
  2. the incident response and recovery procedures, including their connection to the bank's business continuity, disaster recovery and other associated management plans and procedures; and
  3. the implementation of communication plans to report incidents to both internal and external stakeholders (eg regulatory authorities), including performance metrics during, and analysis of lessons learned after, an incident.
4

Recognising that the life cycle on an incident could span multiple measures of time that could range from hours to weeks to months.

20.36

Incident response and recovery procedures should be periodically reviewed, tested and updated. Banks should identify and address the root causes of incidents to prevent or minimise serial recurrence.

20.37

Lessons learned from previous incidents, including incidents experienced by others, should be duly reflected when updating the incident management programme. A bank's incident management programme should manage all incidents impacting the bank, including those attributable to dependencies on, but not limited to, third parties and intragroup entities.

Principle 7: Resilient ICT including cyber security5

5

Cyber security as defined in FSB, Cyber Lexicon, April 2023.

20.38

Banks should ensure resilient ICT, including cyber security, that is subject to protection, detection, response and recovery programmes that are regularly tested, incorporate appropriate situational awareness and convey relevant, timely information for risk management and decision-making processes to fully support and facilitate the delivery of the bank's critical operations.

20.39

Banks should have a documented ICT policy, including cyber security, which stipulates governance and oversight requirements, risk ownership and accountability, ICT security measures (eg access controls, critical information asset protection, identity management), periodic evaluation and monitoring of cyber security controls, and incident response, as well as business continuity and disaster recovery plans.

20.40

Banks should identify their critical information assets and the infrastructure upon which they depend. Banks should also prioritise their cyber security efforts based on their ICT risk assessment and on the significance of the critical information assets to the bank's critical operations, while observing all pertinent legal and regulatory requirements relating to data protection and confidentiality. Banks should develop plans and implement controls to maintain the integrity of critical information in the event of a cyber event, such as secure storage and offline backup on immutable media of data supporting critical operations. Banks should regularly evaluate the threat profile of their critical information assets, test for vulnerabilities and ensure their resilience to ICT-related risks.

Application of the guidelines and sound practices

  1. The Basel Framework is the full set of standards of the BCBS. The membership of the BCBS has agreed to fully implement these standards and apply them to the internationally active banks in their jurisdiction.1 For other banks, BCBS members may adopt a proportional approach to implementing specific rules and principles under the given standard.
  2. Guidelines elaborate the standards in areas where they are considered desirable for the prudential regulation and supervision of banks, in particular internationally active banks. They generally supplement BCBS standards by providing additional guidance for the purpose of their implementation.
  3. Sound practices generally describe actual observed practices, with the goal of promoting common understanding and improving supervisory or banking practices. BCBS members are encouraged to compare these practices with those applied by themselves and their supervised institutions to identify potential areas for improvement.
  4. The BCBS also publishes various other documents, including implementation reports and newsletters. These documents do not constitute standards, guidelines or sound practices.
  5. The Committee's standards (ie those set out in the Basel Framework) are subject to monitoring and assessment of their adoption by jurisdictions through the Regulatory Consistency Assessment Programme (RCAP). The Basel Core Principles are used in assessing the effectiveness of countries' regulatory and supervisory regimes, generally under the Financial Sector Assessment Program (FSAP). Guidelines, sound practices and other publications are not subject to RCAPs or FSAPs.
  6. The Committee periodically reviews its guidelines and sound practices as standards, supervisory practices and the financial system evolve. The consolidated guidelines and sound practices are intended to be a living document, which will be updated when the Committee publishes new materials.
  7. Unless otherwise indicated, the guidelines have been developed with a view towards application to: (i) large, internationally active banks; and (ii) supervisory and other relevant financial authorities in Basel Committee member jurisdictions. However, smaller banks and authorities in all jurisdictions may benefit from considering the guidelines and applying them on a proportionate basis, depending on the size, complexity and risk profile of the bank or banking sector for which the authority is responsible.

1 The Core Principles for effective banking supervision (Basel Core Principles) are also a standard and form part of the Basel Framework but are applicable to all jurisdictions and all banks.

This module describes expectations to combat money laundering and terrorist financing.

This module describes expectations and practices relating to capital adequacy.

This module describes expectations for corporate governance.

This module describes expectations for credit risk and counterparty credit risk management.

This module describes expectations for external audit and sets out references related to public disclosure.

This module describes expectations for banks’ internal audit and compliance functions.

This module describes expectations for liquidity risk management.

This module sets out references related to market risk and interest rate risk.

This module describes expectations for the management of operational risk and operational resilience.

This module describes expectations for the management of problem assets and expected credit losses.

This module describes the application of proportionality in prudential regulation and supervision.

This module describes expectations for risk management.

This module describes the nature and application of prudential supervision.

You might also be interested in